An email opt-in is not an SMS opt-in, and it is definitely not a WhatsApp opt-in
Four channels, four legal bases, one checkout form. What you can reuse, what you have to ask for again, and what auditors look at first.
The most expensive assumption in ecommerce marketing is that permission is a property of a person. It is not. Permission is a property of a channel, a purpose and a moment, and that is true under every serious regime — the EU's GDPR and ePrivacy rules, the US TCPA and CAN-SPAM, Canada's CASL, and the platform terms of Meta and the mobile carriers on top of them.
This is the part teams get wrong when they add a second channel. The email list is 40,000 people. The SMS list, honestly counted, is the few thousand who saw a phone field with a clear description of what it was for.
The EU: two laws stacked on each other
GDPR defines what valid consent looks like: freely given, specific, informed and unambiguous, given by a clear affirmative action, and as easy to withdraw as it was to give. Pre-ticked boxes do not qualify, and neither does a checkbox that bundles “newsletter, SMS and partner offers” into one line.
The ePrivacy Directive then governs the act of sending. Article 13 requires prior consent for unsolicited electronic marketing, with one narrow exception that most shops rely on without knowing its name: the soft opt-in. If you obtained the contact details in the context of a sale, you may market your own similar products to that customer, provided you offered a free and easy refusal at collection and in every message. Member states implement the detail differently, so the safe reading is the strict one.
- Soft opt-in covers your own similar products, not a partner's, and not an unrelated category.
- It applies to the person who bought, not to everyone who filled in a form.
- It does not survive the transfer of a list to another legal entity.
The US: email and SMS are governed by different statutes
CAN-SPAM regulates commercial email and works on an opt-out model: you may email without prior consent, but you must identify yourself, give a real postal address, honour an unsubscribe within 10 business days, and never use deceptive headers or subject lines.
SMS is a different world. The TCPA requires prior express written consent for marketing texts sent with an automatic dialling system, and the penalties are per message. The FCC's rule requiring one-to-one consent per identified seller was vacated by the Eleventh Circuit in January 2025, days before it would have taken effect — which changed the compliance deadline, not the underlying duty to get real consent. Carrier codes of conduct add their own requirements on top: disclosure of message frequency, “message and data rates may apply”, and working STOP handling.
Messaging platforms add a private rulebook
WhatsApp and similar business messaging channels are not just a legal question. Meta's business messaging policy requires an opt-in obtained through a channel the user recognises, stating the business name and that they will receive messages on WhatsApp. Template content is reviewed and categorised before it can be sent, and marketing templates can be paused or rejected for reasons that have nothing to do with the law and everything to do with platform quality scores.
Practically, this means your WhatsApp list can only ever be built deliberately. There is no bulk import that survives contact with reality.
Collecting four permissions without four forms
- One form, separate ticks. Email, SMS and WhatsApp each get their own unticked box with its own one-line description. Bundling is the single most common finding in enforcement decisions.
- Ask in context, not at checkout only. A back-in-stock alert is the best possible moment to ask for SMS, because the value is obvious and immediate.
- Record everything. Timestamp, IP or device, form version, the exact wording shown, and the source page. Store it next to the profile, not in a log that rotates away.
- Make withdrawal symmetric. If it took one click to subscribe, one click has to remove it. A login wall in front of an unsubscribe page is a finding waiting to happen.
- Sunset quietly. Consent does not formally expire in the EU, but regulators expect it to be refreshed when it goes stale, and deliverability punishes old addresses long before a regulator notices.
What an auditor opens first
In our experience of migrations, three things get checked before anything else: whether the consent record survived the move from the previous platform, whether the unsubscribe link works without a login, and whether a single tick ever created more than one permission. Everything else is negotiable. Those three are not.
The honest summary: a smaller list with a clean record is worth more than a big one you cannot defend, because the big one will not deliver anyway.
Sources and further reading (9)
- GDPR Article 7 — Conditions for consent
- GDPR Article 4(11) — Definition of consent
- Directive 2002/58/EC (ePrivacy), Article 13 — Unsolicited communications
- EDPB — Guidelines 05/2020 on consent under Regulation 2016/679
- FTC — CAN-SPAM Act: A compliance guide for business
- FCC — Telephone Consumer Protection Act rules
- Insurance Marketing Coalition v. FCC (11th Cir., January 2025) — one-to-one consent rule vacated
- Government of Canada — Canada's Anti-Spam Legislation
- Meta — WhatsApp Business Messaging Policy
Checked on 21 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
Four permissions, one profile, one audit trail
Auralata keeps a separate consent state for email, SMS, WhatsApp and Viber on every profile, with the timestamp, the source and the exact wording that was shown. Campaigns can only target the channel that was actually agreed to.