Is WhatsApp GDPR Compliant? What EU Businesses Actually Need to Do
The honest answer is that the question is aimed at the wrong thing. GDPR does not certify products; it regulates processing. You are the controller for the personal data you process when you message customers, and Meta and your Business Solution Provider are processors acting on your instructions. So the useful question is not "is WhatsApp compliant?" but "is my use of it compliant?" — and that is answerable.
Who is who
- You: controller. You choose the recipients, the purpose and the retention. Every obligation below is yours.
- Meta: processor for the WhatsApp Business Platform traffic, under its data processing terms, with standard contractual clauses covering transfers outside the EEA.
- Your BSP and platform: processors. They handle the messages and store the surrounding data on your behalf. Their tenancy model and hosting region become part of your compliance posture, which is why they belong in your records rather than in a footnote.
The five obligations that actually apply
1. A lawful basis, chosen deliberately
Transactional messages — order confirmations, delivery updates, appointment reminders — usually rest on contract performance or legitimate interests. Marketing rests on consent. Pick the basis per purpose rather than per channel, write it down, and make sure the message content stays inside the basis you claimed. A delivery notification that ends with a promotion has quietly changed its lawful basis.
2. Opt-in you can actually evidence
Meta requires opt-in before business-initiated messaging, and EU rules on direct marketing point the same way. What matters operationally is the record: who consented, to what purpose, through which surface, at what timestamp, and how they withdrew if they did. Opt-out must be as easy as opt-in and must be enforced at send time, not reconciled later.
3. Data residency and transfers
Message transport is global and covered by SCCs — that part is not yours to relocate. Everything downstream is: the inbox, the contact database, the consent records, the audit trail, the analytics. Keeping that in one named EU region with a short, enumerable sub-processor list is what turns a transfer impact assessment from an essay into a table.
4. Data subject rights, including erasure
Access, rectification, erasure, portability and objection all apply to WhatsApp conversation data. Erasure is the one that exposes weak architecture: a soft-delete flag that hides a contact from the UI while the row, the message bodies and the backups persist is not erasure. You need deletion that reaches the actual records, plus something you can hand back as proof it happened.
5. Article 30 records and retention
Maintain a record of processing activities covering the WhatsApp channel: purposes, categories of data and data subjects, recipients and processors, transfers and safeguards, and retention periods. Then apply the retention periods automatically. Indefinite conversation history is a liability that grows on its own.
What makes each obligation concrete
None of the above requires a particular vendor, but the architecture underneath makes some of it easy and some of it painful. On a single-tenant instance rather than a shared platform, the mapping is direct:
- Lawful basis and purpose are stored per contact, per channel and per purpose, so the basis you claimed is the basis enforced at send time.
- Opt-in lives in an append-only consent ledger with source and timestamp — see the docs on consent and opt-in.
- Residency is a single EU region holding one customer's data, which is a sentence you can put in a DPIA without qualification.
- Erasure is a hard delete against your own database with a receipt — the mechanics are in erasure requests.
- Article 30 evidence comes out of an audit trail rather than a spreadsheet someone maintains by hand; see audit and evidence.
The proportionate summary
WhatsApp is used compliantly by a great many EU businesses, and nothing here suggests otherwise. The failure mode is not the channel — it is treating consent as a checkbox, retention as optional and erasure as a UI state. Get those three right, know where your data sits, and the answer to "is WhatsApp GDPR compliant?" becomes a documented yes about your own processing.
Apply this to your own deployment
This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.