Dedicated vs Shared WhatsApp Business API: A GDPR Comparison

Enterprise teams in regulated industries face a binary choice when adopting WhatsApp Business: a dedicated, regional instance they own, or a shared multi-tenant CPaaS where their contacts sit alongside thousands of other brands. The technical and compliance gap between the two is wider than most buyers realise.

TL;DR

  • Dedicated instance: single-tenant database, regional data residency (EU-only by default; NA or APAC available), controllable retention, signed DPA covering processing on infrastructure you own. Best for healthcare, finance, public sector, and any GDPR-sensitive workload.
  • Shared CPaaS: fast to start, low entry cost, but contact data, message history, and consent records live in a multi-tenant store usually replicated outside the EU. Sub-processor list is long and changes without you.

Side-by-side comparison

DimensionDedicated EU instanceShared CPaaS
TenancySingle-tenant — your database, your queue, your secretsMulti-tenant row-level isolation
Data residencyEU-WEST only, contractually guaranteedUS + EU replicas; sub-processors in 10+ regions
GDPR Article 28Processor contract scoped to one controllerGeneric processor terms; joint-controller ambiguity
DSAR / Right to erasureHard delete with signed receipt within hoursSoft delete; backups retained 30–90 days
Consent ledgerAppend-only audit log, exportableVendor-defined, often not exportable
ThroughputTier dedicated to your number — no noisy neighboursShared rate-limit pool; throttling under peak load
Encryption keysCustomer-managed (CMK) optionVendor-managed only
Number portabilityYou own the BSP relationship and the numberNumber tied to vendor account
Audit logWorkspace-level, GDPR audit trail includedLimited to higher tiers, retention capped

Why GDPR makes this a hard choice

The WhatsApp Business API is operated by Meta, but the controller obligations under GDPR sit with you. A shared CPaaS adds a layer of processing — your contacts' phone numbers, message bodies, and consent state are ingested into the vendor's global data plane before being relayed to Meta. Each replica region and each sub-processor is a new transfer to document, justify with SCCs, and disclose in your privacy notice.

A dedicated instance collapses that chain. Data lives in one EU region, the processor is one entity, and your DPA scopes the relationship to a single tenant. For Article 30 records, Article 32 security measures, and Article 35 DPIAs, the surface area is small enough to actually defend in front of a supervisory authority.

When shared CPaaS still wins

  • You're sending under 10k messages a month and the contacts are not sensitive (e.g. e-commerce shipping notifications).
  • You need to launch in days, not weeks, and compliance review can follow.
  • You don't yet have a Meta BSP relationship and don't want to negotiate one.

When dedicated is the only viable answer

  • Healthcare, banking, insurance, public sector, legal.
  • Contacts include special-category data under Article 9.
  • Your security team requires customer-managed keys or VPC peering.
  • You've had a DSAR or a regulator request that the current vendor couldn't fulfil within the statutory deadline.
  • You operate in a market (Germany, France, the Nordics) where buyers ask "where exactly does the data live?" in the first call.

How Arino One delivers this

Arino One provisions a dedicated, EU-WEST hosted instance per customer. The inbox, CDP, automations, and consent ledger all run on infrastructure you own — not a shared pool. Erasure DSARs complete in minutes with a signed receipt; the consent log is append-only and exportable; data never leaves the EU. The same product surface handles WhatsApp, SMS, voice, and 18+ other channels in one inbox, so you don't trade compliance for capability.

Next step

Bring this to your enterprise stack

See how a dedicated Arino One instance — deployed in your region (EU, NA or APAC) — would sit inside your operation. Architecture, DPA, and rollout plan walked through live.