Tenreply logoTenreply
← Back to Blog
Compliance

GDPR and WhatsApp Business Messaging: What You Need in Place

If you message EU or UK customers on WhatsApp, GDPR governs your lawful basis, records, retention and data subject rights. The practical requirements, plus the transfer question that trips up most WhatsApp deployments.

Scope, and an Honest Caveat

This is practical guidance, not legal advice. GDPR applies if you offer goods or services to people in the EU or monitor their behaviour, regardless of where your business is based — so a business in India or Singapore messaging European customers is in scope. UK GDPR mirrors it closely.

Your Lawful Basis for Messaging

Every processing activity needs a lawful basis. For WhatsApp business messaging, realistically two apply:

  • Consent — the safest basis for marketing. Must be freely given, specific, informed and unambiguous, given by clear affirmative action. Pre-ticked boxes and bundled agreement do not qualify.
  • Contract performance — appropriate for transactional messages the person needs: order confirmations, delivery updates, appointment reminders for a booking they made.

Legitimate interests is sometimes proposed for marketing. Treat that as high-risk on WhatsApp: it is a person's private messaging app, expectations of intrusion are low, and ePrivacy rules on electronic direct marketing generally require consent anyway. If you market on WhatsApp, get consent.

The practical rule that follows: separate transactional from marketing consent, so you can send order updates under contract while marketing only to those who agreed to it.

What You Must Be Able to Show

GDPR is an accountability regime — doing the right thing is not enough if you cannot demonstrate it.

  • Consent records: who consented, when, to what purposes, via what wording, from what source. Store this against the contact.
  • A privacy notice available at collection, covering what you collect, why, your lawful basis, retention periods, who you share with, transfers outside the EEA, and the person's rights.
  • A record of processing activities if you are above the small-scale exemption.
  • A data processing agreement with your WhatsApp provider — they are your processor, you are the controller.

Data Subject Rights, and What They Mean for Your Inbox

These are the requests you must be able to service, generally within one month:

  • Access. Provide a copy of their personal data — including WhatsApp conversation history, which counts.
  • Erasure. Delete it, across contacts, conversations and any exports.
  • Rectification. Correct inaccurate details.
  • Portability. Provide consented or contract data in a machine-readable format.
  • Objection to marketing. Absolute — stop immediately, no balancing test.
  • Withdrawal of consent. As easy as giving it.

Test your erasure process before you receive a request. The common failure is discovering that conversation history cannot easily be deleted per-person, or that a contact deleted in the CRM still exists in three exported spreadsheets.

The Transfer Question Most Teams Miss

WhatsApp business messaging routes through Meta's infrastructure, and your provider may store data outside the EEA. Transfers of personal data out of the EEA need a valid mechanism — an adequacy decision, Standard Contractual Clauses, or another Article 46 safeguard.

What to actually do:

  • Ask your provider where conversation data is stored and processed, and get it in writing
  • Confirm SCCs or equivalent are in place in your DPA
  • List their sub-processors
  • Disclose transfers in your privacy notice

This is not optional detail — it is one of the most frequently enforced parts of GDPR, and "we use WhatsApp so Meta handles it" is not an answer.

Retention: Stop Keeping Everything

Storage limitation requires keeping personal data no longer than necessary. Indefinite retention of every conversation is the default in most inboxes and the wrong answer under GDPR.

Set periods per data type — for example transactional records for the statutory accounting period, marketing consent until withdrawn, support conversations for a defined window after resolution — then actually apply them. A documented policy you do not follow is worse than no policy.

Practical Checklist

  • Marketing consent collected by clear affirmative action, separate from transactional
  • Consent records store timestamp, wording, source and purposes
  • Privacy notice linked at every collection point, covering transfers and retention
  • DPA with your messaging provider, including SCCs where data leaves the EEA
  • Provider sub-processors and storage locations documented
  • Opt-out in every marketing message, honoured immediately
  • Tested processes for access, erasure, rectification and portability
  • Retention periods defined per data type and enforced
  • Export permissions restricted; no unmanaged contact spreadsheets
  • Breach process with a named owner and the 72-hour notification duty understood
  • No purchased or scraped lists — these cannot have valid consent

How Tenreply Helps

Custom fields let you store consent source, timestamp and purposes against each contact, so the accountability record sits with the data. Segments and tags keep marketing-consented contacts separate from transactional-only ones, so a broadcast cannot include people who did not agree. Per-contact export and deletion support access and erasure requests, and role-based access controls who can export data at all. Our privacy policy and security page set out how we act as processor; contact hello@tenreply.com for a DPA.

Frequently Asked Questions

Can I send WhatsApp marketing under legitimate interests?

Treat it as unsafe. WhatsApp is a private messaging channel and ePrivacy rules on electronic direct marketing generally require consent. Get consent.

Is WhatsApp itself GDPR compliant?

The wrong question — compliance is a property of your processing, not a tool. Meta provides the infrastructure and terms; your lawful basis, records, retention and rights handling are yours.

Does conversation history count as personal data?

Yes. It is subject to access and erasure requests and to your retention policy.

Do I need a DPO?

Only in specific cases — public authorities, large-scale systematic monitoring, or large-scale special category data. Most SMBs do not, but you should still have a named person accountable for this.

What if I message both EU and Indian customers?

Both regimes apply to their respective data subjects. The underlying practices — recorded purpose-specific consent, clear notice, working erasure, defined retention — satisfy much of both. See our DPDP guide.

How quickly must I respond to a request?

Generally within one month, extendable for complex cases with notice.

Two Things Fix Most of It

Record consent properly at collection, and make erasure actually work. Those two capabilities carry most of the accountability burden, and they overlap almost entirely with what DPDP asks for — so building them once covers both. Then read the opt-in guide for the mechanics of collecting consent that also performs.