WhatsApp GDPR Compliance UK: What Your Business Needs to Get Right
The compliance gap most businesses do not know about
If your team uses the free WhatsApp Business App to message customers, there is a data protection problem built into the software itself. The WhatsApp Business App automatically uploads the device's entire contact list to Meta's servers. Every contact on that phone, including people who have never messaged your business and never consented to their data being shared, gets sent to Meta (Chatarmin GDPR analysis, Kuba Labs, 2026).
Under Articles 6 and 28 of the UK GDPR, processing personal data requires a lawful basis for each data subject. Uploading contacts who never interacted with your business has no lawful basis. It also creates an uncontrolled data-sharing relationship with Meta as a processor without the contractual safeguards Article 28 requires.
The WhatsApp Business API, by contrast, does not upload device contacts. It is a server-side integration that processes only the conversations your business actually has. For UK GDPR compliance, the API is the only defensible choice for business use.
Meta's December 2025 terms: what changed
On 16 December 2025, Meta updated its terms to permit the use of business chat data to train AI models and target advertising (Proton blog, ICO statements, September 2024 onwards, confirmed in 2025/2026 coverage). The ICO has not approved these terms. The regulator's public position stresses that Meta must demonstrate ongoing compliance with UK data protection law, without confirming that it currently does (ICO statements, 2024).
When a customer messages your business about a booking, they reasonably expect that data to be used for that booking. The purpose limitation principle under Article 5(1)(b) requires that personal data collected for one purpose is not repurposed for something incompatible. Training an advertising model on booking enquiries is difficult to reconcile with that principle (WorkNest GDPR guide, 2026).
The right to erasure under Article 17 adds another layer. Once personal data has been used to train a machine learning model, removing that specific data from the model's weights is technically unfeasible with current methods (Open Rights Group, 2026). A customer exercising their right to erasure may find that their data persists in ways that cannot be fully unwound.
PECR and WhatsApp: the electronic mail question
The Privacy and Electronic Communications Regulations (PECR) govern direct marketing in the UK, and they apply to WhatsApp. The ICO classifies WhatsApp messages as electronic mail for the purposes of Regulation 22 (ICO electronic mail marketing guidance, 2026). This means the soft opt-in rules apply:
- The contact details were collected during a sale or negotiation of a sale.
- The messages promote similar products or services to what the customer originally enquired about.
- The customer was given a clear opportunity to opt out at the point of collection.
- Every subsequent message includes a clear opt-out mechanism.
All four conditions must be met. A business that sends promotional WhatsApp messages to contacts who have not completed a sale, or who were not offered an opt-out when their number was collected, is in breach of PECR.
The practical consequence for AI chatbots is direct. Automated cart-abandonment messages, lead-qualification sequences, or promotional follow-ups sent to first-time visitors who browsed but never purchased do not meet the soft opt-in test. Those visitors have not completed a sale, so condition one fails (Zipchat AI analysis, ICO guidance, 2026).
The PECR enforcement upgrade
The Data (Use and Access) Act 2025, which took effect in February 2026, raised the maximum PECR fine from £500,000 to £17.5 million or 4 per cent of global annual turnover, whichever is higher (BSG World, 2026). PECR fines now match the UK GDPR maximum.
For a small business, the practical risk is not a £17.5 million fine. It is an ICO investigation triggered by customer complaints, which consumes time, creates legal costs, and can result in an enforcement notice restricting how you communicate with customers. The raised ceiling signals that the ICO treats electronic mail marketing violations as seriously as broader data protection breaches.
Subject Access Requests and business WhatsApp messages
Work-related WhatsApp messages are legally subject to Subject Access Requests (SARs) under the UK GDPR. If a customer requests all personal data you hold about them, your WhatsApp conversation history with that customer is in scope (Redwing Solutions, LegalVision UK, 2026).
For businesses using the WhatsApp Business App on a personal device, this creates a retrieval problem. Messages are stored on the device and in WhatsApp's encrypted backup, neither of which is designed for structured data retrieval. Searching through months of conversations on a phone to fulfil a SAR within the 30-day deadline is slow and error-prone.
The API route is cleaner. Conversations handled through the WhatsApp Business API can be logged, searched, and exported through whatever platform you connect to. A SAR response becomes a database query rather than a phone scroll.
Public bodies face an additional obligation: official communications sent via WhatsApp must be transferred to corporate record-keeping systems under FOI requirements (ICO guidance, 2026).
What a compliant WhatsApp setup looks like
For a UK business using WhatsApp to communicate with customers, compliance requires:
Use the API, not the App, for business messaging. The App's contact-list upload creates an uncontrolled data-sharing problem that the API avoids entirely.
Document your lawful basis. For responding to customer enquiries, standard Legitimate Interests under Article 6(1)(f) is usually appropriate. Write a Legitimate Interests Assessment: what data you process, why, and why it does not override the customer's rights. For more on this, see pipeline data and UK GDPR.
Update your privacy policy. State that you use WhatsApp for customer communications, what data you collect through those conversations, how long you retain it, and how customers can exercise their rights.
Get PECR right for outbound messages. Only send promotional WhatsApp messages to contacts who meet the soft opt-in conditions, or who have given explicit prior consent. Every message must include an opt-out mechanism.
Handle SARs and erasure requests. Ensure your WhatsApp platform can search, export, and delete individual customer data within 30 days.
Review your provider's data processing terms. Understand whether the platform provider uses conversation data for its own purposes (model training, advertising) and whether a Data Processing Agreement is in place.
Frequently Asked Questions
Is WhatsApp GDPR compliant in the UK?
The WhatsApp Business API can be used in a GDPR-compliant way. The WhatsApp Business App has a structural compliance problem: it uploads the device's entire contact list to Meta, including contacts who never consented (Chatarmin, Kuba Labs, 2026). For business use, the API is the compliant route.
Can I send marketing messages on WhatsApp under PECR?
Yes, if you meet all four soft opt-in conditions: the contact details were collected during a sale, the messages promote similar products, the customer was offered an opt-out at collection, and every message includes an opt-out. First-time visitors who have not completed a sale do not qualify for soft opt-in (ICO guidance, 2026).
Does Meta use my WhatsApp business messages to train AI?
Meta's December 2025 terms permit the use of business chat data for model training and ad targeting. The ICO has not approved these terms and has stated that Meta must demonstrate ongoing compliance (ICO statements, 2024). Businesses should review their provider's data processing terms and understand whether conversation data is used beyond the purposes they have authorised.
Do I need a Data Processing Agreement for WhatsApp?
If a third-party platform processes customer data on your behalf through the WhatsApp API, Article 28 of the UK GDPR requires a written controller-processor contract. Check your provider's terms for how data is used, stored, and whether it is shared with Meta or other parties beyond what is necessary for the service.
Are WhatsApp messages subject to FOI requests?
For public bodies, yes. Official WhatsApp communications must be transferred to corporate record-keeping systems (ICO guidance, 2026). Private businesses are not subject to FOI but are subject to Subject Access Requests covering WhatsApp conversation history.
Conciergr answers your enquiries in seconds, around the clock, from documents you own — and your team keeps using WhatsApp exactly as before.
Join the waitlist