Is WhatsApp for business legal in Germany under the GDPR?
Using WhatsApp for customer contact is not forbidden in Germany, but how you use it decides whether it fits the GDPR. The business app on a staff member’s phone raises problems that the WhatsApp Business Platform, set up properly, largely avoids.
The DSGVO, as Germans call the GDPR, does not name messaging apps. It asks the same questions of every tool: on what legal basis do you process a customer’s data, who else processes it on your behalf, where is it stored, how long do you keep it, and can you prove what the customer agreed to. WhatsApp Business API GDPR planning is simply answering those questions for one specific channel.
German customers use WhatsApp daily, and many would rather send a message than call a practice or wait in an email queue. That demand is why so many businesses started with an ordinary phone and the free app, and why data protection officers and lawyers often push back.
This guide explains the technical choices that matter, with sources from Meta’s own documentation and German law. It does not replace legal advice: your data protection officer or lawyer makes the final call on your processing, and we build the system to match their requirements.
WhatsApp Business app vs Cloud API: what is the difference?
The WhatsApp Business app is a phone app for one device and a handful of users; the Cloud API is a programmable interface hosted by Meta that your own software talks to. For WhatsApp Business API GDPR compliance, that difference changes who holds the data and whether phone contacts are involved at all.
Business app
Installed on a smartphone, tied to that device, with chats stored on the phone and in its backups. It behaves like the normal messenger, including address-book features. Good for a sole trader testing the waters; hard to control once several employees are involved.
Cloud API (WhatsApp Business Platform)
Meta hosts the messaging infrastructure; your inbox, bots and integrations connect through the API. No phone, no personal address book, and message handling follows your code and configuration.
Solution providers
Companies that resell or host access to the platform and add their own inbox and bot tools on top. They add a processor to your chain, so their contract matters as much as Meta’s.
For most German businesses with more than one person answering messages, the Cloud API is the sensible foundation. It costs more effort to set up than downloading an app, which is exactly where a developer earns their fee.
The messenger app regularly reads the phone’s address book, which means data about people who never agreed to share it with WhatsApp can leave the device. On a business phone full of customer numbers, that is hard to justify.
WhatsApp’s own privacy policy for the European region says that, with the contact upload feature, the app regularly identifies other WhatsApp users in your address book and stores cryptographic hash values of the phone numbers of contacts who are not WhatsApp users. For a private person that is a personal decision; for a business, every customer and supplier in that address book is someone whose data you are responsible for.
Workarounds exist, such as denying the app contact permission or using a separate phone with an empty address book, but they depend on every employee doing the right thing on every device. The API route removes the issue by design: there is no phone and no address book to read.
This is the first thing we raise with clients who want WhatsApp Business API GDPR help, because it is often the reason their data protection officer said no in the first place.
For WhatsApp Business API GDPR purposes, when you use the WhatsApp Business Platform you are the controller and WhatsApp acts as your processor under its Business Data Processing Terms. If you add a solution provider, they become another processor and need their own agreement with you.
According to the WhatsApp Business Data Processing Terms, WhatsApp processes personal information only on your instructions as set out in the business terms. Businesses in the EU contract with WhatsApp Ireland Limited, with a data transfer addendum based on standard contractual clauses. WhatsApp may use sub-processors worldwide, stays liable for them, and gives notice of changes, which you can object to by stopping use of the service. At the end of the contract, WhatsApp stops processing and deletes the data within the period set in the business terms, unless law requires otherwise.
If you choose a solution provider instead of a direct Cloud API connection, ask them four things: where their servers are, which sub-processors they use, what their processing agreement says about deletion, and whether you can export your data if you leave. A good provider answers in writing without hesitation.
Our default is a direct Cloud API connection with your own inbox hosted in your EU cloud account, because it keeps the chain short: you, Meta, and your hosting provider.
Can WhatsApp Business API data be stored in Germany under GDPR rules?
Partly, and it is a key WhatsApp Business API GDPR setting. The Cloud API’s local storage option lets you keep message content at rest in a chosen country, and Germany is on Meta’s list. Some data, such as contact phone numbers, is still stored in Meta’s data centres.
Meta’s Cloud API documentation lists supported data_localization_region values, and the European entries include Germany (DE), Switzerland and the United Kingdom. With local storage enabled, message bodies, media and template components are kept only in the selected region’s data centres once the in-use period ends, and limited metadata is tokenised and encrypted. The same documentation notes that contact phone numbers are stored in Meta’s data centres regardless of this setting.
There is a practical catch: local storage has to be enabled on a number before it is registered. A number already in use must be deregistered first. That is why we configure it at the very start of a WhatsApp Business API GDPR project, not as an afterthought.
Your own side of the data, the inbox, bot logs and CRM links, lives wherever you host it. We set that up in an EU region of your cloud account.
How do you collect WhatsApp opt-in legally in Germany?
Ask clearly, record the answer and make leaving easy; opt-in is the heart of WhatsApp Business API GDPR practice. The opt-in must say that the person will receive messages on WhatsApp from your business, by name, and your system should store when, where and how they agreed.
Meta’s opt-in guidance requires businesses to state clearly that a person is opting in to receive messages, and to name the business. It accepts opt-ins collected on a website, by SMS, over the phone or on paper, and asks businesses to give clear instructions on how to opt out and to honour those requests.
German law adds its own layer for marketing. The Act against Unfair Competition (§ 7 UWG) treats advertising sent by electronic mail without the recipient’s prior express consent as an unacceptable nuisance. Your lawyer will tell you how that applies to WhatsApp promotions; technically, we build separate consent for service messages and for marketing, so a customer can accept appointment reminders without agreeing to newsletters.
- Unticked checkbox at checkout or booking, with WhatsApp and your business named
- Separate choice for marketing messages
- Timestamp, source page or location and wording version stored with each opt-in
- “STOP” and similar keywords handled automatically
- Opt-out status synced to your CRM so no other tool keeps messaging
Template messages, the 24-hour window and WhatsApp Business API GDPR discipline
Business-initiated messages go out as pre-approved templates; free-form replies are possible for 24 hours after a customer writes to you. Your automation has to know which situation it is in.
According to Meta’s pricing documentation, since 1 July 2025 businesses are charged per delivered template message, in three categories: marketing, utility and authentication. When a customer messages you, a 24-hour customer service window opens, during which non-template messages and utility templates are free. Customers who arrive through a click-to-WhatsApp ad open a 72-hour free entry point window once you respond.
For WhatsApp Business API GDPR purposes, templates are also useful discipline: each one is a fixed, reviewed text with a clear purpose, which makes it easier to document what you send and why. We write templates to be short, factual and correctly categorised, because a reminder dressed up with promotional lines can be reclassified as marketing.
A typical German practice or shop needs five to ten utility templates to start: booking confirmation, reminder, rescheduling link, order shipped, delivery issue and a “we tried to reach you” follow-up.
Chatbot flows for appointments and order status
The two flows that pay for themselves fastest are appointment handling and order-status questions. Both are structured, repetitive and easy to hand over to a person when the bot is unsure.
Appointments
The customer asks for a slot, the bot offers free times from your calendar or booking system, confirms, and sends a reminder template the day before. Rescheduling and cancellation work the same way. Health details are not requested in the chat; if a patient volunteers them, the flow hands over to staff.
Order status
The customer sends an order number, the bot checks your shop or ERP and replies with the status and tracking link. It asks for the postcode as a second factor before revealing anything.
Handover
Any message the bot cannot place goes to your team inbox with the full context, within working hours or with an honest “we reply tomorrow morning” outside them.
We design flows around data minimisation, a core WhatsApp Business API GDPR principle: the bot asks only for what the task needs and stores only what your retention rules allow. If you want an AI model to answer free-text questions as well, that is a separate decision with its own data questions, covered on our AI chatbot page.
WhatsApp Business API GDPR retention: how long to keep chats and how to delete them
Under a WhatsApp Business API GDPR set-up, keep chats only as long as the purpose needs, then delete them automatically. The periods are yours to set with your lawyer; our job is to make deletion reliable across the inbox, the logs and any copies.
Storage limitation is a core GDPR principle, and messaging data tends to pile up because nobody owns the clean-up. We build scheduled jobs that remove messages, media and bot logs after the periods you define, for example a shorter period for general enquiries and a longer one where messages form part of a contract or order record. Where a chat must be kept for commercial or tax reasons, we export the relevant part to the record it belongs to and delete the rest.
A customer’s request to erase their data should trigger the same routine for one person: inbox history, CRM links and opt-in record handled consistently, with the opt-out itself kept so they are not messaged again.
Meta’s side follows its own terms, including deletion on contract end as described in the data processing terms. We document both halves so your records of processing reflect what actually happens.
A simple click-to-chat link is harmless; embedded third-party chat widgets that load scripts or set cookies before consent are not. German law requires consent before storing or reading information on a visitor’s device unless it is strictly necessary.
§ 25 of the Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG) makes storing or accessing information on a user’s device subject to consent based on clear information, with exceptions for what is strictly necessary to provide a service the user requested. A plain link that opens WhatsApp only when clicked usually avoids the question; a widget from an outside provider may not.
We build the website entry point as a plain link or a self-hosted button that loads nothing until clicked, and if a third-party widget is required, we put it behind your consent banner. New sites that include this start at US$150.
How much does a WhatsApp Business API GDPR set-up cost?
Our WhatsApp Business API GDPR set-ups start at US$600 for onboarding, opt-in capture, templates and one or two flows. Custom inboxes, deep integrations and AI assistants start at US$900. Meta’s per-message fees are separate and billed to your account.
Quotes in this area vary widely because “WhatsApp integration” can mean anything from connecting a number to a SaaS tool to building a full customer-service system. The drivers in our quotes are concrete: number of flows, systems to connect (booking tool, shop, CRM, ERP), number of opt-in points on web, checkout and in-store, and the complexity of your deletion rules.
Running costs are mainly Meta’s template fees, your hosting, and maintenance after the free two months at US$120/mo. Keeping most conversations inside customer-initiated windows keeps Meta’s fees low, and we design flows with that in mind.
How long does it take to go live on the WhatsApp Business Platform?
A focused WhatsApp Business API GDPR set-up with opt-in, templates and one flow takes about two to three weeks; a custom inbox with several flows and integrations takes four to six. Meta’s business verification and template reviews can add days, so we start them early.
Week one covers your Meta business account, the WhatsApp Business account, number choice and local storage, plus a short workshop on what you want to automate. Week two brings opt-in points, templates submitted for approval and the first flow on a test number. Integrations and the team inbox follow. We finish with a week of internal testing where your staff play customers before any real customer is messaged.
Working with a remote WhatsApp Business API GDPR team in India from Germany
It is straightforward: WhatsApp Business API GDPR work is cloud-based from start to finish, so remote set-up is normal. Our day starts three and a half to four and a half hours before yours, so we overlap from your late morning to the end of your working afternoon.
Accounts stay yours. Your Meta business account, WhatsApp Business account, phone number, cloud hosting and code repository are all in your company’s name; we work with delegated access you can withdraw. We never register numbers or business accounts under our own names.
Language: we work in English, and your customer-facing German texts are written or approved by you. We can draft template wording in English for your team to translate, or implement German texts you supply. Payments are quoted in USD and paid in USD or EUR through Wise or bank wire; invoices come from India, and your accountant advises on VAT treatment. Our terms and written quote cover scope and changes.
The first two weeks: a call to agree flows and data rules, account access, local storage configured, opt-in wording drafted for your lawyer, and a working test flow on a sandbox number by day ten.
Worked example: a hypothetical physiotherapy practice in Düsseldorf
Consider an invented physiotherapy practice with four therapists in Düsseldorf. Patients keep messaging the reception’s private phone, and the data protection officer wants that to stop.
The set-up would be: a new number on the Cloud API with local storage set to Germany; opt-in during online booking and on the paper intake form; utility templates for confirmation, a reminder the day before and a rescheduling link; and a small bot that offers free slots from the booking system. Messages outside the bot’s scope go to a browser inbox that reception uses, with therapists given read access only to their own patients’ threads.
Data rules agreed with the practice’s adviser: no health details requested in chat, general enquiries deleted after a short period, appointment messages kept only as long as the practice specifies. Estimated effort: about four weeks, starting at US$600, rising towards US$900 if the custom inbox is added. This is an illustration, not a client story.
WhatsApp Business API GDPR checklist
Before your first customer message goes out, you, your lawyer and your developer should be able to tick every line below.
- Business app on personal or shared phones retired for customer contact.
- Cloud API number registered with local storage set to Germany.
- Meta’s business and data processing terms accepted by an authorised person.
- Any solution provider covered by its own processing agreement.
- Privacy notice updated to describe WhatsApp processing (your lawyer’s text).
- Opt-in wording approved, with records stored for every contact.
- Separate consent for marketing messages.
- Templates categorised correctly and approved.
- Retention periods set and deletion jobs tested.
- Staff access by role, with an audit log.
Does WhatsApp help your visibility on Google and in AI answers?
Not directly, but it helps conversions from the visibility you already have. A clear, consent-friendly WhatsApp entry point on your site and Google Business Profile turns searchers into conversations.
Search engines and AI assistants increasingly answer “can I book by WhatsApp?” style questions from what your website says. A short FAQ stating that you take bookings and order questions on WhatsApp, and how you handle the data, gives them a precise answer to quote. We can add that page with structured data as part of a site project; monthly SEO starts at US$150/mo. Nobody can promise rankings, but specific answers are what these systems pick up.