GDPR-Compliant WhatsApp Messaging for EU Companies: The Complete Guide
Table of Contents
Your marketing team just built a WhatsApp broadcast list of 5,000 customers. Someone’s finger is hovering over “send” on a promo message. Nobody’s checked whether those 5,000 people actually consented to WhatsApp marketing specifically.
That’s how GDPR fines happen — not through malice, just through skipped steps. GDPR-compliant WhatsApp messaging for EU companies isn’t complicated once you know the rules, but it does require more than a generic privacy policy buried on your website. Here’s exactly what you need to get right.
Why GDPR Applies to WhatsApp Business Messaging
WhatsApp messages contain personal data — a phone number, a name, sometimes order details or health-adjacent information depending on your industry. The moment you process that data to send a message, GDPR applies. Full stop.
It doesn’t matter that WhatsApp is “just a chat app.” Under GDPR, the legal obligations sit with you as the data controller, not with Meta or your Business Solution Provider (BSP). They’re processors. You’re the one who answers to a regulator if something goes wrong.
This catches a lot of companies off guard. They treat WhatsApp like email is treated informally, and email marketing compliance habits don’t map cleanly onto WhatsApp’s rules.
Legal Basis for Messaging Customers on WhatsApp
GDPR requires a lawful basis before you process any personal data. For WhatsApp messaging, two bases come up constantly: consent and legitimate interest.
Consent is the strict one — clear, specific, freely given, and revocable at any time. This is the basis you need for marketing and promotional messages. A pre-ticked checkbox doesn’t count. Neither does consent buried inside a lengthy terms-of-service document nobody reads.
Legitimate interest can cover certain utility messages — an order confirmation, a shipping update, a support reply to a conversation the customer started. Even then, you need a documented legitimate interest assessment, not just an assumption that it’s fine.
Here’s the distinction that trips people up: legitimate interest works for messages tied to something the customer already asked for. It doesn’t stretch to unsolicited marketing, no matter how relevant you think the offer is.
Consent Requirements by Message Type
Not every WhatsApp message needs the same consent level. Meta’s own conversation categories actually map fairly well onto GDPR’s distinctions, which makes this easier than it sounds.
| Message Type | GDPR Basis Needed | Example |
|---|---|---|
| Marketing | Explicit opt-in consent | Promo, discount code, new product announcement |
| Utility | Legitimate interest (usually) | Order confirmation, delivery update |
| Authentication | Legitimate interest / contract | OTP codes, login verification |
| Service | Legitimate interest | Reply to a customer-initiated support chat |
Marketing messages carry the highest risk. If you’re sending anything promotional, you need documented, specific opt-in — a customer agreeing to “receive updates” isn’t the same as agreeing to WhatsApp marketing.
Utility and service messages have more breathing room since they’re tied to an existing transaction or conversation the customer started. Still, don’t stretch a support reply into an upsell without separate consent.
How to Collect Valid WhatsApp Opt-In Consent
You can build a compliant opt-in flow in an afternoon. Here’s the checklist:
- Use a standalone checkbox — never bundle WhatsApp consent with general marketing consent
- Name WhatsApp specifically in the consent language (“I agree to receive WhatsApp messages from [Company]”)
- Keep the checkbox unticked by default
- Log the timestamp, source, and exact consent text shown at the moment of opt-in
- Give customers an easy opt-out — “STOP” should actually stop messages within one business day
- Re-confirm consent periodically if the relationship goes dormant for an extended period
Skip step 4 at your own risk. If a regulator ever asks you to prove consent, “we’re pretty sure they agreed” isn’t an answer that holds up.
Data Residency and Cross-Border Transfers
WhatsApp messages route through Meta’s infrastructure, and Meta operates globally — including servers outside the EU. That raises the cross-border data transfer question GDPR takes seriously.
Meta relies on Standard Contractual Clauses (SCCs) to legitimize these transfers, which covers the baseline legal requirement. But if your industry handles sensitive data — healthcare, financial services, legal — dig deeper into where your specific BSP routes and stores data. Some BSPs offer EU-based hosting for message logs and customer records, which reduces your exposure even further.
Ask this question directly before signing with any provider: where does the data actually sit, and for how long?
The Role of Your Business Solution Provider in Compliance
Your BSP isn’t just a technical vendor — they’re a data processor under GDPR, which means you need a Data Processing Agreement (DPA) in place before you send a single message through their platform.
A solid BSP should offer that DPA without you having to chase them for it. They should also be able to tell you, clearly, where customer data is stored, how long it’s retained, and what happens to it if you switch providers.
If a BSP can’t answer these questions confidently, that’s a signal worth paying attention to.
Message Template Approval as a Compliance Safeguard
Here’s something most compliance guides skip entirely. WhatsApp requires pre-approval for template messages sent outside a live customer conversation — and that approval process doubles as an accidental compliance checkpoint.
Meta reviews templates for policy violations before they go live, which catches some GDPR-risky patterns before they ever reach a customer’s phone. It’s not a substitute for your own compliance process, but it’s a useful second layer worth understanding rather than treating as pure bureaucratic friction.
Penalties for Non-Compliance
GDPR fines scale with severity. Lower-tier violations top out around €10 million or 2% of global annual turnover, whichever is higher. Serious violations — the kind that come from ignoring consent requirements at scale — can reach €20 million or 4% of turnover.
Realistically, most WhatsApp-related enforcement so far has involved warnings and smaller fines rather than the eye-watering headline numbers. But regulators across the EU have been paying closer attention to messaging-app marketing specifically over the past couple of years, and enforcement patterns tend to tighten, not loosen.
Belgium-Specific Guidance
Belgian companies answer to the Gegevensbeschermingsautoriteit (GBA/APD), Belgium’s data protection authority. The GBA has generally aligned with broader EU guidance on consent and marketing communications rather than issuing WhatsApp-specific rules — but that also means Belgian businesses don’t get any local shortcuts or exemptions.
If you’re running WhatsApp marketing for a Belgian audience, the same explicit opt-in standard applies as anywhere else in the EU. Keep your consent records accessible in case the GBA ever requests them — Belgian enforcement has increasingly focused on documentation gaps, not just outright violations.
Belgium-Specific Guidance
Belgian companies answer to the Gegevensbeschermingsautoriteit (GBA/APD), Belgium’s data protection authority. The GBA has generally aligned with broader EU guidance on consent and marketing communications rather than issuing WhatsApp-specific rules — but that also means Belgian businesses don’t get any local shortcuts or exemptions.
If you’re running WhatsApp marketing for a Belgian audience, the same explicit opt-in standard applies as anywhere else in the EU. Keep your consent records accessible in case the GBA ever requests them — Belgian enforcement has increasingly focused on documentation gaps, not just outright violations.
Frequently Asked Questions
Is WhatsApp itself GDPR compliant?
WhatsApp’s Business Platform can be used in a GDPR-compliant way, but compliance depends on how you collect consent and handle data — not on the platform alone.
Do I need explicit consent for order confirmations?
Usually no. Utility messages tied to a purchase typically rely on legitimate interest, though you should still document that basis.
Can I message existing customers without new consent?
Only for utility or service messages connected to an existing transaction. Marketing messages need separate, specific opt-in regardless of your existing relationship.
What happens if a customer opts out?
You must stop marketing messages promptly — within one business day is a reasonable standard — and keep a record that the opt-out was honored.
Does my BSP need a Data Processing Agreement?
Yes. Any BSP handling customer data on your behalf needs a signed DPA before you send messages through their platform.
Table of Contents
Your marketing team just built a WhatsApp broadcast list of 5,000 customers. Someone’s finger is hovering over “send” on a promo message. Nobody’s checked whether those 5,000 people actually consented to WhatsApp marketing specifically.
That’s how GDPR fines happen — not through malice, just through skipped steps. GDPR-compliant WhatsApp messaging for EU companies isn’t complicated once you know the rules, but it does require more than a generic privacy policy buried on your website. Here’s exactly what you need to get right.
Why GDPR Applies to WhatsApp Business Messaging
WhatsApp messages contain personal data — a phone number, a name, sometimes order details or health-adjacent information depending on your industry. The moment you process that data to send a message, GDPR applies. Full stop.
It doesn’t matter that WhatsApp is “just a chat app.” Under GDPR, the legal obligations sit with you as the data controller, not with Meta or your Business Solution Provider (BSP). They’re processors. You’re the one who answers to a regulator if something goes wrong.
This catches a lot of companies off guard. They treat WhatsApp like email is treated informally, and email marketing compliance habits don’t map cleanly onto WhatsApp’s rules.
Legal Basis for Messaging Customers on WhatsApp
GDPR requires a lawful basis before you process any personal data. For WhatsApp messaging, two bases come up constantly: consent and legitimate interest.
Consent is the strict one — clear, specific, freely given, and revocable at any time. This is the basis you need for marketing and promotional messages. A pre-ticked checkbox doesn’t count. Neither does consent buried inside a lengthy terms-of-service document nobody reads.
Legitimate interest can cover certain utility messages — an order confirmation, a shipping update, a support reply to a conversation the customer started. Even then, you need a documented legitimate interest assessment, not just an assumption that it’s fine.
Here’s the distinction that trips people up: legitimate interest works for messages tied to something the customer already asked for. It doesn’t stretch to unsolicited marketing, no matter how relevant you think the offer is.
Consent Requirements by Message Type
Not every WhatsApp message needs the same consent level. Meta’s own conversation categories actually map fairly well onto GDPR’s distinctions, which makes this easier than it sounds.
| Message Type | GDPR Basis Needed | Example |
|---|---|---|
| Marketing | Explicit opt-in consent | Promo, discount code, new product announcement |
| Utility | Legitimate interest (usually) | Order confirmation, delivery update |
| Authentication | Legitimate interest / contract | OTP codes, login verification |
| Service | Legitimate interest | Reply to a customer-initiated support chat |
Marketing messages carry the highest risk. If you’re sending anything promotional, you need documented, specific opt-in — a customer agreeing to “receive updates” isn’t the same as agreeing to WhatsApp marketing.
Utility and service messages have more breathing room since they’re tied to an existing transaction or conversation the customer started. Still, don’t stretch a support reply into an upsell without separate consent.
How to Collect Valid WhatsApp Opt-In Consent
You can build a compliant opt-in flow in an afternoon. Here’s the checklist:
- Use a standalone checkbox — never bundle WhatsApp consent with general marketing consent
- Name WhatsApp specifically in the consent language (“I agree to receive WhatsApp messages from [Company]”)
- Keep the checkbox unticked by default
- Log the timestamp, source, and exact consent text shown at the moment of opt-in
- Give customers an easy opt-out — “STOP” should actually stop messages within one business day
- Re-confirm consent periodically if the relationship goes dormant for an extended period
Skip step 4 at your own risk. If a regulator ever asks you to prove consent, “we’re pretty sure they agreed” isn’t an answer that holds up.
Data Residency and Cross-Border Transfers
WhatsApp messages route through Meta’s infrastructure, and Meta operates globally — including servers outside the EU. That raises the cross-border data transfer question GDPR takes seriously.
Meta relies on Standard Contractual Clauses (SCCs) to legitimize these transfers, which covers the baseline legal requirement. But if your industry handles sensitive data — healthcare, financial services, legal — dig deeper into where your specific BSP routes and stores data. Some BSPs offer EU-based hosting for message logs and customer records, which reduces your exposure even further.
Ask this question directly before signing with any provider: where does the data actually sit, and for how long?
The Role of Your Business Solution Provider in Compliance
Your BSP isn’t just a technical vendor — they’re a data processor under GDPR, which means you need a Data Processing Agreement (DPA) in place before you send a single message through their platform.
A solid BSP should offer that DPA without you having to chase them for it. They should also be able to tell you, clearly, where customer data is stored, how long it’s retained, and what happens to it if you switch providers.
If a BSP can’t answer these questions confidently, that’s a signal worth paying attention to.
Message Template Approval as a Compliance Safeguard
Here’s something most compliance guides skip entirely. WhatsApp requires pre-approval for template messages sent outside a live customer conversation — and that approval process doubles as an accidental compliance checkpoint.
Meta reviews templates for policy violations before they go live, which catches some GDPR-risky patterns before they ever reach a customer’s phone. It’s not a substitute for your own compliance process, but it’s a useful second layer worth understanding rather than treating as pure bureaucratic friction.
Penalties for Non-Compliance
GDPR fines scale with severity. Lower-tier violations top out around €10 million or 2% of global annual turnover, whichever is higher. Serious violations — the kind that come from ignoring consent requirements at scale — can reach €20 million or 4% of turnover.
Realistically, most WhatsApp-related enforcement so far has involved warnings and smaller fines rather than the eye-watering headline numbers. But regulators across the EU have been paying closer attention to messaging-app marketing specifically over the past couple of years, and enforcement patterns tend to tighten, not loosen.
Belgium-Specific Guidance
Belgian companies answer to the Gegevensbeschermingsautoriteit (GBA/APD), Belgium’s data protection authority. The GBA has generally aligned with broader EU guidance on consent and marketing communications rather than issuing WhatsApp-specific rules — but that also means Belgian businesses don’t get any local shortcuts or exemptions.
If you’re running WhatsApp marketing for a Belgian audience, the same explicit opt-in standard applies as anywhere else in the EU. Keep your consent records accessible in case the GBA ever requests them — Belgian enforcement has increasingly focused on documentation gaps, not just outright violations.
Conclusion
GDPR-compliant WhatsApp messaging for EU companies comes down to three things: knowing which message types need which consent, documenting that consent properly, and choosing a BSP that treats data protection as a baseline requirement, not an afterthought. Get those three right, and WhatsApp becomes one of your safest marketing channels rather than your biggest liability. Technologiahub builds compliance into WhatsApp API setups from day one — worth a conversation before you launch your next campaign.
If you’re running WhatsApp marketing for a Belgian audience, the same explicit opt-in standard applies as anywhere else in the EU. Keep your consent records accessible in case the GBA ever requests them — Belgian enforcement has increasingly focused on documentation gaps, not just outright violations.
Frequently Asked Questions
Is WhatsApp itself GDPR compliant?
WhatsApp’s Business Platform can be used in a GDPR-compliant way, but compliance depends on how you collect consent and handle data — not on the platform alone.
Do I need explicit consent for order confirmations?
Usually no. Utility messages tied to a purchase typically rely on legitimate interest, though you should still document that basis.
Can I message existing customers without new consent?
Only for utility or service messages connected to an existing transaction. Marketing messages need separate, specific opt-in regardless of your existing relationship.
What happens if a customer opts out?
You must stop marketing messages promptly — within one business day is a reasonable standard — and keep a record that the opt-out was honored.
Does my BSP need a Data Processing Agreement?
Yes. Any BSP handling customer data on your behalf needs a signed DPA before you send messages through their platform.