PDPL-compliant WhatsApp lead capture checklist
PDPL-compliant WhatsApp lead capture requires clear notices, lawful bases, data minimization, retention limits, and processor agreements — not just a chatbot script.
Notice and consent
Tell users what you collect on WhatsApp, why, and how to exercise rights. Align opt-in with Meta and carrier policies for outbound messages.
Data minimization
Collect only fields needed for qualification — name, contact, intent, timing — and avoid storing sensitive categories without legal basis.
Vendor and retention
Use processors with clear DPAs, define retention periods, and ensure your Lead OS supports export and deletion requests.
Steps
- Publish privacy notice for WhatsApp flows
- Limit fields to qualification essentials
- Document retention and subprocessors