Malaysia's Personal Data Protection Act (PDPA) does not pause for convenience. If you are routing customer WhatsApp conversations through a third-party messaging platform—Respondio, Twilio, or even the native WhatsApp Business API—you inherit specific consent, liability, and audit obligations. Most teams skip this. They launch fast, log nothing, and discover a gap only when PDPC calls. This 14-day audit prevents that. Why PDPA audits fail before they start PDPA compliance for WhatsApp sales is not a checkbox. It is a chain: consent must be captured before the first message, routing platforms must be contractually liable for data they touch, audit logs must prove what happened and when, and data retention must have a documented end date. Break any link, and you expose the company to enforcement notices and financial penalties. Most teams treat WhatsApp as a casual channel. They assume that because the customer initiated contact (often via WhatsApp directly), consent is automatic. It is not. The PDPA distinguishes between consent for marketing and consent for processing via a specific vendor. If you route a customer's number and conversation history through a platform the customer did not explicitly agree to, you have breached the Act. The four PDPA checkpoints for routed WhatsApp messaging 1. Consent capture: explicit, documented, and channel-specific Before a single sales message goes out, verify that the customer has consented to: Marketing contact via WhatsApp (not just 'contact' in general) Data processing by your routing vendor (by name, if possible—e.g., 'Respondio' or 'Twilio') Retention of conversation history for the duration you claim Automated analysis or AI tagging of their messages (if your platform does this) Most consent forms say 'we may contact you via WhatsApp.' That is too broad. PDPA requires consent to be specific and unambiguous . A compliant consent record should read: 'I consent to sales contact via WhatsApp, including through Respondio's platform, for 90 days after purchase.' Document how you captured consent: a checkbox on signup, a WhatsApp message they replied 'yes' to, a phone call log. Keep these records for at least three years. If PDPC audits you, the absence of a consent record is fatal. 2. Vendor liability: the data processing agreement (DPA) If your WhatsApp routing platform is not owned by your company, it is a data processor under PDPA. You remain the data controller. The difference matters legally. Before you sign up or migrate to a platform, verify that your contract includes: Data Processing Agreement (DPA) or equivalent: states that the vendor processes data only on your instruction Sub-processor disclosure : the vendor must tell you if they use other vendors (e.g., Respondio using AWS) Data security obligations : encryption, access controls, breach notification within 72 hours Data deletion on termination : vendor deletes your data and your customers' data within a defined period (30 days is standard) Audit rights : you can audit the vendor's PDPA compliance If the platform's terms do not include a DPA, negotiate one or walk away. Many vendors in the Southeast Asia messaging space do not have one by default; asking often triggers a conversation that results in a DPA addendum. If they refuse, they are signalling they do not take data protection seriously. 3. Audit logging: prove what was processed, when, and by whom PDPA requires you to demonstrate that data was handled correctly. This is not optional. Audit logs are your only evidence if a dispute arises. Your WhatsApp routing platform should provide: Message send/receive logs : timestamp, customer phone number, message content (if retrievable), sender ID Consent audit trail : when the customer opted in, which channel, which consent form version they saw User access logs : which team member accessed which customer record, when, for how long Data export/deletion logs : when customer data was exported, deleted, or archived Vendor action logs : if the vendor takes an action (e.g., flagging a message as spam or applying an automated tag), log it Extract and store these logs monthly. Do not rely on the platform to keep them forever—most platforms offer only 12–24 months of retention. If you need a 5-year audit trail (which PDPC may request), you must download and archive it yourself. 4. Data retention: set a date, document it, stick to it PDPA prohibits indefinite storage. You must define how long you keep each category of data and why. For WhatsApp sales conversations, a defensible policy might be: Active customer: keep full chat history and phone number while the relationship is active (usually defined as last contact within 90 days) Post-sale retention: keep message content for 1 year for dispute resolution, then anonymize (remove phone number, message text) Prospect who never converted: delete after 6 months unless they explicitly opt into a mailing list Opt-out requests: delete within 7 days of request (put this in y