Skip to content
Guides · Other channels

WhatsApp Business data protection: clarify data flows before launch

A WhatsApp enquiry can bring together service, advertising and customer data within the same conversation thread. Therefore, simply choosing between a business app and a platform is not sufficient for a data protection assessment. The actual data flows, purposes and contracts are decisive. This guide describes a technical assessment process based on current official sources dated 5 October 2026; the legal assessment of the specific use is the responsibility of the relevant data protection and legal officers.

Check WhatsApp data flows: limit the data, clarify roles, then test opt-out.
Diagram by Rügamer & Steiner.

At a glance

Document separately why contact details are processed and the purpose for which a message is sent. Limit data and access to what is strictly necessary, review roles and data processing arrangements, and keep verifiable records of marketing consents and unsubscribes. An app, platform or provider label alone does not constitute blanket data protection compliance.

Describe service, marketing and evaluation separately

A customer enquires about the status of her delivery. The response to this enquiry and a subsequent promotion for the next collection serve different purposes. Define the required data, recipients, legal basis and retention period for each process. The European Commission explains that processing requires an appropriate legal basis and that consent may be withdrawn on a case-by-case basis.

As an example of its own organisation, a shop creates three processes: processing a specific enquiry, sending out subscribed product alerts and evaluating the campaign. A telephone number provided during the ordering process does not automatically constitute marketing consent. Check the requirements under competition law in addition to the GDPR. For advertising by email, Section 7 of the German Unfair Competition Act (UWG) is particularly relevant in Germany; possible exceptions must not be applied across the board to the entire customer base.

Business App: Deliberately restrict address book access

The official WhatsApp Help Centre explicitly addresses contacts in the device address book. It assigns responsibility for the legal basis of contact processing to the company and describes WhatsApp as a data processor in relation to this access to contacts. The current Business App Terms and Conditions, effective from 23 September 2026, refer to the WhatsApp Business Data Processing Terms. The statement “In principle, there is no data processing on behalf of others for the app” would therefore be too general.

Check which contacts are actually accessible. Separate private and business contacts, restrict access in line with the operating system’s capabilities, and monitor connected devices and backups. A company mobile phone alone does not solve the problem if its entire address book is shared without a valid basis. Document the setup and permissions.

Platform: Interfaces rather than automatically secure data paths

A platform integration works with the systems and data integrated by the company. It does not require the same device address book process as a manually operated app; nevertheless, CRM, shop, providers, Meta and other service providers can process data. Map out the actual path taken by telephone numbers, consent, messages, orders and replies. Note down which systems receive additional attributes and why.

The current WhatsApp Business Messaging Policy sets out requirements regarding rights, protection and permissible data use. Additionally, check the current platform agreements for your company; these do not imply general authorisation for every data flow. In particular, check exports, webhooks, support access, AI functions and the use of conversation content for other purposes. A European server location alone does not clarify access or further transfers.

Identify roles and contracts for each processing operation

According to the European Commission’s explanation, the party that determines the purposes and means is the data controller; a data processor processes data on behalf of the data controller. The same provider may have different roles for different processes. Therefore, do not assign these roles based solely on a product name. Check the applicable contracts, privacy notices and the described processing activities for the specific use case.

Where data processing on behalf of a client is involved, appropriate contractual arrangements must be in place. Check instructions, sub-processors, technical and organisational measures, support for data subjects’ rights, and the return or erasure of data upon termination of the contract. At Klaviyo, the current data processing agreement is a relevant source, but is not a substitute for reviewing the entire WhatsApp data flow. For transfers outside the European Economic Area, the specific transfer mechanism used must also be reviewed.

Make marketing consent and information transparent

The WhatsApp Business Messaging Policy requires the appropriate contact details and opt-in permission for further messages or calls before making contact. For marketing purposes, you must provide a clear and appropriate consent text specifying the company, channel and expected content. Ensure that the wording, timing, origin and associated telephone number are recorded in a way that is clear and verifiable. Template approval by Meta confirms the message content within the platform process, not the legal basis for each recipient.

Provide information in advance about the actual processing and the recipients involved. A QR code or an initiated chat initially indicates an action; this must not be interpreted as an unlimited advertising subscription without the appropriate context. Klaviyo’s guide to WhatsApp consent supports the technical implementation. You must align the final consent and privacy notice with your specific form, purpose and data flow.

Testing opt-out, deletion and permissions in practice

An unsubscribe request must take effect whilst the system is running. Check whether a supported unsubscribe keyword or a manual request via chat excludes the contact from receiving the next marketing message. Synchronise the status across relevant systems and queues. Imported contacts must not simply override a documented unsubscribe request. However, opting out of marketing does not automatically mean that legally required order documents may be deleted immediately.

You should therefore set reasonable time limits for conversation histories, exports, records of consent and blocking information. Restrict access according to roles, secure administrative accounts and remove former employees. The Commission describes data protection as an obligation right from the design and operation stages. Also consider device loss, support access and requests for information. A ‘delete’ button in an inbox alone does not prove that data has been deleted from all connected systems.

Approve the deployment based on concrete evidence

Check purposes, legal bases, data fields, roles, contracts, information and opt-outs. Identify the data controllers responsible for enquiries, data exports and incidents. Sensitive data and sectors require a separate assessment.

Only approve the verified use case. A service review does not constitute automatic approval for marketing or new AI analyses. Align the process description and actual account settings with your data protection responsibilities, without generally declaring the app or platform to be compliant.

Sources and further documentation

Product documentation and primary sources relating to the steps described. Editorial source date: 5 October 2026.

Book a discovery call

A free, 10-minute call with no obligation. We’ll get back to you within 24 hours.

We only use your details to arrange your call. Privacy policy