← All articles
uk gdpr whatsapp audit 2026 article 30 ropa whatsapp business By BossBot Editorial Team · · Updated
Drafted with AI assistance under founder-led editorial direction. How our editorial team works.

UK GDPR WhatsApp Audit Checklist Week-by-Week (£17.5M Penalty Exposure)

UK small business owner running week-by-week GDPR audit for WhatsApp Business — RoPA + Article 6 lawful basis + retention + DPA + DSAR readiness 2026

Week-by-week UK GDPR audit for WhatsApp Business — Week 1 RoPA gap check, Week 2 lawful basis mapping, Week 3 retention enforcement, Week 4 DPA + DSAR readiness.

In this article Hide ▲
  1. The 4-week audit sequence + why doing it in this order matters
  2. Week 1 — RoPA inventory + Article 30 gap check (3-4 hours)
  3. Week 2 — Lawful basis mapping + consent record audit (4-6 hours)
  4. Week 3 — Retention policy + deletion enforcement (3-5 hours)
  5. Week 4 — DPA verification with vendors + DSAR readiness for 30-day window (4-6 hours)
  6. The industries where this audit is not optional (heightened enforcement risk)

The 4-week audit sequence + why doing it in this order matters

Most UK GDPR guides tell you what compliance looks like without saying what to actually do this week. This walkthrough goes the other way — 4 weeks, 4 concrete audit tasks per week, each takes 3-6 hours for a typical UK SME.

Why this order matters:

  1. Week 1 first — RoPA inventory — because you cannot fix what you have not documented. Most UK small businesses discover during Week 1 that they have 4-6 undocumented processing activities running through WhatsApp. Fixing takes weeks of Week 2-4 work; discovering happens in a single afternoon of Week 1.
  2. Week 2 second — lawful basis mapping — because the RoPA from Week 1 is where the lawful-basis gaps become visible. Article 6 failure is the enforcement trigger the ICO flags most often for SME reprimands (per ICO enforcement register review 2024-2025).
  3. Week 3 third — retention + deletion — because WhatsApp itself has zero retention enforcement (conversations persist forever unless manually deleted). Fixing this requires a policy + a workflow, both of which need Week 1-2 work to be meaningful.
  4. Week 4 last — DPA + DSAR readiness — because the DPA verification with every vendor + DSAR response infrastructure builds on the Article 30 record from Week 1. Running Week 4 first without the prior weeks means you cannot answer a Data Subject Access Request even if the infrastructure is technically ready.

Total time commitment: 12-24 hours over 4 weeks (3-6 hours per week) for a typical 3-15 person UK SME. Not a full-time project. Can run alongside normal operations if you block dedicated audit slots (Friday afternoons work for most).

When to bring in a UK data protection solicitor: if you find Article 9 special-category data processing (health, financial account details, criminal records) without documented lawful basis + explicit Article 9 exception, escalate to legal counsel before Week 4. Sensitive-data breaches carry higher enforcement priority.

What this walkthrough is not: it is not a substitute for a formal GDPR audit by a UK data protection solicitor. For regulated sectors (healthcare CQC, legal SRA, financial FCA, education DfE), professional audit remains necessary. This walkthrough is the SME-appropriate first pass that catches the most common Article 30 + Article 6 + DPA gaps.

Week 1 — RoPA inventory + Article 30 gap check (3-4 hours)

Article 30 UK GDPR requires written Records of Processing Activities (RoPA). The Article 30(5) small-business exemption (fewer than 250 employees) does not apply if processing is not occasional, or carries risk to data subjects, or involves special category data. Continuous customer messaging via WhatsApp fails the 'not occasional' test — so RoPA is required for essentially every UK business using WhatsApp with customers.

Week 1 checklist (do all 4 in a single Friday afternoon):

1. Download the ICO RoPA template.

Free at ico.org.uk RoPA guidance. One spreadsheet, one row per processing activity. Do not overthink the format — the ICO's own template is authoritative and covers the Article 30 requirements exactly.

2. List every WhatsApp processing activity you actually run.

Sit down for 30 minutes and list every distinct way you use WhatsApp with customer data:

Most UK SMEs discover 4-8 distinct processing activities they had never documented. This is normal.

3. Fill one RoPA row per activity.

For each processing activity, complete the ICO template columns:

4. Flag every row where you cannot answer a column.

The rows you cannot complete are the audit gaps. Common gaps in Week 1:

This inventory is not the compliance destination — it is the map that shows you where the fixes need to happen. Week 2-4 work through the gaps in order.

🎯 For small-business owners
Weekly notes on what's actually working for small businesses.
WhatsApp scripts, SaaS-tool comparisons, real revenue tactics — honest, no fluff.

Week 3 — Retention policy + deletion enforcement (3-5 hours)

Article 5(1)(e) UK GDPR storage limitation principle: personal data must be kept 'for no longer than is necessary for the purposes for which the personal data are processed'. WhatsApp itself provides no retention enforcement — conversations persist forever unless manually deleted. This is the second-most-common gap flagged in ICO enforcement.

Week 3 checklist:

1. Define retention periods per processing activity.

Go back to your RoPA and complete the retention period column. Some UK-specific defaults for reference (but check your sector regulator + solicitor for authoritative answers):

Do not write '10 years' or 'forever' as a default. Storage limitation requires you to justify the period. If your business genuinely needs 10 years for a specific purpose, document why (e.g., 'for tax audit response window').

2. Build the deletion enforcement workflow.

WhatsApp has no automatic deletion. You need a manual or semi-automated workflow:

3. Test the deletion workflow.

Pick 3 test contacts past your defined retention period. Delete them across all systems (WhatsApp chat, BSP dashboard, CRM, accounting software if applicable, any cloud backup). Verify:

4. Document the retention + deletion workflow in your RoPA.

Add a column: 'Retention enforcement mechanism + review schedule'. This becomes evidence that you actually enforce retention, not just document it.

Common gap discovered in Week 3: UK SMEs discover they have 3-5 year old WhatsApp conversation histories with data from customers who last interacted long ago. Standard fix: bulk deletion of contacts past retention with signed-off retention policy going forward. If you have to explain to the ICO why you kept the data that long, 'we forgot' is not an acceptable answer.

Time to complete: 3-5 hours (2-3 hours defining policy + 1-2 hours building workflow + testing).

Week 4 — DPA verification with vendors + DSAR readiness for 30-day window (4-6 hours)

Final week — everything comes together. Article 28 requires a written Data Processing Agreement (DPA) with every processor. WhatsApp Business API BSPs, CRMs, accounting software, cloud storage — all are processors. Article 12(3) DSAR response window is 30 calendar days from request.

Week 4 checklist:

1. Verify DPA with every vendor from your RoPA recipient list.

Go through the 'categories of recipients' column from Week 1 RoPA. For each vendor:

Most UK SMEs discover they never signed DPAs with vendors during onboarding. Request DPA now from any vendor without one. Vendors will provide standard DPA on request; sign + retain a copy.

2. Document cross-border transfer mechanisms.

For every vendor storing UK personal data outside the UK/EEA:

Add cross-border transfer mechanism per vendor to your RoPA.

3. Build DSAR response infrastructure.

UK GDPR Article 12(3) requires response within 30 calendar days of a data subject access request. Failing this deadline is a separate GDPR violation regardless of underlying data-quality issues. Infrastructure needed:

Test end-to-end: pick a real contact from your database, run through the DSAR workflow as if they had submitted a request. Can you complete within 30 days? If not, identify the bottleneck (usually the WhatsApp export step) and fix now.

4. Publish or update your privacy notice.

Article 13-14 requires transparent information to data subjects about how you process their data. Your privacy notice should reference:

Most UK SMEs have privacy notices that are 3-5 years old and don't mention WhatsApp. Update now.

Time to complete: 4-6 hours if you have 3-8 vendors + a functioning CRM. Longer if you have 10+ vendors or a fragmented data landscape.

The industries where this audit is not optional (heightened enforcement risk)

All UK businesses using WhatsApp with customers should run this 4-week audit. Some industries face significantly higher regulatory + reputational + legal risk without it.

Healthcare (dental practices, private GPs, physiotherapists, dermatology clinics, mental health services)

Health data is Article 9 special-category data. Processing via WhatsApp requires explicit Article 9(2) basis (typically 9(2)(h) health/social care with professional secrecy obligations) plus full Article 30 documentation. NHS England data protection framework + CQC registration + ICO health sector guidance all reference UK GDPR obligations. Add to the Week 2 lawful basis audit: explicit Article 9(2) mapping for every health-data touching activity.

Legal services (solicitors, barristers, mediators)

Client communications via WhatsApp often combine legally-privileged information with personal data. SRA's data protection standards + Solicitors Regulation Authority Code of Conduct 2019 reference GDPR compliance. Additional obligation: legal professional privilege applies to solicitor-client communications, which affects how you handle DSARs (privileged material typically exempt from disclosure). Consult a specialist solicitor for privilege + GDPR interaction if you are a UK legal-services firm.

Financial services (mortgage brokers, IFAs, insurance advisers, fintech customer service)

FCA-regulated firms must demonstrate audit trails under FCA SYSC sourcebook + COBS record-keeping requirements (typically 5-7 years) — in addition to UK GDPR. WhatsApp communications about regulated products are financial promotions subject to FCA approval requirements. This is a case where WhatsApp is arguably the wrong channel entirely for anything discussing regulated products; audit should identify these communications for migration to a compliant channel.

Education + childcare (schools, nurseries, tutors, childcare providers)

Processing children's data carries heightened risk. ICO children's code + DPIA (Data Protection Impact Assessment) guidance applies. Add to the audit: DPIA for any processing of children's data likely to result in high risk. DfE + Ofsted requirements apply for schools + regulated childcare.

Recruitment (agencies + in-house talent acquisition)

Processing CVs + candidate data via WhatsApp requires careful lawful-basis documentation. ICO Employment Practices Code applies alongside UK GDPR. Add to audit: lawful basis for retaining unsuccessful candidate CVs (typically 6-12 months with consent for future opportunities; longer requires explicit consent).

What to do if you're in a heightened-risk sector:

Complete the 4-week self-audit above, then engage a UK GDPR solicitor for a formal review before your annual regulator submission (CQC, SRA, FCA, DfE, EAS). The self-audit gets you 80% of the way; the professional review closes the remaining sector-specific gaps.

Sources

Data + numbers referenced in this article are sourced from these public documents:

  1. ICO — Article 30 Records of Processing Activities (RoPA) guidance and template
  2. UK GDPR Article 30 (legislation.gov.uk)
  3. ICO — PECR guide: electronic and telephone marketing (Regulation 22)
  4. ICO — International data transfers + UK-US Data Bridge
  5. ICO — Article 28 Data Processing Agreements + contracts
  6. ICO — Legitimate Interests Assessment (LIA) guidance + template
  7. ICO — International Data Transfer Agreement (IDTA) template + guidance
  8. ICO — Enforcement register (fines + reprimands public list)
  9. ICO — Children's information + DPIA guidance
  10. Meta — WhatsApp Business Data Processing Terms
  11. NHS X — Records Management Code of Practice 2021 (healthcare retention)
  12. FCA Handbook — SYSC sourcebook (financial services record-keeping)

Frequently Asked Questions

**No — the exemption at Article 30(5) UK GDPR only applies if processing is 'not occasional', does not carry risk to individuals, and does not involve special category data. Continuous customer messaging via WhatsApp fails the 'not occasional' test for essentially every UK business using WhatsApp with customers.** Additionally, if you handle health, financial, or minor's data, the exemption does not apply regardless of processing frequency. ICO recommends all businesses keep a RoPA as best practice regardless of size. Practical implication: assume you need a RoPA and skip the exemption analysis — it saves argument time and satisfies auditor + ICO expectation.
**Different Article 6 basis per activity: service reminders confirming an existing booking are typically covered by Article 6(1)(b) contract performance or Article 6(1)(f) legitimate interests. Marketing broadcasts — promotions, re-engagement broadcasts, offers — require explicit consent under both UK GDPR Article 6(1)(a) and PECR Regulation 22.** For legitimate interests, you must conduct and document a Legitimate Interests Assessment (LIA) — [ICO LIA template](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/legitimate-interests/) is free. Purpose limitation under Article 5(1)(b) means you cannot reuse consent obtained for one purpose (e.g., 'we will contact you about your appointment') for a different purpose (marketing) without new consent.
**No single universal minimum — retention depends on the purpose. Healthcare records follow NHS retention schedules (typically 8 years for adults, longer for minors). FCA-regulated firms retain client communications 5-7 years under MiFID II/COBS. For general UK SMEs, UK GDPR storage limitation Article 5(1)(e) requires deletion once processing purpose is fulfilled.** Document your chosen retention period per activity in your RoPA and enforce it systematically. WhatsApp has no automatic retention enforcement — you need manual monthly review OR BSP-side auto-deletion configuration OR CRM auto-deletion rules. 'We never delete' is not a retention policy and creates ongoing Article 5 violation.
**You must respond within 30 calendar days per UK GDPR Article 12(3) regardless of which channel the request arrives on. You must provide a copy of all personal data you hold on that individual — WhatsApp messages + CRM entries + any connected system + backup extracts.** No fee for the first request. If you cannot locate, export, or compile the data within 30 days, the ICO treats this as failure to comply independently of any underlying privacy issue. Test your DSAR workflow end-to-end in Week 4 of the audit — pick a real contact from your database and run through the process as if they had submitted a request. Common bottleneck: WhatsApp export step (WhatsApp Business App export is unwieldy; BSP dashboards vary). Fix now.
**Yes. The BSP becomes a data processor under Article 28 UK GDPR, meaning you must have a signed Data Processing Agreement (DPA) with them before processing any customer data through their platform.** Most reputable BSPs (WATI, respond.io, Twilio, Zenvia) provide a standard DPA on request. Without a signed DPA, even if the BSP is compliant in practice, you have an undocumented Article 28 gap. Additionally verify where the BSP hosts your data + document the cross-border transfer mechanism if outside the UK (UK-US Data Bridge for US-hosted BSPs certified under it, IDTA otherwise). Full Article 28 guidance at [ICO Article 28 DPAs](https://ico.org.uk/for-organisations/accountability-framework/contracts-and-data-sharing/).
**UK GDPR Article 83 sets maximum penalties: lower tier (Article 30 record-keeping failures) reaches £8.7 million or 2% global annual turnover. Upper tier (more serious infringements including Article 6 lawful-basis failures + Article 9 special-category processing without exception) reaches £17.5 million or 4%.** In practice, ICO often issues formal reprimands — published on [ICO enforcement register](https://ico.org.uk/action-weve-taken/enforcement/) — before reaching fines for record-keeping failures. But a reprimand is public, reputationally damaging, and increasingly material in procurement decisions (many UK enterprise buyers now require GDPR-clean supplier history). Precedent-setting fine for context: British Airways originally proposed £183M, settled at £20M in 2020 — the ICO does enforce material penalties for large breaches.
What a conversation looks like
🤖
BossBot AI
● Online
Hi! I came across your business and wanted to find out more
Hi there! Happy to help 😊 What would you like to know? I can help with bookings, pricing, availability, or any questions you have.
Great — do you have any appointments available this week?
Yes! I have availability Tuesday and Thursday this week. What time of day works best for you?
Thursday afternoon if possible
Thursday afternoon is available ✅ I'll get that booked for you. Can I take your name to confirm?

The 4-week audit is not a project — it's a Friday-afternoon habit

This walkthrough is one of a series covering UK regulatory compliance for SMB customer-communication tools. If your audit finds gaps needing WhatsApp-native platform migration, our AI virtual assistant UK teardown covers the alternatives with signed DPA + UK data residency options.

Read the AI virtual assistant UK teardown

Not ready to sign up yet? Try the free demo →

How did this land for you?
Tap what fits. Anonymous, one per browser.
✨ Recorded. Thanks for the vote.
📧 Small business owner? Weekly notes on what actually works. Free.