WA Creator
Back to articles
Marketing

GDPR Compliance for WhatsApp Marketing

A plain-English guide to using WhatsApp for marketing in the EU without breaking GDPR β€” consent, retention, DPIA, and the practical checklist.

8 min readΒ·
Ad space β€” will show ads once AdSense is connected (top)

Marketing over WhatsApp in the EU is completely legal β€” and completely regulated. GDPR doesn't ban business chat; it just requires you to treat a phone number the same way you'd treat an email address or a customer's home address. Get consent, be transparent, don't hoard data, and let people leave.

This is the practical guide, not legal advice. If you handle large volumes or sensitive categories (health, finance), talk to a lawyer. For everyone else, follow the checklist below and you're 95% of the way there.

What GDPR actually requires

Four principles matter most for WhatsApp marketing:

  1. Lawful basis β€” you need a legal reason to process each phone number.
  2. Transparency β€” the person must know who you are, why you have their number, and what you'll do with it.
  3. Purpose limitation and data minimisation β€” collect only what you need, use it only for the stated purpose.
  4. Rights of the data subject β€” access, deletion, portability, objection, withdrawal of consent.

WhatsApp's end-to-end encryption doesn't exempt you. You're the data controller for the contact list and the chat history you keep.

The two lawful bases you'll actually use

  • Consent (Art. 6(1)(a)) β€” for marketing broadcasts, cold outreach, adding someone to a segmented list.
  • Legitimate interest (Art. 6(1)(f)) β€” for replying to a customer who contacted you first, or sending an order-status update to someone who bought from you.

Inbound click-to-chat is the easiest case. When a customer taps your wa.me link and messages you, you have a clear legitimate interest to reply. You don't need a separate opt-in for that specific reply thread β€” but you do need one before you broadcast future marketing to them.

The three consent traps most businesses fall into

  1. "They messaged me, so I can broadcast to them." No. Replying is fine; adding them to a mass broadcast list is a new purpose that needs its own consent.
  2. Pre-ticked opt-in boxes. GDPR requires unambiguous, affirmative action. A pre-checked checkbox is void.
  3. Bundled consent. "Sign up for the newsletter" cannot include "and we'll also WhatsApp you." Marketing channels must be optional and separately opt-in-able.

How to collect valid consent

The wording you use on your website form, receipt, or chatbot needs to be:

  • Specific β€” name the channel: "Send me WhatsApp updates."
  • Informed β€” link to your privacy policy right there.
  • Granular β€” separate boxes for different types of messages (offers vs. order updates).
  • Freely given β€” no service should be conditional on it.
  • Documented β€” you must be able to prove who consented, when, and to what wording.

A minimal compliant checkbox:

I agree to receive occasional promotional messages from [Company] on WhatsApp. I can opt out any time by replying STOP. See our privacy policy.

Retention: how long you can keep a number

GDPR doesn't set a fixed period. The rule is: as long as necessary for the purpose you collected it for.

Sensible defaults:

| Purpose | Typical retention | |---|---| | Active marketing consent | Until withdrawal or 24 months of inactivity | | Order/support history | 6 years (many tax jurisdictions) | | Cart abandonment nudge | 30–90 days | | One-off inquiry, no purchase | 6–12 months |

Set a calendar reminder to purge inactive contacts. "We keep everything forever" is not a defensible answer to a supervisory authority.

The privacy notice you must show

Before or at the moment of collection, tell the person:

  • Who you are (legal name and contact).
  • Why you're collecting the number.
  • What lawful basis you rely on.
  • How long you'll keep it.
  • Who you share it with (WhatsApp/Meta is a processor β€” mention them).
  • Their rights (access, deletion, objection, withdrawal, complaint to supervisor).
  • Whether data leaves the EU (WhatsApp routes through Meta infrastructure β€” yes, it does; rely on Meta's SCCs).

You can link to a single privacy policy page from every touch point (website, chatbot, printed QR code).

Handling the standard rights requests

  • Access β€” someone messages "send me my data." Export your CRM record + chat history and email it within 30 days.
  • Deletion β€” someone replies "delete me." Remove them from your contacts, mark broadcast lists, and confirm.
  • Objection to marketing β€” an opt-out is unconditional and immediate. Reply STOP β†’ no more marketing. Ever.
  • Data portability β€” export in a common format (CSV, JSON).

Pre-write templates for each so you can respond in minutes, not days.

WhatsApp-specific issues

  • Contact list uploads. If you sync your phone contacts to the WhatsApp Business app, you're processing that data. Only sync what you have consent for.
  • Broadcast lists vs. Groups. A broadcast list keeps recipients private; a group exposes everyone's number to everyone. Groups for marketing are almost always non-compliant.
  • Read receipts and typing indicators. These are personal data by CJEU standards. Your privacy notice should mention that you may see them.
  • Backups. WhatsApp chat backups (Google Drive/iCloud) sit outside E2E encryption. If you back up business chats, disclose it.

The 60-second compliance checklist

  • Separate, unbundled consent checkbox for WhatsApp marketing.
  • Privacy policy linked from every point of collection.
  • Documented log of who consented, when, to what wording.
  • STOP keyword handling in your chatbot / SOP.
  • Retention schedule with a quarterly purge.
  • Data subject request template ready to send.
  • Data processing register (Art. 30) lists WhatsApp/Meta as a processor.
  • DPIA (Data Protection Impact Assessment) if you profile users or send at large scale.

Do you need a DPIA?

A DPIA is mandatory if your processing is "high risk." For most small businesses using WhatsApp for click-to-chat, the answer is no. You need one if you:

  • Do systematic profiling that drives automated decisions.
  • Process special-category data (health, biometrics, political opinions).
  • Monitor a public area on a large scale.
  • Broadcast to tens of thousands of users regularly.

If in doubt, do a light-touch DPIA anyway β€” it's a one-page risk assessment, and having it on file is your best defense.

Practical setup for a small EU business

  1. Add a WhatsApp opt-in checkbox to every form on your site.
  2. Keep a Google Sheet or CRM field: contact, timestamp, source, consent wording version.
  3. Publish a privacy notice that mentions WhatsApp/Meta specifically.
  4. Save a "STOP" auto-reply that confirms opt-out and triggers your deletion workflow.
  5. Every quarter, delete inactive contacts and log the purge.

Do that, and GDPR is not the reason you can't grow on WhatsApp.

Ready to start compliantly? Generate a wa.me link that pre-fills a consent-friendly first message with our free WhatsApp link generator β€” for example: "Hi, I'd like to get updates on WhatsApp. I confirm I've read your privacy policy."

Ad space β€” will show ads once AdSense is connected (in-content)

Related articles