.png)
Whether WhatsApp is GDPR compliant depends on which version of it your business is running. Personal WhatsApp and the free WhatsApp Business app keep conversations on individual handsets, with no central record and no reliable way to export a customer’s history. The official WhatsApp Business Platform, built on Meta’s Cloud API, holds conversations centrally and can be run in line with UK GDPR.
The obligation sits with your business rather than with Meta, and that is the part most people miss. The Information Commissioner’s Office will ask whether you know what personal data you hold, where it sits, who has access to it, and whether you can produce it when a customer requests it. Everything below works back from those four questions, and our approach to WhatsApp compliance is built around them.
Most UK businesses sit in one of three positions, and they are a long way apart on data protection.
The first two are where the exposure sits. For the detail on how ICO expectations apply, including data residency and retention periods, our guide to UK GDPR and WhatsApp business messaging works through it at length.
The free app was built for a single owner-operator answering their own messages, so the controls a data controller needs were never part of it. Five gaps come up again and again.
These gaps matter most in regulated sectors, where a firm has to evidence what was said to a client and when. We go through them in more depth in the real risks of using WhatsApp for business, along with what a fix looks like.
No. UK GDPR permits personal data to be transferred outside the UK where appropriate safeguards are in place, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. A regulator will ask whether the transfer is documented and covered, rather than whether the servers happen to sit in Britain.
This is another place the consumer apps leave you exposed, because there is no business arrangement in which those safeguards are recorded. On the official platform the service is supplied to your business under commercial terms, so the transfer position becomes something you can document and evidence.
Moving the same conversations onto the Cloud API changes the record-keeping position rather than the customer experience. In practice that means:
We built msgboxx to do this on the official Cloud API. It gives a team one shared WhatsApp number with assigned conversations, CRM logging, permissions and exportable history, rather than a workaround built on WhatsApp Web.
This is the usual sticking point, and Meta’s Coexistence feature was introduced to answer it. The free WhatsApp Business app carries on running on the handset while the same number is connected to the Cloud API, with messages mirrored both ways. Staff keep the tool they know and the business gets the central record it needs. We cover how it works, and what it still leaves undone, in our WhatsApp Coexistence FAQ.
Three checks will tell you where you stand.
If you would like to see what a compliant setup looks like against your own numbers, book a short demo and we will walk through it with you.
This article is general guidance on UK data protection practice and is not legal advice. Check your own position with your data protection officer or legal adviser.