Compliance · 5 min read
WhatsApp Business Policy Compliance (2026): The Rules That Matter
Most compliance advice for this channel is a list of rules, which is the least useful form it could take. The rules change, the list ages, and a business following a summary from eighteen months ago is following something that has quietly stopped being true.
What does not age is the map: which documents govern which part of your operation, who owns each one, and what a sensible business does to stay current. That is what this is.
The layers, and who owns each
- The platform's own business messaging policy. Meta's rules about what may be sent, to whom, with what consent. Owned entirely by Meta, applies identically to every vendor, and no tool grants an exception to it.
- The commerce rules. A separate set governing what may be sold or promoted through business messaging. Certain categories of goods and services are restricted in ways that surprise people, and the restriction is upstream of your tooling.
- Template and category rules. How messages that open a conversation must be structured and classified, and what content gets refused at review. Also Meta's, and revised more often than the rest.
- The terms you signed. With Meta, and separately with your solution provider if you use one. These cover liability, data handling and what happens if the number is suspended.
- The law where your customers live. India's DPDP Act if they are here, GDPR if some are in Europe, and whatever applies wherever else you sell. This layer is not Meta's, does not appear in any vendor's dashboard, and outranks all of the above.
The confusion that causes real damage is treating layer five as a subset of layer one. It is not. Satisfying Meta's policy does not discharge a legal obligation, and no vendor's compliance page can.
Meta can stop you sending. The law can do considerably more than that, and it does not read your dashboard.
The one thing that is true across every layer
If you strip all five documents down, the same requirement is underneath most of them: the person receiving the message agreed to receive it, for the purpose you are using it for, and can change their mind easily.
Consent, purpose limitation, revocability. Get those three right and most of what any of these documents asks of you is already satisfied. Get them wrong and no amount of correct template formatting saves you.
What a tool can and cannot carry for you
Software can hold
Only you can hold
A vendor selling "compliance" as a product badge is selling something nobody in this category can sell, because the right-hand column is where the obligations actually sit and no software makes those decisions. What a good vendor can honestly offer is the left-hand column, and it is worth asking for each item by name during evaluation.

A routine that actually keeps you current
Four habits, none of which requires a compliance team.
Give it an owner. One named person whose job includes reading the source documents. Not a committee, not "everyone". The failure mode of shared responsibility here is total.
Re-read at a fixed interval. Once a quarter, open the policy pages themselves rather than a newsletter about them, and skim for what changed. It takes an hour and it is the single highest-value hour in this whole topic.
Keep a change log. Three lines each time: what changed, what we do differently now, when we made the change. When something goes wrong two years later, this file is the difference between a defensible position and a guess.
Subscribe to the vendor's change notices and read them sceptically. A provider will usually tell you when the platform changes something that affects you. They will describe it in terms of their product, which is not the same as in terms of your obligations.
The specifically Indian layer
If your customers are in India, the DPDP Act applies to how you handle their personal data, and a phone number and a conversation history are both personal data. What that means for your notice, your consent record, your retention period and who inside your business may read a thread depends on facts about your business that no blog post knows.
We are not lawyers and this is not legal advice. Take your own — the DPDP post explains why that sentence is unavoidable rather than defensive.
Where we actually stand
PostEngage does not ship WhatsApp, so none of these layers currently applies to anything you would run with us on that channel.
On Instagram, where we do run, the corresponding mechanics exist and are worth stating plainly because they are what we would carry across: the official Graph API only, a fixed gate of ten named checks before every reply, a recorded reason for every refusal, named staff accounts rather than a shared login, a downloadable export, and an erasure that walks the same list of tables the export does so the two cannot drift apart.
If the recipient's-eye view of what earns a complaint is what you need, the spam post covers it. If you want the data inventory instead of the policy map, that one is here.



