Sari la conținut

Guide

WhatsApp Business API and GDPR (2026)

A practical compliance guide: what obligations you have as a business, how to collect opt-in correctly, what agreements are needed with Meta, and how to handle user rights. The information below is general, not legal advice for your specific situation. For a particular case, talk to a lawyer or a data protection officer (DPO).

Written by the Nemvio teamUpdated on August 19, 20263 min read

In short

  • The regular app is not GDPR-compliant by default. The official platform can be used compliantly.
  • You are the controller of your customers' data and need a legal basis for each type of message.
  • Specific opt-in, with the box unticked by default, and simple opt-out: a written "STOP" is enough.
  • The DPA is signed with the provider (BSP), and a breach is reported to the ANSPDCP within 72 hours.

01It’s possible, but not by default

The regular WhatsApp Business app isn't GDPR-compliant by default. On install, it requests access to your contact list and uploads numbers to Meta's servers, without a clear legal basis for that. The official platform (Business Platform / Cloud API), used through an accredited provider (BSP), can be compliant, but compliance comes from how you use it, not automatically from it being "official."

02What obligations you have as a business

As a business sending WhatsApp messages, you're the data controller for your customers' data. That means:

  • You need a legal basis for each type of message: consent for marketing, contract performance for a reminder about a booking already made
  • You clearly inform the customer what data you collect and why, before collecting it
  • You only collect the data you need, not everything you could collect
  • You keep it only as long as necessary, not indefinitely

03How to collect opt-in correctly

  • "I agree to WhatsApp messages about bookings" is not the same consent as "I agree to marketing"
  • An unchecked-by-default box, not a pre-checked one: the customer has to actively act to consent
  • Don't import existing contacts (from a phone, an old spreadsheet) without already having valid consent for WhatsApp messages from them
  • The opt-out option has to be simple and immediate: a "STOP" written in the conversation is enough to stop marketing messages

04What agreements are needed with Meta

A DPA (Data Processing Agreement), under Article 28 GDPR, is mandatory. It's signed with the provider (BSP) through which you use the platform, not directly with Meta. That provider processes data only on your instructions, while Meta itself acts as a sub-processor under its own Data Processing Terms.

05How to handle user rights

Any customer has the right to request access to their data, its correction, its deletion, or a portable copy. You need a clear process, even a simple one, "email us and we handle it within X days". It doesn't need to be automated from day one, but it needs to exist and actually work.

06The competent authority in Romania

In Romania, the supervisory authority is the ANSPDCP (National Supervisory Authority for Personal Data Processing). A data breach with risk to individuals has to be reported within 72 hours of discovery.

Read nextComplete WhatsApp Business guide
Want us to put this into practice for your business?A free conversation where we tell you what can concretely be done, on the official platform, and what it costs.Book a conversation