Compliance

Learn WhatsApp compliance best practices for opt-in, opt-out, consent records and restricted keywords to manage compliant business messaging.

7 min readUpdated Sep 7, 2026

WhatsApp Opt-In

WhatsApp Opt-In occurs when a customer provides their mobile phone number and explicitly consents to receive messages from your business through WhatsApp.

Before sending any messages to a user on WhatsApp, businesses must first obtain valid opt-in consent from the customer.

Opt-In Requirements

When collecting WhatsApp opt-ins, businesses must ensure the following:

Explicit Consent:

  • The user must clearly agree, in writing or through a recorded action, to receive messages from your business via WhatsApp.

Business Identification:

  • The opt-in request must clearly state the name of the business that will be sending the messages.

Legal Compliance:

  • The opt-in process must comply with all applicable laws and regulations related to customer communication and data protection.

Policy Update on Third-Party Opt-Ins

Previously, opt-ins were often collected through third-party channels, such as:

  • Website forms

  • SMS confirmations

  • Other external communication channels

However, WhatsApp updated its policy in July 2020, removing the requirement for opt-ins to be collected through third-party channels. This means that customers can now request notifications directly through a WhatsApp conversation with your business.

For example, a customer may initiate a WhatsApp chat with your support team and request updates or notifications.

Important Compliance Reminder

Even though third-party opt-ins are no longer mandatory, businesses must still:

  • Store and maintain records of customer opt-ins

  • Ensure that every user contacted via WhatsApp has provided consent

Maintaining proper opt-in records helps ensure compliance with WhatsApp messaging policies and applicable regulations.


➤ Activating Opt-In and Opt-Out

tip

To comply with messaging regulations and ensure customers receive relevant communications, businesses must provide clear Opt-In and Opt-Out mechanisms for WhatsApp messaging.

Activating Opt-In

Customers must provide consent before receiving messages from your business on WhatsApp. Below are several methods businesses can use to collect opt-in permissions.

When customers contact your business for assistance, your support representative can request permission to send future notifications.

For example, after resolving a customer’s issue, the representative may ask whether the customer would like to opt in to receive updates or notifications via WhatsApp.

Option 2: Use Your Website

Your website is an effective channel for collecting opt-in permissions from both new and existing customers.

You can invite users to subscribe to WhatsApp messages through:

  • Website forms

  • Subscription pages

  • Contact forms

This method works across all industries and provides a simple way for users to opt in.

Option 3: Use Third-Party Communication Channels

Businesses can also collect opt-in consent through channels they already use to communicate with customers.

Examples include:

  • SMS

  • Voice calls

  • ATM notifications

These channels often attract immediate attention and can encourage quick responses from customers.

Option 4: Integrate Opt-In into Existing Processes

Opt-in requests can be incorporated into existing customer workflows, such as during the purchase process.

Since customers often receive important notifications like order confirmations, boarding passes, and delivery updates via WhatsApp, they may be more likely to opt in during transactions.

This approach is particularly effective for industries such as:

  • Retail

  • Airlines

  • Logistics

Businesses can include a checkbox option at points where customers enter their phone number, such as during billing or delivery information submission.

Option 5: Include WhatsApp in Contact Preferences

Many businesses allow customers to choose their preferred communication channels during account creation or when filling out contact forms.

In these cases, WhatsApp can be included as one of the available contact options.

Because WhatsApp is widely used, offering it as a contact preference may increase sign-up conversions and customer engagement.

Activating Opt-Out

Customers must also have the ability to stop receiving marketing messages from a business.

Some businesses provide an Opt Out of Marketing Messages button within the chat interface.

When a user taps this button:

  • The business receives a request to remove the user’s WhatsApp number from marketing communications.

  • The customer is removed from the business’s marketing mailing list.

In some cases, the removal process may take time if it requires manual updates.

Providing Feedback During Opt-Out

Businesses may ask customers to provide a reason for opting out. Providing feedback is optional, but it can help companies improve the relevance of their messaging. After opting out, some businesses may send a confirmation message that also provides an option to opt back in if the customer changes their mind or opted out accidentally.

Opting Out vs Blocking a Business

It is important to understand the difference between opting out of marketing messages and blocking a business.

Opting Out of Marketing Messages

  • Removes the user from the business’s marketing mailing list.

  • Allows the user to continue communicating with the business for service-related messages.

Blocking a Business

  • Prevents the business from sending any messages to the user.

  • Also prevents the user from sending messages to the business.

Using the opt-out option allows customers to stop promotional communications while still receiving important transactional messages, such as order updates or shipping notifications.


➤ Restricted Keywords

tip

The Restricted Keywords feature allows administrators to define specific words or phrases that should be restricted within conversations. This helps organizations maintain compliance with messaging policies, prevent the use of inappropriate language, and ensure that communication aligns with regulatory or brand guidelines.

When a restricted keyword is detected in a message, the system can block, flag, or prevent the message from being sent depending on the configured policies.

This feature is particularly useful for organizations that need to comply with platform messaging policies, regulatory standards, or internal communication rules.

Accessing Restricted Keywords

To manage restricted keywords:

Navigate to Settings from the dashboard.

  • Select Compliance from the left-side menu.

  • Open the Restricted Words tab.

This section displays all the restricted keyword rules configured for your account.

Restricted Keywords Dashboard

The Restricted Words dashboard displays a list of all configured keyword restrictions. Each entry includes the following details:

  • Title:Name of the restricted keyword rule.

  • Restricted Words:The keyword or phrase that is restricted

  • Status:Indicates whether the rule is active or disabled.

  • Action:Options to edit or delete the rule

Administrators can enable or disable a rule using the status toggle.

Creating a Restricted Keyword Rule

Follow these steps to add a new restricted keyword.

Step 1: Add a New Keyword

  1. Navigate to Settings → Compliance → Restricted Words.

  2. Click Add Keyword.

A configuration window will appear.

Step 2: Configure Rule Details

Provide the required information.

  • Title: Enter a descriptive name for the rule.

  • Scope: Define where the restriction will apply.

  • Global: The restricted keyword applies to all accounts or bots in the workspace.

  • Account Specific: The keyword restriction applies only to a specific account or configuration.

Step 3: Add Restricted Keywords

Enter the keyword or phrase that should be restricted. You can add additional keywords by selecting:

Add Extra Restrict Keyword: This allows multiple restricted phrases to be grouped under one rule.

Step 4: Save the Rule

Click Create to save the rule. Once created, the rule will appear in the Restricted Words list and can be enabled or disabled using the status toggle.

Managing Restricted Keywords

Administrators can manage existing rules using the Actions column. Available actions include:

  • Edit: Modify the rule name, scope, or keywords.

  • Delete:Remove the rule permanently from the system.

  • Enable / Disable: Use the toggle switch to activate or deactivate a rule without deleting it.

Regulatory Compliance

Industries such as finance, healthcare, and insurance may restrict certain terms that could violate compliance regulations.