The short answer is precise: WhatsApp-specific opt-in is no longer always required, but advance permission still is. A phone number in a CRM, a completed order, or one customer-initiated chat is not a permanent licence to send every future promotion.
Meta's current opt-in page, updated 16 June 2026, says a general opt-in may qualify following the November 2024 policy update. The person must have provided a mobile number and given permission to receive subsequent messages or calls from the particular business, and the business must comply with applicable law. Meta still requires clarity about who is opting in and which business will communicate (Meta's current opt-in guidance).
That clarification removes one channel-specific phrase from some consent flows. It does not remove purpose, evidence, withdrawal, or local-law questions. The safest operating response is not to ask, “Can we message this number?” It is to ask, “What exactly did this person expect this named business to send, what proves it, and is that permission still active?” This article is an operational framework, not legal advice; requirements can vary by jurisdiction and use case.
1. Read the rule without losing the safeguards
Meta lists SMS, a website, a phone or IVR flow, and an in-person or paper process as possible opt-in methods. The collection channel is flexible. The evidence test is not. A useful record needs to show an identifiable person, a named business, a permission statement, a time, and the context in which the statement appeared.
WhatsApp's April 2026 marketing guide makes the distinction especially clear. Its footnote says WhatsApp-specific opt-in is no longer required, while the following pages repeat that advance opt-in is required. The guide also recommends separate explicit consent for promotional messages rather than bundling promotions with transactional updates (WhatsApp marketing best practices).
Therefore, “general” does not mean “unlimited.” It can mean the permission was collected outside WhatsApp or described as communications from the business rather than using a channel-only checkbox. Whether that wording is sufficient for a particular promotional purpose still depends on the disclosure, customer expectation, and applicable law.
2. Apply a two-layer permission test
Use two gates before a contact enters a campaign.
Layer A — platform eligibility. Can the record show that the person supplied the mobile number, agreed in advance to subsequent communications from the named business, and has not opted out? Has the team checked the law that applies to the person and the campaign? If any answer is unknown, do not interpret silence as permission.
Layer B — the purpose envelope. What message categories would a reasonable person expect from the actual disclosure? Record service updates, appointment reminders, product education, and promotions separately when the flow creates different expectations. Add the acquisition source, disclosure version, timestamp and timezone, relevant jurisdiction, evidence pointer, current status, and any expiry or review rule.
The purpose envelope is a business control, not an official Meta field. It turns a legal or policy conclusion into an executable campaign rule. A segment can then require permission_status = active and promotion_scope = true instead of relying on a vague Boolean called opted_in.
- Customer asks for an order update — Permission to handle that service request, not proof of all future marketing: Reply in context; collect separate promotional permission if needed
- Website form names the business and future offers — Possible promotional permission if the wording, evidence and local law support it: Store the disclosure version and category
- Old CRM record contains only a phone number — No provable permission: Exclude it from business-initiated campaigns
- Click-to-WhatsApp ad opens a conversation — A clear customer-initiated thread, not perpetual promotional permission: Serve the request; make any later opt-in explicit
- Person says “stop” or uses another clear refusal — Permission is withdrawn for the affected scope: Suppress immediately across campaigns
3. Keep evidence that survives a complaint
A defensible record should answer a complaint without reconstructing the journey from screenshots and staff memory. Store only the data your governance permits, but make these fields explicit:
- contact identifier and normalized phone number;
- business identity shown at collection;
- acquisition source and form, script, paper, or conversation reference;
- exact disclosure text or an immutable version identifier;
- permitted categories and channel expectation;
- timestamp, timezone, and relevant jurisdiction note;
- evidence location and the person or system that captured it;
- opt-out, re-opt-in, and scope-change history;
- current status, suppression reason, and last review date.
Do not overwrite an old “yes” with a new “no.” Append the change and derive the current state. That preserves the sequence: what was accepted, what changed, and which campaigns were eligible at each point. Limit access and retention according to your own privacy and security program; an audit trail is not permission to hoard personal data.
Use reason codes that operators and software can share: no_evidence, service_only, promotion_allowed, global_opt_out, category_opt_out, expired, and manual_review. Free-text notes can add context, but they should not be the only control stopping a send.
4. Separate service messages from promotions
The service window and permission scope answer different questions. Meta's platform documentation describes a rolling 24-hour customer-service window after a user message. Free-form replies are available within that window; outside it, a business-initiated message requires an approved template (Meta WhatsApp messages documentation).
Being inside the 24-hour window does not automatically expand a service request into consent for unrelated offers. Conversely, having promotional permission does not eliminate template and window rules. Treat these as independent gates: conversation format, platform opt-in baseline, purpose envelope, and applicable law.
For example, a customer may ask a laundry to confirm whether an order is ready. The attendant can resolve that request in the active conversation. A message about a seasonal membership a week later is a different purpose. If the original collection flow did not create that expectation, the business should collect or verify promotional permission first.
This separation also improves customer experience. Meta says people can block or report businesses and describes template review, feedback, and messaging restrictions as safeguards against unwanted communication (Meta on business-chat controls). Relevance is therefore an operational protection, not just copywriting style.
5. Build the permission workflow
Start at acquisition, not at campaign launch.
- Name the business and purposes. The customer should not have to infer who will message or whether “updates” includes offers.
- Capture the evidence. Save the disclosure version, source, time, scope, and evidence pointer when the choice happens.
- Normalize into categories. Map the human disclosure to stable permissions such as service, reminders, education, or promotion.
- Evaluate before every send. Join current permission, later withdrawals, customer state, suppression, message purpose, and platform rules.
- Route replies to an owner. A permission question or opt-out is work, not merely an analytics event.
- Propagate withdrawals. A clear refusal must update every relevant audience and queued journey, not only the campaign that received it.
- Review drift. When a form, script, purpose, business identity, or law changes, reassess what old evidence actually supports.
Make the decision observable. For every excluded contact, record a reason. For every included contact, keep the permission snapshot used at launch. If a scheduled campaign is re-evaluated on send day, retain both the planning count and the final eligible count.
6. Example: a neighborhood laundry
A laundry collects a mobile number at drop-off. Its form names the business and asks whether the customer wants pickup notifications. That evidence supports service updates for the order. It does not silently become permission for monthly discounts.
The business adds a separate, unticked promotional choice with a clear description and opt-out route. The record stores the form version, location, time, service scope, promotional choice, and evidence reference. When a customer later replies “no more offers,” the system appends a promotion opt-out while preserving service notifications the customer still expects, unless the refusal clearly covers all communication or applicable law requires a broader result.
Before the next offer, the campaign segment requires active promotional scope, excludes later opt-outs and unresolved complaints, and records the version evaluated. Replies enter an owned queue. The customer can still request service without being forced into marketing.
This design has a useful property: the team can explain both a send and a non-send. It does not depend on remembering which checkbox existed six months ago.
7. Put the controls into DripTell
DripTell's current customer CRM presents custom fields, tags and groups, campaign attribution, and an opt-in audit trail. Use those surfaces to represent the purpose envelope: source, disclosure version, categories, evidence pointer, status, and withdrawal history. Keep the underlying evidence in the governed system designated by your organization.
The campaign workspace supports scheduling, segmentation, delivery handling, and recipient-level delivered, read, and replied analytics. Build eligibility from current permission and suppression fields before scheduling; do not treat delivery as proof that permission existed. The team inbox supports assignment, notes, status, and shared context, which gives opt-out or scope questions a named owner.
DripTell can help execute and observe the workflow; it does not decide which law applies or guarantee compliance. Your organization remains responsible for the wording, legal basis, scope, retention, and response policy.
8. Audit one path in 30 minutes
Choose one live acquisition path and one campaign. Then answer with records:
- Does the disclosure identify the business and distinguish service from promotion?
- Can you retrieve the exact disclosure version a contact saw?
- Is the timestamp reliable and does the record retain its timezone?
- Can the campaign require a purpose-specific active status?
- Does a later opt-out suppress every relevant segment and queued journey?
- Can service replies continue without re-enrolling the person in promotion?
- Is the 24-hour service window checked separately from permission scope?
- Does every reply or permission dispute have an owner?
- Can you explain why one contact was included and another excluded?
- Is personal evidence access-limited and retained under a defined policy?
If several answers are “no,” pause that audience, repair the evidence path, and test again with a small group. The 2026 clarification is useful because it gives businesses more collection flexibility. The durable advantage, however, comes from keeping permission specific enough to honor what a person expected.
If you want to map one real acquisition flow into executable fields and suppressions, book a DripTell demo with the disclosure, categories, opt-out rule, and evidence owner ready.
DripTell Editorial
Practical guidance reviewed by the DripTell product and customer workflow team.
See how DripTell checks product claims, uses primary sources and handles corrections.
Editorial and source policy



