Consent-Compliant WhatsApp Bulk Messaging (KVKK/GDPR)

≈ 9 min read

Sending WhatsApp bulk messages is not banned by law; sending them without permission is. A recipient's phone number is personal data, so processing it falls under data-protection law — Turkey's KVKK (Law 6698) and, for EU recipients, the GDPR. If your message is promotional, Turkey's Law 6563 and the İYS registry also apply. This guide explains consent, the service-message exception, opt-out and GDPR in plain language, then boils it down to four practical rules.

Important legal notice: This article is general information and not legal advice. Laws and regulator decisions change; for your specific case consult a qualified lawyer or data-protection specialist. Responsibility always rests with the sender acting as data controller.

1. Why a phone number is "personal data"

Any information that makes a person identifiable, directly or indirectly, is personal data. A phone number sits right at the centre of that definition because it lets you reach one specific individual. So loading numbers into a list and messaging them in bulk is, legally, a personal-data processing activity that needs a lawful basis.

Data-protection law offers several bases: consent, performance of a contract, a legal obligation, legitimate interest and so on. In practice, the safest and most common basis for marketing messages is explicit consent. For the broader "is it legal at all?" question, see is WhatsApp bulk messaging legal.

Valid consent has three ingredients, and all three must be present:

  • Specific: Vague, blanket "for any and all processing" consent is invalid. The person must know exactly what they agreed to (e.g. "campaign announcements").
  • Informed: Before consenting, the person must be told who processes what data, for what purpose, and what their rights are.
  • Freely given: Consent can't be a precondition for a service. "No consent, no account" removes the free-will element and voids the consent.

A crucial distinction: someone giving you their number does not mean they agreed to receive marketing. A number collected on a business card, an order form or during a booking may only be used for that original purpose. Marketing needs a separate, explicit opt-in.

Tip: Keep consent provable. Store when it was collected, with what wording, and through which channel (web form, wet signature, double opt-in email). The burden of proof is on you — saying "they agreed" isn't enough; you have to show it.

3. Commercial electronic messages (6563) and İYS

Messages that promote, advertise, congratulate or run a campaign are commercial electronic messages under Turkey's Law 6563. They require the recipient's prior consent, and both those consents and any opt-out requests are recorded in İYS (the Message Management System).

İYS is an official consent pool covering electronic channels alongside SMS, email and phone calls. If you are a business sending marketing bulk messages to recipients in Turkey, consent is expected to be logged in İYS and, when a recipient opts out, that choice must be honoured across channels. Once someone opts out, sending must stop within three business days at the latest.

Message typeConsent / İYS opt-inExample
Marketing / campaignRequired"20% off starts now"
Service / transactionalNot required (exception)"Your order has shipped"
Appointment / reminderNot required (requested service)"You have a 2 PM appointment tomorrow"
Notice with hidden promoCounts as marketing if mixedAdding a discount to a shipping note

4. The service-message exception: the most misunderstood point

Notifications that result from something the person themselves requested are not commercial messages. Order confirmations, shipping updates, appointment reminders, dues/payment notices and back-in-stock alerts fall into this exception. They need no separate marketing consent because they are the performance of a service, not promotion.

But the line is thin: add a discount, campaign or cross-sell line to a service message and the whole message becomes commercial and loses the exception. The golden rule is one message, one purpose. An order notice should mention only the order; an appointment reminder only the appointment. For these scenarios in detail, see e-commerce order and shipping notifications and appointment reminders.

5. Opt-out belongs in every message

The right to object is the shared backbone of both KVKK and Law 6563. Every marketing message must give the recipient an easy, free way out. On WhatsApp the most practical route is a simple instruction at the end of the message:

"If you no longer want these updates, just reply STOP." — that single line satisfies the legal duty and lowers your complaint rate, which in turn lowers your ban risk.

Always act on incoming "STOP / CANCEL / UNSUBSCRIBE" replies: remove the person from the list, update the İYS opt-out record, and never send them marketing again. The cleaner and more willing a list is, the lower both your legal exposure and your spam-complaint-driven WhatsApp ban risk. For the technical side of that relationship, see rules to avoid a ban.

6. GDPR: an extra layer for EU recipients

If any of your recipients are in the European Union, the GDPR applies too. Its logic closely mirrors KVKK: a valid lawful basis (consent for most marketing), transparent notice, data minimisation, rights of erasure and access, and easy withdrawal. In practice, a well-documented, KVKK-compliant consent flow already covers most GDPR requirements — though international data transfers and topics like a Data Protection Officer may need extra assessment.

7. The data-protection advantage of self-hosting

The system described on this blog is a QR-based, open-source setup that runs on your own server — it uses whatsapp-web.js, not the official Business API. From a data-protection angle the most concrete benefit is that your contacts and message history stay on a server you control instead of a third-party SaaS cloud:

  • Fewer data transfers: Personal data doesn't flow to an external panel, shortening your chain as the data controller.
  • Retention control: You decide how long data is kept and when it is deleted.
  • Accountability: The server can sit in Turkey or your chosen jurisdiction, reducing cross-border-transfer questions.

This advantage doesn't remove responsibility — server security, access controls and backups are now your job. For the architecture, see the self-hosted messaging system. We cover nonprofit-specific scenarios in nonprofit WhatsApp notifications.

8. Practical summary: four rules for compliance

  1. Collect and prove consent. For marketing, get specific, informed, freely-given consent; record when and how it was collected, and log it in İYS where required.
  2. Separate the purpose. Never mix a service notification with marketing in the same message — one message, one purpose.
  3. Make leaving easy. Put an opt-out line in every marketing message ("reply STOP") and act on opt-outs immediately.
  4. Protect the data. Keep the list current and willing, don't store data you don't need, secure your server — and host the data under your own control where you can.

The right template wording makes these rules easy to apply. For personalised, single-purpose examples that include an opt-out, see bulk message templates, and the main guide that ties every topic together.

Reminder: This system is designed only for sending legitimate notifications to people whose consent you already have. Blasting purchased or scraped lists violates both WhatsApp's terms and KVKK/6563 and can lead to administrative fines. Legal compliance is not a technical feature — it is your responsibility.

Frequently asked questions

Is sending WhatsApp bulk messages against data-protection law?

What's unlawful is not bulk messaging itself but sending without a legal basis. A phone number is personal data, so processing it needs a lawful ground — usually explicit consent for marketing. With consent, an opt-out and a transparent purpose, bulk messaging is legal.

Do I need consent for order and appointment notifications?

No. Order confirmations, shipping updates and appointment reminders are the performance of a service the person requested and fall outside the commercial-message definition. They need no separate marketing consent, but the message must stay strictly about that service.

What is İYS and does it apply to WhatsApp?

İYS is Turkey's official registry for the consent and opt-out records of commercial electronic messages, covering electronic channels as well as SMS, email and calls. If you send marketing bulk messages in Turkey, consent is expected to be logged in İYS and opt-outs honoured. Service notifications are out of scope.

Is self-hosting an advantage for data protection?

Yes. In a self-hosted system your contacts and message history stay on a server you control rather than in a third-party SaaS cloud, which reduces data transfers and simplifies accountability. You remain responsible for server security, retention and access controls.

Message your opted-in list with confidence

Keep the data on your own server with an open-source, self-hosted system that makes compliance easier. Deploy it, scan the QR, send your consented notifications.

Open the panel →