Compliance

Saudi PDPL and WhatsApp — what it means for your store

9 min read Updated 4 September 2026 ArabyBot team An explainer — not legal advice
On this page 7
  1. Consent — the foundation
  2. Purpose — do not use it for something else
  3. The customer's rights, in practice
  4. Questions to ask any platform
  5. Frequently asked
  6. Where to go next
  7. Read next

The short answer

Saudi Arabia's Personal Data Protection Law rests on a simple idea: your customer's data belongs to them, and processing it needs a lawful basis — most commonly their consent. And they hold rights over it: to know what you have, to correct what is wrong, and to object to marketing use.

For a merchant on WhatsApp this comes down to three habits: do not message anyone who did not consent, keep the evidence of that consent, and make opting out easy and honour it at once. Usefully, those same three habits are what protect your number from being restricted by Meta.

Read this first

This page is an explainer written by a product team so you know which questions to ask — it is not legal advice. The official text is issued by the competent authority, and if you handle sensitive data, take professional advice.

The short answer

You need explicit consent before the first marketing message, a stated purpose for every field you store, and a way for the customer to stop — those three are what gets asked about.

Also asked as: «نظام حماية البيانات وش يفرض على رسائل الواتساب» · «هل أقدر أرسل واتساب للعميل بدون موافقته» · «PDPL والواتساب للمتجر» · «وش اللي يلزمني للتسويق بالواتساب نظاميًا»

Consent must be clear and specific: the customer knows who will message them, about what, and can refuse. A pre-ticked box in a form, or a number that came from a bought list, is not consent.

  • They wrote to you: the strongest basis, and it also opens Meta's 24-hour window.
  • They tapped a "chat on WhatsApp" button: an explicit act, recorded with its timestamp.
  • They ticked a consent box at checkout: not pre-ticked, and its wording says what they will receive.

2. Purpose — do not use it for something else

A number collected to confirm an order and then used for a discount campaign is being used for a different purpose. If you intend to market, ask for marketing consent explicitly at the moment you collect it.

Meta says the same thing

Meta's Business Messaging Policy also separates service from marketing conversations and requires consent before you start one. So the legal obligation and the operational one point the same way — and it is what keeps your number from being restricted.

3. The customer's rights, in practice

The rightWhat it means for you
To be informedThey can learn what you hold about them and where it came from
To correctYou update it when it is wrong
To eraseYou delete the contact and their conversations in the defined cases
To objectOpting out of marketing is easy and honoured immediately

4. Questions to ask any platform

Before handing any platform your customers' data, these are the questions whose answers matter:

  1. Whose business account is the number under?

    If it is under the provider's, your data and history sit with them and moving later is harder. The right answer is that the number is under your own Meta Business Manager.

  2. Is there a written data processing agreement?

    It should be published and readable before you subscribe, not after. Ours is here.

  3. Can you delete one customer's data?

    If the answer is "email us and we will see", that is not enough for a right you are supposed to be able to exercise.

  4. Who on your team can see what?

    Scoped permissions are not a luxury: a teammate sees only the channels they work on. We enforce that per page and per number.

And you run all of it from your phoneTeam permissions are set from the app too — you can scope a teammate to one number or page without being at a laptop.

Frequently asked

Can I message a list of numbers I bought?

No. The law is built on the principle that processing personal data needs a lawful basis, and consent is the most common one. Quite apart from the law, Meta's own policy requires consent before you start a conversation — and a bought list usually ends in complaints that drag your quality rating down and then restrict the number.

How do I record consent?

Keep the evidence: the customer wrote to you, tapped a "chat on WhatsApp" button, or ticked a box at checkout — with the timestamp and the source. ArabyBot records the source of every contact and their opt-in state, so the basis can be shown when it is needed.

A customer asked for their data to be deleted — what now?

The law grants the data subject rights including access, correction and erasure in defined cases. Practically: you can delete a contact and their conversations from inside the platform, and we publish a account deletion route for a full account.

Where is my customers' data stored?

The WhatsApp conversations themselves pass through Meta's infrastructure. What we hold — contacts, the inbox history, your agent's configuration — is stored on our servers and encrypted in transit. Details are on our security page and in the data processing agreement.

Is this legal advice?

No. This is an explainer written by a product team, not by lawyers. The official text and any updates come from the competent authority, and if your case is sensitive — health data, minors, or transferring data outside the Kingdom — take professional advice.

Start on the right footing

The source and opt-in state of every contact recorded from day one, and your templates approved by Meta before they send.

Where to go next

Read next