Sales Outreach Compliance: GDPR, Consent and WhatsApp
Last verified: 2026-10-05A practical map of which rules apply to automated outbound, which ones bite first, and the one obligation almost nobody sends.
You automated outbound, and now you are not sure what you are breaking. The honest answer is that sales outreach compliance under GDPR is rarely the thing that stops you first. The channel rules do: ePrivacy and PECR for email, Meta's own policy for WhatsApp, platform terms for LinkedIn. GDPR sits underneath all of them and asks a different question — not "may I send this message" but "may I hold this person's data at all."
Get those two layers in the right order and the rest is paperwork. Get them backwards and you will spend a week building a consent flow you did not need while ignoring the notice you actually owe.
This is a map, not legal advice. Every claim below links to a primary source, and the places where the sources are thin are marked as thin.
Sales outreach compliance under GDPR starts with one question
Which lawful basis are you processing on? A business email address is personal data. So is a mobile number. You need a basis under Article 6 before you load the list, never mind before you send.
For cold B2B, the usual answer is legitimate interest, Article 6(1)(f). The EDPB's guidelines on it set three cumulative tests: the interest must be real and clearly articulated rather than hypothetical, the processing must be genuinely necessary for it with no less intrusive route available, and it must not be overridden by the individual's rights — judged partly on their reasonable expectations given their relationship with you.
Two things follow that teams get wrong.
Your vendor's compliance is not your basis. "Sourced from a GDPR-compliant provider" describes their processing, not yours. You still have to run and record your own assessment.
Necessity is a real test. If you can reach the same buyer through a channel that needs less data, the more intrusive route is harder to defend. Scraping twelve personal fields to write one line of personalization is the example that fails.
The channel rules bite before GDPR does
ePrivacy is the layer that decides whether a given message is allowed, and in the UK its implementation is PECR. The split that matters is who the subscriber is, not what you are selling.
The ICO's guidance is blunt: you can email or text any corporate body — a company, a limited liability partnership, a Scottish partnership, a government body — without specific consent. Sole traders and non-LLP partnerships are treated as individuals, so those need consent or the soft opt-in, which only covers people who bought or negotiated to buy something similar from you and were given a simple way out at collection and in every message since.
So ops@company.com and a freelancer's name@gmail.com sit on opposite sides of a legal line while looking identical in your CRM. If your list does not record which is which, you cannot show you got it right. The ICO also asks for a do-not-contact list for businesses that object — not strictly required for corporate subscribers, but it is the artifact a regulator looks for.
WhatsApp is stricter than the law, and that is the operative constraint
Here is the part the GDPR guides skip. Meta's WhatsApp Business Messaging Policy requires two things before you message anyone: that they gave you their mobile phone number, and that you "received opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from you."
That is a consent standard, not a legitimate-interest standard. It means a purchased mobile list fails on WhatsApp even in a jurisdiction where the equivalent email would be lawful. The policy also puts the burden on you to show the opt-in was collected in a way that complies with local law, and prohibits messaging that would "confuse, deceive, defraud, mislead, spam, or surprise" the recipient.
Enforcement is not a regulator with a three-year docket. It is Meta, and the remedy is your number's quality rating and template approvals.
What changed on 1 October 2026
Four days ago the economics shifted, and the compliance consequence is direct.
Meta's documentation confirms that from 1 October 2026 it charges per message for service messages — free-form replies sent inside an open customer service window — and for utility templates sent in reply inside that window. Both were free: service messages since November 2024, in-window utility templates since July 2025. The customer service window is 24 hours, and it "opens and resets with each user message." Marketing template rates are unchanged, and inbound messages stay free.
This sits on top of per-message billing, which replaced conversation-based billing on 1 July 2025.
Why it belongs in a compliance article: the free in-window reply was the thing that made sloppy opt-in cheap. You could blast templates, absorb the mess in free conversation, and never feel it. From this month every reply to every conversation you provoked is a line item. Bad consent now has a unit cost, and it compounds exactly where volume is highest.
The honest caveat: Meta's main pricing page had not been updated to describe this change when I read it today, though the non-template pricing documentation had. Treat the figures from your BSP as the operative ones and check your own invoice.
The table
What you need, by channel and contact type. EU/UK framing; verify your own market.
| Channel | Corporate subscriber | Sole trader / individual | Who enforces |
|---|---|---|---|
| No specific consent needed; lawful basis plus opt-out still required | Consent, or soft opt-in from a prior purchase | Data protection authority | |
| Opt-in required by Meta policy regardless of entity type | Opt-in required; consent also the likely legal basis | Meta first, regulator second | |
| Platform terms and rate limits; exporting data to sequence it is a separate processing act | Same, plus individual-subscriber treatment if you move off-platform | ||
| Any AI-driven conversation | Disclose the AI under AI Act Article 50, applicable since 2 Aug 2026 | Same | Market surveillance authority |
The obligation almost nobody sends
If you did not get the data from the person, Article 14 says you must tell them you have it. Identity, purposes, lawful basis, the legitimate interests you are relying on, retention, where the data came from, their rights — and the deadline in 14(3)(a) is "within a reasonable period after obtaining the personal data, but at the latest within one month."
One month from enrichment, not from your first send. Most outbound stacks have no mechanism for this at all. The common workaround is to fold the Article 14 disclosure into the first message as a short line plus a link to a privacy notice written for prospects rather than customers. That is a one-time build and it is the single highest-leverage compliance task on this page.
There are narrow exemptions in 14(5), including disproportionate effort, but "we send a lot of email" is not what that was written for.
Two things that are absolute
An objection to direct marketing has no balancing test. Article 21(2) gives the right to object at any time, including to profiling connected to that marketing, and 21(3) says the data must then no longer be processed for those purposes. Full stop — unlike Article 21(1), there is no "compelling legitimate grounds" escape. Practically: suppression has to be global across every channel and every sequence, and it has to survive a re-import. A list refresh that resurrects an opted-out contact is the failure mode regulators find, because the person tells them.
And since 2 August 2026, AI Act Article 50 requires that people interacting with an AI system be informed they are, unless it is obvious from context. A WhatsApp thread that answers in fluent local language is not obvious from context. We wrote that one up separately in the EU AI Act Article 50 piece, and the full cross-channel reference lives in the outbound compliance handbook.
Pre-send checklist
Run this against your own stack, or against a vendor's.
- Lawful basis chosen and the legitimate-interest assessment written down, dated, and findable.
- Contact records flag corporate body versus sole trader or individual, and the sequence branches on it.
- WhatsApp sends gated on a recorded opt-in with its source and timestamp, not on possession of a number.
- Article 14 notice delivered within one month of obtaining the data, with a prospect-facing privacy notice behind it.
- Suppression global, instant, cross-channel, and immune to the next CSV import.
- AI disclosure present wherever an agent writes or replies.
- Opt-out in every message, and the sender identity never disguised.
- Someone named is accountable for all of the above. Not a tool.
Where BOSRAI fits, and where it does not
BOSRAI is a human-in-the-loop outbound platform with WhatsApp as a first-class channel, which means these constraints shaped the product rather than being bolted to it. Messages queue for a person's approval before they go out, which produces a reviewable record of who approved what; suppression applies across email, WhatsApp and LinkedIn rather than per-sequence; and the WhatsApp side is built on the opt-in model Meta's policy requires, which we covered in detail in the WhatsApp Business API guide. Tiers run from a free plan through Starter at $79.99, Growth at $199, Scale at $499 and Pro at $999, with annual billing discounted — current pricing is here.
The limits, stated plainly. No software makes you compliant: the lawful basis, the Article 14 notice and the accountability are yours, and any vendor claiming otherwise is selling you a liability. BOSRAI has no published case studies, customer logos or compliance certifications to point at, and this article is a map of primary sources, not legal advice — for a real assessment in your market, pay a lawyer. What a tool can do is make the right thing the default and the wrong thing require a deliberate override. That is the whole claim.
Sources
- Meta — WhatsApp Business Messaging Policy — the two-part opt-in requirement and prohibited messaging practices.
- Meta — upcoming pricing updates for service and utility messages — the 1 October 2026 change and the 24-hour customer service window.
- Meta — WhatsApp Business Platform pricing — per-message billing effective 1 July 2025; service conversations free from 1 November 2024.
- ICO — PECR guidance on electronic mail marketing — corporate subscribers versus individuals and sole traders, soft opt-in conditions.
- EDPB — Guidelines 1/2024 on legitimate interest, summary — the three cumulative conditions and reasonable expectations.
- GDPR Article 14 — information duty for indirectly collected data and the one-month deadline in 14(3)(a).
- GDPR Article 21 — the right to object to direct marketing, with no balancing test.
- EU AI Act Article 50 — AI interaction disclosure, applicable from 2 August 2026.