Yes, bulk WhatsApp marketing is legal in the UK, provided every person you message has specifically consented to WhatsApp marketing from your business, or is an existing customer covered by the soft opt-in. WhatsApp messages fall under the electronic mail rules in PECR regulation 22, alongside UK GDPR. The Telephone Preference Service applies to live sales calls, so screening a list against it does not make a WhatsApp broadcast lawful.
This page is the full transcript of Stitch AI's video explainer Is Bulk WhatsApp Marketing Legal in the UK? PECR, Consent & the TPS Explained, presented by Paul Gandar and published on 15 September 2026. Watch the video on YouTube or read the full written guide to bulk WhatsApp marketing, PECR and the TPS.
Is sending bulk WhatsApp marketing messages compliant with UK data protection and TPS rules? The answer: yes, provided every person you message has specifically consented to WhatsApp marketing from your business, or is an existing customer covered by the soft opt-in.
Welcome to this explainer. Today we are going to completely unpack exactly what that means for your marketing strategy and, more importantly, your compliance risk.
As we just established, sending these messages can absolutely be perfectly compliant. But the legal framework governing them is incredibly strict. A lot of businesses are operating under some dangerous misconceptions about what they are actually allowed to do.
We will unpack the legal frameworks across five key areas: the compliance reality; why TPS is not enough; consent and soft opt-in; Meta policies versus UK law; and the MessageBox broadcasting solution.
Short answer: Yes. Under PECR regulation 22 a WhatsApp marketing message counts as electronic mail, whether it is text, video, a voice note or an image, and the maximum PECR fine is now £17.5 million or 4% of global annual turnover.
If you are sitting there thinking a rogue WhatsApp message is just a minor annoyance for a customer, you need to hear this. Under the Data Use and Access Act, the maximum fines under PECR have skyrocketed: from a previous cap of £500,000 all the way up to £17.5 million or 4% of your global annual turnover, whichever is higher. The Information Commissioner's Office regularly issues large fines for unsolicited marketing texts and is fully empowered to do the same here.
The crucial takeaway is that the ICO treats WhatsApp the same as SMS or email. Under PECR regulation 22, the term electronic mail is deliberately broad. It does not matter if you are sending a text, a video, a voice note or an image. If it goes over a public network like WhatsApp, it falls under these electronic mail marketing rules.
Short answer: No. The TPS covers live sales and marketing calls only. There is no TPS equivalent for messaging, and a number being absent from the TPS register gives no permission to send WhatsApp marketing.
By far the biggest myth is that simply screening your contact list against the Telephone Preference Service keeps you legally safe. That illustrates the trap many marketers fall into. The TPS limits apply strictly to live sales and marketing calls. It has no bearing on electronic messages, because the law already requires specific consent or a valid soft opt-in for emails and texts. There is no TPS equivalent for messaging.
Finding that a number is not on the TPS register gives you no legal permission to send a WhatsApp marketing message.
Short answer: Consent must be a clear affirmative action that names your business and names WhatsApp as the channel, with proof of when, where and what wording the person saw. Without it, the only other route is the soft opt-in for genuine past customers, with an opt-out offered at collection and in every message.
If the TPS does not protect you, what counts as valid permission to send a broadcast? If you are relying on consent, it cannot be hidden. Pre-ticked boxes, assuming silence means yes, or burying consent in terms and conditions do not qualify. Valid consent has to be a clear affirmative action. It must specifically name your business. Bought lists or vague third-party checkboxes will not hold up under ICO scrutiny.
You also have to specifically name WhatsApp as the marketing channel. You need to be able to prove when, where, and what exact wording that person saw.
If you do not have that specific consent, your only other legitimate route is the soft opt-in. You can message past customers about similar products without getting fresh consent, but the rules are strict. You must have offered an opt-out at the moment you collected their data, and in every message since.
To put the severity in perspective: the recent £120,000 fine against Allay Claims. The ICO found they had not given customers a simple way to refuse marketing when collecting their details, so their reliance on the soft opt-in collapsed.
Short answer: No. Meta accepts general opt-ins that do not mention WhatsApp, as long as they comply with local law, but UK law is the stricter standard. Complying with Meta's platform rules does not satisfy the ICO.
You might think: if Meta allows it on their platform, I must be in the clear. That is a dangerous assumption. Meta's business messaging policy requires an opt-in, and as of late 2024 they accept general opt-ins that do not need to mention WhatsApp specifically, as long as it complies with local law.
Here is the catch: UK law is the strictest standard. Complying with Meta's platform rules does not satisfy the ICO. Always treat UK law as the higher bar and design data capture to meet that standard.
The rulebooks sit side by side: PECR regulating the sending of the message; UK GDPR governing the personal data behind it; the TPS only caring about live calls; and Meta governing access to their platform. You need a centralised system to satisfy messaging rules and data protection records at the same time. You cannot manage this across a dozen staff iPhones.
Short answer: Move broadcasting off staff handsets and into a governed system on the official WhatsApp Cloud API, with pre-approved templates, a shared inbox linked to your CRM, automated STOP opt-outs and clean exports for subject access requests. In the video this is our msgboxx platform, referred to as MessageBox.
Because the legal consequences of using scattered personal WhatsApp accounts are severe, the solution has to be structural. You cannot just tell sales staff to be careful when £17.5 million fines are on the table.
Purpose-built platforms matter here. Stitch built the MessageBox platform on the official WhatsApp Cloud API, specifically for regulated sectors like property and finance. Broadcasts run through Meta's approved route using pre-approved templates, with GDPR compliance built into the workflow. It takes the compliance burden off the individual handset and locks it into a governed system.
By centralising communications into a shared inbox that links to your CRM, you solve data scatter. If a client submits a subject access request, you can answer with a full clean export instead of searching ten employees' phones. You can handle automated opt-outs with a clean STOP reply. And you stop regulated client data walking out the door when an employee leaves.
Short answer: Five checks, taken from the video:
A dedicated system like MessageBox can automate these guardrails using tags and CRM integrations.
Your customers want to communicate with you on WhatsApp. That is where their attention is. But if staff still rely on personal phones or free consumer apps, you are carrying a hidden liability. The technology to centralise and secure this data already exists. The question is whether you modernise compliance before the ICO or a subject access request forces your hand.
Thank you for joining this explainer.
Yes, provided every individual you message has specifically consented to WhatsApp marketing from your business or is covered by the soft opt-in. WhatsApp marketing is governed by PECR regulation 22 and UK GDPR. Screening against the TPS does not make a broadcast lawful.
No. The TPS covers live sales and marketing calls only. WhatsApp messages fall under PECR electronic mail rules, which require consent or a soft opt-in regardless of TPS status.
No. Meta's rules and UK PECR apply independently. A list that satisfies Meta can still breach regulation 22. Treat UK law as the higher bar.
Possibly, under the soft opt-in. You can market your own similar products or services to past customers if you collected their number during a sale or negotiation, offered them a simple way to opt out at that point, and include one in every message. It does not cover prospects, competition entrants or third-party lists.
Since the Data (Use and Access) Act provisions took effect on 5 February 2026, the maximum PECR penalty is £17.5 million or 4% of global annual turnover, whichever is higher. Before that the cap was £500,000. The ICO fined two firms £225,000 in January 2026 for unlawful texts and emails.
We built msgboxx on the official WhatsApp Cloud API for regulated sectors such as property and finance. Broadcasts go out through pre-approved templates, conversations sit in a shared inbox linked to your CRM, STOP replies are handled automatically and subject access requests can be answered with a single export. Book a msgboxx demo to see how it handles consent tags, opt-outs and records for your team.
The full written guide covers the same ground in more depth, including the rules for business customers, what every marketing message must include, when a service message counts as marketing, and a table showing how PECR, UK GDPR, the TPS and Meta fit together. Read the written guide: Is sending bulk WhatsApp marketing messages compliant with UK data protection and TPS rules?