WhatsApp Business API has become the fastest sales channel in Southeast Asia. Customers expect quotes in minutes, not emails in hours. But speed and compliance are not opposites—they just require the right routing, consent, and audit rules built in from the start. If you're sending sale confirmations, payment requests, or deposit links over WhatsApp without documented consent and audit trails, PDPA fines in Malaysia, PGDA in Singapore, and GDPR-adjacent laws in Indonesia will find you. This guide walks you through the exact routing, consent, and logging rules that let you accelerate sales without regulatory risk. The PDPA consent trap: Why 'they gave us their number' isn't enough Most sales teams treat a WhatsApp number as permission to message. That assumption has cost companies across Southeast Asia six-figure fines. PDPA (Personal Data Protection Act in Malaysia), PDPA-equivalent laws in Singapore and Indonesia, and similar frameworks require explicit consent for each channel and message category . A phone number from a form does not automatically grant you permission to send sales messages, payment reminders, or contract links over WhatsApp. The rule is strict: consent must be opt-in, recorded, and linked to a specific use case . 'SMS reminders' is not the same as 'WhatsApp payment links.' 'Marketing emails' is not the same as 'deposit confirmations.' If your prospect fills out a contact form and ticks 'I agree to be contacted,' you have permission for one channel. Adding a second message on a different platform requires a new consent record. Here's the compliance skeleton that works: Consent capture at entry: When a prospect lands on your website, booking, or form, ask explicitly: 'May we contact you about your booking via WhatsApp?' Capture the timestamp and their response. Channel-specific consent: Keep separate consent records for SMS, WhatsApp, email, and phone calls. A 'yes' to one does not mean 'yes' to all. Use-case specificity: 'Sales updates' and 'payment collection' should be separate consent records. Deposit confirmations can go to those who opt in for 'transaction updates,' but not to those who only opted in for 'promotional offers.' Easy opt-out: Every WhatsApp message must include a way to unsubscribe (usually a reply mechanism or a link within the message, depending on the message type). Consent is the foundation. Without it, routing architecture doesn't matter. Build consent capture into your booking, form, and CRM from day one, not as an afterthought when you scale. Routing rules: Which messages go where and why Not all sales messages belong on WhatsApp. The compliance sweet spot is transactional and time-sensitive messages : deposit confirmations, payment reminders, quote delivery, and contract signing links. These messages are expected, tied to a specific customer action, and have clear business purpose. Promotional spam is not. Here's the routing logic your system should enforce: Transactional messages (WhatsApp, always allowed if they consented) Booking confirmation: 'Your booking for [date] is confirmed. Deposit link: [link]. Questions? Reply here.' Deposit/payment reminders: 'Your deposit is due by [date]. Link: [link].' Follow-ups at +24h, +48h, +72h, then escalate to phone or email. Quote delivery: 'Your quote for [project] is ready: [link or inline]. Valid until [date].' Contract/e-signature link: 'Please sign your contract here: [link]. Expires [date].' Payment confirmation: 'Payment of [amount] received. Invoice: [link].' Appointment reminder: 'Reminder: Your appointment is [date/time]. Reply to confirm.' Messages that should NOT go via WhatsApp Promotional campaigns (no clear transactional trigger). Newsletters and updates (unless specifically opted in for WhatsApp updates). Bulk outreach (cold prospecting, mass follow-ups). Messages to contacts without documented WhatsApp consent. Use your unified messaging platform to enforce these rules. Set up rules that prevent promotional templates from routing to WhatsApp, and require explicit consent records before any transactional message is sent. This is not just compliance—it's also better UX. Customers expect WhatsApp to be fast and relevant, not noisy. Audit trail: Logging what you send, when, and to whom PDPA auditors do not care about intent. They care about evidence. If you cannot show when you captured consent, to which channel, for which use case, and which messages were sent and delivered , you lose. Regulatory fines start at RM250,000 (≈$54,000 USD) in Malaysia and scale upward. Your audit trail must capture and retain: Consent timestamp and channel: When did the customer opt in to WhatsApp messages? Save the exact date and time, the form or page they were on, and their IP address if possible. Consent category: Did they consent to 'transactional messages,' 'promotional messages,' 'payment reminders,' or all three? Be specific. Message metadata: For each message sent—timestamp, recipient phone number, message content or