Saudi PDPL and WhatsApp — what it means for your store
On this page 7
The short answer
Saudi Arabia's Personal Data Protection Law rests on a simple idea: your customer's data belongs to them, and processing it needs a lawful basis — most commonly their consent. And they hold rights over it: to know what you have, to correct what is wrong, and to object to marketing use.
For a merchant on WhatsApp this comes down to three habits: do not message anyone who did not consent, keep the evidence of that consent, and make opting out easy and honour it at once. Usefully, those same three habits are what protect your number from being restricted by Meta.
This page is an explainer written by a product team so you know which questions to ask — it is not legal advice. The official text is issued by the competent authority, and if you handle sensitive data, take professional advice.
The short answer
You need explicit consent before the first marketing message, a stated purpose for every field you store, and a way for the customer to stop — those three are what gets asked about.
Also asked as: «نظام حماية البيانات وش يفرض على رسائل الواتساب» · «هل أقدر أرسل واتساب للعميل بدون موافقته» · «PDPL والواتساب للمتجر» · «وش اللي يلزمني للتسويق بالواتساب نظاميًا»
1. Consent — the foundation
Consent must be clear and specific: the customer knows who will message them, about what, and can refuse. A pre-ticked box in a form, or a number that came from a bought list, is not consent.
- They wrote to you: the strongest basis, and it also opens Meta's 24-hour window.
- They tapped a "chat on WhatsApp" button: an explicit act, recorded with its timestamp.
- They ticked a consent box at checkout: not pre-ticked, and its wording says what they will receive.
2. Purpose — do not use it for something else
A number collected to confirm an order and then used for a discount campaign is being used for a different purpose. If you intend to market, ask for marketing consent explicitly at the moment you collect it.
Meta's Business Messaging Policy also separates service from marketing conversations and requires consent before you start one. So the legal obligation and the operational one point the same way — and it is what keeps your number from being restricted.
3. The customer's rights, in practice
| The right | What it means for you |
|---|---|
| To be informed | They can learn what you hold about them and where it came from |
| To correct | You update it when it is wrong |
| To erase | You delete the contact and their conversations in the defined cases |
| To object | Opting out of marketing is easy and honoured immediately |
4. Questions to ask any platform
Before handing any platform your customers' data, these are the questions whose answers matter:
- Whose business account is the number under?
If it is under the provider's, your data and history sit with them and moving later is harder. The right answer is that the number is under your own Meta Business Manager.
- Is there a written data processing agreement?
It should be published and readable before you subscribe, not after. Ours is here.
- Can you delete one customer's data?
If the answer is "email us and we will see", that is not enough for a right you are supposed to be able to exercise.
- Who on your team can see what?
Scoped permissions are not a luxury: a teammate sees only the channels they work on. We enforce that per page and per number.
Frequently asked
Can I message a list of numbers I bought?
No. The law is built on the principle that processing personal data needs a lawful basis, and consent is the most common one. Quite apart from the law, Meta's own policy requires consent before you start a conversation — and a bought list usually ends in complaints that drag your quality rating down and then restrict the number.
How do I record consent?
Keep the evidence: the customer wrote to you, tapped a "chat on WhatsApp" button, or ticked a box at checkout — with the timestamp and the source. ArabyBot records the source of every contact and their opt-in state, so the basis can be shown when it is needed.
A customer asked for their data to be deleted — what now?
The law grants the data subject rights including access, correction and erasure in defined cases. Practically: you can delete a contact and their conversations from inside the platform, and we publish a account deletion route for a full account.
Where is my customers' data stored?
The WhatsApp conversations themselves pass through Meta's infrastructure. What we hold — contacts, the inbox history, your agent's configuration — is stored on our servers and encrypted in transit. Details are on our security page and in the data processing agreement.
Is this legal advice?
No. This is an explainer written by a product team, not by lawyers. The official text and any updates come from the competent authority, and if your case is sensitive — health data, minors, or transferring data outside the Kingdom — take professional advice.
Start on the right footing
The source and opt-in state of every contact recorded from day one, and your templates approved by Meta before they send.