PDPA fines are escalating. Malaysia's enforcement agencies have moved past warnings—they're now issuing penalties for companies that send WhatsApp invoices, promotions, or sales messages without documented opt-in consent. What most businesses miss: it's not just the consent moment. Regulators audit the entire chain: how you captured permission, how long you kept the data, whether your audit trail survives inspection, and whether your platform even logs who did what and when. If you're using WhatsApp to send invoices, payment reminders, or sales follow-ups, you need to run this audit before regulators come looking. Most teams skip four critical steps. This checklist catches them. Why PDPA audits fail: The four gates regulators check PDPA enforcement doesn't look for perfection. It looks for documentation. A regulator's audit trail question is simple: Can you prove this customer opted in, and can you show the date, time, and method? If you can't, the burden shifts to you. Same with retention: Why are you still holding this contact's phone number if they haven't transacted in 18 months? And with archival: Can you produce every message sent to this contact in the past 24 months? Most WhatsApp deployments fail on one or more of these: Consent capture method. Verbal opt-in during a phone call, a checkbox buried in T&Cs, or a link in an email doesn't meet the standard. PDPA requires explicit, documented consent specifically for WhatsApp messaging. Generic 'contact me' does not cut it. Archival completeness. WhatsApp's native API does not retain message history. You must integrate a third-party archival layer, or every message older than 30 days vanishes. Regulators ask for 12–24 months of proof. If you can't produce it, assume the violation stands. Data retention logic. Keeping a contact's phone number indefinitely without re-consent or transaction activity is a violation. You must document a retention policy and enforce it: delete or re-consent every 12–18 months if there's no business purpose. Audit trail formatting. Your system must log who accessed contact data, when, why, and what they did. A spreadsheet export or a native WhatsApp chat history does not count. Regulators need structured, tamper-proof logs. The 14-day audit checklist Run this before your next invoice campaign. Each item is a binary gate—you either pass or fail. If you fail more than one, pause and remediate. Days 1–3: Consent audit Locate your consent records. Export every contact you've messaged on WhatsApp in the past 12 months. For each one, find the original opt-in document. Is it an email, a form submission, a call recording, a purchase order? List the method and date. Check specificity. Does the consent document explicitly mention WhatsApp, or does it say 'contact via SMS/email/phone'? Generic consent fails. You need WhatsApp-specific language. If 80%+ of your contacts don't have WhatsApp-specific consent, flag this as a risk. Verify date recency. Any consent older than 24 months is a re-consent candidate. If a customer bought once in 2022 and you're still messaging them in 2025 without a fresh opt-in, that's a violation. Count how many contacts fall into this bucket. If it's more than 10% of your list, you have a compliance debt. Days 4–6: Archival audit Test your message history export. Pick three random customer accounts. Export every message sent to them via WhatsApp in the past 90 days. Does your system produce a complete, timestamped, machine-readable export? (CSV or JSON with fields: sender, recipient, message text, timestamp, delivery status.) If you can't export this in under 10 minutes per customer, your archival system is broken. Check metadata completeness. For each message, verify that the export includes: exact timestamp (to the second), unique message ID, delivery status (sent/read/failed), and any attachments. Missing metadata is a red flag. Regulators will ask you to prove the message was actually delivered. Verify retention window. Native WhatsApp API does not archive messages. If you're relying on WhatsApp's own chat history, you have zero archival past 30 days. This is a blocker. You must integrate a messaging platform with built-in archival or accept that you cannot comply with audits older than one month. Days 7–9: Data retention audit Document your retention policy. Write down: 'We retain WhatsApp contact data for [X months] from last transaction or re-consent date.' If you don't have a written policy, create one now. This is your defense in an audit. Identify dormant contacts. Pull a list of everyone in your WhatsApp contact database who has not transacted, opened a message, or re-consented in the past 18 months. If this list is 5%+ of your active contacts, you have a cleanup job. Plan a soft re-opt-in campaign or deletion batch. Verify deletion mechanism. When you decide to delete a contact, can your system actually delete it from WhatsApp, your CRM, and your archival logs simultaneously? If deletion is manual or