WhatsApp for Healthcare Under GDPR: Handling Special-Category Data

Patients answer WhatsApp messages, which is exactly why clinics want to use it and exactly why the compliance question is sharper here than anywhere else. Health data is special-category data under Article 9, so the ordinary lawful-basis analysis is a floor, not the whole assessment. Nothing below prohibits the channel — it sets out what has to be true around it.

This is practical guidance, not legal advice. Healthcare processing is regulated at national level as well as by GDPR; confirm your position with your DPO or legal counsel before you go live.

What Article 9 actually says

Article 9(1) prohibits processing data concerning health unless one of the conditions in Article 9(2) applies. The two that usually matter for patient messaging are explicit consent (9(2)(a)) and provision of health or social care (9(2)(h)), the latter carrying an obligation of professional secrecy. This condition sits on top of an Article 6 lawful basis; you need both, and you should record both per purpose.

The trap is scope creep in what counts as health data. A message does not need a diagnosis in it to reveal one. The sender's display name, the clinic's specialism, an appointment type, a prescription-ready notification — each can disclose a health condition by inference. Assume any patient-facing thread is special-category unless you have deliberately designed it not to be.

The four things that get harder

Minimisation, enforced in the message body

The single most effective control is keeping clinical detail out of the channel. Notify and reference; do not narrate. "Your results are ready — sign in to view them" carries far less risk than the results themselves, and it is the difference between a notification channel and a clinical record living in a chat thread. Template design is where this is won or lost, because templates are what scale.

Residency, and being able to name it

Message transport runs through Meta's global infrastructure under standard contractual clauses — that part is fixed for every provider. Everything downstream is yours to place: the inbox, the contact record, consent, audit trail, analytics. For special-category data a DPIA will ask precisely where that sits and who else's data sits beside it, and "an EU region, our data only, this sub-processor list" is a materially shorter answer than a multi-tenant global estate.

Access control and professional secrecy

If you rely on 9(2)(h), the professional-secrecy obligation follows the data into the inbox. That means role-based access, no shared logins, and an audit trail showing who opened which conversation. Support staff at your platform vendor are part of this picture too — the fewer people outside your organisation who can reach the data, the simpler the assessment.

Retention and erasure that reach the record

Special-category data should not accumulate indefinitely. Define retention per purpose, apply it automatically, and make sure erasure removes rows, message bodies and derived copies rather than setting a hidden flag. Where national law requires you to retain a clinical record, that obligation limits the erasure right — but it does not extend to the messaging layer by default, so decide explicitly which side of that line each dataset sits on.

DPIA territory

Article 35 requires a DPIA where processing is likely to result in high risk, and large-scale special-category processing is an explicit trigger. Patient messaging typically qualifies. Done early, the DPIA is useful: it forces you to write down the Article 9 condition, the residency, the retention, the access model and the erasure path — which is most of your Article 30 record too.

How an owned EU instance shortens the paperwork

On a single-tenant instance rather than a shared platform, several DPIA questions collapse into one-line answers:

  • Where is the data? One named EU region, holding one organisation's data.
  • Who else's data is co-mingled? Nobody's — the database is yours.
  • What is the lawful basis and condition? Recorded per contact, channel and purpose in an append-only consent ledger, and enforced at send time.
  • How do you honour erasure? A hard delete with a receipt, documented in erasure requests.
  • What evidence exists? An audit trail you can export, rather than a manually maintained spreadsheet — see audit and evidence.

None of that makes the assessment go away, and no platform can supply your Article 9 condition for you. It does mean the answers are short, factual and the same next year — which is what a supervisory authority is looking for.

The proportionate summary

Healthcare organisations can use WhatsApp with patients, and the reachability argument is real. The work sits in four places: pick and document your Article 9 condition, keep clinical detail out of the message body, know exactly where the surrounding data lives, and be able to delete it properly. Start with the general GDPR position on WhatsApp and treat this page as the layer on top.

Next step

Apply this to your own deployment

This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.