← All articles
WhatsApp UK GDPR Data Protection Act 2018 Kseniia Petruk By Kseniia Petruk · 2026-07-31 · Updated 2026-08-03 · 7 min read
Written by Kseniia Petruk, founder of BossBot. Original research and product experience. About the author.
Fact-checked against primary sources · Last reviewed 2026-08-03 · How we fact-check

WhatsApp and UK GDPR: A Practical Compliance Guide for Small Businesses

A person reviewing data protection documents at a desk
Photo: Francis Odeyemi · Unsplash
Short answer

UK businesses using WhatsApp for customer communication must comply with UK GDPR and PECR: transactional messages (order confirmations, appointment reminders) are permitted on existing relationship grounds; marketing messages require explicit opt-in consent. The ICO enforces these rules. Consent must be documented, opt-outs honoured promptly, and data retained no longer than necessary.

What UK small businesses need to know about using WhatsApp Business under UK GDPR and the Data Protection Act 2018 — consent, data minimisation, ICO

In this article Hide ▲
  1. UK GDPR and WhatsApp: The Basics
  2. What Personal Data WhatsApp Involves
  3. Lawful Basis: When You Need Consent and When You Don't
  4. Consent in Practice: What Works and What Doesn't
  5. Data Minimisation, Retention, and Individual Rights
  6. ICO Enforcement and What Small Businesses Should Know

UK GDPR and WhatsApp: The Basics

Using WhatsApp Business to communicate with customers in the UK means processing personal data — phone numbers, names, message content, and in some cases order details, addresses, and payment references. The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 apply to all of this.

This does not mean WhatsApp is prohibited for UK businesses. It means businesses that use WhatsApp must meet the same data protection obligations that apply to any other channel where personal data is processed: lawful basis, transparency, data minimisation, security, and respect for individual rights.

The Information Commissioner's Office (ICO) is the UK's regulator for data protection. It does not specifically address WhatsApp in guidance aimed at small businesses, but its general principles for mobile and messaging communications apply. The practical implication: a business that uses WhatsApp responsibly — with consent captured, data handled securely, and opt-outs processed — is operating within the UK GDPR framework. A business using WhatsApp to send marketing messages to contacts who did not opt in is in breach of both UK GDPR and the Privacy and Electronic Communications Regulations (PECR).

What Personal Data WhatsApp Involves

When a customer contacts your business on WhatsApp, a range of personal data enters your business environment:

WhatsApp end-to-end encryption protects messages in transit, but it does not satisfy your UK GDPR obligations. Encryption protects the message from being intercepted between sender and recipient — it does not determine your lawful basis for processing the data, how long you may retain it, or whether the person consented to receive marketing messages.

For WhatsApp Business API users, where conversation data is also processed by the WhatsApp platform and potentially by third-party integrations, a Data Processing Agreement (DPA) with each processor is required. BossBot provides a standard DPA for UK businesses.

🎯 For small-business owners
Weekly notes on what's actually working for small businesses.
WhatsApp scripts, SaaS-tool comparisons, real revenue tactics — honest, no fluff.

Data Minimisation, Retention, and Individual Rights

Beyond consent, the operational data protection requirements for WhatsApp use are:

Data minimisation: Collect only what you need. If you are booking a hair appointment via WhatsApp, you need the customer's name, phone number, and appointment details. You do not need their home address, date of birth, or payment card number (which should not be collected via WhatsApp regardless).

Retention: Personal data should not be held longer than necessary. For WhatsApp conversations, this means defining how long you retain conversation history and deleting it when the retention period has passed. A useful rule of thumb: retain for the duration of the customer relationship plus a reasonable period for complaint resolution (commonly 12–24 months for service businesses), then delete.

Right to access: A customer can submit a Subject Access Request (SAR) asking for all personal data you hold about them. WhatsApp conversation history is personal data and must be included in your SAR response. You have one calendar month to respond.

Right to erasure: A customer can ask you to delete their personal data. If there is no overriding legal basis to retain it (for example, tax records have mandatory retention periods), you must comply. Deletion must include WhatsApp conversation history held in your CRM or connected system.

Right to object to marketing: Any customer can withdraw consent for marketing at any time. When a customer opts out, remove them from your WhatsApp broadcast lists immediately and do not contact them with promotional messages again.

ICO Enforcement and What Small Businesses Should Know

The ICO can issue fines of up to £17.5 million or 4% of annual global turnover (whichever is higher) for serious infringements, and up to £8.7 million or 2% of turnover for a lower tier of violations. Most ICO enforcement against small businesses involves direct marketing violations — sending unsolicited emails or texts — rather than systemic data breaches.

For a small business using WhatsApp, the most common compliance failures that attract ICO attention are:
- Sending promotional WhatsApp messages to contacts who did not opt in
- Using purchased contact lists for WhatsApp marketing
- Not providing an opt-out mechanism in marketing messages
- Failing to respond to a Subject Access Request or erasure request

For a business that processes personal data on a small scale, uses WhatsApp for transactional communications and only sends marketing to opted-in contacts, the practical risk of ICO investigation is low — provided complaints are handled promptly when they arise.

The ICO's guidance for small businesses on direct marketing, data subject rights, and lawful basis is published at ico.org.uk and is more accessible than the regulation text itself. If you are implementing WhatsApp automation for customer communication, it is worth spending an hour with the ICO's self-assessment checklists to verify your setup is compliant before you go live.

Sources

Data + numbers referenced in this article are sourced from these public documents:

  1. WhatsApp Business Platform — official product page
  2. Meta: WhatsApp Business Platform pricing
  3. WATI — WhatsApp Business API platform
  4. Respond.io — business messaging platform
  5. Statista: WhatsApp users worldwide
  6. Statista: WhatsApp users in the United Kingdom
  7. ICO: UK GDPR — lawful basis for processing

Frequently Asked Questions

Yes, but only to customers who have explicitly opted in to receive WhatsApp marketing messages from you. Under UK GDPR and PECR, sending promotional messages to contacts who did not consent is unlawful direct marketing. The consent must be freely given, specific to WhatsApp marketing, and documented. Simply having a customer's phone number — whether from a previous purchase, a business card, or an imported list — does not constitute valid consent for marketing messages.
The same UK GDPR principles apply to both — lawful basis, data minimisation, retention, and individual rights. The channel-specific rules under PECR (Privacy and Electronic Communications Regulations) also apply to both. The practical difference is that WhatsApp is a more intimate channel than email: messages arrive in the same app as personal conversations, which increases the intrusiveness of unsolicited marketing. This makes proper consent even more important for WhatsApp marketing than for bulk email marketing, where consumers have somewhat normalised opt-out mechanisms.
Yes. Under UK GDPR, when you use a third-party service to process personal data on your behalf (as BossBot does when handling WhatsApp conversations), that service is a data processor and you must have a written Data Processing Agreement (DPA) with them. BossBot provides a standard DPA for UK customers as part of its terms. This DPA covers: the scope of processing, data security measures, restrictions on further processing, and deletion of data at the end of the relationship.
Yes. Appointment reminders sent to a customer who has booked an appointment with you are transactional communications — they relate directly to a service the customer has already requested. You can send these on the basis of 'contract performance' or 'legitimate interest' without a separate WhatsApp marketing consent. The key distinction is purpose: a reminder about an existing booking is transactional; a message encouraging the customer to book another appointment or try a new service is marketing and requires consent.
You must comply within one calendar month. Deletion should cover: the conversation history held in your WhatsApp Business account, any records derived from the conversation stored in your CRM or booking system, and any broadcast or marketing lists the contact appears on. If there is a legal basis to retain some of the data (for example, a payment record that must be kept for tax purposes under HMRC rules), you may retain the minimum required data for the mandatory period but should delete everything else. Acknowledge the erasure request promptly and confirm completion once done.
What a conversation looks like
🤖
BossBot AI
● Online
')">
Hi! I came across your business and wanted to find out more
Hi there! Happy to help 😊 What would you like to know? I can help with bookings, pricing, availability, or any questions you have.
Great — do you have any appointments available this week?
Yes! I have availability Tuesday and Thursday this week. What time of day works best for you?
Thursday afternoon if possible
Thursday afternoon is available ✅ I'll get that booked for you. Can I take your name to confirm?

WhatsApp for UK businesses — compliance built in.

BossBot captures consent, maintains audit logs, and provides a UK GDPR-aligned DPA. 7-day free trial.

Start Free Trial

Not ready to sign up yet? Try the free demo →

How did this land for you?
Tap what fits. Anonymous, one per browser.
✨ Recorded. Thanks for the vote.
📧 Small business owner? Weekly notes on what actually works. Free.