WhatsApp Business for customer contact: what is allowed and what must you arrange?
Using WhatsApp for business is allowed, but you need a separate legal basis per purpose. Replying within 24 hours of a customer message is free-form; outside that, and for messages you start yourself, it only works through a pre-approved template, and commercial messages require prior consent or a link to a similar earlier purchase. Record per number when and for what someone consented, sign a processing agreement with everyone who can reach the messages, and know where the conversations sit and how long you keep them.
Published on
WhatsApp feels like the easiest channel there is. You have a number, customers message you, you message back. That is exactly why it gets used for business without much thought, and exactly why it goes wrong legally. WhatsApp is not an extension of your email, and it is not a chat window on your own site either. It is a separate channel, with its own legal basis, its own platform rules, and its own question about where the data ends up.
Below is what applies when you use WhatsApp Business for customer contact in the Netherlands: which legal basis you need, why it matters whether you are replying or starting the conversation, what template messages are and why they have to be approved in advance, how to record an opt-in that holds up, and what happens to your conversations once they sit on the platform.
Why is WhatsApp legally a separate channel and not just 'chat'?
Three sets of rules run across this channel at the same time, and they demand different things.
- The GDPR. Every message contains personal data: a phone number, a name, often the substance of a complaint or an appointment. To process that you need a legal basis under Article 6 GDPR. Without a basis the processing is unlawful, however harmless the message looks.
- The Dutch Telecommunications Act. Article 11.7 prohibits sending unsolicited commercial electronic messages without prior consent. A WhatsApp message is such an electronic message. That article explicitly also covers "automated calling and communication systems without human intervention", so systems that send messages on their own.
- Meta's platform rules. Not law, but binding on your account. They technically determine when you can and cannot send something, and that does not always line up with what the law allows.
The practical consequence: something is only allowed once it passes all three filters. Meta can permit a message that the Telecommunications Act forbids. And the law can permit something that you can technically only send through an approved template. So you need to know both sides.
Which legal basis do you need before you switch the number on?
Start with the question of what you are using the channel for. Every purpose needs its own basis; you cannot throw all your processing onto one pile.
For ongoing customer contact the basis is usually performance of the contract, or a legitimate interest. A customer who messages you about their order, their appointment or a fault expects an answer. You do not need a separate consent checkbox for that.
For marketing and sales it is different. As soon as you start a message intended to sell or promote something, you land on the spam prohibition, and the main rule there is prior consent. The exception is your own customer base. You may send existing customers unsolicited messages about products or services related to earlier purchases. The conditions are that they can unsubscribe and that it is clear you are the sender.
Note exactly what that exception says. It is about similar products or services, and about existing customers. A list of numbers you built from quote requests, trade fair visitors or a purchased file does not qualify. Neither, automatically, does a customer who bought one thing three years ago in a completely different product category.
And state that basis somewhere. Article 13 GDPR requires you to name the purpose and the legal ground when you collect the data. In practice that means a line in your privacy statement about the WhatsApp channel, plus a short reference in the first message or in the channel description.
What is the difference between replying and starting the conversation?
This is the hinge of the whole channel, and it is a legal and a technical distinction at the same time.
Technically, WhatsApp works with a window. When a user messages you or calls you, a 24-hour customer service window starts. If that same user messages or calls again before the timer expires, the timer resets to 24 hours. Inside that window you can reply freely: plain text, in your own words, for as long as the conversation runs.
Outside that window you cannot simply send something back. Then it only works through a template message that has been approved in advance. That is not a detail for your technical administrator. It shapes your entire reply flow, because it means every conversation that has gone quiet is handled differently from one that is still running.
A second dividing line runs straight through it: are you starting, or is the customer starting? If the customer starts, the message is by definition not unsolicited and you are in the realm of customer contact. As soon as you start, you have to ask yourself the spam question: is this service or is this commerce? An appointment reminder, a shipping notice or an answer to an open question is service. An offer, a promotion or a "we still have room this week" is commerce, however friendly the wording.
Those two dividing lines do not coincide. You can be inside the window and still send something commercial that is not allowed. And you can be outside the window with a pure service message that is perfectly lawful but technically only possible through a template.
Why do template messages have to be approved in advance?
A template message is a pre-submitted fixed text with variable fields, for instance a name, a date or an order number. Meta reviews such a template before you may use it and classifies it by category: service, utility or marketing.
For you that has four practical consequences.
- You cannot improvise outside the window. Whatever you want to say has to be written and submitted before the situation arises. That requires thinking ahead: which messages do I send on my own initiative, and how exactly are they worded?
- The category is not a formality. A marketing message you submit as a service message is still a marketing message. The Telecommunications Act looks at the content and purpose of the message, not at the label you attached to it inside the platform.
- Approval is not consent. This is the mistake made most often. The fact that Meta approves a marketing template says nothing about whether you may send that template to this particular number. That depends on that one person's opt-in.
- Changes take time. Every edit to the text means a new review. So a template is not the place for information that changes quickly.
The table below sets out the types of message alongside what has to be arranged for each.
| Type of message | When it is possible | What you must have arranged beforehand |
|---|---|---|
| Reply to a customer question | Within 24 hours of the customer's last message or call | Legal basis for customer contact, mention in the privacy statement, retention period for the conversation |
| Follow-up after the conversation has gone quiet | Only through an approved template | Approved template in the right category, plus the question whether this is service or commerce |
| Service message you start, such as an appointment reminder | Only through an approved template | A template, and a legal basis that fits the contract or the appointment itself |
| Commercial message to an existing customer | Only through an approved template | Link to earlier purchases of similar products, recognisable sender, working unsubscribe option |
| Commercial message to someone who is not yet a customer | Only through an approved template | Demonstrable prior consent from that person, recorded per number |
| Message drafted or sent automatically | Follows the same rules as above | Everything above, plus making clear to the customer that they are talking to an automated system |
How do you record an opt-in that holds up?
If you need consent, you have to be able to prove it. A list of numbers is not proof. Proof is a record that shows, per number, when, where and for what that person gave consent.
Record at least the following for every opt-in:
- The phone number.
- The moment consent was given, with date and time.
- Where it happened: which form, which page, which channel.
- The exact wording that stood next to the checkbox or button at that moment.
- What the consent covered: service messages only, or offers as well.
- Whether and when the consent was withdrawn.
That fourth line is skipped most often and matters most. If you change the wording, your new wording proves nothing about consents collected under the old wording. So keep the version that applied at the moment of the opt-in.
On the form of the checkbox the Dutch supervisory authority is clear: you may not assume that someone gives consent implicitly, and pre-ticked boxes are not permitted. A box that is already ticked when the visitor opens the page therefore produces no valid opt-in. The same goes for consent buried in general terms and conditions or tied to something else, such as "by ordering you agree to our WhatsApp messages".
Think about how someone gets out again, too. Unsubscribing has to be easy. On WhatsApp that means in practice: a short, explicit unsubscribe instruction in the message itself, and a system that actually processes a "stop" or "unsubscribe". An unsubscribe request that just sits in an inbox and never reaches your send list is not a working unsubscribe option.
What happens to the data and where does it sit?
As soon as you use WhatsApp for business, customer data sits in a system you do not run yourself. The content of the conversation travels encrypted, but around it data arises that is not: numbers, timestamps, who was in contact with whom, and in most business setups the messages themselves as soon as they land in your customer system or in a third party's management environment.
Who does what is the first question here. You decide why you message customers and what you do with the conversations, so you are the controller. Parties that carry that out on your behalf, such as the supplier of your customer system or the intermediary providing the connection, are usually processors. For that relationship Article 28 GDPR requires a contract or other legal act that binds the processor to you and that sets out the subject matter, duration, nature and purpose of the processing. That is the data processing agreement, and without it you are in the wrong, even if the supplier has everything else in order.
So for every channel you switch on, work through the same four questions. Which parties can reach the messages? With which of them do you have a processing agreement? What does it say about transfers and about sub-processors? And how long do the conversations stay?
For that last question there is no off-the-shelf answer. The starting point is that you do not keep personal data longer than necessary, and what is necessary depends on the situation, so you determine that yourself and you explain it yourself. A conversation about an open complaint has a different shelf life from a conversation about an appointment last year. Pick a period per type of conversation, write down why that period makes sense, and make sure something actually gets deleted. A retention period that exists only on paper is not a retention period.
Do you have to deal with the transfer question?
Yes, and with WhatsApp this is not theoretical. The platform belongs to an American company, and many intermediaries and customer systems connected to it are American too.
The rule is that you may only transfer personal data abroad if that country offers sufficient protection, and that separate rules apply to transfers to the United States. How that works out in a given case depends on the organisation the data goes to.
Concretely, do this. Ask your supplier where the data is stored and where it is processed, and do not accept "in the cloud" as an answer. Ask which sub-processors have access and where they sit. Ask on what basis the transfer outside the EEA takes place and have that confirmed in writing. Keep that answer with your processing agreement, so you can show it when someone asks.
Prohibiting transfers is usually not realistic if you want to use this channel. The point is that you know what happens, that it rests on something, and that you can explain the choice. Not knowing where your customer conversations sit is the problem.
What changes when an AI assistant handles the messages?
The legal basis does not change. An AI assistant answering WhatsApp messages does what an employee does: it processes customer data for your purpose, under your responsibility. Three things do get added.
First, transparency. The customer should know they are communicating with an automated system, and that has to be apparent at first contact, not somewhere at the bottom of a privacy statement.
Second, the spam prohibition, which explicitly covers automated communication systems without human intervention. A system that decides for itself when to message a number falls squarely under it. So the question "did I have consent for this number?" has to be answerable by the system before it sends, not afterwards.
Third, the data the system receives. An assistant answering a question about an order needs the order, not the entire customer file. Limit what is supplied per conversation, and record what is kept from the conversation and where.
What do you arrange before the number goes live?
- Determine the legal basis per purpose: customer contact, service notifications and marketing are three different things with three different answers.
- Put a passage about the WhatsApp channel in your privacy statement, with purpose, legal ground and retention period.
- Split your messages into what fits inside the window and what needs a template, and write those templates out before you submit them.
- Set up an opt-in record that stores, per number, when, where, for what and with which wording consent was given.
- Build an unsubscribe route that technically reaches your send list, and test it.
- Sign a processing agreement with every party that can reach the messages, and ask about storage location, sub-processors and transfers.
- Set a retention period per type of conversation, write down the reasoning and make sure clean-up actually happens.
- Put the channel in your record of processing activities, so you can show later what you arranged and where.
None of these steps is complicated. They only cost time at the moment you do them, and they cost far more time at the moment someone asks and you have not done them. WhatsApp is a perfectly good business channel. It is just not a channel you switch on casually.