Is using WhatsApp for business GDPR compliant? What you need to do, what risks to avoid, and how to handle customer data legally on WhatsApp.
The short answer: WhatsApp Business API can be used in a GDPR-compliant way. The personal WhatsApp app and the free WhatsApp Business app present data transfer risks that many businesses are unaware of.
Here is the core issue. When customers in the EU or UK message a business using the free WhatsApp Business app, Meta processes that conversation data under its own privacy policy. Meta uses this data for its advertising business — which means EU customer data may be processed for purposes the customer did not specifically consent to. Several EU data protection authorities, including the Hamburg DPA, have raised concerns about this practice. The European Data Protection Board's 2023 guidance on instant messaging for businesses noted that the free app presents consent documentation challenges.
WhatsApp Business API — the paid API accessed through a Meta-approved Business Solution Provider (BSP) — operates under different terms. The BSP provides a Data Processing Agreement (DPA) that defines how data is processed, where it is stored, and who has access. Businesses can configure data residency within the EEA for EU customers. This is the version that can be GDPR-compliant when set up correctly.
The practical test: if your BSP is EU-hosted, you have a signed DPA covering Article 28 processor requirements, and you have documented lawful bases for each message type — your WhatsApp business use can be GDPR-compliant. Without these three elements, you carry compliance risk.
GDPR's Article 6 requires a lawful basis for every instance of personal data processing. For WhatsApp business communications, there are three commonly applicable grounds, each with different requirements:
Contract performance (Article 6(1)(b)): applies to messages that are necessary to deliver a service the customer has agreed to purchase. Appointment confirmation, order dispatch notification, service delivery reminder — these are contract-performance communications. You do not need separate consent for these messages; the contract itself is the lawful basis. The customer's phone number collected at booking is processed under this ground for these specific purposes.
Consent (Article 6(1)(a)): required for marketing messages, promotional broadcasts, and any use of customer data beyond what is directly necessary for the contracted service. Consent must be freely given, specific, informed, and unambiguous — a pre-ticked 'send me offers' checkbox does not satisfy GDPR. A customer who opts in to appointment reminders has not automatically opted in to promotional broadcasts.
Legitimate interest (Article 6(1)(f)): potentially applicable for service-related communications that go slightly beyond the strict contract scope — for example, a post-appointment satisfaction check-in. However, legitimate interest requires a three-part balancing test (necessity, proportionality, and that the customer's rights do not override the interest) and documented evidence of that assessment. The ICO's guidance suggests that small businesses should use this ground cautiously and ensure they conduct and record the legitimate interest assessment.
The practical implication: maintain a data register that documents, for each type of WhatsApp message you send, which lawful basis applies. This register is what a supervisory authority will request in any compliance review.
GDPR consent for WhatsApp marketing messages has specific requirements that differ from common consent practices:
It must be separate from other consents. A customer who consents to a service agreement has not consented to marketing messages. A single 'I agree to the terms and conditions' checkbox does not satisfy GDPR consent for WhatsApp marketing.
It must be specific to the channel. Consent to 'receive updates by email' does not extend to WhatsApp messages. If you want to send both, you need to collect consent for each channel separately, or clearly state that consent covers both in the same disclosure.
It must be easy to withdraw. Every marketing broadcast must include a clear opt-out mechanism — typically 'Reply STOP to unsubscribe' — and the business must honour opt-outs immediately. WhatsApp Business API platforms typically handle opt-out management at the platform level.
The consent record must be retained. The business must be able to demonstrate that consent was given — ideally with a timestamp, the channel through which it was obtained, and the wording of the consent request. This record must be retained for the duration of the marketing relationship, plus enough time to respond to any complaint.
Practical collection methods: a checkbox on the booking form ('I consent to receive WhatsApp updates and special offers from [Business Name] — unsubscribe at any time by replying STOP'), or a first-WhatsApp-contact opt-in message that the customer must affirmatively confirm.
The data transfer issue is the most legally significant GDPR distinction between WhatsApp Business API and the free WhatsApp Business app.
The EU-US data transfer framework (the EU-US Data Privacy Framework, adopted July 2023) provides a legal mechanism for transferring EU personal data to the United States. Meta relies on this framework for its data transfers. However, EU-US data transfer frameworks have been successfully challenged and invalidated twice before (Safe Harbor in 2015, Privacy Shield in 2020). If the current framework is similarly invalidated, businesses relying solely on Meta's privacy policy for transfer legitimacy could face renewed compliance exposure.
WhatsApp Business API through a European-hosted BSP avoids this risk: data is processed within the EU under EU data protection standards, with contractual protections that do not depend on the stability of the EU-US Data Privacy Framework. For businesses handling sensitive data (healthcare, financial, legal services), this is the preferred configuration.
The ICO's 2024 guidance on instant messaging for UK businesses notes that businesses using the WhatsApp Business app for commercial communications 'should review whether their current arrangements provide an adequate level of data protection for the personal data they are processing.' This is regulatory advisory language that signals potential future enforcement.
Business owners who have never reviewed their WhatsApp data processing arrangements should conduct a data protection impact assessment (DPIA) if they process a significant volume of EU customer data via WhatsApp.
Article 9 of GDPR defines 'special categories of personal data' that receive heightened protection: health data, biometric data, genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, and criminal records.
For healthcare providers, therapists, nutritionists, physiotherapists, and other health-adjacent businesses, WhatsApp communications almost invariably involve health data — even if the message appears innocuous. A physiotherapy clinic sending 'your next appointment is for your lower back pain' is processing health data about that patient.
Article 9 processing requires one of ten specific grounds — the most common for health businesses being 'explicit consent' (Article 9(2)(a)) or the 'health or social care' derogation (Article 9(2)(h)), which applies to registered health professionals. Unlike Article 6 consent, Article 9 explicit consent must be even clearer — verbally stated or written acknowledgement that specifically names the sensitive data category.
For healthcare businesses using WhatsApp, the compliance checklist extends beyond Article 6:
- Written explicit consent for health data processing via WhatsApp
- A documented DPIA (Data Protection Impact Assessment) for high-risk processing
- Technical security measures appropriate to the sensitivity of health data (end-to-end encryption alone is not sufficient — the message content is visible to both parties and potentially to platform staff in compliance investigations)
- Data retention policies that match clinical record retention requirements (in the UK: minimum 8 years for adult patients' clinical records, per NHS guidance)
A practical checklist for small businesses using WhatsApp Business API for EU and UK customer communications:
Setup:
- Use WhatsApp Business API accessed through a BSP with an EU-hosted data option
- Sign a Data Processing Agreement (DPA) with your BSP — confirm it covers GDPR Article 28 requirements
- Document data residency (where your customer data is stored)
Data register:
- List every type of WhatsApp message you send and the lawful basis for each
- Record consent dates, wording, and channel for any consent-based processing
- Note data retention period for each message/customer record type
Customer-facing:
- Update your privacy policy to include WhatsApp as a data processing channel
- Include WhatsApp data processing disclosure at customer intake (booking form, first contact)
- Ensure every marketing broadcast includes a functional opt-out mechanism
Ongoing:
- Honour opt-out requests within 24 hours
- Run a data subject access request (DSAR) process — customers can request all personal data you hold including WhatsApp records
- Review data retention: purge customer WhatsApp records that exceed your stated retention period
- Conduct an annual DPA review with your BSP to confirm continued compliance
For special category data (health, financial, legal businesses): add DPIA, explicit consent documentation, and heightened security review to the above.
Data + numbers referenced in this article are sourced from these public documents:
BossBot includes GDPR consent capture, data processing agreements, and optional blockchain audit trails.
Learn MoreNot ready to sign up yet? Try the free demo →