Skip to content
Novot AI
NLBook a call
← Back to knowledge base

How long must and may you keep customer conversations on WhatsApp and email?

There is no single period that fits all your customer conversations. The GDPR deliberately gives no number: Article 5(1)(e) only says you may not keep data longer than necessary for your purpose. The seven years everybody quotes comes from Article 52 of the Dutch General State Taxes Act and applies to your business records: messages recording an order, price, discount or invoice, even inside WhatsApp. Ordinary service questions are not business records and should be kept briefly. So you set a period per type of message, with a basis, and write it down.

Published on

The moment an AI assistant starts answering your inbox or your WhatsApp number, an archive grows that you never asked for. Thousands of messages, with names, phone numbers, addresses, complaints, appointments and the occasional photo of a broken boiler. And then the question arrives: how long does all of that have to stay, and how long is it allowed to stay?

Two answers circulate among Dutch small businesses. The first is: seven years, because the tax authority says so. The second is: as short as possible, because GDPR. Both are half right. And precisely because they are half right, things go wrong: business owners either set everything to seven years, or they let their chat platform wipe itself every month. Each choice is defensible for part of your messages and indefensible for the rest.

Below is where the seven years actually comes from, why the privacy law refuses to name a number, and how to arrive at a retention period per type of message that you can explain if someone ever asks.

Why does the GDPR not name a single number of years?

That is not an oversight. The GDPR works with principles, and the principle that applies here is storage limitation: Article 5(1)(e). Personal data may not be kept in a form that identifies the individual for longer than is necessary for the purpose you are processing it for. No number of years, no maximum, no minimum. Just the word necessary.

The Dutch Data Protection Authority puts it just as plainly: the GDPR contains no concrete retention period, organisations decide for themselves how long they keep personal data, and other laws do contain concrete periods. That means something uncomfortable for you as a business owner. The legislator pushes the choice onto you. You set the period, and you have to be able to justify it.

The consequence is that "we keep everything just to be safe" is not a policy but the absence of one. Necessity is measured against your purpose, and the purpose comes from Article 5(1)(b): you collect for a specified, explicit purpose. If the purpose of a WhatsApp conversation was "help this customer get an appointment", then at some point that purpose is achieved or gone. From that moment you need a fresh reason to keep the message. If you do not have one, it should go.

The reverse is equally true. "We delete everything after thirty days, nice and safe" is also not a policy if business agreements are mixed into that stream that you are legally required to keep. Then you are throwing away your books, and that stops being a privacy problem and becomes a tax problem. So the storage limitation principle does not ask you to keep things as briefly as possible; it asks you to keep them as long as needed and not a day longer. That is a different instruction, and it forces you to think per type of data instead of pulling one single lever across your whole system.

Seven years comes from tax law, not from privacy law

The period everybody knows sits in Article 52 of the Dutch General State Taxes Act (Algemene wet inzake rijksbelastingen). The first paragraph sets out the bookkeeping duty: business owners must keep records of their financial position and of everything concerning their business, in such a way that the rights and obligations of the business are clear from those records. The fourth paragraph then says that those subject to the duty must keep the data carriers for seven years, unless tax law provides otherwise.

Note two things in that sentence. First: it speaks of data carriers, not of paper. A chat log is as much a data carrier as a ring binder. Second: the duty attaches to the concept of business records, not to the channel. Whether something sits in your accounting package or in a WhatsApp thread makes no difference to the law.

So this is an inverted duty compared to the GDPR. The GDPR says: delete unless you have a reason to keep. Tax law says: keep, full stop. Those two collide less often than business owners think, because they cover different things. They only collide once you treat your entire message stream as one and the same thing.

Alongside the tax duty there is a civil-law bookkeeping duty. For legal entities it sits in Book 2 of the Dutch Civil Code and it rests on the board personally; for sole traders and freelancers a comparable duty sits in Book 3, Article 15i. In practice, following the tax line will nearly always keep you safe, but it is useful to know this is not "a tax office rule" you can negotiate away with a phone call. It is a duty resting on your business and, in a company, on the people who run it.

A customer conversation is not the same thing as an invoice

This is the heart of it. The Dutch tax authority itself writes that communication tools used mainly for private purposes — a private email address, WhatsApp, and similar channels — can form part of the business records if they are also used for business. That word can does all the work. It does not mean every little message in your business WhatsApp has to sit there for seven years. It means the channel will not save you: you cannot say "it was only a quick message" about a message in which you agree a price.

The practical test you can apply is this question: does this message record a right or an obligation of my business, or does it explain how an amount came about?

  • "Agreed, we will fit it on Thursday and it will be the package we discussed" — that is business records.
  • "You get ten percent off because we were late last time" — that is business records, because it explains your invoice.
  • "The engineer is on his way, he will be there in twenty minutes" — that is not business records.
  • "Are you open on Saturday?" — that is not business records.

The vast majority of what an AI assistant handles falls into the second category. Opening hours, directions, "where is my parcel", a question about parking. Those are personal data, because a phone number or email address is attached to them, but they are not business records. No law requires you to keep those messages, so it falls back on Article 5 GDPR: as short as your purpose allows.

The consequence for how you set things up matters. You do not need one single retention period, you need two streams. One stream carrying a duty to keep, and one carrying a duty to delete. Anyone who does not separate them is automatically choosing the longest period for everything — and that is exactly the choice a supervisory authority will not accept.

When does that seven-year clock actually start?

Almost everybody counts from the date of the message. That is not what the tax authority says. For determining the start of the retention period, the current value of a piece of data is what counts: as long as data remains current it belongs to the business records, and only once that currency falls away does the period start running.

That changes your arithmetic. A maintenance contract that runs for three years, with messages going back and forth in the same WhatsApp thread, is current for that whole term. So the clock does not start at the first message. The same goes for a customer's master data: as long as that customer is a customer, the address is current.

In practice this means a simple rule such as "automatically delete everything older than X" in your chat platform does not make you compliant, in either direction. Set too short and you throw away live files. Set too long and you keep years of conversations that are about nothing any more. The workable approach is to attach the period to the file or the customer relationship, not to the date of the individual message. That asks something of your setup, because many chat platforms only offer a setting based on message date. If you cannot configure it that finely, choose consciously: periodically lift whatever belongs to the business records out of the channel and put it into your bookkeeping, so that you can keep a short period on the conversation archive itself.

How to set a retention period per type of message

You do not need to be a lawyer for this. Run four questions past each category of message, in this order.

  1. Is there a statutory duty to keep it? If the message is part of the business records, the period is given and you have no choice. Done.
  2. Do I still need it for the purpose I received it for? If not, the default is: delete. Even if keeping it would be handy.
  3. Do I need it for a real risk? A live complaint, a warranty issue, a dispute that may be coming. That can be a reason to keep it longer, but it has to be a concrete risk, not a general feeling.
  4. Is there a sector rule? Healthcare, financial services and legal services have their own statutory periods that override your own choice.

Write the outcome into a table like the one below. The column that really matters is the last one: the basis. A period without a basis is a guess, and a guess cannot be explained.

Example retention schedule for customer messages over email and WhatsApp: a period per type of message and the legal basis that period rests on.
Type of messageRetention periodBasis
Confirmation of an order, quote, agreed price or discountSeven yearsArticle 52(4) AWR — the message forms part of the business records
Correspondence about an invoice, payment arrangement or credit noteSeven yearsArticle 52(4) AWR — it explains an amount in your books
Complaint about a delivered order, including how it was handledSeven yearsArticle 52 AWR, because it touches rights and obligations under the contract
Service question with no follow-up (opening hours, delivery status, directions)Short; you set it yourselfArticle 5(1)(e) GDPR — purpose achieved, so no longer necessary
Abandoned conversation that led nowhereAs short as possibleArticle 5(1)(e) GDPR — there is no purpose left to keep it for
Job application or open enquiry arriving through the inboxNo later than four weeks after the procedure ends; longer only with the applicant's consentGuidance from the Dutch Data Protection Authority on applicant data
Conversation forming part of a live disputeFor as long as the dispute runs, then closed offNecessary for your own legal position; a concrete risk, not general caution
Message from a patient or client in healthcareIts own statutory period, separate from this scheduleArticle 7:454 of the Dutch Civil Code (WGBO) — the medical file has its own retention period

What if your conversations sit with a supplier?

This is where AI-driven customer contact most often goes wrong. Your messages live in a chat platform, a helpdesk tool or somebody else's AI environment. That feels like their problem. It is not.

The tax authority writes that if you have your records kept wholly or partly by third parties, the data those third parties hold about your business must be kept as well — and that you must keep your records even after you have wound the business up. So the duty to keep does not travel to your supplier. It stays with you.

That has three concrete consequences for how you pick a supplier:

  • Can you get out? Ask for an export of conversations in a readable format, and actually test that export once. A supplier who only offers a dashboard is a risk at the moment you switch or stop.
  • What does their own retention setting do? Some platforms delete logs by default after a short period, others keep everything forever. Either can conflict with what you have written down. Set your own period in the system, or consciously accept what is there and record why.
  • What happens when the contract ends? Agree that you get your data back before anything is deleted, and within what period the supplier deletes afterwards. This belongs in the processor agreement you have to have with them anyway under Article 28 GDPR.

Think about the practical side too: you must still be able to open and use your files during an inspection. An export that no program can read five years from now is not preserved business records. So prefer a neutral, readable file format over an archive that only opens inside one supplier's software.

What if a customer says: delete everything you have on me?

That request concerns Article 17 GDPR, the right to erasure. The main rule is that you erase without undue delay. But the third paragraph of that article carves out processing that is necessary for compliance with a legal obligation. And the tax retention duty is exactly such a legal obligation.

So the practical answer is rarely "yes" or "no", but a split. The messages that form part of your business records stay, with an explanation of why. The rest goes: the service questions, the abandoned chats, the number in your marketing list. That is not a trick to dodge the request, but nor is it a licence to keep everything because there happens to be one invoice somewhere in the file.

Article 12 GDPR gives you a statutory response deadline here, and it applies just as much when the request arrives by WhatsApp at an AI assistant as when it arrives by registered post. So make sure such requests are recognised and reach a human being, and that you can actually retrieve which messages belong to which customer. A system in which you cannot search per individual cannot carry out Article 15 (access) or Article 17 (erasure), however well it works otherwise.

How do you record your retention periods so they hold up?

Writing it down is not bureaucracy here, it is the core of your defence. You chose the period yourself, so the evidence that the choice was reasonable has to come from you as well.

Three places where it belongs:

  1. In your record of processing activities. Article 30(1) GDPR asks, among other things, for the envisaged time limits for erasure of the different categories of data. That is precisely the table above. The often-quoted exemption for organisations with fewer than 250 employees does not apply when your processing is not occasional, and continuous customer contact is by definition not occasional.
  2. In your privacy statement. Article 13(2)(a) GDPR requires you to tell the customer how long you keep their data, or how you determine that period. So do not write a slogan there, write the logic: business records seven years, other customer correspondence shorter, with an explanation per category.
  3. In the system itself. A period that exists only on paper is not a period. Set the retention configuration of your inbox, your chat platform and your backups so the policy happens by itself, and check once a year that it really did.

Finally, note who made the choice and when. If you are asked in three years' time why service chats disappear after six months, a dated line in a document is an entirely different conversation from a reconstruction out of your head.

The five mistakes that come up most often

  • "Seven years for everything, then I am always fine." Not true. For messages with no duty to keep, seven years is itself a breach of storage limitation. Keeping data too long is just as wrong as keeping it too short.
  • "WhatsApp is chat, that is ephemeral." The tax authority says literally the opposite: communication tools used for business can form part of the records. The medium decides nothing.
  • "My supplier handles the retention periods." The duty sits with you, even when the data physically sits with them. They execute what you configure.
  • "We are too small for rules like this." The bookkeeping duty in Article 52 AWR applies to every business owner, regardless of size. And the GDPR sets no lower threshold for the storage limitation principle.
  • "It is in our privacy statement, so it is fine." What you write down and what your system does have to be the same. A statement promising erasure after a year while four years of chats are still sitting there is a piece of evidence against yourself.

What you can do about this in a week

  1. List the types of message that actually arrive in your AI channels. Five to ten categories is enough; more becomes unworkable.
  2. Behind each category, note whether it forms part of the business records, yes or no. That is the most important cut.
  3. Fill in a period and a basis per category, in the shape of the table above.
  4. Look at what is currently configured in your inbox, your chat platform and your backups, and bring it in line with what you wrote down.
  5. Add the schedule to your record of processing activities, and put the retention periods into your privacy statement in plain language.

That is all it takes. The law does not demand perfection here, it demands a choice you can explain. A business owner with a simple retention schedule they understand themselves is in a far better position than one who never chose anything and hopes that "keep everything" is the safe option.

See what Novot AI can do for your business.

Book a call