Is Sending Bulk WhatsApp Marketing Messages Compliant With UK Data Protection and Telephone Preference Rules?

Is Sending Bulk WhatsApp Marketing Messages Compliant With UK Data Protection and Telephone Preference Rules?

Bulk WhatsApp marketing sits at the intersection of two rulebooks that many UK businesses confuse: telephone marketing law and electronic mail law. Getting this wrong is not a technicality, it is the difference between a lawful campaign and a Regulation 22 breach with penalty exposure that changed significantly in 2025. This FAQ answers the questions a UK business should work through before sending its first bulk WhatsApp campaign.

The Legal Basis For WhatsApp Marketing

Is it legal to send bulk WhatsApp marketing messages in the UK?

Yes, sending bulk WhatsApp marketing messages to UK customers is lawful, but it is governed by Regulation 22 of the Privacy and Electronic Communications Regulations 2003 (PECR), not by the Telephone Preference Service. A WhatsApp marketing message is treated as electronic mail under PECR, in the same category as an email or an SMS. That means a business needs either the recipient's consent or a valid soft opt-in before sending marketing messages to an individual subscriber. Screening a list against the TPS or CTPS register does not make a WhatsApp campaign compliant, because those registers cover live marketing telephone calls only. Any business building a WhatsApp marketing programme should treat Regulation 22, not a call-preference register, as the relevant control.

Why does WhatsApp count as "electronic mail" under UK law?

WhatsApp messages meet PECR's legal definition of electronic mail, which covers "any text, voice, sound or image message sent over a public electronic communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient". The ICO's guidance on direct marketing by electronic mail explicitly lists the channels this covers: email, SMS text messages, picture and video messages, voicemail messages, in-app messages, and private direct messages on social media. The ICO does not name WhatsApp by name, but it does not need to, since a WhatsApp message is a text message sent over a public electronic communications network and stored on the recipient's device until opened, which is the statutory definition, and it falls squarely within the "in-app messages" and "private direct messages" examples the ICO gives. Public social media advertising in a news feed is a different case and is not covered by this definition, only private messages are. The practical consequence is straightforward: treat a WhatsApp marketing campaign exactly as you would treat an SMS campaign.

What is Regulation 22 and what does it actually require?

Regulation 22 states that a business must not send unsolicited direct marketing by electronic mail to an individual subscriber unless the recipient has consented, or the soft opt-in exemption applies. This is the core legal test for any WhatsApp, SMS or email marketing message sent to a person in the UK. It applies regardless of how sophisticated the messaging platform is or how the recipient's number was originally collected. Any WhatsApp broadcast strategy needs to be built around satisfying this rule before a single message goes out, and the two available legal bases, consent and the soft opt-in, work differently and carry different conditions.

Consent, Soft Opt-In and Who Counts As A Consumer

What counts as valid consent for WhatsApp marketing?

Valid consent under UK data protection law must be freely given, specific, informed and unambiguous, and it is distinct from the soft opt-in exemption, which allows marketing without this fuller consent standard where its own conditions are met. This means a pre-ticked box, a buried clause in terms and conditions, or an assumption based on prior purchase behaviour does not meet the bar for consent on its own. Businesses relying on consent as their legal basis need a record of what the person was told, when, and which business was named, captured at the point of collection.

What is the soft opt-in and when can I rely on it instead of consent?

The soft opt-in is an exemption that allows marketing without full Regulation 22 consent, but it applies only where all five of the following following conditions are true. One, you obtained the recipient's contact details. Two, you did so while selling or negotiating to sell a product or service. Three, you are only marketing your own similar products and services. Four, you provided the recipient with an opportunity to refuse or opt out when you collected their contact details. Five, you give the recipient an opportunity to refuse or opt out in every subsequent communication.

All five conditions must hold together, not just most of them. A number collected from a competition entry, a third-party list, or an enquiry that never became a sale negotiation does not qualify. Condition four is the one businesses fail most often, because an enquiry form that collected a mobile number without saying anything about marketing does not create a soft opt-in for that number. Condition three is the second most common failure, since the exemption covers similar products and services rather than the whole catalogue.

Businesses relying on the soft opt-in as the legal basis for a WhatsApp campaign should document the original sale or negotiation that gives rise to the exemption, alongside the similarity test for anything subsequently marketed.

Does the individual versus corporate subscriber distinction matter for WhatsApp marketing?

Yes, and it catches out more B2B marketers than any other part of PECR. The ICO defines individual subscribers as "people, sole traders, ordinary partnerships", while corporate subscribers are "organisations with their own legal personality, for example limited companies, LLPs and Scottish partnerships". Regulation 22's consent requirement applies to individual subscribers, which means sole traders and ordinary partnerships are treated as individuals, not as businesses, for this purpose. Operationally, this means a business cannot assume its entire B2B contact list is exempt from consent requirements simply because the recipients are business contacts, since sole traders and ordinary partnerships sitting inside that list are legally individual subscribers. Any B2B WhatsApp list should be segmented to identify sole traders and ordinary partnerships separately from limited companies and LLPs, rather than applying a single "B2B, so no consent needed" logic across the whole list.

Sender Obligations And Common Misconceptions

What information must every WhatsApp marketing message include?

Every marketing message, whether solicited or unsolicited and regardless of subscriber type, must not disguise or hide the sender's identity, and must provide a valid contact address for recipients to opt out or unsubscribe. This applies to every message in a campaign, not just the first one a recipient receives. A WhatsApp broadcast that identifies the sending business clearly and gives a working opt-out route in every send is meeting a baseline obligation that exists independently of whether consent or soft opt-in is the legal basis being relied on.

Can I just screen my WhatsApp list against the TPS or CTPS register instead?

No, and this is the single most common misunderstanding in the market. The TPS is the register of individuals who have opted out of receiving live marketing calls, and the CTPS works the same way for corporate bodies, but both registers concern telephone calls specifically. They do not govern electronic mail, which is where WhatsApp, SMS and email sit. A business that screens its WhatsApp list against the TPS has not addressed its Regulation 22 obligation, and conversely a business with valid consent under Regulation 22 does not need to screen against the TPS for messaging purposes. Treating a TPS or CTPS check as the compliance control for a WhatsApp campaign leaves the actual legal requirement, consent or soft opt-in under Regulation 22, entirely unaddressed.

Does having a WhatsApp Business API connection make my messaging GDPR compliant?

No single technical setup satisfies UK GDPR or PECR on its own; compliance depends on the consent basis, message content and data handling practices behind the campaign. What a platform can do is make certain obligations achievable, such as keeping data where it can be located, exported and deleted, which is a UK GDPR obligation that personal handsets and the free WhatsApp Business app make difficult to meet. Businesses should treat platform choice as one operational factor supporting compliance, not as a substitute for having a valid legal basis to message each recipient. Before committing to a specific tool, it is helpful to understand [what questions should I ask a WhatsApp Business platform provider](https://stitch-ai.com/blog/whatsapp-business-provider-due-diligence-checklist) to ensure their infrastructure supports your regulatory needs.

Meta's Opt-In Policy As A Separate Layer

Does Meta have its own rules on top of UK law?

Yes, Meta requires businesses to obtain opt-in permission before sending WhatsApp messages, separately from any UK legal requirement. Meta's policy states that before sending, the recipient must have given their mobile number and the business must have "received opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from a particular business". Meta's stated requirements are that businesses must clearly state that the person is opting in to receive communication from a business, must clearly state the name of the business they are opting in to hear from, and must comply with applicable law. Meta does not prescribe the collection method: opt-in can be gathered via SMS, a website, an IVR phone system, or in person on paper, provided the disclosure requirements are met.

If I meet Meta's opt-in requirement, am I automatically compliant with UK law?

No, satisfying Meta's policy does not satisfy UK law, and satisfying UK law does not satisfy Meta's policy, because both layers apply independently and must each be met. There is a real gap between the two: Meta's policy asks for opt-in permission naming the business, while UK law asks for consent that is freely given, specific, informed and unambiguous, or a soft opt-in meeting all five conditions. A Meta-compliant opt-in collected on a third party's website, without naming the sending business and without an opt-out at the point of collection, may satisfy Meta and still breach Regulation 22. Any UK business running WhatsApp marketing needs to check both boxes separately, not treat Meta's approval process as a proxy for UK legal compliance.

Penalties And Enforcement

What is the current penalty exposure for a PECR breach?

The Data (Use and Access) Act 2025 raised the maximum fine for a PECR breach from GBP 500,000 to UK GDPR levels, being GBP 17.5 million or 4 per cent of global annual turnover. Key provisions of the Act took effect on 5 February 2026. This is a substantial increase in exposure compared to the previous fixed cap, and it applies to Regulation 22 breaches involving WhatsApp, SMS and email marketing alike, since all three sit within the same electronic mail definition.

Has the ICO actually enforced Regulation 22 recently?

Yes, enforcement is active. On 20 January 2026 the ICO issued fines totalling GBP 225,000 for Regulation 22 breaches. Allay Claims Ltd was fined GBP 120,000 for sending 4,046,947 text messages without valid consent between February 2023 and February 2024. ZMLUK Limited was fined GBP 105,000 for sending 67,772,285 marketing emails using third-party sourced data without informed consent between January and July 2023. These cases both involved electronic mail channels rather than telephone calls, underlining that the ICO treats bulk messaging failures, not just call-based marketing, as a live enforcement priority.

Putting This Into Practice

What should a business actually do before running a bulk WhatsApp campaign?

Build the consent record at the point of collection, storing what the person was told, when, and which business was named. Keep a working opt-out mechanism in every marketing message sent, not only the first message in a sequence. Do not rely on a TPS or CTPS screen as the compliance control for a messaging campaign. Segment sole traders and ordinary partnerships out of any blanket "B2B, so no consent needed" assumption applied to a contact list. Where the soft opt-in is the legal basis, confirm that the products being marketed are genuinely similar to what was previously sold or negotiated with that recipient. Keep data in a location where it can be found, exported and deleted, satisfying the UK GDPR obligation that personal handsets and the free WhatsApp Business app are not built to meet.

For the data residency and Subject Access Request implications of running WhatsApp on personal devices versus a proper business platform, see our companion piece on UK GDPR and WhatsApp Business messaging compliance. For the separate question of how to structure broadcast campaigns to avoid Meta's own spam and quality restrictions, see our guide to WhatsApp broadcast marketing and avoiding Meta spam blocks.

This article is not legal advice. Every legal statement above is traceable to the ICO, UK legislation or Meta's own documentation, and businesses should take independent legal advice before finalising a WhatsApp marketing compliance programme.

Take the next step

Book Demo