UK GDPR does not prohibit WhatsApp. It requires that a firm can locate, export and account for the client data it holds. Personal handsets and the free WhatsApp Business app make that impossible, because records sit on devices the business does not control. The WhatsApp Business Platform centralises those conversations, which is what makes a Subject Access Request answerable inside the statutory one-month deadline.
An eight-minute explainer covering the same ground as this guide, including the three versions of WhatsApp, how Subject Access Requests are handled on the Business Platform, what an audit trail contains, and what a compliant deployment costs per branch. The full transcript is at the foot of this page.
A subject access request lands on your desk. Somewhere across your negotiators' and mortgage advisers' phones sit months of client conversations, some on personal WhatsApp, some on the business app, none of it centrally retrievable inside your SAR deadline. This is the exact scenario that has pushed compliance officers in UK property and financial services to question whether WhatsApp can be used at all, when the real issue is not the channel but which version of it the business is running.
Stitch, the WhatsApp business communication platform, works with estate agents and regulated financial services firms precisely because this distinction, between WhatsApp Personal, WhatsApp Business, and the WhatsApp Business Platform, determines whether a firm can meet UK GDPR and ICO obligations or not. Two large London estate agents raised this exact concern before adopting the platform: one had actively discouraged WhatsApp use across affiliated sites because staff were using personal accounts and SARs became unmanageable. The fix was not abandoning WhatsApp. It was moving to infrastructure built for centralised data control.
This article sets out how UK GDPR requirements map onto WhatsApp Business Platform architecture, what "audit trail" actually means in this context, and where the cost and retention trade-offs sit for regulated sectors evaluating a vendor.
Examples drawn from Stitch client deployments are labelled as such throughout. Regulatory positions and platform limits are sourced to the ICO and to Meta's WhatsApp Business Platform documentation, checked in August 2026. Platform rules change frequently, so verify current limits before relying on them.
WhatsApp exists in three distinct forms, and only one of them is built for regulated business use. WhatsApp Personal is the consumer app. WhatsApp Business is a free, standalone app aimed at small businesses or sole operators. The WhatsApp Business Platform, formerly known as the API, is an API-only product with no app of its own, requiring a platform layer to access and manage it. Using individual WhatsApp accounts for business communication is discouraged specifically because it means a lack of control and elevated compliance risk.
The practical problem is data scatter. When staff use personal or WhatsApp Business accounts, client conversations sit on individual devices under individual control, not under the firm's. A client-facing consequence of this was observed directly in a Stitch deployment: one agency actively discouraged WhatsApp use across affiliated sites because handling Subject Access Requests under the personal or business app versions was unworkable, and staff using individual accounts scattered the data in a way the firm could not manage. Regulatory compliance requires that data protection obligations be met at the firm level, not left to whichever handset a negotiator happens to be using.
This is the starting point for any UK compliance officer assessing WhatsApp as a channel: the app your staff already have installed is not the version that can be governed.
The WhatsApp Business Platform routes all conversations through a centralised system rather than individual devices. Centralised management gives a firm the ability to manage conversations and data centrally in order to comply with regulations, rather than relying on scattered, device-level records. msgboxx, the software layer Stitch built on top of the Business Platform, functions as a centralised "WhatsApp switchboard," meaning inbound and outbound messages across an entire team run through one governed system rather than through personal phones.
With that architectural distinction established, the next question compliance officers ask is how it actually resolves SAR handling in practice.
Subject Access Requests are requests made by individuals to access the personal data an organisation holds on them, and under the WhatsApp Business Platform these become straightforward to process because all conversations are accessible from one central system. Under UK GDPR the response deadline is one month from receipt. This is the direct answer to the concern raised by the two London estate agents: switching to platform-based WhatsApp, rather than personal or free-app usage, is what makes SAR handling manageable.
Centralisation also solves a related problem for firms running multiple branches or offices. In one Stitch deployment, a group of 15 offices with 100 users adopted the platform with GDPR compliance as a primary driver, alongside communication efficiency and automation. Bringing 100 users under one system, rather than 100 separate personal accounts, is what makes ongoing regulatory obligations, not just SAR responses, achievable at scale.
Conversations on the WhatsApp Business Platform can be exported as CSV files for audit or legal purposes. This is a capability, not a compliance guarantee: it means a firm can produce a structured, reviewable record of client communications on demand, whether for an ICO enquiry, an internal audit, or litigation disclosure. The platform also maintains audit trails that track chat assignment and status changes for compliance and accountability, so a firm can demonstrate not just what was said but who owned the conversation and when responsibility for it changed hands.
For regulated sectors, this exportability sits alongside CRM integration as a second layer of record-keeping, which is where the compliance picture extends beyond WhatsApp itself.
Embedding WhatsApp messaging inside an existing CRM closes the gap between conversation records and case files. Where the platform is integrated with a system like Reapit, all messages are logged in the activity feed linked to the relevant applicant, landlord, vendor, or tenant record, ensuring full visibility and compliance. For a letting agent or financial adviser, this means a WhatsApp exchange about a mortgage query or a tenancy issue is not a standalone thread sitting outside the client file. It becomes part of the same record the firm already uses for regulatory reporting and internal review.
The Chrome extension version of this integration extends the same principle to CRMs like Microsoft Dynamics, overlaying WhatsApp inbox functionality directly on CRM screens so staff can send templates and view conversation history without leaving the system of record. Chats include full history, covering text, images, videos, voice notes, and documents, which matters for regulated firms because a client's instruction, consent, or complaint delivered via voice note is as much a data point as one delivered in writing.
Team-based chat ownership adds a further accountability layer relevant to audit requirements. Chats can be assigned to individuals or teams such as sales, lettings, or support, and the system tracks assignment and status changes, functioning much like a telephone switchboard with call routing and ownership. A compliance officer reviewing a complaint or a SAR response can therefore see not only the message content but the chain of ownership behind it.
This combination, centralised storage, CSV export, and CRM-linked audit trails, is what distinguishes a governed messaging channel from an ungoverned one. It is also where UK data residency and retention questions come into sharper focus.
Retention and message handling under the WhatsApp Business Platform operate under rules set by Meta, not by individual users, which is itself a compliance advantage over personal-account usage. Businesses cannot freely initiate conversations: Meta restricts outbound messaging to prevent spam, meaning the customer must make first contact through a channel such as a website widget, QR code, or phone call. After that, businesses can only start or restart a conversation using a pre-approved template message, and once a customer replies, a 24-hour window opens for free-form messaging without template restrictions.
This structure matters for compliance officers because it constrains how outreach happens by design. Bulk marketing messages must be carefully managed to avoid Meta penalties, with guidance to limit sends to small groups of 10 to 30 recipients at a time. Firms in finance and property, where unsolicited contact carries its own regulatory sensitivity, benefit from a channel where Meta's own architecture, not just internal policy, limits indiscriminate outbound messaging.
Group messaging also differs sharply between versions. The Business Platform's Groups API caps each group at eight participants, requires an Official Business Account, and allows up to 10,000 groups per business number. Members join by invite link rather than being added, so consent is built into the mechanism. A consumer WhatsApp group, by contrast, holds up to 1,024 people. For a compliance officer weighing tenant or landlord group communications, the eight-participant cap and the invite-only join are the two facts to design around, and the second is an argument in the platform's favour rather than a limitation. (Meta, WhatsApp Business Platform documentation; checked August 2026.)
On retention specifically, out-of-hours automated reply delays were initially configured at 6 months by default in one Stitch deployment, before being reduced to 7 days for better operational relevance, illustrating that retention and workflow settings on the platform are configurable rather than fixed, and should be reviewed against a firm's own data retention policy rather than left on default.
Message sending limits scale with business verification and message quality, and since October 2025 they are set at Meta Business Portfolio level rather than per number, so every WhatsApp number in the same portfolio draws on one shared allowance. A new, unverified portfolio starts at 250 unique recipients in a rolling 24-hour period. Completing Business Verification lifts that to 1,000, and sustained quality then unlocks 10,000, 100,000 and finally unlimited. Replies sent inside the 24-hour customer service window do not count towards any of it. For a growing estate agency network or a multi-branch financial services firm, the verification work done early determines the outbound scale available later. (Meta, WhatsApp Business Platform documentation; checked August 2026.)
Having covered how data is structured, exported, and retained, it is worth setting out what this costs in practice, since budget approval for regulated firms often depends on transparent, sterling-denominated figures.
Pricing for the WhatsApp Business Platform through Stitch is transparent and denominated in pounds sterling throughout, which matters for finance and property directors building a business case. A basic licence covering shared inbox and manual messaging runs at £99 per branch per month, with Agent Assist automation adding approximately £75 to £80 per branch, bringing the total to roughly £175 per branch. AI bot functionality adds a further £10 to £50 per month depending on complexity and volume.
Setup fees are £295 for the first branch and £70 for each additional branch, and there are no long-term contracts, only a 30-day notice period. For a 15-office deployment with 100 users, total estimated cost ran between £120 and £150 per branch per month, alongside Meta's own conversation fees of £3 to £15 per branch per month. Template message costs sit at roughly 1.6 pence each, with typical monthly conversation costs across a branch falling in the £3 to £15 range.
For a smaller agency scaling toward 20 or more users, onboarding fees start at £295, with monthly plans of £99 for up to five users and £149 for up to ten, plus £50 per additional five users. Average WhatsApp messaging costs per user run between £3 and £8 monthly. These figures are billed in GBP with Meta's USD-denominated usage fees converted without markup, removing a currency-risk variable that UK finance directors would otherwise need to model separately.
Compliance officers evaluating a vendor should treat the SAR-handling question as the first test, not an afterthought. Ask directly whether conversations can be exported in a structured format for audit or legal purposes, whether chat assignment history is tracked, and whether the platform integrates with your existing CRM so WhatsApp records sit inside the same case file as everything else. These three capabilities, exportability, audit trail, and CRM linkage, are what separate a governed deployment from the scattered personal-account usage that created SAR problems for the two London agencies in the first place.
Setup is not trivial. Meta's own onboarding process is complex and lacks direct support, which is why providers assist clients through it directly. Previous SMS-based solutions at some firms failed due to weak integration and poor reliability, underscoring that the compliance benefit only materialises if the underlying platform is properly configured, not simply switched on.
Bringing WhatsApp into a regulated UK business is a governance decision as much as a communication one. Getting it right means choosing the Business Platform over personal or free-app usage, confirming that conversations export cleanly for audit and SAR purposes, and verifying that message logs sit inside the same CRM record as the rest of a client's file. Stitch's role is building and supporting that infrastructure for property, finance, and other regulated sectors across the UK, with pricing in sterling and onboarding support built around the realities of Meta's platform rules.
If your firm is still relying on personal WhatsApp accounts or weighing up whether the Business Platform is worth the setup effort, book a demo with Stitch to see how centralised messaging, audit trails, and CRM integration work together before your next Subject Access Request arrives.
WhatsApp itself is not the issue; how a business runs it is. On personal handsets or the free Business app there is no central record, so a Subject Access Request cannot be answered within the statutory deadline. On the WhatsApp Business Platform every conversation is captured centrally and exportable, which turns a SAR into a data export.
No. The free app runs on one device at a time, has no shared inbox, no assignment history and no export route, and Meta's terms do not cover team use of it. It is built for a sole trader or a single-handed operator, not for a branch of negotiators or advisers sharing a customer base.
You need a central record. On the WhatsApp Business Platform, conversations for a given contact can be exported as a CSV covering text, images, voice notes and documents, alongside the assignment history showing who handled the chat. On personal handsets there is no equivalent, which is why firms miss the one-month deadline.
Yes. Alongside message content, the platform records chat assignment and status changes, so a compliance officer can show who owned a conversation and when responsibility moved between staff. Combined with CRM logging, that gives you both what was said to a client and who was accountable for saying it.
Yes. Messages can be written into the activity feed against the relevant applicant, landlord, vendor or tenant record. Stitch integrates with Reapit and others directly, and a Chrome extension overlays the WhatsApp inbox on CRM screens including Microsoft Dynamics, so staff never leave the system of record.
A basic shared inbox licence is £99 per branch per month. Adding Agent Assist automation takes the total to roughly £175 per branch, with AI bot functionality adding £10 to £50 depending on complexity. Setup is £295 for the first branch and £70 for each additional one, on a 30-day notice period.
Not necessarily. Meta's Coexistence feature connects an existing WhatsApp Business app number to the Cloud API while the app keeps running on staff handsets, mirroring messages both ways. Conversations are then captured centrally for export and CRM logging without asking the team to change how they work on day one.
Transcript of "UK GDPR and WhatsApp: How Regulated Firms Stay Compliant", published by Stitch, running time 8 minutes 3 seconds.
[00:00] Welcome to today's explainer. I am absolutely thrilled you're joining me, because we're tackling a massively high-stakes topic today for professional firms across the UK, and that is WhatsApp compliance.
[00:10] Look, if you work in property, financial services, or really any regulated sector, you already know the deal. Your clients want to reach you on WhatsApp. They expect it. But the way most businesses are currently handling it? Well, it's creating an absolute compliance minefield. So today we're going to visually break down exactly how you contain this wild west of communications and actually protect your firm.
[00:31] Okay, let's dive into this. I want you to picture this nightmare scenario for a second. A Subject Access Request, or SAR, suddenly lands on your compliance officer's desk. The clock immediately starts ticking. And you know, failure to comply can result in ICO fines of up to 4% of your firm's turnover.
[00:46] But here's the problem. The client's communications aren't sitting neatly in a central file. No, they're scattered across your negotiators' and mortgage advisers' personal phones, buried in months of mixed personal and business group chats. With data scattered literally everywhere, and no centralised way to pull it together before the legal deadline? Honestly, could your firm actually survive that audit?
[01:11] This chaos creates what we call the data scatter problem. As you can see here, when your staff use personal or unmanaged WhatsApp accounts, those crucial client conversations just get trapped inside individual devices. Your firm has absolutely zero control over them.
[01:23] And this rogue employee messaging leads to huge blind spots. We're talking mis-selling risk, because a colleague can't see what was promised, missing client history in your CRM, and, crucially, failed SAR deadlines purely because that data is functionally unretrievable at a firm-wide level.
[01:42] To solve this, here is our roadmap for today's explainer. We're going to define the compliance nightmare. Bust a major myth by comparing the three versions of WhatsApp. Introduce you to the centralised msgboxx switchboard. Explore CRM audit trails. And finally, look at how to scale all of this compliantly.
[01:56] All right, let's get into part one, the WhatsApp compliance nightmare. Let's look at a real-world example. There were two large London estate agents who got so overwhelmed they nearly abandoned WhatsApp entirely because of unmanageable SARs. Both firms were facing this incredibly common crisis.
[02:17] But the major takeaway here is this. Abandoning WhatsApp is not the fix. Your clients demand it. Banning it just drives the behaviour underground, which is even worse. The real issue isn't the app itself. It's simply which version of the channel your business is running. To fix the compliance nightmare, you just have to fix the underlying infrastructure.
[02:38] Which leads us perfectly into part two, three versions of WhatsApp. Okay, this is a crucial myth-busting moment. Take a look at the massive gap between those first two columns and the third. The personal app and even the free business app are fundamentally flawed for regulated firms. Why? Because they completely lack centralised control. They fail SAR compliance right out of the gate, and they offer zero true CRM integration.
[03:02] It's only that third column, the WhatsApp Business Platform, which used to be known as the API, that actually routes all conversations through a centralised system. It is literally the only version built for regulated business use.
[03:18] So moving on to part three, the centralised msgboxx switchboard. Now, what's really interesting about this slide is how you actually access that Business Platform. Designed by Stitch, this msgboxx software essentially acts exactly like an old-school traditional telephone switchboard. You've got the shared WhatsApp inbox alongside baked-in GDPR compliance and CRM connectivity. It basically pulls all those hidden conversations off personal phones and brings them right into one governed, visible environment.
[03:42] To put that into perspective, just think about the operational scale for a second. If you have, say, a group of 15 offices with 100 users running WhatsApp on separate personal phones, well, you have 100 individual compliance risks walking around. But if you bring those 100 users under one governed system, which was actually done successfully for a multi-branch firm, you instantly achieve GDPR compliance at scale. The risk just evaporates, because the firm is finally back in control.
[04:12] Let's dive into the mechanics of that in part four, audit trails and CRM. In the context of the WhatsApp Business Platform, an audit trail isn't just some corporate buzzword. As you can see defined here, it is a highly structured, exportable record. If the ICO ever comes knocking on your door, you can easily export a secure CSV file, and that file shows not just what was said to the client, but exactly who owned that conversation and precisely when responsibility for it changed hands between your staff members.
[04:42] So here's how that builds a compliant workflow in practice. Walk through this message lifecycle with me. First, a customer initiates contact, maybe from a website widget. Then that chat is routed centrally. Next, a human agent steps in with full context of the situation. And crucially, step four, the entire history logs directly into your CRM. Stitch integrates seamlessly with major systems like Reapit or Microsoft Dynamics. Actually, through a really handy Chrome extension, your staff can view chat history and send templates without ever having to leave their CRM screen.
[05:12] Another incredibly powerful layer here is automation. Before a human even takes over the chat, virtual assistant bots can prompt customers and pre-qualify leads. And because everything is happening on the Business Platform, this automated journey captures the complete history. It doesn't matter if the client replies with a text, a photo, or even a voice note, it's all captured as a neat data point and logged for compliance way before your human agent even says hello.
[05:37] Finally, let's look at part five, scaling compliantly with Stitch. So the crucial point is that Meta's own rules actually enforce compliance for you. You cannot freely spam clients. There's just no way to do it. All outbound contact has to use pre-approved templates, which totally prevents indiscriminate marketing. Once a customer does reply, you then get a 24-hour window for free-form chatting. And even groups are strictly limited to just 8 people on the Business Platform, as opposed to the 256 you get on the consumer app.
Correction: the consumer WhatsApp group limit is 1,024, not 256. It was raised from 256 to 512 in 2022 and then to 1,024. The eight-participant cap on the Business Platform Groups API is correct.
[06:05] These constraints are absolutely massive advantages for compliance officers who want to lock down unauthorised communications.
[06:17] Now, I know what you're thinking. Let's talk about budget. If you're a finance director, you obviously want clear, predictable pricing. The starting monthly cost per branch is just £99 for a basic shared inbox licence. With the whole shebang, a full setup with Agent Assist automation, it typically totals around £175 per branch. And critically, this is all billed cleanly in sterling, completely removing the headache of any currency risk.
[06:42] Breaking those costs down just a bit further, you can see how highly scalable this model is. The initial setup fee is £295 for the first branch, and then it drops to just £70 for additional ones. Meta's conversation fees are surprisingly minimal, usually sitting between £3 and £15 a month per branch. It's an incredibly predictable model. It ensures you get robust infrastructure that doesn't break the bank, all while saving you from those massive regulatory fines down the road.
[07:10] I want to pause on this quote. Compliance officers evaluating a vendor should treat the SAR handling question as the first test, not an afterthought. Buying generic software just isn't enough any more. You need infrastructure that is purpose-built and configured for your specific regulatory realities. Centralised messaging, rigorous audit trails, and deep CRM integration. Those are your ultimate safeguards.
[07:35] Which leaves us with one final, pretty provocative thought. Will you wait for a Subject Access Request to completely expose the massive risks hiding on your employees' personal phones? Or will you take control today, centralise your data, and look into booking a Stitch demo?
[07:50] The technology is absolutely there to make WhatsApp a powerful, fully compliant tool for your firm. Thank you so much for joining me to unpack this explainer today, and I'll catch you in the next one.