Do I need authorization from the LGPD to send a message on WhatsApp?
LGPD on WhatsApp: when you need explicit opt-in, when legitimate interest is enough, how to document consent and unsubscribe that the law requires.
Yes, in practice almost always: the LGPD requires a legal basis for you to process a customer's name and number on WhatsApp, and this usually means explicit consent or legitimate interest justified by a relationship that already exists — he bought from you, he looked for you first. Sending a message to those who have never had contact with your company, from a list purchased from third parties, is the scenario that becomes the most problematic. Below, the two bases that apply to commercial WhatsApp, what counts as a defensible opt-in and how to document this without becoming bureaucracy.
LGPD does not prohibit commercial WhatsApp — requires a legal basis
The most common mistake is treating the LGPD as a list of prohibitions. It doesn't say "you can't send WhatsApp to customers"; says that any processing of personal data — and name plus telephone number is already personal data — must be based on one of the legal bases provided for by law. In the practice of commercial WhatsApp, only two appear frequently: consent and legitimate interest. Understanding the difference between them is what separates a defensible campaign from one that becomes a complaint.
This guide uses the ANPD guide for small businesses as a central reference[1] — but does not replace legal advice. LGPD applied to a real case changes depending on the sector, the history of the base and how the data was collected; for decisions involving large volumes or sensitive data, it is worth consulting a lawyer or a DPO before acting.
The two legal bases that apply to commercial WhatsApp
Explicit consent is the safest basis and the easiest to defend: the person said "yes, I want to receive a message from you on WhatsApp" in a free, informed and specific way — not hidden within a generic term of use. It can be revoked at any time, and revocation needs to be as easy as giving consent.
Legitimate interest is more flexible, but also more risky to apply alone: it covers situations in which a relationship already exists and the message is within what the person would reasonably expect — a customer who purchased receiving notice about the delivery itself, for example. Legitimate interest is not a blank check: the law expects an analysis of proportionality between your commercial interest and the rights of the holder, and it does not cover any message — much less an offer of a product with no relation whatsoever to the original purchase, sent to those who have never heard of your company.
The table summarizes where each base tends to fit — "tends", because the final assessment is always case by case:
| Situation | More defensible base | Need explicit opt-in? |
|---|---|---|
| Customer purchased and is contacted about the purchase itself (delivery, invoice, support) | Legitimate interest / execution of the contract | Normally not, but the content must be within the scope of the purchase |
| Customer purchased and receives offer for another product (upsell, campaign) | Gray area — depends on the history and what was informed during the purchase | Explicit consent is recommended |
| Lead filled out form and marked specific acceptance for WhatsApp | Explicit consent | Yes — and it is already documented |
| Cold contact from a list purchased from a third party | No clear basis | Yes, and normally there is no way to prove it |
What counts as a defensible opt-in in practice
Three contact sources usually hold up well to checking:
- Form with specific acceptance. The customer filled out a form (website, landing page, WhatsApp Business) and checked an acceptance box specifically talking about receiving a message on WhatsApp — not a generic “I accept the terms of use” box.
- Customer who started the conversation. He clicked on the wa.me link, scanned the QR Code or sent the first message. His initiative shows that the channel was opened voluntarily — but this is not a permanent license: months of silence require common sense before reopening with an offer.
- Customer who purchased and provided the contact number regarding the purchase. Order confirmation, delivery notice, invoice — the number was given for that purpose, and using it for that purpose is the most defensible use there is.
A recurring problem when the base grows: no one remembers off the top of their head which contact came from a form and which came from a list purchased two years ago. The simple solution is to register the origin as a tag in the conversation itself as soon as the contact enters — the stickers on WhatsApp Business shows how to set up this taxonomy without becoming a parallel system.
What is risk: where do the contacts that generate the most complaints come from
- Number purchased from a third party list, with no connection whatsoever to your company. The person has never heard of you — any message arrives as spam, and there is no legal basis to support the sending, because there was no consent or prior relationship.
- Scraping numbers in WhatsApp groups or social networks. Number that appears in a public group did not become consent to receive a private message — the person authorized to participate in that group, not to be contacted individually by someone they do not even know.
Both scenarios accumulate risk on two fronts at the same time: in the LGPD, due to treatment without a legal basis; and in WhatsApp policy, unsolicited messages — the most likely to become a complaint (more on this second layer later). ANPD treats small businesses with simplified compliance rules, but this is a deadline and proportionality in inspection, not exemption from liability[1].
How to document consent without becoming bureaucracy
No need for a sophisticated legal system — you need three pieces of information saved for each contact:
- Origin. Where did the number come from: form X, campaign Y, purchase of product Z.
- Date and time of acceptance. A simple timestamp is already evidence — a spreadsheet with a date column does the trick for most small businesses.
- The exact text of what was accepted. "I agree to receive news and promotions on WhatsApp" is different from accepting generic terms of use — keep the specific phrase, not just the fact that "you accepted something".
If consent is later revoked, record that too — and stop sending marketing messages to that contact from then on. A “do not contact” label on the conversation itself, crossed with the origin, covers most of what a small business needs to show if questioned.
The right to opt out: easy unsubscribe and data minimization
The LGPD guarantees the holder the right to revoke consent at any time, and the practical rule is simple: leaving must be as easy as entering[1]. On WhatsApp, this usually means a keyword — "STOP", "QUIT" — that removes the person from the messaging list for real, not as a decorative formality in the footer of a message that no one processes. If you use a keyword chatbot, it's worth configuring this trigger as one of the first automatic responses in the flow.
Unsubscribing from a marketing message is not the same as deleting the customer from your system: if there is another legal basis for maintaining the registration (invoice, contractual or tax obligation), the registration can continue to exist — what needs to stop is the sending of a promotional message to those who asked to leave.
The other side of the same coin is data minimization: keep only what you need when sending messages. For most businesses, name and telephone number are enough — asking for CPF, full address or date of birth without a clear purpose for this data is an unnecessary risk, it is not zealous.
LGPD is the law; WhatsApp policy is another layer — the two count separately
Even with perfect and documented opt-in, WhatsApp can act on its own: Meta's messaging policy prohibits unsolicited mass contact and can suspend a number due to the volume of reports, without asking whether there was a legal basis behind the sending[2]. And the reverse is also true — following WhatsApp's policy and not being banned does not mean being compliant with the LGPD. There are two independent layers: a legal layer, applied by a data protection authority; another platform, applied by the company that owns WhatsApp. Being clean in one does not replace the other, and each one punishes for a different reason.
Checklist before running the next campaign
- Segment before sending messages. Only those who have an identifiable opt-in — form, conversation initiated by it or related purchase — enter the campaign.
- Offer exit on first message of any new campaign, with a word that really works.
- Never buy a ready-made list from a third party — the cost of a mass report, legal or platform, is greater than that of any list.
- Review the base periodically: remove anyone who never responded in months and anyone who asked to leave.
- Filter by tag before sending. No Zapext trigger, you can segment by tag and exclude those marked as "do not contact" before any mass sending goes out.
Nothing in this article replaces legal guidance: LGPD applied to a real case — especially when the basis used is legitimate interest — requires specific analysis, and the company's history also weighs in this assessment. If your message sending already has a relevant volume, it is worth reviewing the list base with a lawyer or DPO before growing it further. What can be resolved today, without depending on anyone: label the database by origin, ensure that the output word actually works and stop buying ready-made lists. A Zapext extension helps organize this control — labels, CRM Kanban and segmented sending, from R$29/month with a 7-day guarantee —, but the legal basis for sending messages remains the responsibility of the sender, not the tool.
Sources
- [1] Guia Orientativo — LGPD para pequenas empresas — ANPD (Autoridade Nacional de Proteção de Dados) (2022). accessed 2026-05-19.
- [2] WhatsApp Business Messaging Policy — WhatsApp (2024). accessed 2026-05-19.
Frequently asked questions
Do I need authorization to send a WhatsApp message to a customer?
In practice, yes: the LGPD requires a legal basis for processing name and telephone number, and this usually means explicit consent or legitimate interest justified by a relationship that already exists. Customers who filled out the acceptance form, initiated the conversation or purchased and provided the contact number regarding the purchase have a defensible basis. Cold contact from a list purchased from a third party, generally no.
Does a customer who has already purchased from me need to sign something new to receive a message on WhatsApp?
For messages about the purchase itself — confirmation, delivery, support — legitimate interest is usually sufficient, without requiring a new opt-in. For offers of other products or marketing campaigns that are not directly related to the purchase, the safest option is to have explicit consent. The line between the two situations is not always obvious, and it is worth confirming with a specialist in cases of doubt.
Can I buy a list of numbers and send messages via WhatsApp?
This is the highest risk scenario: without a prior relationship with whoever is on the list, there is no legal basis supporting the sending by the LGPD, and the message also tends to conflict with WhatsApp's policy against unsolicited mass contact. Scraping group or social media numbers has the same problem — joining a group does not constitute consent to receive a private message.
How do I prove that the customer authorized to receive my messages?
Keep three pieces of information per contact: the origin (form, campaign, purchase), the date and time of acceptance, and the exact text of what was accepted — a generic acceptance of terms of use is not enough. A spreadsheet or a tag in the conversation itself solves this for most small businesses.
Am I obliged to offer an unsubscribe option on WhatsApp?
The LGPD guarantees the holder the right to revoke consent at any time, and the practical rule is that leaving needs to be as easy as entering. On WhatsApp, this is typically a keyword like "STOP" that actually removes the person from your messaging list — not just a decorative warning that no one processes.
