Data Privacy and Compliance on WhatsApp, Without the Legalese
Guide

Keeping Consent Records That Survive an Audit

4 أغسطس 2026 · 4 دقائق قراءة
Hands going through a row of filing folders, standing for the consent evidence a business has to retrieve on request.
Photo: Unsplash

Ask a team whether they have consent for their WhatsApp list and the answer is almost always yes. Ask them to prove it for one contact — the person who complained this morning — and it takes days, or never arrives. Consent you cannot evidence works out much like no consent at all: an auditor, a regulator, or an annoyed customer only ever sees what you can show. Our in-depth guide to data privacy and compliance on WhatsApp covers the wider picture; this article is about the paperwork that holds the rest of it up.

Why the claim is worthless on its own

In a dispute, the burden sits with you. Nobody has to prove they never opted in — you have to show that they did. That is a practical problem more than a legal one, because ordinary business activity quietly destroys the evidence. The signup form gets redesigned, the checkbox wording changes, a spreadsheet is re-imported, the colleague who took the number in store leaves. Six months later the field says "consent: yes" and nothing else. That is a claim, not proof.

What a defensible record contains

Five fields do most of the work. Store them per contact and per permission:

  1. Who — the contact, identified the way you identify them everywhere else, normally the phone number in full international format.
  2. When — a timestamp written by the system, not a date typed in later from memory.
  3. What they saw — the exact wording shown at the moment they agreed, or a version reference that resolves to it.
  4. Where — the channel and the source: checkout checkbox, QR code in store, click-to-chat link, a reply inside the conversation.
  5. What they agreed to — the scope. Marketing on WhatsApp is not the same permission as service updates, and one never implies the other.

The wording field is the one teams skip and later regret. Consent text changes constantly, and "they ticked a box in March" means nothing if you cannot say which box. Keeping a versioned copy of each consent text, with the dates it was live, turns a vague claim into something checkable in seconds. It also answers the lawful-basis question from GDPR and WhatsApp Business: the record shows which basis you relied on for that contact, and why.

Capture it automatically, never reconstruct it

Anything a human has to remember to log will eventually not be logged. The record should be written by the same system that captures the opt-in: the form submits, the contact is created, and the consent event is stored with its timestamp and wording version in the same step. When someone opts in by replying inside a chat, the reply itself is the evidence — keep the message rather than summarising it into a checkbox.

Reconstructing later is worse than useless. A record assembled three months after the fact from an export and a best guess is exactly what an auditor is trained to distrust.

A consent record written by a person is a memory. One written by the system at the moment of opt-in is evidence.

be digital ai team

Log withdrawal just as carefully

Withdrawal is where records most often fall apart. Someone replies STOP, an agent quietly removes them from a campaign audience, and nothing is written down. Later you cannot show when they left, and you have no defence if a template reaches them by mistake. Capture the same fields — who, when, through which channel, and what exactly was withdrawn. Someone who opts out of promotions may still want delivery updates, and losing that distinction means suppressing too much or too little.

Where the record lives, and who else holds it

Consent evidence tends to spread across a form provider, a CRM, and whatever tool sends the messages. That works, but only if you know which system is the source of truth and can retrieve from it without asking a developer. It also means outside companies hold proof you depend on, so the exit terms matter: what you can export, in what format, and what happens to it when you leave. That ground is covered in data processing agreements and subprocessors.

When a customer changes number

Numbers get recycled, and in the Gulf in particular customers change them more often than a European CRM expects. Consent belongs to a person, but WhatsApp addresses a number. When someone gives you a new one, do not silently copy the old permission across: link the records, note the change and how you confirmed it, and ask again if the permission is marketing rather than service. On a reassigned number, an inherited opt-in becomes an unsolicited message to a stranger.

The one-minute test

Pick a contact at random and answer out loud: when did this person consent, to what, in which wording, through which channel, and have they withdrawn anything since? If it takes more than a minute, what you have is not yet a record. Run the test once a quarter and after every change to a signup form. What exactly you must keep depends on your markets and sector, so confirm the details with your own legal counsel — but no lawyer can retrieve evidence you never captured in the first place.

See it live

See how be digital ai logs consent and withdrawal automatically, contact by contact.

Book a Demo

المزيد من هذه السلسلة