All articles
Compliance

WhatsApp Opt-In Evidence: What Meta Asks in a Review 2026

When Meta or your BSP reviews a template appeal or account, "we had their number" is not opt-in evidence — they want per-contact proof: timestamp, source, exact wording and scope. This 2026 guide covers what triggers a review, the record fields that make consent defensible, retention, what WhatsApp already stores vs what only you can log, and a 24-hour evidence-pack checklist. RichAutomate logs consent at capture: WABA you own, ₹0 platform/setup/monthly, Client Pay ₹0.10/msg or SaaS Pay ₹1.20 marketing / ₹0.30 utility.

RichAutomate Editorial
10 min read 0 views
WhatsApp Opt-In Evidence: What Meta Asks in a Review 2026

When Meta or your BSP questions how you got a contact's consent — during a template appeal, a quality review, or an account review — you get days, sometimes hours, to produce proof. The proof they want is specific: for a given phone number, when consent was captured, on what channel, and the exact wording the person agreed to. If your "opt-in" is a spreadsheet of numbers with no timestamp, no source and no record of what was actually shown, you have contacts, not evidence — and that is what gets a template rejected or a number restricted. This applies to any business on the WhatsApp Business API, whatever your industry.

This 2026 guide is the operational side of opt-in — not the legal theory, but the record you must be able to pull on demand. It covers what triggers a review, exactly which fields make an opt-in defensible, how long to keep them, how to export what WhatsApp Manager and your BSP already store, and a checklist to assemble the evidence pack in 24 hours. Meta's review process and the DPDP rulebook both evolve — treat the specifics below as directional and confirm the current requirements in WhatsApp Manager and with your compliance advisor before you rely on them.

What triggers an opt-in review

You rarely get to choose the moment. Any of these can put your consent record under scrutiny:

  • Template rejection or appeal — a marketing template gets rejected and the appeal asks how recipients opted in.
  • Quality-rating drop — blocks and "not useful" reports pull the number's rating down; Meta looks at whether recipients expected the message.
  • Account or WABA review — a broader integrity check where opt-in evidence is one of the things assessed.
  • User complaint — a recipient reports the business, and the burden shifts to you to show consent.

The common thread: the trigger is unplanned, and the clock is short. The businesses that survive it are the ones who were already logging consent properly — you cannot reconstruct a timestamp after the fact. If your rating is already slipping, the red-rating recovery playbook covers the sending side; this page covers the paper trail.

What counts as opt-in evidence

A list of phone numbers is not evidence. Evidence is a per-contact record you can produce that shows a real person agreed to hear from you on WhatsApp. At minimum, for each contact you should be able to show:

FieldWhy it mattersExample
Contact identifierTies the consent to the exact number that received the message+91 98XXXXXX01
TimestampProves consent came before the message, and how recent it is2026-07-14 11:32 IST
Source / channelWhere consent happened — a review can ask you to reproduce itWebsite checkout checkbox / WhatsApp click-to-chat / paper form at store
Exact wording shownThe consent must match what you actually send (marketing vs utility scope)"Yes, send me offers & order updates on WhatsApp"
Consent scopeDistinguishes transactional/utility from marketing permissionMarketing + utility, or utility-only
Action takenHow the person expressed it — an affirmative act, not a pre-ticked boxTicked an unchecked box / replied "JOIN" / signed

The two fields businesses most often miss are exact wording and source. "We had their number" is not consent. "On 14 July at checkout they ticked an unticked box that said 'send me offers and order updates on WhatsApp'" is. If you cannot say what the person actually saw and agreed to, you cannot defend the send. For how the underlying consent should be structured legally, see the DPDP Act opt-in compliance guide; treat the DPDP specifics there as directional and confirm the operative rules with your advisor.

Stop overpaying on WhatsApp

Get the DPDP WhatsApp checklist

A founder-led WhatsApp reply with the DPDP consent + audit-log checklist for WhatsApp Business messaging. India-hosted. No spam.

DPDP-compliant · India-hosted · 1-min reply

Pre-ticked boxes and bought lists are not consent

Two patterns fail every review: a pre-checked opt-in box (consent must be an affirmative act by the user), and a purchased or scraped list (no per-contact record exists, because the person never agreed with you). Both also feed the block-and-report cycle that drops your quality rating. If your list has a hygiene problem, re-permission it rather than send into it — the list-hygiene and re-permissioning guide walks the cleanup.

How long to keep it

Keep opt-in records for at least as long as you message the contact, plus a buffer after they leave or opt out — you may need to prove the consent was valid for the period you actually sent. There is no single universal retention number that fits every obligation, and Indian data-protection expectations are still settling, so set the retention with your compliance advisor rather than guessing. The practical rule: never delete the consent record before you stop messaging the contact, and keep a record of opt-outs too, so you can prove you honoured a withdrawal.

What WhatsApp and your BSP already store

Some evidence you must capture yourself; some is already sitting in the platform. Know the split:

RecordWho holds itHow to get it
The consent itself (wording, source, timestamp)You — it is your record, not Meta'sLog it at capture time in your CRM/opt-in table; nobody captures it for you
Message send + delivery historyWhatsApp Manager / your BSPExport from WhatsApp Manager or the BSP dashboard/API
Template content & approval statusWhatsApp ManagerMessage Templates section shows category, status and body
Block / report signalsMeta (aggregate)Quality rating and messaging insights in WhatsApp Manager

The critical gap: the opt-in wording and source are the one thing no platform captures for you. If you are not logging them at the moment of capture — checkout, form submit, click-to-chat, in-store — they do not exist, and no amount of exporting later will create them. That is why opt-in evidence is an architecture decision, not a report you run when a review lands.

Assemble the evidence pack in 24 hours — checklist

  • Pull the flagged numbers from the template appeal / review notice.
  • Match each to its opt-in record — timestamp, source, exact wording, scope, action taken.
  • Export the send + delivery history for those numbers from WhatsApp Manager / your BSP.
  • Screenshot the consent surface as it appears today — the checkout box, the form, the click-to-chat entry — so the reviewer can see what the user saw.
  • Confirm message-to-consent match — a marketing send needs marketing-scope consent, not utility-only.
  • Note any opt-outs honoured for the flagged cohort, with dates.
  • Package it per-contact, not as a bulk list — a review wants to trace one number end to end.

If you cannot complete this checklist for a given cohort today, that cohort is your risk. Fix the capture now so the next review is a five-minute export, not a fire drill.

How RichAutomate keeps the evidence ready

Opt-in evidence should be a byproduct of how you capture contacts, not a scramble when Meta asks. RichAutomate logs consent at the point of capture — timestamp, source and scope tied to the number — so the record exists before you ever need it, and the send history sits alongside it in one place. Templates are tracked with their category and status, so a marketing-vs-utility scope mismatch is visible before you send, not after a rejection. Pricing is flat and usage-only — ₹0 platform fee, ₹0 setup, ₹0 monthly, Client Pay at ₹0.10 per message or SaaS Pay all-in at ₹1.20 marketing / ₹0.30 utility — so proper consent logging is not a premium tier, it is how the platform works. See the full feature set.

Bottom line

A phone list is not opt-in evidence; a per-contact record of timestamp, source, exact wording and scope is. The review that asks for it arrives unannounced and on a short clock, and you cannot backfill a timestamp — so capture the consent properly at the moment it happens, keep it as long as you message the contact, and know which pieces WhatsApp already stores versus the wording and source only you can log. Do that and a template appeal or account review is a quick export. Skip it and you are defending sends you cannot prove anyone agreed to.

Ready to ship this?

Get the DPDP WhatsApp checklist

A founder-led WhatsApp reply with the DPDP consent + audit-log checklist for WhatsApp Business messaging. India-hosted. No spam.

DPDP-compliant · India-hosted · 1-min reply
Tagged
WhatsApp Business APIOpt-In EvidenceMeta Account ReviewTemplate AppealConsent RecordsDPDPComplianceIndia 2026
Written by
RichAutomate Editorial
Editorial team at RichAutomate. We build the WhatsApp Business automation platform Indian D2C brands, fintechs, and agencies use to ship campaigns and flows on the official Meta Cloud API.
FAQ

Frequently asked questions

What counts as valid WhatsApp opt-in evidence?
A list of phone numbers is not evidence. Valid opt-in evidence is a per-contact record you can produce showing, for a given number: when consent was captured (timestamp), where it happened (source/channel — website checkout, click-to-chat, in-store form), the exact wording the person agreed to, the consent scope (marketing vs utility), and the affirmative action they took (ticked an unticked box, replied JOIN, signed). The two fields businesses most often miss are the exact wording shown and the source — "we had their number" is not consent.
When does Meta or my BSP ask for opt-in proof?
Usually at an unplanned moment: a marketing template gets rejected and the appeal asks how recipients opted in; your quality rating drops from blocks and "not useful" reports; a WABA or account review opens; or a recipient complains and the burden shifts to you to show consent. The clock is always short, and you cannot reconstruct a timestamp after the fact — the businesses that pass these reviews are the ones already logging consent properly before the review lands.
How long should I keep WhatsApp opt-in records?
Keep the consent record for at least as long as you message the contact, plus a buffer after they leave or opt out, since you may need to prove consent was valid for the whole period you actually sent. There is no single universal retention number that fits every obligation and Indian data-protection expectations are still settling, so set the exact retention with your compliance advisor. The practical rule: never delete a consent record before you stop messaging the contact, and keep opt-out records too so you can prove you honoured a withdrawal.
Does WhatsApp store my opt-in records for me?
No — the consent itself (the exact wording, the source and the capture timestamp) is your record, not Meta's, and no platform captures it for you. WhatsApp Manager and your BSP do store the message send and delivery history, template content and approval status, and aggregate block/report signals, which you can export during a review. But the opt-in wording and source only exist if you log them at the moment of capture — checkout, form submit, click-to-chat or in-store — which is why opt-in evidence is an architecture decision, not a report you run later.
Are pre-ticked boxes or purchased lists valid consent?
No. A pre-checked opt-in box fails because consent must be an affirmative act by the user, not a default they had to notice and undo. A purchased or scraped list fails because no per-contact record of agreement exists — the person never consented to you. Both patterns also feed the block-and-report cycle that drags your quality rating down. If your list has this problem, re-permission it (ask contacts to opt in afresh) rather than send into it.
RichAutomate · WhatsApp BSP for India 2026

Ship WhatsApp campaigns + flows on a transparent, compliance-ready BSP.

₹0 platform fee. DPDP audit log included. Visual flow builder. Multi-tenant from day one.

Start free trial
Want this for your brand?

Get a free 24-hour BSP audit

Send us your last invoice. We line-item it against Meta's published rates and benchmark against three alternatives.

Limited Spots Available

Get a Free
Automation Audit

Stop leaving revenue on the table. Get a custom roadmap to automate your growth.

Secure & Confidential

Continue reading

All articles
Compliance

WhatsApp Dark Patterns & CCPA Compliance India 2026

India's CCPA dark-patterns guidelines name a specific list of prohibited deceptive designs (commonly cited as 13 patterns), and nearly every one has a direct analogue inside a WhatsApp commerce journey — false urgency timers, basket sneaking in order edits, forced-bundled opt-ins, subscription traps, confirm-shaming buttons, disguised ads, drip pricing, bait-and-switch, nagging, interface interference, trick questions, SaaS billing and rogue links. This guide maps all 13 patterns onto WhatsApp with compliant alternatives, gives a journey-stage self-audit checklist and side-by-side dark-vs-compliant message copy, explains the CCPA + DPDP Act 2023 double-consent rule, hedges the penalties/enforcement reality, and provides a 30-day audit runbook. As of 2026 — general information, not legal advice.

Read article
Compliance

Telecom Act 2023 and WhatsApp OTT Messaging: India 2026

A scenario map for Indian business senders on whether WhatsApp business messaging acquires telecom-style obligations — authorisation, KYC, lawful-interception readiness — under the Telecommunications Act 2023 rollout and TRAI's OTT consultation. Covers what the Act is and what is still open, the core is-it-a-telecom-service question, why this is distinct from the TCCCPR/DLT commercial-comms rules, three landing scenarios with sender impact, the authorisation/KYC/interception watchlist, the lawful-interception-vs-DPDP-confidentiality tension, and no-regrets compliance moves that pay off under every outcome. Every regulatory, Meta and legal specific is evolving and hedged — verify as of 2026. General information, not legal advice.

Read article
Compliance

AI Disclosure & Labelling for WhatsApp Bots India 2026

A practical, transparency-first guide for Indian businesses running AI bots, GenAI replies, and synthetic voice/image creatives on WhatsApp: when you must disclose you are an AI, how to label AI-generated media, consent for AI-processing of messages under DPDP 2023, a copy-ready disclosure-pattern library, high-risk pitfalls, a self-audit checklist, and a 30-day compliance runbook. India's AI-governance landscape (MeitY advisories, IT Rules synthetic-media obligations, DPDP Act 2023, ASCI) is evolving — all specifics hedged, verify as of 2026.

Read article
Guide

Best WhatsApp API for Healthcare in India (2026)

For clinics, diagnostic labs, hospitals and telehealth practices in India, choosing a WhatsApp Business API is a compliance decision first. This buyer's guide ranks providers on the criteria that actually matter for health data — DPDP Act Sec 8, consent capture and data minimisation, audit trails, no-PII-to-third-parties, ABDM/ABHA readiness and India data handling — with a decision table, a who-should-pick-what block, consent-gated use-cases (appointment reminders, report-ready alerts, cashless/pre-auth status, Rx recalls), 24-48h go-live steps and real rupee pricing. Honest disclosure: no BSP makes you compliant on its own. As of 2026 — general information, not legal or medical advice.

Read article
Compliance

Labour Codes 2026: Gig-Worker WhatsApp Compliance India

India's four Labour Codes are moving into enforcement through 2026, and the Code on Social Security's gig- and platform-worker provisions hand every delivery, ride-hailing, home-services and micro-task platform a new operational problem: running enrolment drives, contribution disclosures, accident intimations and statutory grievance channels across a workforce that lives on WhatsApp — with proof. This guide maps the four Codes to what each touches for a platform employer, then builds the 5-stage worker-comms lifecycle on WhatsApp: onboarding and e-KYC via Flows, eShram and state welfare-board enrolment nudges, per-cycle contribution-and-deduction transparency statements, one-word accident intimation with structured capture, and an always-on grievance channel with a timestamped audit trail. Includes the SMS/email/in-app vs WhatsApp comparison, state-variation strategy for Rajasthan/Karnataka/Telangana-style boards (verify each state as of 2026), the DPDP carve-out for worker PII and welfare data, and a 7-point compliance-comms checklist. Distinct from our gig-rider operations playbook — this is the compliance-reaction layer the Codes bolt on top. Honest scope: the platform helps deliver, remind, capture and log; it does not make an employer compliant, does not compute statutory contributions, and is not the system of record. RichAutomate runs on the official Meta WhatsApp Business API with INR 0 platform fee, INR 0 setup, INR 0 monthly, Client Pay 0.10/message with Meta billed directly, SaaS Pay 1.20 marketing / 0.30 utility, and a 14-day trial with 100 credits. General information, not legal advice.

Read article
Compliance

WhatsApp and India's Digital Competition Bill / CCI Gatekeeper Regime 2026

A forward-looking scenario guide to India's proposed Digital Competition Bill and the CCI ex-ante digital-markets regime for businesses that run on WhatsApp. Explains what an ex-ante gatekeeper regime is, why large Meta services are likely — but not confirmed — in scope, and the kinds of obligations it could bring: anti-self-preferencing, data-portability and interoperability mandates. The heart of the piece is a no-regrets hedging checklist: export your contact list and consent ledger, keep conversation history outside the app, stay multi-channel-ready, and own your customer data — moves that pay off whether the bill passes, passes differently or stalls. Includes a likely-obligations table, a DMA-vs-India-DCB-vs-status-quo comparison, and the competition-law-portability x DPDP data-rights intersection. Distinct from our Telecom Act and DPDP blogs: this is the competition / ex-ante-platform-regulation angle, governed by the CCI, not TRAI or the DPDP authority. The bill is proposed and evolving as of 2026 — every specific is hedged and illustrative. General information, not legal advice.

Read article