UK WhatsApp compliance after the Data (Use and Access) Act — how the new £17.5M PECR ceiling, cookie exemptions, and Article 30 records apply to business use.
UK compliance is a four-layer stack. Understanding the layers separately — and how the Data (Use and Access) Act 2025 amends each of them — is the first move before any operational decision.
Layer 1 — UK GDPR (Retained EU GDPR). The onshored version of the General Data Protection Regulation continues to apply. Article 6 lawful basis, Articles 13-14 transparency, Article 30 records of processing, Article 32 security, Article 33 breach notification within 72 hours to the Information Commissioner, Article 34 breach notification to affected data subjects where the risk is high. Data subject rights — access (30 days), rectification, erasure, restriction, portability, objection — apply to WhatsApp data the same way they apply to any other channel.
Layer 2 — Data Protection Act 2018 (c. 12). The UK statute that supplements UK GDPR with UK-specific provisions (Part 2 general processing, Part 3 law enforcement, Part 4 intelligence services, Part 5 ICO powers). This is where ICO investigatory and enforcement powers derive from, and where the age-of-consent for information society services is set (13 in the UK, higher than the EU baseline of 16 unless a Member State lowers).
Layer 3 — Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426). Direct marketing by electronic means, including WhatsApp Business Platform broadcasts, WhatsApp Business App bulk sends, SMS, email and phone calls. Regulation 22 is the operative provision for consent-based marketing; Regulation 21 covers unsolicited phone calls; Regulation 6 covers cookies and similar technologies.
Layer 4 — Data (Use and Access) Act 2025 (c. 18). The umbrella statute that amends the three layers above. It received Royal Assent on 19 June 2025 and its principal provisions came into force on 5 February 2026, with further obligations landing 19 June 2026. It is not a standalone data protection regime — it modifies UK GDPR (automated decision-making rules, purpose-limitation adjustments, exemption clarifications), DPA 2018 (ICO governance, cost recovery, new rules for research), and PECR 2003 (penalty ceiling, cookie exemptions, damage/distress threshold removal).
For UK WhatsApp compliance purposes the DUAA changes with immediate operational consequence are three: the PECR penalty ceiling jump from £500,000 to £17.5 million or 4% (whichever is higher); the removal of the substantial damage/distress procedural precondition for larger penalties; and the five new cookie consent exemptions. Everything else in the stack — lawful basis, breach reporting, DSAR response, Article 30 records — continues to apply in materially the same way, with clarifications rather than substantive change.
A fifth layer applies to regulated verticals. Dental practices operate under the General Dental Council Standards for the Dental Team plus the Care Quality Commission fundamental standards; physiotherapy clinics under the Health and Care Professions Council Standards of Conduct and Standards of Proficiency; solicitors under the Solicitors Regulation Authority Standards and Regulations; financial advisers under the Financial Conduct Authority Consumer Duty (in force since 31 July 2023); childcare settings under the Ofsted Early Years Foundation Stage statutory framework and Department for Education safeguarding guidance. In each case the sector regulator layers on top of UK GDPR + PECR — it does not replace them.
Regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 is the operative provision for WhatsApp marketing compliance. It prohibits the transmission of unsolicited communications for the purposes of direct marketing by means of electronic mail — a definition the Information Commissioner has repeatedly confirmed extends to SMS, WhatsApp Business Platform broadcasts, WhatsApp Business App bulk sends, and any comparable messaging system — unless the recipient has previously notified the sender that they consent to receive such communications.
The consent standard is UK GDPR consent: freely given, specific, informed, and unambiguous, with clear affirmative action. Silence, pre-ticked boxes, and inactivity do not constitute consent. Consent must be specific to the sender, the type of marketing, and — critically for WhatsApp — the channel. A customer who consents to 'marketing communications' has not consented to WhatsApp marketing specifically. A customer who consents to 'email marketing offers' has not consented to WhatsApp marketing. Best practice is a dedicated consent field naming WhatsApp explicitly: 'I consent to receive marketing offers from [business name] via WhatsApp' with a clear unchecked tickbox and a link to the privacy notice.
The Regulation 22(3) soft opt-in provides a narrow exception for existing customers. Three conditions must all be met: (a) the contact details were obtained in the course of a sale or negotiations for a sale of a product or service to that recipient; (b) the direct marketing is in respect of the sender's similar products and services only; and (c) the recipient was given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) at the time the details were initially collected, and at each subsequent communication. The ICO has not published dedicated WhatsApp guidance on soft opt-in application; conservative UK compliance practice treats WhatsApp marketing as requiring express opt-in rather than relying on the Regulation 22(3) route.
What DUAA 2025 changed here — three material shifts.
Shift 1 — the penalty ceiling. Section 128 and adjacent provisions of the Data (Use and Access) Act 2025 amend Schedule 1 of the Data Protection Act 2018 (which contains ICO enforcement machinery applicable to PECR) to raise the maximum PECR penalty from the historical £500,000 to £17.5 million or 4% of global annual turnover, whichever is higher. This matches the UK GDPR higher-tier maximum. It came into force 5 February 2026 with the main tranche of DUAA provisions. For UK small businesses this remains a theoretical ceiling rather than a realistic day-to-day exposure — the ICO's graduated penalty scale continues to consider organisational size, culpability, cooperation and remediation — but the abolition of the £500,000 cap means the fine calculation is now the same UK GDPR calculus with the same upper limits, and the psychological effect on repeat serious offenders is material.
Shift 2 — the damage or distress test. Under the pre-DUAA regime, the Information Commissioner had to be satisfied (per section 55A of DPA 1998, later carried into the DPA 2018 machinery for PECR) that the contravention was of a kind likely to cause substantial damage or substantial distress before imposing the higher PECR monetary penalties. DUAA 2025 removes this procedural precondition. The Commissioner now moves directly to enforcement calibration using the UK GDPR-style factors: nature and gravity, intentional or negligent character, actions to mitigate damage, degree of responsibility, previous infringements, cooperation, categories of personal data affected. This makes enforcement faster and lowers the bar the ICO must clear before issuing a substantial penalty.
Shift 3 — enforcement toolset. DUAA 2025 also extends the ICO's information notice, assessment notice, and enforcement notice powers to align with post-DUAA UK GDPR enforcement patterns, and adjusts the appeal route to align with First-tier Tribunal jurisdiction. The practical consequence: an ICO investigation of a WhatsApp marketing complaint now proceeds under the same procedural template as a UK GDPR investigation.
The Capita plc and Capita Pension Solutions combined £14 million penalty issued by the ICO on 15 October 2025 — for a security incident that exposed data of approximately 6.6 million people following a 58-hour delay in quarantining an infected device — is the largest single UK ICO penalty to date and sits under UK GDPR rather than PECR. It illustrates the ICO's willingness to apply the higher-tier calculus. Every 2025 major UK GDPR enforcement case cited the same set of root causes: missing multi-factor authentication, slow incident containment, inadequate vulnerability management, weak network segmentation, incomplete security testing. WhatsApp businesses processing customer contact data should read that pattern as guidance on where investigations focus.
UK WhatsApp compliance operates on a two-track model that is the most consistently misunderstood aspect of the frame. UK GDPR Article 6 governs the processing of personal data — storing a customer's WhatsApp number in the CRM, retaining message content in the platform log, running the customer through an automated workflow. PECR Regulation 22 governs the marketing act itself — the transmission of the promotional message. Both must clear. Clearing one does not clear the other.
For transactional messages — appointment reminders for booked customers, order confirmations for purchases, delivery updates, receipt of payment, service completion notifications, feedback requests tied to a specific service interaction — the appropriate UK GDPR lawful basis is typically Article 6(1)(b) performance of a contract or Article 6(1)(f) legitimate interest. Contract performance applies where the message is necessary to fulfil the service the customer has requested — a hotel booking confirmation, a physiotherapy appointment reminder, a legal case update to an active client. Legitimate interest applies where the message serves the business's legitimate purpose in an existing customer relationship and does not override the individual's interests or rights — a follow-up feedback request 24 hours after a beauty salon visit, a service anniversary reminder, a rebooking prompt after a natural service interval. Legitimate interest requires a Legitimate Interest Assessment (LIA) documented in writing — the ICO provides a template. PECR Regulation 22 does not apply to transactional messages because they are not for the purpose of direct marketing.
For marketing messages — promotional offers, new service announcements, cross-sell or upsell communications, re-engagement campaigns for dormant customers, seasonal promotions, referral programmes — PECR Regulation 22 requires explicit prior consent naming WhatsApp as the channel. The UK GDPR lawful basis for storing and processing the contact data underlying the marketing is typically Article 6(1)(a) consent, and the two consents (Article 6 consent for data processing + Regulation 22 consent for the marketing act) can be captured together in a single well-drafted consent field. The mechanical requirement is: the customer must actively tick a specific unchecked box saying they agree to receive WhatsApp marketing from the business; the wording must name WhatsApp; the customer must be told what the marketing will cover and how to withdraw consent; and the record must be maintained showing date, exact wording, channel named, and evidence of affirmative action.
The 'named channel' problem is the most common consent audit failure. A pre-2023 marketing consent captured as 'yes, please contact me with offers' does not lawfully cover WhatsApp marketing under PECR 2003 as interpreted by ICO 2024 direct marketing guidance. Businesses migrating existing email-consented customer lists onto WhatsApp cannot assume the email consent transfers — they must recapture consent naming WhatsApp before the first broadcast lands. A prudent migration path is: (i) audit existing consent records for channel specificity; (ii) re-consent audit through a bounded email or SMS campaign explaining the WhatsApp option; (iii) migrate only customers who actively opt in to the WhatsApp channel; (iv) treat everyone else as opted out for WhatsApp purposes even if they remain consented for email.
Special-category data (Article 9 UK GDPR). Health data (dental, physiotherapy, medical, pharmacy, care), racial or ethnic origin, religious beliefs, trade union membership, biometric data, sexual orientation — these require an Article 9 condition in addition to an Article 6 basis. For healthcare vertical WhatsApp use, the typical Article 9 condition is Article 9(2)(h) provision of health or social care, subject to the professional secrecy conditions in the Data Protection Act 2018 Schedule 3. Marketing to a special-category data holder requires an Article 9 condition that permits marketing (rare — normally explicit consent under Article 9(2)(a)) plus the PECR Regulation 22 consent. This is why healthcare WhatsApp marketing is exceptionally rare and typically limited to transactional communication only.
Children's data. UK GDPR sets the age of consent for information society services at 13 (DPA 2018 s. 9). WhatsApp's own terms of service require users to be at least 16 in most jurisdictions and 13 in the UK. Any UK business processing children's data via WhatsApp — tutoring services, private clinics, childcare communication with older children — must confirm the child meets the age of consent or obtain parental consent, and must apply the ICO Age Appropriate Design Code (in force since 2 September 2021) in any digital service touching children.
UK GDPR Article 28 requires that data controllers use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures such that processing meets the requirements of UK GDPR. The controller-processor relationship must be documented in a written contract that binds the processor to the controller. For UK WhatsApp Business Platform users, Meta Platforms Ireland Ltd (the WhatsApp entity operating for EEA and UK customers) is the processor of WhatsApp message data on the business's behalf, and the WhatsApp Business Terms of Service incorporates a data processing agreement (DPA) satisfying the Article 28 requirement.
The Meta WhatsApp Business DPA — available at whatsapp.com/legal/business-data-processing-terms — covers the following:
Important limitation of scope. The Meta DPA covers Meta's processing of WhatsApp message data on the business's behalf. It does not cover the business's own processing of customer data held outside Meta's system — the business's CRM, contact list, consent records, custom marketing database, or any other data held in the business's own systems remains the business's controller-level processing and is fully subject to UK GDPR independently. The Meta DPA does not transfer the controller's compliance obligations; it discharges only the Article 28 processor-diligence duty.
Cross-border transfer to the United States. Meta's infrastructure includes US-based servers. Post-Brexit, UK controllers transferring personal data to a US company or entity must rely on an appropriate UK GDPR Chapter V transfer mechanism. The relevant mechanisms are:
UK-US Data Bridge. The UK Extension to the EU-US Data Privacy Framework came into force on 12 October 2023 and allows UK controllers to transfer personal data to US organisations that have self-certified under both the EU-US Data Privacy Framework and the UK Extension. WhatsApp LLC and Meta Platforms have self-certified under the EU-US Data Privacy Framework. UK-US Data Bridge coverage requires the US entity to have self-certified specifically to the UK Extension in addition to the EU DPF certification, and this status can be verified at the US Department of Commerce Data Privacy Framework website. Before relying on the UK-US Data Bridge as the transfer mechanism, controllers should check Meta's current UK Extension certification status.
Standard Contractual Clauses (SCCs) with the UK Addendum. The UK International Data Transfer Agreement and the UK Addendum to the EU SCCs can be used as an alternative transfer mechanism where the UK-US Data Bridge does not apply or its certification lapses. Businesses should verify that the current Meta WhatsApp Business Terms and DPA include the appropriate SCC references.
Transfer risk assessment. UK ICO guidance recommends a transfer risk assessment for onward transfers to jurisdictions without a formal adequacy decision. The UK-US Data Bridge functions as an adequacy-equivalent for certified organisations; for uncertified onward transfers, a formal TRA is required.
The practical UK compliance step is: verify Meta's UK-US Data Bridge certification at the US Data Privacy Framework list before or at the time of onboarding to WhatsApp Business Platform, and document the verification in the Article 30 processing record under 'international transfers'. If the certification is present and current, the UK-US Data Bridge is the transfer mechanism. If it is not, the DPA's SCC references become the operative mechanism, and a TRA should be documented.
The theoretical UK GDPR and PECR maxima — £17.5 million or 4% — are the ceiling. The realistic exposure for a UK SMB running compliant transactional WhatsApp communication with an opt-in customer base is materially lower. Understanding where actual enforcement lands is more useful than fixating on the ceiling.
Where ICO enforcement action database shows fines landing (2023-2026 pattern):
Bulk unsolicited electronic marketing to unconsented recipients. The overwhelming majority of PECR direct marketing enforcement cases involve organisations sending millions of SMS or email messages without valid consent, typically to lists purchased from third-party brokers where the original consent did not cover the specific marketing category or specific sender. Fine ranges have typically fallen in the £50,000 to £300,000 band pre-DUAA; post-DUAA these are likely to move upward as the £500,000 cap is removed.
Data breaches involving customer contact data. Security incidents where insufficient technical measures allowed unauthorised access to customer records — including WhatsApp message content or metadata — attract UK GDPR Article 32 penalties. The Capita combined £14 million (15 October 2025) is the leading recent example, involving 6.6 million affected data subjects and a 58-hour delay in device quarantine.
Failure to honour data subject rights within 30 days. Recurring smaller fines and formal enforcement notices are issued for organisations failing to respond to Subject Access Requests within the UK GDPR Article 12(3) one-month deadline, or refusing rectification/erasure requests without valid legal basis.
Article 30 records missing or inadequate. In multiple ICO investigations, the absence of a Records of Processing Activities document has been treated as an aggravating factor and evidence of poor governance culture — the RoPA is the first document the ICO requests, and its absence signals inadequate accountability.
Where ICO enforcement does not typically land, for realistic SMB risk calibration:
A UK small business sending transactional WhatsApp messages (appointment reminders, order confirmations, service updates) to customers who booked or purchased, with a functioning STOP mechanism and reasonable data retention, is at low enforcement risk. This is the intended and permitted operational envelope.
A UK business marketing to opted-in customers with genuine, specific, channel-named consent records and honoured opt-outs is at low enforcement risk. Occasional individual complaints tend to be resolved through advisory correspondence rather than penalty.
A UK business making occasional individual compliance errors — accidentally sending one message after a STOP request, briefly missing a DSAR deadline due to staff illness — typically receives advisory guidance rather than formal enforcement. The ICO's stated approach prioritises systemic non-compliance and repeat offenders.
Practical risk hierarchy for UK WhatsApp businesses:
A UK small business that runs a category 4 or 5 operation, with an Article 30 record, an accessible privacy notice, and a documented breach and DSAR runbook, is not the target profile of ICO enforcement. The ICO's public rhetoric emphasises graduated enforcement calibrated to organisational size and cooperation. The DUAA 2025 ceiling raise is the theoretical extreme; the operational exposure for well-run SMB WhatsApp compliance remains manageable.
The operational compliance work — Article 30 records, cookie consent (touching WhatsApp Web pixels), breach reporting, and data subject rights response — is where day-to-day UK WhatsApp compliance actually happens.
Article 30 Records of Processing Activities. UK GDPR Article 30 requires organisations with 250 or more employees to maintain records of processing activities in writing, plus smaller organisations that process personal data 'not occasionally', that process special-category data, or where the processing is likely to result in a risk to individuals' rights. For most UK SMBs using WhatsApp for regular customer communication, Article 30 records are required. A compliant WhatsApp processing record documents:
The ICO publishes a Records of Processing Activities template that UK small businesses can adapt. A one-page tabular document that captures the fields above is compliant; ornate documentation is not required.
Cookies under DUAA 2025. The Data (Use and Access) Act 2025 introduced five new categories of cookies exempt from consent requirements under Regulation 6 of PECR: (i) aggregate analytics cookies used solely for producing aggregate statistics about site use where the controller has taken appropriate confidentiality measures; (ii) cookies necessary for security purposes; (iii) cookies enabling website functionality that adapts the site to the user (language preference, geographic locality); (iv) first-party autofill cookies for information the user has entered; and (v) cookies related to software updates. Advertising cookies, cross-site tracking, and third-party analytics remain outside the exemption and require consent.
For UK WhatsApp businesses this matters because business websites that embed WhatsApp Web click-to-chat widgets, WhatsApp Business API integration status widgets, or marketing tracking pixels that attribute WhatsApp-driven conversions typically use cookies that fall on the advertising or third-party tracking side of the line. WhatsApp Web itself, when embedded via a click-to-chat link or a chat widget, may set cookies for session persistence — first-party functional cookies for the chat session are within the new exemption; tracking pixels that fire on chat-initiation events for advertising measurement purposes are not exempt and require consent.
Breach reporting under Article 33. Where a personal data breach occurs that is likely to result in a risk to the rights and freedoms of natural persons, the controller must notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it. For WhatsApp-specific breaches — a compromised BSP account exposing customer message history, a device theft where the WhatsApp Business App was logged in and unlocked, an accidental broadcast to the wrong customer group exposing customer names to each other — the 72-hour clock starts on awareness by the controller. Where the breach is likely to result in a high risk to rights and freedoms of natural persons, Article 34 requires notification to the affected data subjects as well.
Operationally the small business owner needs a documented breach runbook: who notices, who assesses, who classifies risk, who prepares the ICO submission (ICO provides an online breach reporting form at ico.org.uk/for-organisations/report-a-breach/), and who communicates with affected customers. A one-page document naming the three or four people and their responsibilities is compliant.
Data Subject Access Requests. UK GDPR Article 12(3) requires that the controller respond to a DSAR (or any Article 15-22 rights request) without undue delay and in any event within one month. The period may be extended by up to two further months where necessary, taking into account complexity and number of requests, with the extension communicated to the data subject within the first month. For a UK WhatsApp business, a DSAR typically requires: producing all personal data held about the requester (contact details, service history, communication history including WhatsApp message content, consent records, transaction records); providing information required by Articles 13-14 about how the data is processed; and — where the requester also invokes Article 17 erasure or Article 21 objection — actioning those requests unless a lawful basis for continued processing is documented. A DSAR SOP that a small business owner can execute in under 4 hours is achievable with the WhatsApp Business App export function plus CRM export.
The operational compliance work reduces to eleven items that a UK small business owner can complete in a single working day, without external counsel, using ICO templates and free-tier or existing tooling.
Foundation (items 1-4) — one-time setup.
ICO registration. Register with the ICO as a data controller if not already registered. Registration is administered under the Data Protection (Charges and Information) Regulations 2018. Annual fee is £40 for tier 1 (micro-business, turnover under £632,000 and staff up to 10), £60 for tier 2 (small-medium, turnover up to £36 million and staff up to 250). Registration takes approximately 15 minutes at ico.org.uk/for-organisations/data-protection-fee/pay-the-fee/. Payment triggers an automatic ICO registration certificate.
Privacy notice update. Update the business privacy notice or privacy policy to expressly name WhatsApp Business Platform as a communication channel, identify Meta Platforms Ireland Ltd as processor and WhatsApp LLC / Meta Platforms Inc as onward recipient, state the lawful basis for WhatsApp communication (contract, legitimate interest, or consent as applicable), state the international transfer mechanism (UK-US Data Bridge with verification, or SCCs fallback), state the retention schedule, and identify data subject rights and the ICO complaint mechanism. Publish at bossbot.uk/privacy or equivalent and link from every consent-capture point.
Article 30 processing record. Populate the Article 30 record entry for WhatsApp processing using the ICO template. One page. Cover the fields listed in the section above.
Legitimate Interest Assessment (LIA) where relied on. If any WhatsApp use case will rely on Article 6(1)(f) legitimate interest (typical for transactional feedback requests or service anniversary reminders), complete the ICO LIA template documenting the purpose, necessity, and balance test.
Consent capture (items 5-7) — operational integration.
WhatsApp-named consent field. Add an explicit consent capture field to every point of customer data collection: booking forms, website contact forms, in-person booking sheets, phone-booking scripts. The field should be an unchecked tickbox with wording along the lines of: 'I would like to receive booking updates and, optionally, marketing offers from [business name] via WhatsApp. I can withdraw consent at any time by replying STOP.' Distinguish transactional consent (typically implicit in booking or purchase) from marketing consent (must be explicit).
Consent record database. Maintain a consent record capturing date of consent, exact consent wording shown, channel named (WhatsApp), how consent was given (booking form / website / phone), and customer identifier. For volumes under 5,000 customers, a spreadsheet is compliant. For higher volumes, integration with the CRM is recommended so that consent records are joined to customer records.
STOP keyword handling. Configure the WhatsApp Business platform to recognise inbound STOP (and equivalent variants — 'unsubscribe', 'no more', 'remove me') messages as opt-out requests. On receipt of a STOP, mark the customer as opted-out in the consent record and suppress from the marketing send list before the next cron cycle. Confirm the opt-out to the customer via a single confirmation message ('You have been unsubscribed. You will still receive booking and service messages').
Operational (items 8-11) — ongoing rhythms.
DSAR response process. Document a DSAR SOP identifying who receives DSAR requests, the 30-day deadline, the data sources to query (CRM, WhatsApp Business App / BSP archive, booking system, payment platform, accounting), the identity verification step (typically a match of email or phone number to CRM record), and the response format (typically a written summary plus data export).
Breach runbook. Document the breach identification, classification and reporting process. Include the 72-hour ICO notification form URL, the internal escalation path, the three or four named individuals and their roles, and a communication template for affected customers where Article 34 notification is required.
Annual consent hygiene review. Once per year, review consent records and remove from marketing sends any customer who has not engaged (opened a message, clicked a link, replied) for 12-18 months, subject to a soft re-consent opportunity. Legitimate interest and contract-performance-based transactional messaging is not affected.
Sector regulator layer where applicable. For regulated verticals — dental (GDC + CQC), physiotherapy (HCPC + CSP), pharmacy (GPhC + CQC), optician (GOC), legal (SRA + BSB), financial advice (FCA Consumer Duty), childcare and care (Ofsted + CQC + Care Inspectorate + CIW + RQIA) — layer the sector regulator's client communication, record-keeping, professional secrecy and safeguarding obligations on top of the UK GDPR + PECR + DUAA baseline. In every case the sector obligations are additional to, not a replacement for, the ICO-enforced regime.
Certain UK verticals operate under a sector regulator that layers profession-specific obligations on top of the UK GDPR + PECR + DUAA baseline. WhatsApp communication in these verticals is not prohibited — it is permissible with layered controls. The pattern is consistent: the sector regulator sets standards for practitioner conduct, record-keeping and communication; the ICO framework governs the personal data underlying those communications; both must clear.
Dental practice (GDC + CQC). The General Dental Council Standards for the Dental Team apply, particularly Standard 4 (maintain and protect patients' information) and Standard 8 (raise concerns if patients are at risk). Care Quality Commission fundamental standards apply for the practice. WhatsApp communication with patients about appointment reminders and post-treatment care is compliant with GDC Standard 4.5 (using electronic communication in a way that maintains patient confidentiality) provided the practice uses WhatsApp Business Platform (not personal WhatsApp accounts), applies appropriate encryption, restricts access to the patient's clinical record holder, and documents the communication channel in the patient record. Marketing to dental patients is subject to the same PECR Regulation 22 consent standard as any other vertical, plus GDC guidance restricting misleading advertising claims.
Physiotherapy (HCPC + CSP). The Health and Care Professions Council Standards of Conduct, Performance and Ethics apply, particularly Standard 5 (keep records of your work) and Standard 5.2 (records of your professional practice must be complete and accurate). Chartered Society of Physiotherapy member guidance layers additional professional expectations. WhatsApp communication with physiotherapy patients about session bookings, exercise programme reminders, and follow-up is permissible where the practice documents the communication method in the patient record, uses WhatsApp Business Platform rather than personal accounts, and separates transactional communication (contract or legitimate interest under UK GDPR) from marketing (explicit PECR consent).
Solicitor practice (SRA). The Solicitors Regulation Authority Standards and Regulations apply, particularly the Standards Chapter 6 (client identification and file management), the Client Account Rules, and the Transparency Rules requiring price publication for certain regulated activities. WhatsApp communication with solicitor clients is permissible for administrative matters (appointment scheduling, document collection reminders, matter status updates) where the firm distinguishes matter privilege-material from routine administration and does not send matter-privileged content via WhatsApp unless the client has expressly consented after being advised of the confidentiality implications. Marketing to solicitor clients is subject to PECR consent and the SRA's requirement that all client communication is fair, respectful, and does not exploit vulnerability.
Financial adviser (FCA Consumer Duty). The Financial Conduct Authority Consumer Duty (in force since 31 July 2023 for new and existing products) requires firms to act to deliver good outcomes for retail customers. Product communication, price and value, consumer understanding, and consumer support are the four outcomes. WhatsApp communication with regulated financial customers about product performance, portfolio updates, and administrative matters is permissible where the firm can demonstrate the communication supports the Consumer Duty outcomes and is retained for record-keeping under FCA rules (typically 5 years for regulated activities, longer for pension advice). Marketing subject to FCA financial promotion rules layers on top of PECR consent.
Childcare (Ofsted + EYFS). The Ofsted-registered childcare provider operates under the Early Years Foundation Stage statutory framework and Department for Education safeguarding guidance. Parent-facing WhatsApp communication about attendance, collection, illness, developmental observations, and daily updates is a standard element of a modern early years setting. Compliance requires: (i) written parent consent for WhatsApp as the communication channel; (ii) named designated safeguarding lead who reviews any WhatsApp exchange raising safeguarding concerns; (iii) documented data retention aligned to the EYFS record-keeping requirement; (iv) explicit prohibition on any staff use of personal WhatsApp accounts for parent communication; (v) use of a business WhatsApp account with role-based access controlled by the manager.
Pharmacy (GPhC + CQC). The General Pharmaceutical Council Standards for Pharmacy Professionals apply, particularly Standard 6 (behave in a professional manner). Distance-selling pharmacy communication is additionally regulated. WhatsApp prescription reminders, adherence check-ins, and administrative communication is permissible under UK GDPR Article 9(2)(h) provision of health care with layered GPhC professional secrecy. Marketing is subject to PECR consent plus the GPhC advertising restrictions.
Care and nursing home (CQC + Care Inspectorate + CIW + RQIA). WhatsApp family communication about resident wellbeing is a common practice. Compliance requires the resident's or nominated family contact's documented consent for the specific WhatsApp use case, care record documentation of the communication channel, and mental capacity assessment where the resident's capacity to consent is uncertain. The four national regulators (CQC in England, Care Inspectorate in Scotland, Care Inspectorate Wales, RQIA in Northern Ireland) each have their own regulations layered on top of UK GDPR.
The consistent pattern across regulated verticals is that WhatsApp is not prohibited — it is permissible with layered documentation. The eleven-item compliance checklist in the previous section is the ICO-enforced baseline; sector regulator obligations add specific record-keeping, communication-channel documentation, safeguarding and professional secrecy overlays. A well-run regulated UK business can operate WhatsApp Business Platform compliantly and often does — the key is treating both compliance layers as parallel rather than substituting one for the other.
Data + numbers referenced in this article are sourced from these public documents:
BossBot's WhatsApp Business Platform integration includes named-channel consent capture, STOP opt-out cron-cycle suppression, Article 30 record templates, and end-to-end encrypted message logging. Free trial available.
Start Free TrialNot ready to sign up yet? Try the free demo →