Is Sending Bulk WhatsApp Marketing Messages Compliant With UK Data Protection and Telephone Preference Rules?

Yes, provided every person you message has specifically consented to WhatsApp marketing from your business, or is an existing customer covered by the soft opt-in. WhatsApp messages fall under the electronic mail rules in PECR regulation 22, alongside UK GDPR. The Telephone Preference Service applies to live sales calls, so screening a list against it does not make a WhatsApp broadcast lawful.

This guide is part of our WhatsApp compliance hub, which brings together our guidance on UK GDPR, marketing consent, Meta's platform rules and staff use of WhatsApp.

Prefer reading or citing the full transcript? Full video transcript: Bulk WhatsApp marketing UK law (PECR, consent and TPS) →

Key takeaways

  • WhatsApp marketing is governed by PECR regulation 22, which the ICO applies to texts, in-app messages, social media direct messages and any similar message stored electronically.
  • There is no TPS equivalent for messages, because PECR already requires consent or a soft opt-in before you send marketing to individuals.
  • The soft opt-in needs all of its conditions met, including an opt-out offered when the number was collected, and it only covers your own similar products.
  • Since 5 February 2026 the maximum PECR fine has risen from £500,000 to £17.5 million or 4% of global annual turnover.
  • Meta's opt-in policy defers to local law, so a list that satisfies WhatsApp's rules can still breach PECR.

Imagine it is Thursday afternoon and the marketing manager at a busy leisure venue has a weekend to fill. There is a spreadsheet of 6,000 mobile numbers built up over several years: ticket buyers, people who entered a competition, contacts from a partner's database, and a few hundred numbers staff saved on their phones. The plan is to send a WhatsApp broadcast with a discount code. To be safe, someone has run the list against the Telephone Preference Service and removed the matches.

It feels like the careful thing to do. Unfortunately the TPS check has no bearing on whether that broadcast is lawful. The questions that matter are where each number came from and what each person agreed to when they handed it over. For most lists built this way, only part of the list would pass.

Bulk WhatsApp marketing sits where two rulebooks meet, and many UK businesses confuse them: the rules on telephone marketing and the rules on electronic mail. This guide sets out which one applies, what it requires, where Meta's own rules fit, and how to run a broadcast you can defend.

Which law governs WhatsApp marketing messages in the UK?

Stitch compliance graphic with two teal ticks and the headline Where WhatsApp actually sits in UK law, subtitled Bulk WhatsApp marketing in the UK: the rules explained by Stitch
WhatsApp marketing messages are electronic mail under PECR regulation 22, with UK GDPR governing the personal data behind them. The TPS covers live calls only.

WhatsApp marketing is governed by regulation 22 of the Privacy and Electronic Communications Regulations 2003 (PECR), together with UK GDPR and the Data Protection Act 2018. Regulation 22 says a business must not send unsolicited direct marketing by electronic mail to an individual subscriber unless that person has consented, or the soft opt-in exemption applies. It applies however sophisticated your messaging platform is and however the number was collected.

Why does WhatsApp count as electronic mail?

PECR defines electronic mail as "any text, voice, sound or image message sent over a public electronic communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient". The ICO's guidance lists the channels this covers, including SMS, picture and video messages, voicemail, in-app messages and private direct messages on social media (ICO guidance on electronic mail marketing). It does not name WhatsApp, and it does not need to: a WhatsApp message is stored on the recipient's device until opened, so it falls squarely within the definition. Public adverts in a social feed are treated differently; private messages are covered. In practice, treat a WhatsApp campaign exactly as you would an SMS campaign.

PECR sets the rules for sending the message. UK GDPR sets the rules for handling the personal data behind it: a lawful basis, telling people how their number will be used, keeping records, honouring objections and answering Subject Access Requests. You need to satisfy both. For the data protection side in more depth, see our guide to UK GDPR and WhatsApp Business messaging.

Responsibility stays with your business even if someone else presses send. The ICO treats both the sender and the instigator as responsible, so appointing an agency or platform to send messages on your behalf leaves you accountable.

Does the Telephone Preference Service apply to WhatsApp messages?

No, and this is the most common misunderstanding in the market. The TPS is a register of people who have opted out of live marketing calls, and the Corporate TPS does the same job for companies and other corporate bodies (ICO guidance on telephone marketing). Both sit under the PECR rules on live calls, which are separate from the rules on electronic mail.

The ICO explains why there is no messaging equivalent. Because you can only email or text individuals who have consented or who were already offered an opt-out, a central opt-out register for messages should not be needed. A number missing from the TPS gives you no permission to send it marketing, and a business with valid consent under regulation 22 does not need a TPS screen for its messaging. Treating a TPS check as the control for a WhatsApp campaign leaves the actual legal requirement unaddressed.

Where the TPS could become relevant: WhatsApp calls

Meta now supports voice calling on the WhatsApp Business Platform, including calls placed by the business. Before a business can call a WhatsApp user, that user must accept a call permission request. If your team uses WhatsApp calling to make live sales or marketing calls, treat those calls with the same care as any other live marketing call, including screening against the TPS and your own do-not-call list. The ICO has not published guidance specific to WhatsApp calls, so take advice if calling forms a significant part of your outreach.

What counts as valid consent for WhatsApp marketing?

Valid consent under UK data protection law must be freely given, specific, informed and unambiguous. A pre-ticked box, a clause buried in terms and conditions, or an assumption based on past purchases does not meet that bar.

Consent is also specific to the sender and the method. ICO guidance says consent is invalid if it does not name the sender or cover the form of electronic marketing the sender plans to use. That catches two common practices. Numbers bought from a list broker, or collected by a partner for "carefully selected third parties", rarely carry consent that names your business. And consent given at a checkout that mentions email only is weak ground for a WhatsApp broadcast.

Good opt-in wording names your business, says the person will receive marketing messages on WhatsApp, and explains how to stop them. Keep a record of what each person was told, when, and which business was named, captured at the point of collection. If a complaint reaches the ICO, that record is your evidence.

When can you rely on the soft opt-in?

The soft opt-in lets you send marketing to existing customers without specific consent, but only where all of the following are true:

  1. You obtained the person's contact details yourself.
  2. You obtained them while selling, or negotiating to sell, a product or service to that person.
  3. You are marketing only your own similar products or services.
  4. You gave them a simple way to refuse marketing when you collected their details.
  5. You give them a simple way to opt out in every message you send.

Every condition must hold. A number collected from a competition entry, a third-party list, or an enquiry that never became a sale negotiation does not qualify. The fourth condition is where businesses fail most often: an enquiry form that collected a mobile number without saying anything about marketing does not create a soft opt-in. The third is the next most common failure, because the exemption covers similar products rather than your whole catalogue. A customer who bought a car service from a dealership can reasonably receive servicing offers; a message promoting a partner's insurance product is a different matter.

The Data (Use and Access) Act 2025 added a separate soft opt-in for charities, but for commercial businesses the rule is unchanged. If you rely on the soft opt-in, document the sale or negotiation that gave rise to it, alongside how anything you now market passes the similarity test.

The ICO's case against Allay Claims shows how the soft opt-in fails in practice. In January 2026 Allay was fined £120,000 for sending more than 4 million marketing texts between February 2023 and February 2024. The ICO found it had not given customers a simple way to refuse marketing when collecting their details, so it could not rely on the soft opt-in it claimed (ICO announcement). The messages were texts, but the same regulation governs WhatsApp.

Stitch warning graphic showing £120,000 in large teal figures: fine after sending more than 4 million marketing texts between February 2023 and February 2024. Allay Claims fined in January 2026 by the ICO.
Allay Claims Ltd was fined £120,000 by the Information Commissioner's Office in January 2026 for sending more than 4 million marketing texts without valid consent or a valid soft opt-in. Source: ICO.

Are the rules different for business customers?

Yes, and this catches out more B2B marketers than any other part of PECR. The ICO treats people, sole traders and ordinary partnerships as individual subscribers. Corporate subscribers are organisations with their own legal personality, such as limited companies, LLPs and Scottish partnerships. Regulation 22's consent requirement applies to individual subscribers, so a sole trader on your list needs the same consent or soft opt-in as a consumer. Corporate subscribers can be sent marketing, though keeping a list of businesses that object is good practice.

This matters more on WhatsApp than on email. A merchant or trade counter's customer list is often full of sole-trader plumbers, electricians and builders messaging from their own mobiles. Segment sole traders and ordinary partnerships out of any blanket "B2B, so no consent needed" assumption. Even where the customer is a limited company, a WhatsApp number usually belongs to a named person, so UK GDPR still applies to how you use it. For more on how trade businesses use WhatsApp with customers, see our trade counters page.

What must every WhatsApp marketing message include?

Every marketing message, solicited or unsolicited and whatever the subscriber type, must identify the sender clearly and give a valid way to opt out. That applies to every message in a campaign, not only the first. It is a baseline obligation that exists whether you rely on consent or the soft opt-in, and on WhatsApp it is usually met with a clear business display name and a reply-STOP instruction or opt-out button.

Can a WhatsApp service message count as marketing?

Yes, if it contains promotional content. Messages sent purely for administrative or customer service purposes fall outside the marketing rules, but adding promotional content to a service message turns it into marketing.

An appointment reminder, a delivery update or a reply to a customer's question is a service message. The same reminder with "and 20% off accessories this weekend" added to the end is marketing, and needs consent or a soft opt-in. Meta draws a similar line through its template categories, and misclassifying a promotional message as a utility message breaches WhatsApp's policies as well as risking a PECR breach.

Does using the WhatsApp Business API make your messaging compliant?

No single technical setup satisfies UK GDPR or PECR on its own. Compliance depends on the legal basis, the message content and the data handling behind each campaign. What the official platform does is make certain obligations achievable, such as keeping data where it can be located, exported and deleted, which is a UK GDPR obligation that personal handsets and the free WhatsApp Business app make difficult to meet. Platform choice supports compliance, and a valid legal basis for each recipient is still required. Before committing to a provider, it helps to know what questions to ask a WhatsApp Business platform provider.

What does Meta require on top of UK law?

Meta's WhatsApp Business Messaging Policy requires opt-in before a business messages someone, separately from any UK legal requirement. The person must have given their mobile number, and the business must have opt-in permission confirming they want to receive messages or calls from that particular business. The opt-in must clearly say the person is opting in to hear from a business, must name that business, and must comply with applicable law. Meta does not prescribe the collection method: a website form, SMS, an IVR phone system or a paper form in person can all work (Meta developer documentation on opt-in).

Since November 2024, that opt-in can be general and need not mention WhatsApp specifically, provided local law is met. This is where UK businesses need care. Meeting Meta's policy does not satisfy UK law, and meeting UK law does not satisfy Meta's policy, because each layer applies independently. A Meta-compliant opt-in collected on a third party's website, without naming your business and without an opt-out at the point of collection, may pass Meta's check and still breach regulation 22. Treat UK law as the higher bar and design your opt-in to meet both.

Meta also enforces quality on its own terms. People can stop marketing messages from individual businesses, block them or report them, and Meta will rate limit businesses whose quality stays low for a sustained period. Our guide to structuring broadcasts to avoid Meta spam blocks covers this in detail.

Marketing messages on the official platform are sent as pre-approved templates and charged per message. Marketing and authentication templates are already billable, and from 1 October 2026 service messages and utility templates sent inside the 24-hour window also become billable. Sending to people who never wanted your messages costs money as well as reputation.

What are the penalties for getting it wrong?

Stitch split graphic headed ICO and WhatsApp messaging, asking What are the penalties for getting it wrong?, with the line The ICO continues to act on unlawful electronic marketing
Since 5 February 2026, PECR breaches, including unlawful WhatsApp marketing, can draw fines of up to £17.5 million or 4% of global annual turnover.

The Data (Use and Access) Act 2025 raised the maximum fine for a PECR breach from £500,000 to UK GDPR levels: £17.5 million or 4% of global annual turnover, whichever is higher. The relevant provisions took effect on 5 February 2026 (ICO statement on the commencement of the Act). The higher ceiling applies to regulation 22 breaches across WhatsApp, SMS and email alike, because all three sit within the same electronic mail definition.

Enforcement is active. In January 2026 the ICO issued fines totalling £225,000 for regulation 22 breaches: £120,000 against Allay Claims Ltd for marketing texts, and £105,000 against ZMLUK Limited for sending 67,772,285 marketing emails between January and July 2023 using third-party data without informed consent. In June 2026 it fined KRA Consultancy £300,000 for more than 5.5 million unlawful marketing texts and ordered it to stop marketing without consent. Complaints trigger most investigations, and a WhatsApp broadcast to people who do not recognise the sender is a reliable way to generate them.

The guidance itself is still being revised. The ICO has flagged that its electronic mail marketing guidance is under review following the Data (Use and Access) Act and may change. We will update this article when it does.

How the rules fit together

RulebookWhat it coversWhat it means for a WhatsApp broadcast
PECR regulation 22Marketing by electronic mail, including WhatsApp, SMS and emailConsent or soft opt-in for individual subscribers; identify your business; include an opt-out in every message
UK GDPR and DPA 2018Handling the personal data behind the messageLawful basis, transparency, records of consent, honouring objections, answering SARs
TPS and CTPS (PECR live-call rules)Live sales and marketing callsNo bearing on WhatsApp messages; screen before live marketing calls, including WhatsApp calls
Meta Business Messaging PolicyUse of the WhatsApp platformOpt-in naming your business and compliant with local law; approved templates; honest message categories; quality ratings

How to run a compliant WhatsApp broadcast

  1. Audit where every number came from. Separate customers, people who opted in, and anything bought, borrowed or saved on staff phones. The last group should not receive marketing.
  2. Check what each person agreed to. Consent should name your business and cover WhatsApp marketing. Where it only covered email, ask again before broadcasting.
  3. Apply the soft opt-in narrowly. Use it only for genuine customers, only for your own similar products, and only where they were offered an opt-out when you collected their number.
  4. Segment business contacts. Treat sole traders and ordinary partnerships as individuals, not as corporate subscribers.
  5. Screen against your own suppression list before every send, so anyone who has opted out on any channel stays out.
  6. Identify yourself and include a clear opt-out in every marketing message, such as replying STOP, and act on it promptly.
  7. Classify templates honestly, keeping promotions out of utility messages.
  8. Keep evidence of when and how each contact opted in, and be ready to produce a customer's full WhatsApp history if they submit a Subject Access Request.

Our guide to WhatsApp broadcast messages covers segmentation and message design, and how to avoid getting your WhatsApp account blocked explains how consent affects your number's standing with Meta.

How msgboxx supports compliant broadcasting

Stitch graphic headed How msgboxx supports compliant broadcasting, with the headline How to run a compliant WhatsApp broadcast and the line Stitch is a Meta Business Partner
msgboxx runs broadcasts on the official WhatsApp Cloud API, with tag-based segmentation and a STOP opt-out in every marketing message.

We built msgboxx on the official WhatsApp Cloud API, so every broadcast runs through Meta's approved route with approved templates. Contacts can be segmented with tags, so a message about a new instruction goes only to matched applicants who opted in, and a service reminder never becomes a blanket promotion. Marketing messages can carry a STOP opt-out so customers can unsubscribe cleanly, and quick-reply buttons such as "Interested" or "Not for me" let people respond in a tap.

Because every conversation is held centrally and belongs to the business, you can answer a Subject Access Request with an export in place of a search across staff phones, and nothing leaves when a member of staff does. For teams moving from the free WhatsApp Business app, Meta's Coexistence feature connects the existing number to the official platform without changing how staff work day to day. Our Coexistence FAQ explains how it works.

If you would like to see how this works for your own customer list, book a demo with the Stitch team.

Frequently asked questions

Is it legal to send bulk WhatsApp marketing messages in the UK?

Yes, provided every individual you message has specifically consented to WhatsApp marketing from your business or is covered by the soft opt-in. WhatsApp marketing is governed by PECR regulation 22 and UK GDPR. Screening a list against the Telephone Preference Service does not make a broadcast lawful, because the TPS only covers live sales calls.

Why does WhatsApp count as electronic mail under UK law?

PECR defines electronic mail as any text, voice, sound or image message sent over a public network and stored until the recipient collects it. A WhatsApp message meets that definition, and the ICO lists in-app messages and private direct messages among the channels covered. Treat a WhatsApp campaign as you would an SMS campaign.

Do I need to screen WhatsApp numbers against the TPS?

No. The TPS and Corporate TPS are registers for live marketing calls. WhatsApp messages fall under PECR's electronic mail rules, which require consent or a soft opt-in regardless of TPS status. If your team makes live marketing calls over WhatsApp, treat those calls as you would any live marketing call and screen accordingly.

Can I send WhatsApp marketing to people who bought from us before?

Possibly, under the soft opt-in. You can market your own similar products or services to past customers if you collected their number during a sale or negotiation, offered them a simple way to opt out at that point, and include one in every message. It does not cover prospects, competition entrants or third-party lists.

Does meeting Meta's opt-in policy make my broadcast compliant with UK law?

No. Meta requires opt-in that names your business and complies with local law, and it accepts general opt-ins that do not mention WhatsApp. UK law sets its own tests for consent and the soft opt-in. Both layers apply independently, so a list that satisfies Meta can still breach PECR.

Can I send WhatsApp marketing to business customers without consent?

Only to corporate subscribers such as limited companies, LLPs and Scottish partnerships. Sole traders and ordinary partnerships count as individuals under PECR, so they need to have consented or fall within the soft opt-in. Segment B2B lists accordingly, and remember UK GDPR still applies to named people's numbers.

Does using the WhatsApp Business API make my marketing compliant?

Not on its own. Compliance depends on having a valid legal basis for each recipient, honest message content and sound data handling. The official platform makes several obligations achievable, such as central records, recorded opt-outs and SAR exports, but it does not replace consent or a valid soft opt-in.

How much can the ICO fine for unlawful WhatsApp marketing?

Since the Data (Use and Access) Act provisions took effect on 5 February 2026, the maximum PECR penalty is £17.5 million or 4% of global annual turnover, whichever is higher. Before that the cap was £500,000. The ICO fined two firms £225,000 in January 2026 for unlawful texts and emails.

This article explains the UK rules in general terms and is not legal advice. Legal statements are drawn from the ICO, UK legislation and Meta's own documentation, checked in September 2026. Guidance may change as the ICO updates its materials following the Data (Use and Access) Act, so take specific advice before finalising a WhatsApp marketing programme.

About the author: Paul Gandar is the Director of Stitch AI, a Meta Business Partner and UK-based WhatsApp Business Solution Provider.

Want the video word for word? Read the full video transcript: Bulk WhatsApp marketing UK law (PECR, consent and TPS), with each section of the explainer, the five-point checklist and the sources in one place.

Take the next step

Book Demo