Free interactive checker for 12 privacy regulations across 40+ countries. Pick your regulation, walk through 10 requirements, get a prioritized list of gaps to fix. Sourced from official regulator websites — not legal advice, but a real practical checklist to start from.
Step 1 · Pick your applicable regulation
If you serve customers in multiple regions, pick the strictest applicable regulation first (usually GDPR / UK GDPR / LGPD).
Step 2 · Walk through applicable requirements
For each item, check the box if your business already does it. Leave unchecked if you haven't set it up yet. Result appears at the bottom.
Not legal advice. This checker surfaces common practical gaps in WhatsApp Business API compliance for SMB operators. It does NOT replace jurisdictional counsel. Regulations change, enforcement varies, and sector-specific carve-outs exist (healthcare, finance, children's data). Bring your 3-5 highest-priority gaps to a lawyer licensed in your jurisdiction before making any commitments.
Yes. GDPR applies to any business processing EU/EEA residents' personal data, regardless of where the business is based. If you send a WhatsApp message to a customer in Germany, Spain, or Italy, GDPR's obligations attach: lawful basis, opt-in for marketing, opt-out mechanism, right-to-erasure, privacy policy disclosure, DPA with your BSP, breach notification within 72 hours.
What consent do I need before sending WhatsApp marketing?
Explicit opt-in captured at a documented point — website checkbox, in-store signup, checkout flow, or unambiguous opt-in via WhatsApp click-to-chat. Every regulation on this checklist (12 total) prohibits sending unsolicited marketing to people whose consent you haven't captured. Purchased lists are illegal under all 12 regimes.
Do I need a Data Processing Agreement (DPA) with my WhatsApp BSP?
Yes for GDPR / UK GDPR / LGPD / POPIA / KVKK / PDPL Saudi / PDPL UAE / PDPA Singapore. Your BSP acts as your Data Processor; a DPA is legally required. Reputable BSPs auto-attach one on paid plans; free tiers sometimes skip it — read fine print before running EU/UK/BR/SA traffic through a free plan.
How long can I keep WhatsApp customer chat history?
Depends on your documented retention policy + legal basis. Common SMB patterns: 30 days after last interaction (relationship ended) · 2-7 years for anything tied to a billed transaction (tax law) · indefinitely with explicit ongoing-subscriber consent. GDPR / LGPD / POPIA / KVKK require a documented policy — the number matters less than having ONE that you actually follow.
What happens if I'm reported for non-compliance?
Depends on regulator + severity. GDPR up to €20M or 4% global turnover; LGPD up to R$50M; POPIA up to R10M; KVKK millions of TL; DPDP India up to INR 250 crore. SMBs rarely see max fines — enforcement usually starts with a warning + 30-90 days to fix. But 'we didn't know' is not a defense.
Is opting out of processing different from unsubscribing from marketing?
Yes. Unsubscribing stops promotional messages. Objecting to processing (GDPR / LGPD / POPIA / CCPA right) is broader: 'don't use my chat history to train your AI'. You need a distinct channel for these broader objections — a STOP-reply mechanism doesn't cover them.
Where is my WhatsApp customer data physically stored?
Depends on your BSP's infrastructure. Meta's WhatsApp Business Platform hosts globally. Your BSP additionally stores chat + CRM data in their own data centers (usually US or EU). Cross-border transfer for EU/UK/BR/SA/TR/IN/SA/AE/SG customers requires SCCs, adequacy decision, or explicit consent. Ask your BSP for their data-location statement.
Does this checker replace legal advice?
No — practical SMB checklist to surface gaps and prioritize fixes. Every regulation has nuances (sector carve-outs, size thresholds, controller-vs-processor distinctions) that require jurisdictional counsel. Use this tool to identify 3-5 highest-priority items, then bring them to counsel.
BossBot ships with a DPA, retention controls, right-to-erasure workflow, consent-capture templates, and privacy-policy language — the plumbing that makes GDPR / LGPD / POPIA / KVKK compliance the default instead of the extra step. Try free for 7 days.