The 4-week audit sequence + why doing it in this order matters
Most UK GDPR guides tell you what compliance looks like without saying what to actually do this week. This walkthrough goes the other way — 4 weeks, 4 concrete audit tasks per week, each takes 3-6 hours for a typical UK SME.
Why this order matters:
Week 1 first — RoPA inventory — because you cannot fix what you have not documented. Most UK small businesses discover during Week 1 that they have 4-6 undocumented processing activities running through WhatsApp. Fixing takes weeks of Week 2-4 work; discovering happens in a single afternoon of Week 1.
Week 2 second — lawful basis mapping — because the RoPA from Week 1 is where the lawful-basis gaps become visible. Article 6 failure is the enforcement trigger the ICO flags most often for SME reprimands (per ICO enforcement register review 2024-2025).
Week 3 third — retention + deletion — because WhatsApp itself has zero retention enforcement (conversations persist forever unless manually deleted). Fixing this requires a policy + a workflow, both of which need Week 1-2 work to be meaningful.
Week 4 last — DPA + DSAR readiness — because the DPA verification with every vendor + DSAR response infrastructure builds on the Article 30 record from Week 1. Running Week 4 first without the prior weeks means you cannot answer a Data Subject Access Request even if the infrastructure is technically ready.
Total time commitment: 12-24 hours over 4 weeks (3-6 hours per week) for a typical 3-15 person UK SME. Not a full-time project. Can run alongside normal operations if you block dedicated audit slots (Friday afternoons work for most).
When to bring in a UK data protection solicitor: if you find Article 9 special-category data processing (health, financial account details, criminal records) without documented lawful basis + explicit Article 9 exception, escalate to legal counsel before Week 4. Sensitive-data breaches carry higher enforcement priority.
What this walkthrough is not: it is not a substitute for a formal GDPR audit by a UK data protection solicitor. For regulated sectors (healthcare CQC, legal SRA, financial FCA, education DfE), professional audit remains necessary. This walkthrough is the SME-appropriate first pass that catches the most common Article 30 + Article 6 + DPA gaps.
Article 30 UK GDPR requires written Records of Processing Activities (RoPA). The Article 30(5) small-business exemption (fewer than 250 employees) does not apply if processing is not occasional, or carries risk to data subjects, or involves special category data. Continuous customer messaging via WhatsApp fails the 'not occasional' test — so RoPA is required for essentially every UK business using WhatsApp with customers.
Week 1 checklist (do all 4 in a single Friday afternoon):
1. Download the ICO RoPA template.
Free at ico.org.uk RoPA guidance. One spreadsheet, one row per processing activity. Do not overthink the format — the ICO's own template is authoritative and covers the Article 30 requirements exactly.
2. List every WhatsApp processing activity you actually run.
Sit down for 30 minutes and list every distinct way you use WhatsApp with customer data:
Customer enquiry response (inbound Q&A)
Appointment booking + confirmation
Reminder messages before appointment
Post-service follow-up (feedback, review request)
Marketing broadcasts (opt-in list)
Payment link + invoice delivery
Customer complaint handling
Referral tracking
Most UK SMEs discover 4-8 distinct processing activities they had never documented. This is normal.
3. Fill one RoPA row per activity.
For each processing activity, complete the ICO template columns:
Purpose: what business goal this serves (e.g., 'reminder to reduce no-shows')
Categories of data subjects: current customers, prospects, past customers, staff, referrals
Categories of personal data: name, phone number, appointment history, health information (special category), financial details (special category)
Categories of recipients: your BSP (WATI, respond.io, etc.), CRM, cloud storage, accounting software
Cross-border transfers: WhatsApp routes through Meta servers in US — this is a transfer requiring documented mechanism (see Week 4)
Retention period: how long you keep this specific data (see Week 3)
Security measures: encryption in transit + at rest, access controls, staff training
4. Flag every row where you cannot answer a column.
The rows you cannot complete are the audit gaps. Common gaps in Week 1:
Lawful basis field blank (fix in Week 2)
Retention period blank ('we never delete' is not a retention policy) (fix in Week 3)
Cross-border transfer mechanism not documented (fix in Week 4)
Category of recipient BSP not listed → no DPA with them (fix in Week 4)
This inventory is not the compliance destination — it is the map that shows you where the fixes need to happen. Week 2-4 work through the gaps in order.
🎯 For small-business owners
Weekly notes on what's actually working for small businesses.
WhatsApp scripts, SaaS-tool comparisons, real revenue tactics — honest, no fluff.
Every processing activity from Week 1 needs a documented lawful basis under Article 6 UK GDPR. Missing this documentation is the single most-common Article 30 violation flagged in ICO enforcement register reprimands 2024-2025.
Week 2 checklist:
1. Map lawful basis per processing activity.
Go back to your RoPA from Week 1 and add a column: 'Article 6 lawful basis + evidence'. Fill for each row:
Processing activity
Modal Article 6 basis
Evidence you need
Appointment booking + confirmation
6(1)(b) contract performance
Booking record + customer request in-chat
Service reminder message
6(1)(f) legitimate interests
Legitimate Interests Assessment (LIA) document
Payment link + invoice delivery
6(1)(b) contract performance
Invoice record + linked service
Marketing broadcast
6(1)(a) consent
Timestamped opt-in record + source
Complaint handling
6(1)(b) contract or 6(1)(f) LI
Complaint log entry
Referral tracking without prior consent
Likely no basis available
Stop this processing until consent obtained
2. Complete the LIA for any legitimate-interests processing.
Legitimate Interests basis (Article 6(1)(f)) requires a documented Legitimate Interests Assessment. ICO provides a free LIA template at ICO LIA guidance. The LIA has 3 tests: purpose (what's your interest?), necessity (is processing needed?), and balancing (does your interest outweigh the data subject's rights?). Complete the template for each LI-based activity in your RoPA.
3. Audit your consent records for marketing.
Marketing broadcasts under UK GDPR Article 6(1)(a) + PECR Regulation 22 require timestamped consent records. Check your CRM or customer database:
Do you have a 'WhatsApp marketing consent' field with date + source per contact?
Can you produce the consent evidence if the ICO asks?
Is opt-out honored in the WhatsApp broadcast workflow (do STOP replies actually stop the marketing)?
Common gap discovered in Week 2: UK SMEs marketing to their full contact list without documented consent, or with consent that was obtained for one purpose (e.g., 'we will contact you about your appointment') being reused for marketing without new consent. This is a purpose limitation violation under Article 5(1)(b) — different processing purpose requires new consent.
4. Fix immediate gaps.
Stop any marketing without consent immediately. Do not continue while you 'gather consent' — that is ongoing violation.
Add consent capture to your onboarding flow (opt-in in first automated reply: 'Would you like to receive our updates? Reply YES to subscribe, NO to skip').
Document any historical consent gaps in your RoPA notes — you will need to address at next Week 4 DSAR review.
Time to complete: 4-6 hours if you have 4-8 processing activities. Longer for regulated sectors (healthcare needs Article 9(2) mapping in addition — likely another 2-3 hours).
Article 5(1)(e) UK GDPR storage limitation principle: personal data must be kept 'for no longer than is necessary for the purposes for which the personal data are processed'. WhatsApp itself provides no retention enforcement — conversations persist forever unless manually deleted. This is the second-most-common gap flagged in ICO enforcement.
Week 3 checklist:
1. Define retention periods per processing activity.
Go back to your RoPA and complete the retention period column. Some UK-specific defaults for reference (but check your sector regulator + solicitor for authoritative answers):
Payment records: 6 years for HMRC requirements (or 7 years if you file corporation tax)
Marketing consent records: while consent is active + 6 years after opt-out (for consent-evidence purposes)
Complaint handling: 6 years (typical UK complaint-handling retention)
Healthcare records: NHS retention schedules apply (typically 8 years for adults, longer for minors) — NHS retention schedule
Financial services communications: 5-7 years under FCA COBS + SYSC sourcebook
Do not write '10 years' or 'forever' as a default. Storage limitation requires you to justify the period. If your business genuinely needs 10 years for a specific purpose, document why (e.g., 'for tax audit response window').
2. Build the deletion enforcement workflow.
WhatsApp has no automatic deletion. You need a manual or semi-automated workflow:
Manual monthly review: first Monday of the month, review contacts past retention period, delete conversation history + CRM records + backup exports
BSP-side auto-deletion: WATI, respond.io, and some other BSPs support conversation auto-deletion after configurable time (e.g., 90 days). Check your BSP's admin settings.
CRM auto-deletion: most CRMs (HubSpot, Zoho, Salesforce) support contact-level retention rules. Configure to auto-delete or auto-anonymize after retention period.
3. Test the deletion workflow.
Pick 3 test contacts past your defined retention period. Delete them across all systems (WhatsApp chat, BSP dashboard, CRM, accounting software if applicable, any cloud backup). Verify:
The deletion actually happened (not just soft-deleted, but hard-deleted where retention period requires)
No trace remains in system-level backups you have access to (for full compliance, backups may need separate handling)
Deletion is logged (date + who executed) for audit-trail
4. Document the retention + deletion workflow in your RoPA.
Add a column: 'Retention enforcement mechanism + review schedule'. This becomes evidence that you actually enforce retention, not just document it.
Common gap discovered in Week 3: UK SMEs discover they have 3-5 year old WhatsApp conversation histories with data from customers who last interacted long ago. Standard fix: bulk deletion of contacts past retention with signed-off retention policy going forward. If you have to explain to the ICO why you kept the data that long, 'we forgot' is not an acceptable answer.
Time to complete: 3-5 hours (2-3 hours defining policy + 1-2 hours building workflow + testing).
Week 4 — DPA verification with vendors + DSAR readiness for 30-day window (4-6 hours)
Final week — everything comes together. Article 28 requires a written Data Processing Agreement (DPA) with every processor. WhatsApp Business API BSPs, CRMs, accounting software, cloud storage — all are processors. Article 12(3) DSAR response window is 30 calendar days from request.
Week 4 checklist:
1. Verify DPA with every vendor from your RoPA recipient list.
Go through the 'categories of recipients' column from Week 1 RoPA. For each vendor:
Do you have a signed DPA on file? Not 'they have one on their website' — actually signed by both parties.
Does the DPA reference UK GDPR specifically (not just EU GDPR)?
Does it name your organisation as controller and them as processor?
Does it include sub-processor arrangements + notification obligations?
Most UK SMEs discover they never signed DPAs with vendors during onboarding. Request DPA now from any vendor without one. Vendors will provide standard DPA on request; sign + retain a copy.
2. Document cross-border transfer mechanisms.
For every vendor storing UK personal data outside the UK/EEA:
US-based vendors (Meta/WhatsApp, HubSpot, most US BSPs): check if they're certified under UK-US Data Bridge — this is the simplest transfer mechanism (effective from 12 October 2023). Meta Platforms is certified.
Other-country vendors (WATI Hong Kong, some LATAM/APAC BSPs): may require the UK IDTA (International Data Transfer Agreement, the UK equivalent of SCCs). ICO template + guidance free at ICO IDTA.
Add cross-border transfer mechanism per vendor to your RoPA.
3. Build DSAR response infrastructure.
UK GDPR Article 12(3) requires response within 30 calendar days of a data subject access request. Failing this deadline is a separate GDPR violation regardless of underlying data-quality issues. Infrastructure needed:
DSAR intake process: email address or web form for DSAR receipt, logged with timestamp
Identity verification workflow: verify requester's identity before releasing data (protect against fraudulent DSAR)
Data compilation workflow: you can export a specific data subject's data from every system (WhatsApp export, CRM export, accounting export, backup search) within the 30-day window
Response template: GDPR-compliant response including data provided + explanation of any exemptions + information about right to complain to ICO
Test end-to-end: pick a real contact from your database, run through the DSAR workflow as if they had submitted a request. Can you complete within 30 days? If not, identify the bottleneck (usually the WhatsApp export step) and fix now.
4. Publish or update your privacy notice.
Article 13-14 requires transparent information to data subjects about how you process their data. Your privacy notice should reference:
Most UK SMEs have privacy notices that are 3-5 years old and don't mention WhatsApp. Update now.
Time to complete: 4-6 hours if you have 3-8 vendors + a functioning CRM. Longer if you have 10+ vendors or a fragmented data landscape.
The industries where this audit is not optional (heightened enforcement risk)
All UK businesses using WhatsApp with customers should run this 4-week audit. Some industries face significantly higher regulatory + reputational + legal risk without it.
Health data is Article 9 special-category data. Processing via WhatsApp requires explicit Article 9(2) basis (typically 9(2)(h) health/social care with professional secrecy obligations) plus full Article 30 documentation. NHS England data protection framework + CQC registration + ICO health sector guidance all reference UK GDPR obligations. Add to the Week 2 lawful basis audit: explicit Article 9(2) mapping for every health-data touching activity.
Client communications via WhatsApp often combine legally-privileged information with personal data. SRA's data protection standards + Solicitors Regulation Authority Code of Conduct 2019 reference GDPR compliance. Additional obligation: legal professional privilege applies to solicitor-client communications, which affects how you handle DSARs (privileged material typically exempt from disclosure). Consult a specialist solicitor for privilege + GDPR interaction if you are a UK legal-services firm.
FCA-regulated firms must demonstrate audit trails under FCA SYSC sourcebook + COBS record-keeping requirements (typically 5-7 years) — in addition to UK GDPR. WhatsApp communications about regulated products are financial promotions subject to FCA approval requirements. This is a case where WhatsApp is arguably the wrong channel entirely for anything discussing regulated products; audit should identify these communications for migration to a compliant channel.
Processing children's data carries heightened risk. ICO children's code + DPIA (Data Protection Impact Assessment) guidance applies. Add to the audit: DPIA for any processing of children's data likely to result in high risk. DfE + Ofsted requirements apply for schools + regulated childcare.
Processing CVs + candidate data via WhatsApp requires careful lawful-basis documentation. ICO Employment Practices Code applies alongside UK GDPR. Add to audit: lawful basis for retaining unsuccessful candidate CVs (typically 6-12 months with consent for future opportunities; longer requires explicit consent).
What to do if you're in a heightened-risk sector:
Complete the 4-week self-audit above, then engage a UK GDPR solicitor for a formal review before your annual regulator submission (CQC, SRA, FCA, DfE, EAS). The self-audit gets you 80% of the way; the professional review closes the remaining sector-specific gaps.
Sources
Data + numbers referenced in this article are sourced from these public documents:
**No — the exemption at Article 30(5) UK GDPR only applies if processing is 'not occasional', does not carry risk to individuals, and does not involve special category data. Continuous customer messaging via WhatsApp fails the 'not occasional' test for essentially every UK business using WhatsApp with customers.** Additionally, if you handle health, financial, or minor's data, the exemption does not apply regardless of processing frequency. ICO recommends all businesses keep a RoPA as best practice regardless of size. Practical implication: assume you need a RoPA and skip the exemption analysis — it saves argument time and satisfies auditor + ICO expectation.
**Different Article 6 basis per activity: service reminders confirming an existing booking are typically covered by Article 6(1)(b) contract performance or Article 6(1)(f) legitimate interests. Marketing broadcasts — promotions, re-engagement broadcasts, offers — require explicit consent under both UK GDPR Article 6(1)(a) and PECR Regulation 22.** For legitimate interests, you must conduct and document a Legitimate Interests Assessment (LIA) — [ICO LIA template](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/legitimate-interests/) is free. Purpose limitation under Article 5(1)(b) means you cannot reuse consent obtained for one purpose (e.g., 'we will contact you about your appointment') for a different purpose (marketing) without new consent.
**No single universal minimum — retention depends on the purpose. Healthcare records follow NHS retention schedules (typically 8 years for adults, longer for minors). FCA-regulated firms retain client communications 5-7 years under MiFID II/COBS. For general UK SMEs, UK GDPR storage limitation Article 5(1)(e) requires deletion once processing purpose is fulfilled.** Document your chosen retention period per activity in your RoPA and enforce it systematically. WhatsApp has no automatic retention enforcement — you need manual monthly review OR BSP-side auto-deletion configuration OR CRM auto-deletion rules. 'We never delete' is not a retention policy and creates ongoing Article 5 violation.
**You must respond within 30 calendar days per UK GDPR Article 12(3) regardless of which channel the request arrives on. You must provide a copy of all personal data you hold on that individual — WhatsApp messages + CRM entries + any connected system + backup extracts.** No fee for the first request. If you cannot locate, export, or compile the data within 30 days, the ICO treats this as failure to comply independently of any underlying privacy issue. Test your DSAR workflow end-to-end in Week 4 of the audit — pick a real contact from your database and run through the process as if they had submitted a request. Common bottleneck: WhatsApp export step (WhatsApp Business App export is unwieldy; BSP dashboards vary). Fix now.
**Yes. The BSP becomes a data processor under Article 28 UK GDPR, meaning you must have a signed Data Processing Agreement (DPA) with them before processing any customer data through their platform.** Most reputable BSPs (WATI, respond.io, Twilio, Zenvia) provide a standard DPA on request. Without a signed DPA, even if the BSP is compliant in practice, you have an undocumented Article 28 gap. Additionally verify where the BSP hosts your data + document the cross-border transfer mechanism if outside the UK (UK-US Data Bridge for US-hosted BSPs certified under it, IDTA otherwise). Full Article 28 guidance at [ICO Article 28 DPAs](https://ico.org.uk/for-organisations/accountability-framework/contracts-and-data-sharing/).
**UK GDPR Article 83 sets maximum penalties: lower tier (Article 30 record-keeping failures) reaches £8.7 million or 2% global annual turnover. Upper tier (more serious infringements including Article 6 lawful-basis failures + Article 9 special-category processing without exception) reaches £17.5 million or 4%.** In practice, ICO often issues formal reprimands — published on [ICO enforcement register](https://ico.org.uk/action-weve-taken/enforcement/) — before reaching fines for record-keeping failures. But a reprimand is public, reputationally damaging, and increasingly material in procurement decisions (many UK enterprise buyers now require GDPR-clean supplier history). Precedent-setting fine for context: British Airways originally proposed £183M, settled at £20M in 2020 — the ICO does enforce material penalties for large breaches.
What a conversation looks like
🤖
BossBot AI
● Online
Hi! I came across your business and wanted to find out more
Hi there! Happy to help 😊 What would you like to know? I can help with bookings, pricing, availability, or any questions you have.
Great — do you have any appointments available this week?
Yes! I have availability Tuesday and Thursday this week. What time of day works best for you?
Thursday afternoon if possible
Thursday afternoon is available ✅ I'll get that booked for you. Can I take your name to confirm?
The 4-week audit is not a project — it's a Friday-afternoon habit
This walkthrough is one of a series covering UK regulatory compliance for SMB customer-communication tools. If your audit finds gaps needing WhatsApp-native platform migration, our AI virtual assistant UK teardown covers the alternatives with signed DPA + UK data residency options.