UK businesses using WhatsApp for customer communication must comply with UK GDPR and PECR: transactional messages (order confirmations, appointment reminders) are permitted on existing relationship grounds; marketing messages require explicit opt-in consent. The ICO enforces these rules. Consent must be documented, opt-outs honoured promptly, and data retained no longer than necessary.
What UK small businesses need to know about using WhatsApp Business under UK GDPR and the Data Protection Act 2018 — consent, data minimisation, ICO
Using WhatsApp Business to communicate with customers in the UK means processing personal data — phone numbers, names, message content, and in some cases order details, addresses, and payment references. The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 apply to all of this.
This does not mean WhatsApp is prohibited for UK businesses. It means businesses that use WhatsApp must meet the same data protection obligations that apply to any other channel where personal data is processed: lawful basis, transparency, data minimisation, security, and respect for individual rights.
The Information Commissioner's Office (ICO) is the UK's regulator for data protection. It does not specifically address WhatsApp in guidance aimed at small businesses, but its general principles for mobile and messaging communications apply. The practical implication: a business that uses WhatsApp responsibly — with consent captured, data handled securely, and opt-outs processed — is operating within the UK GDPR framework. A business using WhatsApp to send marketing messages to contacts who did not opt in is in breach of both UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
When a customer contacts your business on WhatsApp, a range of personal data enters your business environment:
WhatsApp end-to-end encryption protects messages in transit, but it does not satisfy your UK GDPR obligations. Encryption protects the message from being intercepted between sender and recipient — it does not determine your lawful basis for processing the data, how long you may retain it, or whether the person consented to receive marketing messages.
For WhatsApp Business API users, where conversation data is also processed by the WhatsApp platform and potentially by third-party integrations, a Data Processing Agreement (DPA) with each processor is required. BossBot provides a standard DPA for UK businesses.
UK GDPR requires every processing activity to have a lawful basis. For WhatsApp communications, the two most relevant bases are:
Legitimate interest or contract performance (transactional messages):
If a customer has placed an order, booked an appointment, or initiated a service enquiry, sending them updates directly related to that transaction — confirmation, status update, delivery notification — can be done under 'contract performance' or 'legitimate interest' without requiring a separate WhatsApp consent tick-box. The customer reasonably expects to receive these communications.
Consent (marketing messages):
Sending promotional content, special offers, product announcements, or any message whose purpose is to encourage the customer to purchase or re-engage (rather than fulfil a transaction they've already initiated) requires prior, freely given, specific, informed consent. This applies even if the customer has bought from you before.
Under PECR — which governs electronic direct marketing — this distinction is clear: transactional WhatsApp messages are permitted on existing business relationship grounds; marketing messages require opt-in. The ICO's published guidance on direct marketing applies to WhatsApp in the same way it applies to email and SMS.
Practical implication: A customer who enquires about your services on WhatsApp has not thereby consented to receive future promotional messages. Consent needs to be explicitly captured — for example, during the conversation: 'Would you like to receive offers and updates from us via WhatsApp? Reply YES to opt in or NO to receive only messages about your bookings.'
UK GDPR sets specific requirements for valid consent that are frequently misapplied in WhatsApp marketing:
What counts as valid consent:
- A customer actively replies YES (or equivalent) to a specific opt-in message that explains what they are consenting to receive
- A customer ticks an opt-in box on a contact form that clearly states 'I agree to receive WhatsApp marketing messages from [Business Name]'
- A customer scans a WhatsApp QR code that links to an opt-in confirmation message
What does not count as valid consent:
- A customer sharing their phone number with you (for any reason)
- A customer buying from you previously
- A pre-ticked opt-in box
- A statement like 'By contacting us you agree to receive updates' buried in a privacy notice the customer did not read
- Importing contacts from a purchased list
Consent must be recorded. For each contact, you should hold: when consent was given, through what mechanism, and what they consented to receive. If the ICO receives a complaint about an unsolicited WhatsApp message, the ability to produce this record is your primary defence.
BossBot captures WhatsApp opt-in consent as part of the initial customer conversation and logs the timestamp and consent text against each contact record.
Beyond consent, the operational data protection requirements for WhatsApp use are:
Data minimisation: Collect only what you need. If you are booking a hair appointment via WhatsApp, you need the customer's name, phone number, and appointment details. You do not need their home address, date of birth, or payment card number (which should not be collected via WhatsApp regardless).
Retention: Personal data should not be held longer than necessary. For WhatsApp conversations, this means defining how long you retain conversation history and deleting it when the retention period has passed. A useful rule of thumb: retain for the duration of the customer relationship plus a reasonable period for complaint resolution (commonly 12–24 months for service businesses), then delete.
Right to access: A customer can submit a Subject Access Request (SAR) asking for all personal data you hold about them. WhatsApp conversation history is personal data and must be included in your SAR response. You have one calendar month to respond.
Right to erasure: A customer can ask you to delete their personal data. If there is no overriding legal basis to retain it (for example, tax records have mandatory retention periods), you must comply. Deletion must include WhatsApp conversation history held in your CRM or connected system.
Right to object to marketing: Any customer can withdraw consent for marketing at any time. When a customer opts out, remove them from your WhatsApp broadcast lists immediately and do not contact them with promotional messages again.
The ICO can issue fines of up to £17.5 million or 4% of annual global turnover (whichever is higher) for serious infringements, and up to £8.7 million or 2% of turnover for a lower tier of violations. Most ICO enforcement against small businesses involves direct marketing violations — sending unsolicited emails or texts — rather than systemic data breaches.
For a small business using WhatsApp, the most common compliance failures that attract ICO attention are:
- Sending promotional WhatsApp messages to contacts who did not opt in
- Using purchased contact lists for WhatsApp marketing
- Not providing an opt-out mechanism in marketing messages
- Failing to respond to a Subject Access Request or erasure request
For a business that processes personal data on a small scale, uses WhatsApp for transactional communications and only sends marketing to opted-in contacts, the practical risk of ICO investigation is low — provided complaints are handled promptly when they arise.
The ICO's guidance for small businesses on direct marketing, data subject rights, and lawful basis is published at ico.org.uk and is more accessible than the regulation text itself. If you are implementing WhatsApp automation for customer communication, it is worth spending an hour with the ICO's self-assessment checklists to verify your setup is compliant before you go live.
Data + numbers referenced in this article are sourced from these public documents:
BossBot captures consent, maintains audit logs, and provides a UK GDPR-aligned DPA. 7-day free trial.
Start Free TrialNot ready to sign up yet? Try the free demo →