At a glance
Document separately why contact details are processed and the purpose for which a message is sent. Limit data and access to what is strictly necessary, review roles and data processing arrangements, and keep verifiable records of marketing consents and unsubscribes. An app, platform or provider label alone does not constitute blanket data protection compliance.
Describe service, marketing and evaluation separately
A customer enquires about the status of her delivery. The response to this enquiry and a subsequent promotion for the next collection serve different purposes. Define the required data, recipients, legal basis and retention period for each process. The European Commission explains that processing requires an appropriate legal basis and that consent may be withdrawn on a case-by-case basis.
As an example of its own organisation, a shop creates three processes: processing a specific enquiry, sending out subscribed product alerts and evaluating the campaign. A telephone number provided during the ordering process does not automatically constitute marketing consent. Check the requirements under competition law in addition to the GDPR. For advertising by email, Section 7 of the German Unfair Competition Act (UWG) is particularly relevant in Germany; possible exceptions must not be applied across the board to the entire customer base.
Business App: Deliberately restrict address book access
The official WhatsApp Help Centre explicitly addresses contacts in the device address book. It assigns responsibility for the legal basis of contact processing to the company and describes WhatsApp as a data processor in relation to this access to contacts. The current Business App Terms and Conditions, effective from 23 September 2026, refer to the WhatsApp Business Data Processing Terms. The statement “In principle, there is no data processing on behalf of others for the app” would therefore be too general.
Check which contacts are actually accessible. Separate private and business contacts, restrict access in line with the operating system’s capabilities, and monitor connected devices and backups. A company mobile phone alone does not solve the problem if its entire address book is shared without a valid basis. Document the setup and permissions.
Platform: Interfaces rather than automatically secure data paths
A platform integration works with the systems and data integrated by the company. It does not require the same device address book process as a manually operated app; nevertheless, CRM, shop, providers, Meta and other service providers can process data. Map out the actual path taken by telephone numbers, consent, messages, orders and replies. Note down which systems receive additional attributes and why.
The current WhatsApp Business Messaging Policy sets out requirements regarding rights, protection and permissible data use. Additionally, check the current platform agreements for your company; these do not imply general authorisation for every data flow. In particular, check exports, webhooks, support access, AI functions and the use of conversation content for other purposes. A European server location alone does not clarify access or further transfers.
Identify roles and contracts for each processing operation
According to the European Commission’s explanation, the party that determines the purposes and means is the data controller; a data processor processes data on behalf of the data controller. The same provider may have different roles for different processes. Therefore, do not assign these roles based solely on a product name. Check the applicable contracts, privacy notices and the described processing activities for the specific use case.
Where data processing on behalf of a client is involved, appropriate contractual arrangements must be in place. Check instructions, sub-processors, technical and organisational measures, support for data subjects’ rights, and the return or erasure of data upon termination of the contract. At Klaviyo, the current data processing agreement is a relevant source, but is not a substitute for reviewing the entire WhatsApp data flow. For transfers outside the European Economic Area, the specific transfer mechanism used must also be reviewed.
Make marketing consent and information transparent
The WhatsApp Business Messaging Policy requires the appropriate contact details and opt-in permission for further messages or calls before making contact. For marketing purposes, you must provide a clear and appropriate consent text specifying the company, channel and expected content. Ensure that the wording, timing, origin and associated telephone number are recorded in a way that is clear and verifiable. Template approval by Meta confirms the message content within the platform process, not the legal basis for each recipient.
Provide information in advance about the actual processing and the recipients involved. A QR code or an initiated chat initially indicates an action; this must not be interpreted as an unlimited advertising subscription without the appropriate context. Klaviyo’s guide to WhatsApp consent supports the technical implementation. You must align the final consent and privacy notice with your specific form, purpose and data flow.
Testing opt-out, deletion and permissions in practice
An unsubscribe request must take effect whilst the system is running. Check whether a supported unsubscribe keyword or a manual request via chat excludes the contact from receiving the next marketing message. Synchronise the status across relevant systems and queues. Imported contacts must not simply override a documented unsubscribe request. However, opting out of marketing does not automatically mean that legally required order documents may be deleted immediately.
You should therefore set reasonable time limits for conversation histories, exports, records of consent and blocking information. Restrict access according to roles, secure administrative accounts and remove former employees. The Commission describes data protection as an obligation right from the design and operation stages. Also consider device loss, support access and requests for information. A ‘delete’ button in an inbox alone does not prove that data has been deleted from all connected systems.
Approve the deployment based on concrete evidence
Check purposes, legal bases, data fields, roles, contracts, information and opt-outs. Identify the data controllers responsible for enquiries, data exports and incidents. Sensitive data and sectors require a separate assessment.
Only approve the verified use case. A service review does not constitute automatic approval for marketing or new AI analyses. Align the process description and actual account settings with your data protection responsibilities, without generally declaring the app or platform to be compliant.
Sources and further documentation
Product documentation and primary sources relating to the steps described. Editorial source date: 5 October 2026.
- WhatsApp: Contacts and Business App
- WhatsApp: Business App Terms effective from 23 September 2026
- WhatsApp: Business Data Processing Terms
- Meta: WhatsApp Business Messaging Policy
- European Commission: Principles of lawful processing
- European Commission: Application of the GDPR and roles
- European Commission: Obligations of businesses
- European Commission: international data transfers
- Laws on the internet: Section 7 UWG
- Klaviyo: Data Processing Agreement
- Klaviyo: WhatsApp consent