Adding a Customer to a WhatsApp Group Shows Everyone Their Number
WhatsApp is an electronic communication, so section 69 applies in full. But the channel has three problems email does not, starting with groups.
General information, not legal advice, and not reviewed by a lawyer. Meta's platform rules in particular change without notice and are not a guide to your legal position, so check the current policy rather than this page.
The channel South African business actually runs on
Bookings, quotes, order confirmations, delivery photographs, after-hours emergencies and a great deal of marketing all move over WhatsApp here in a way they do not in most countries. It is the default, not a side channel.
Which makes it worth being precise about, because the general rules for electronic marketing are covered in section 69 and cold outreach and we are not going to repeat them. This page is about the three things WhatsApp does that email does not: it exposes phone numbers to strangers, it has two entirely different products people confuse, and it comes with a second rulebook that is not the law.
Section 69 applies, and this is not really arguable
Section 69 restricts direct marketing by means of any form of electronic communication, which POPIA defines as any text, voice, sound or image message sent over an electronic communications network and stored in the network or the recipient's device until collected.
A WhatsApp message is a text, voice, sound or image message, sent over a network, sitting on a handset until read. The Information Regulator's direct marketing guidance has taken an expansive view of the category, extending it to platform direct messages and even to telephone calls. Nobody sensible is arguing WhatsApp falls outside it.
So the same structure applies as for email. Consent, requested once and substantially in the terms of Form 4, or the existing customer exception in section 69(3). The channel changes nothing about the basis you need. What it changes is everything about how easily you breach the rest of POPIA while using it.
Groups are a disclosure, not a mailing list
This is the one worth stopping on.
When you add a customer to a WhatsApp group, every other member of that group can see their phone number, and usually their profile name and photograph. You have not sent that customer a message. You have disclosed their personal information to every other person in the group, most of whom are strangers to them.
A phone number is personal information under section 1. Disclosing it to third parties is processing, and it needs a ground under section 11 and a purpose under section 13. "I wanted an efficient way to announce our specials" is neither.
The practical consequences are worse than the theory. Group members can and do message each other privately. Competitors join. A customer of a debt counselling service, a clinic or a legal practice has now been identified as such to everyone else on the list, which is a disclosure that may reveal something about them they would never have volunteered.
A broadcast list is the correct tool. It sends individually, recipients cannot see each other, and it is structurally the WhatsApp equivalent of BCC. It has one quirk: a broadcast only reaches people who have saved your number. That is a limitation, but it is also a rough proxy for interest.
The same problem arises outside marketing. We have written about it for parent groups at schools and for the clinical group at a practice. Groups of people who already know each other, like one class's parents, are a much softer case than a group of unrelated customers assembled by you.
Two different products, two different problems
People say "WhatsApp Business" to mean two things that behave differently.
The WhatsApp Business app is the free one on a phone. Messages are sent by a person, broadcast lists cap out, and there is no approval process. Everything above applies and nothing further.
The WhatsApp Business Platform, the API, is what sits behind bulk and automated messaging, usually through a provider. Here, business-initiated messages outside a 24 hour window must use templates that Meta approves in advance, and Meta requires you to hold an opt-in before you send them.
That opt-in requirement is the source of the most common misunderstanding in this area, and it deserves its own heading.
Meta's rules are not POPIA, and satisfying one is not satisfying the other
Businesses on the API often assume that because Meta demanded an opt-in, approved the template and let the message through, the message is lawful. It is not the same question.
Meta's policy is a commercial condition of using their platform. Section 69 is South African law. They overlap without matching:
- You can satisfy Meta and breach POPIA. A tickbox on a web form saying "I agree to receive updates on WhatsApp" is a perfectly good opt-in as far as Meta is concerned. Section 69(2) requires a consent request made substantially in the form of Form 4, which asks for considerably more.
- You can satisfy POPIA and still be blocked by Meta. A properly consented list means nothing if your template is rejected or your number gets rated poorly because people report it.
- Meta does not check your legal basis. Template approval is a review of content and category, not of whether you were entitled to message that person.
Treat them as two gates in series. Your provider will help you through the first and has no interest in the second.
Answering a customer is not marketing
Worth saying plainly, because the rules above make people nervous about ordinary business.
Section 69 is about direct marketing. A customer who messages you asking about stock, and gets an answer, is not being marketed to. Sending a quote that was requested, confirming a booking, sending an invoice or telling somebody their order is ready are service communications arising from the transaction. None of that needs a Form 4.
Meta's 24 hour customer service window is a related but separate idea: it is their rule about when you may reply freely rather than by template. Do not mistake the window for a legal permission. It says nothing about whether you may switch from answering a query to promoting something else, and that switch is where a service conversation becomes marketing.
The line is purpose. If the message exists to sell something they did not ask about, it is marketing, whatever thread it arrives in.
The existing customer exception works here too
Section 69(3) lets you market to someone who has already bought from you, on conditions: you obtained the number in the context of a sale, you are marketing your own similar products or services, and you gave them a reasonable opportunity to object both when you collected it and in every message since, free of charge.
On WhatsApp the third condition is the one that gets skipped, because there is no unsubscribe link. You have to build one. A line at the end saying to reply STOP, honoured properly and permanently, is the accepted equivalent. Two things make it real rather than decorative: somebody has to actually monitor for those replies, and the removal has to persist when you next export the list from your point of sale system.
The number itself, and where it ends up
- Where did you get it? Numbers scraped from Facebook groups, community directories or a WhatsApp group somebody else runs have no basis behind them, and this is the single most common way South African businesses build a list.
- Meta is processing it. Contact details you upload for messaging are processed by Meta on infrastructure outside South Africa, which is an offshore transfer under section 72 as well as an operator relationship under section 21. Your bulk messaging provider is a second operator in the same chain.
- Keep the evidence. If consent is your basis, you need to be able to show it later: what was asked, when, and what the person agreed to. A screenshot or a timestamped record against the customer is enough. Remembering that they said yes is not.
- Personal phones. If staff message customers from their own handsets, the customer list leaves with the employee. That is worth a policy before it is worth a dispute.
A short checklist
- Are you using groups where a broadcast list would do?
- If you use groups, can members see each other's numbers, and would any of them mind?
- Do you know whether you are on the Business app or the API, and who your provider is?
- If you rely on consent, was it requested substantially in the terms of Form 4?
- If you rely on the customer exception, did the number come from a sale, and is what you are sending genuinely similar?
- Does every marketing message carry a working way to opt out, and does somebody watch for the replies?
- Do opt-outs survive the next list export?
- Can you produce evidence of consent for a given number?
- Does your privacy notice mention WhatsApp and the offshore processing behind it?
POPIA Ready generates a privacy policy that covers marketing consent and offshore processing, plus six other documents customised to your business, free to preview. The free checklist will show you what else is missing.
General guidance on South African law as at September 2026, not legal advice. Meta's platform policies change without notice and are not a guide to your legal position, and a business running large-scale messaging deserves a professional opinion.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview