Is WhatsApp GDPR Compliant for Business Use?

Whether WhatsApp is GDPR compliant depends on which version of it your business is running. Personal WhatsApp and the free WhatsApp Business app keep conversations on individual handsets, with no central record and no reliable way to export a customer’s history. The official WhatsApp Business Platform, built on Meta’s Cloud API, holds conversations centrally and can be run in line with UK GDPR.

The obligation sits with your business rather than with Meta, and that is the part most people miss. The Information Commissioner’s Office will ask whether you know what personal data you hold, where it sits, who has access to it, and whether you can produce it when a customer requests it. Everything below works back from those four questions, and our approach to WhatsApp compliance is built around them.

Which version of WhatsApp is your team actually using?

Most UK businesses sit in one of three positions, and they are a long way apart on data protection.

  • Personal WhatsApp on staff phones. The business holds no copy of the conversation, cannot see it, and loses it entirely when the member of staff moves on.
  • The free WhatsApp Business app. Designed for sole traders and very small operations. It runs on one device at a time, offers no shared access and no audit trail, and Meta’s terms do not cover a team working from it.
  • The official WhatsApp Business Platform. Conversations run through Meta’s Cloud API into a system the business controls, with user permissions, retention settings and a full export.

The first two are where the exposure sits. For the detail on how ICO expectations apply, including data residency and retention periods, our guide to UK GDPR and WhatsApp business messaging works through it at length.

Why is the free WhatsApp Business app a GDPR problem?

The free app was built for a single owner-operator answering their own messages, so the controls a data controller needs were never part of it. Five gaps come up again and again.

  • Subject access requests cannot be answered reliably. A customer can ask for everything you hold on them and you have a month to produce it. If the conversation lives on one person’s handset there is no central record to export and no audit trail to evidence what was sent.
  • There is no processor agreement to point to. UK GDPR expects a documented arrangement with any third party processing personal data on your behalf. The consumer apps are not supplied to businesses on those terms, so there is nothing to put in front of an auditor.
  • Consent and opt-out go unrecorded. Messaging customers from the free app leaves no record of who agreed to hear from you or who asked you to stop, which is exactly the evidence you need if a complaint is made.
  • Deletion and retention are out of your hands. When a customer asks to be erased, you are relying on individual members of staff to delete threads on their own phones and to confirm they have done it.
  • Data walks out with the handset. When someone leaves, their contacts and conversation history leave with them and you keep nothing.

These gaps matter most in regulated sectors, where a firm has to evidence what was said to a client and when. We go through them in more depth in the real risks of using WhatsApp for business, along with what a fix looks like.

Does WhatsApp data have to be stored in the UK?

No. UK GDPR permits personal data to be transferred outside the UK where appropriate safeguards are in place, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. A regulator will ask whether the transfer is documented and covered, rather than whether the servers happen to sit in Britain.

This is another place the consumer apps leave you exposed, because there is no business arrangement in which those safeguards are recorded. On the official platform the service is supplied to your business under commercial terms, so the transfer position becomes something you can document and evidence.

What changes on the official WhatsApp Business Platform?

Moving the same conversations onto the Cloud API changes the record-keeping position rather than the customer experience. In practice that means:

  • Every message, inbound and outbound, is captured centrally against one customer record.
  • A subject access request becomes a data export rather than a search across staff phones.
  • Permissions decide who can see full phone numbers, who can export contacts and who can send broadcasts.
  • Marketing messages carry a clear opt-out, and the opt-out itself is recorded.
  • Conversations can be logged automatically into your CRM, so your system of record stays complete.
  • When a member of staff leaves, the history stays with the business.

We built msgboxx to do this on the official Cloud API. It gives a team one shared WhatsApp number with assigned conversations, CRM logging, permissions and exportable history, rather than a workaround built on WhatsApp Web.

What if your staff will not give up the app they already use?

This is the usual sticking point, and Meta’s Coexistence feature was introduced to answer it. The free WhatsApp Business app carries on running on the handset while the same number is connected to the Cloud API, with messages mirrored both ways. Staff keep the tool they know and the business gets the central record it needs. We cover how it works, and what it still leaves undone, in our WhatsApp Coexistence FAQ.

Where to start

Three checks will tell you where you stand.

  • Ask how many people are messaging customers from a personal or free WhatsApp account today, and where those conversations live. Our piece on staff using WhatsApp for customer communication covers what usually turns up.
  • Pick a customer at random and try to produce their full WhatsApp history within the hour. If that is not possible, a subject access request would be a genuine problem.
  • Check whether any WhatsApp automation you already run goes through the official API or through a QR-code or WhatsApp Web workaround, because the second sits outside Meta’s terms.

If you would like to see what a compliant setup looks like against your own numbers, book a short demo and we will walk through it with you.

This article is general guidance on UK data protection practice and is not legal advice. Check your own position with your data protection officer or legal adviser.

Take the next step

Book Demo