When Meta or your BSP questions how you got a contact's consent — during a template appeal, a quality review, or an account review — you get days, sometimes hours, to produce proof. The proof they want is specific: for a given phone number, when consent was captured, on what channel, and the exact wording the person agreed to. If your "opt-in" is a spreadsheet of numbers with no timestamp, no source and no record of what was actually shown, you have contacts, not evidence — and that is what gets a template rejected or a number restricted. This applies to any business on the WhatsApp Business API, whatever your industry.
This 2026 guide is the operational side of opt-in — not the legal theory, but the record you must be able to pull on demand. It covers what triggers a review, exactly which fields make an opt-in defensible, how long to keep them, how to export what WhatsApp Manager and your BSP already store, and a checklist to assemble the evidence pack in 24 hours. Meta's review process and the DPDP rulebook both evolve — treat the specifics below as directional and confirm the current requirements in WhatsApp Manager and with your compliance advisor before you rely on them.
What triggers an opt-in review
You rarely get to choose the moment. Any of these can put your consent record under scrutiny:
- Template rejection or appeal — a marketing template gets rejected and the appeal asks how recipients opted in.
- Quality-rating drop — blocks and "not useful" reports pull the number's rating down; Meta looks at whether recipients expected the message.
- Account or WABA review — a broader integrity check where opt-in evidence is one of the things assessed.
- User complaint — a recipient reports the business, and the burden shifts to you to show consent.
The common thread: the trigger is unplanned, and the clock is short. The businesses that survive it are the ones who were already logging consent properly — you cannot reconstruct a timestamp after the fact. If your rating is already slipping, the red-rating recovery playbook covers the sending side; this page covers the paper trail.
What counts as opt-in evidence
A list of phone numbers is not evidence. Evidence is a per-contact record you can produce that shows a real person agreed to hear from you on WhatsApp. At minimum, for each contact you should be able to show:
| Field | Why it matters | Example |
|---|---|---|
| Contact identifier | Ties the consent to the exact number that received the message | +91 98XXXXXX01 |
| Timestamp | Proves consent came before the message, and how recent it is | 2026-07-14 11:32 IST |
| Source / channel | Where consent happened — a review can ask you to reproduce it | Website checkout checkbox / WhatsApp click-to-chat / paper form at store |
| Exact wording shown | The consent must match what you actually send (marketing vs utility scope) | "Yes, send me offers & order updates on WhatsApp" |
| Consent scope | Distinguishes transactional/utility from marketing permission | Marketing + utility, or utility-only |
| Action taken | How the person expressed it — an affirmative act, not a pre-ticked box | Ticked an unchecked box / replied "JOIN" / signed |
The two fields businesses most often miss are exact wording and source. "We had their number" is not consent. "On 14 July at checkout they ticked an unticked box that said 'send me offers and order updates on WhatsApp'" is. If you cannot say what the person actually saw and agreed to, you cannot defend the send. For how the underlying consent should be structured legally, see the DPDP Act opt-in compliance guide; treat the DPDP specifics there as directional and confirm the operative rules with your advisor.
Get the DPDP WhatsApp checklist
A founder-led WhatsApp reply with the DPDP consent + audit-log checklist for WhatsApp Business messaging. India-hosted. No spam.
Pre-ticked boxes and bought lists are not consent
Two patterns fail every review: a pre-checked opt-in box (consent must be an affirmative act by the user), and a purchased or scraped list (no per-contact record exists, because the person never agreed with you). Both also feed the block-and-report cycle that drops your quality rating. If your list has a hygiene problem, re-permission it rather than send into it — the list-hygiene and re-permissioning guide walks the cleanup.
How long to keep it
Keep opt-in records for at least as long as you message the contact, plus a buffer after they leave or opt out — you may need to prove the consent was valid for the period you actually sent. There is no single universal retention number that fits every obligation, and Indian data-protection expectations are still settling, so set the retention with your compliance advisor rather than guessing. The practical rule: never delete the consent record before you stop messaging the contact, and keep a record of opt-outs too, so you can prove you honoured a withdrawal.
What WhatsApp and your BSP already store
Some evidence you must capture yourself; some is already sitting in the platform. Know the split:
| Record | Who holds it | How to get it |
|---|---|---|
| The consent itself (wording, source, timestamp) | You — it is your record, not Meta's | Log it at capture time in your CRM/opt-in table; nobody captures it for you |
| Message send + delivery history | WhatsApp Manager / your BSP | Export from WhatsApp Manager or the BSP dashboard/API |
| Template content & approval status | WhatsApp Manager | Message Templates section shows category, status and body |
| Block / report signals | Meta (aggregate) | Quality rating and messaging insights in WhatsApp Manager |
The critical gap: the opt-in wording and source are the one thing no platform captures for you. If you are not logging them at the moment of capture — checkout, form submit, click-to-chat, in-store — they do not exist, and no amount of exporting later will create them. That is why opt-in evidence is an architecture decision, not a report you run when a review lands.
Assemble the evidence pack in 24 hours — checklist
- Pull the flagged numbers from the template appeal / review notice.
- Match each to its opt-in record — timestamp, source, exact wording, scope, action taken.
- Export the send + delivery history for those numbers from WhatsApp Manager / your BSP.
- Screenshot the consent surface as it appears today — the checkout box, the form, the click-to-chat entry — so the reviewer can see what the user saw.
- Confirm message-to-consent match — a marketing send needs marketing-scope consent, not utility-only.
- Note any opt-outs honoured for the flagged cohort, with dates.
- Package it per-contact, not as a bulk list — a review wants to trace one number end to end.
If you cannot complete this checklist for a given cohort today, that cohort is your risk. Fix the capture now so the next review is a five-minute export, not a fire drill.
How RichAutomate keeps the evidence ready
Opt-in evidence should be a byproduct of how you capture contacts, not a scramble when Meta asks. RichAutomate logs consent at the point of capture — timestamp, source and scope tied to the number — so the record exists before you ever need it, and the send history sits alongside it in one place. Templates are tracked with their category and status, so a marketing-vs-utility scope mismatch is visible before you send, not after a rejection. Pricing is flat and usage-only — ₹0 platform fee, ₹0 setup, ₹0 monthly, Client Pay at ₹0.10 per message or SaaS Pay all-in at ₹1.20 marketing / ₹0.30 utility — so proper consent logging is not a premium tier, it is how the platform works. See the full feature set.
Bottom line
A phone list is not opt-in evidence; a per-contact record of timestamp, source, exact wording and scope is. The review that asks for it arrives unannounced and on a short clock, and you cannot backfill a timestamp — so capture the consent properly at the moment it happens, keep it as long as you message the contact, and know which pieces WhatsApp already stores versus the wording and source only you can log. Do that and a template appeal or account review is a quick export. Skip it and you are defending sends you cannot prove anyone agreed to.