WhatsApp is where your customers already are. But the moment you ask for a tax ID—NPWP in Indonesia, or proof of business registration in Malaysia—you enter compliance territory. Tax authorities want audit trails. Customers want privacy. Your invoicing software wants clean data that matches what the tax office sees. And if any of those three things break, your entire sales process stalls. This playbook walks you through building a WhatsApp sales workflow that actually satisfies all three: tax compliance, customer consent, and data integrity. Why tax IDs on WhatsApp matter more than you think In Indonesia, if you invoice a business without its NPWP (Nomor Pokok Wajib Pajak), e-Faktur rejection is automatic. In Malaysia, if you're above the GST threshold and your invoice doesn't match your own LHDN/AKRA records, your invoice gets flagged or worse—you face penalties for inconsistent reporting. The problem: most teams collect tax IDs via email, text, or separate portals. Data arrives late, incomplete, or inconsistent. Your CRM has one version, your accountant has another. By the time it reaches invoicing, nobody remembers whether the customer actually consented to you storing that data, or whether they asked you to delete it three months ago. WhatsApp, by contrast, is synchronous. You ask, they answer, the conversation is logged. But only if you build the workflow to capture, validate, and audit it properly. Step 1: Design the tax ID request with explicit consent Your first message should not be a demand. It should be a clear, friendly request paired with explicit consent language. Example WhatsApp message flow: "Hi [name], thanks for your interest. To issue your invoice, we'll need your NPWP. We'll store this securely and use it only to create your tax-compliant invoice. We won't share it with anyone else. Can we proceed?" Customer responds with NPWP or "yes, send me the form." You send a simple form link (or ask for the NPWP directly if they're willing). They provide the number. You confirm receipt and summarize what you're storing: "Got it—we've recorded your NPWP [last 4 digits] for invoicing only." Why this matters: In Malaysia and Indonesia, consent is not assumed. Asking upfront, logging their agreement, and summarizing what you're storing protects you if the customer later disputes data usage or asks for deletion. Document consent in your CRM. In Orin, log the exact timestamp and message thread where they agreed. If they later ask you to delete their NPWP, you have proof of when they consented and can action a deletion request with an audit trail. Step 2: Validate the tax ID in real time within your CRM Once you have the NPWP or registration number, validate it before it reaches your accountant. Most teams skip this step and wonder why invoices bounce. What to validate: Format check: Indonesian NPWP is 15 digits. Malaysian business registration is 12 characters (e.g., 123456-12-3456). A quick regex catch filters 60% of typos. Checksum validation: Indonesian NPWP has a built-in checksum. Run it before storing. (The 15th digit is a check digit; the first 8 are the tax ID holder's date of birth reversed.) Cross-check with your invoice database: If this customer has invoiced with you before under a different NPWP, flag it. Duplicate or inconsistent tax IDs trigger audit alerts later. In Orin's CRM , use a validation automation: when a customer provides a tax ID, trigger a workflow that checks format, runs the checksum, and flags mismatches. If valid, mark the field as "verified" and log the timestamp. If not, send a follow-up message on WhatsApp: "That NPWP didn't validate—could you double-check the number?" This saves your accounting team hours of phone calls and invoice corrections. Step 3: Sync the verified tax ID to your invoicing software Once the NPWP is validated in your CRM, it needs to flow to your invoicing tool automatically. No manual entry. No copy-paste errors. The sync should happen in this order: Tax ID validated in CRM ✓ Customer record updated with "tax ID verified" flag Invoice template pulls the verified tax ID automatically Invoicing software (e.g., for e-Faktur or MyInvois submission) references the same validated ID Why the order matters: if you invoice first and validate later, you'll have invoices with mismatched tax IDs. When the tax authority reconciles, they see different totals or IDs between your invoice and their registry. Rejection, or worse—audit flags. Use Orin's invoicing integrations or native sync to your accounting software. Most modern invoicing tools (Xero, Zoho Books, Wave) accept API calls with customer tax ID data. Once you've validated, push the ID via API to the invoice platform. Log the sync attempt (success or failure) in your CRM for audit purposes. Step 4: Build the message retention and audit trail Tax authorities in Indonesia and Malaysia increasingly ask for evidence of business transactions, including communication records. WhatsApp conversations are not