There is a question almost nobody asks before putting a chatbot on their business WhatsApp, and almost everybody should: what happens to the data?
The short answer: the moment a bot replies to your customers, your business is processing personal data, with everything the UK GDPR hangs off that phrase. That is not a reason not to do it — we make our living from this — but it is a reason to do it with your homework done.
A note on scope: the UK GDPR and the EU GDPR ask essentially the same things of you here, and if you serve EU customers as well, both can apply at once.
What data a WhatsApp bot actually handles
More than it looks like at first glance:
- The phone number. It is WhatsApp's identifier and personal data in its own right. It arrives with every message.
- The profile name. Whatever the customer has set in their own WhatsApp.
- The content of the conversation. This is the serious one: people write freely. An ordinary sales conversation can surface addresses, family circumstances, financial details and — in sectors like healthcare — health data, which is special category data and demands extra care. Your bot does not choose what it gets told.
- Metadata. Dates, times, conversation status.
The first duty, then: know what is collected, where it lives and who can see it. Without that map, everything else is decoration.
Lawful basis: why you are allowed to process it
The UK GDPR requires a lawful basis for every processing activity (Article 6). For a sales bot, the usual candidates are two:
- Steps prior to a contract (Article 6(1)(b)): the customer messages you asking for information or a quote, and answering is exactly what that basis was written for.
- Legitimate interests or consent for anything beyond that: keeping conversations for analytics, reusing the number for later marketing. There, "they messaged us once" no longer does the job; it needs assessing, and often it needs permission. For marketing messages in the UK, PECR also applies, with its own rules.
The rule of thumb: answering someone who messages you has a clear footing; using their data for something else does not automatically. Write down which basis you rely on for what.
The duty to inform: say who you are and what you do
Articles 13 and 14 require you to tell people: who is processing their data, why, on what basis, for how long, and what rights they have. There is no page footer on WhatsApp, so the sensible practice is a short first layer in the conversation itself — who you are, plus a link to your privacy notice — with the full detail living in that notice.
There is a second transparency duty, newer to the scene: Article 50 of the EU AI Act requires that anyone talking to an AI knows it, from the first message and without small print. It is EU law, but it reaches UK businesses serving EU customers — and it is good practice wherever your customers sit. We wrote a whole piece on it, not least because the customer who discovers mid-conversation that "Laura" was a bot does not come back.
Who is who: controller and processors
This is where the paperwork gets interesting: a WhatsApp bot involves more actors than you can see.
- Your business is the data controller: you decide what the data is used for, and you answer to the customer and to the ICO.
- The bot vendor (us, or whoever) is normally a data processor: handling data on your behalf, on your instructions. That requires a written data processing agreement (Article 28). A vendor who does not offer you one is telling you something.
- The BSP — the technical intermediary for the WhatsApp API; we explain what that is here — is another processor or sub-processor in the chain.
- Meta has its own role depending on which part of the service you look at, defined in its own terms.
You do not need to memorise the org chart. You do need signed processing agreements with every link in the chain that handles data on your behalf, and to know whether any of them takes the data outside the UK, because international transfers come with their own safeguards to verify.
Individual rights and retention
Customers can exercise the same rights over a bot conversation as over any other data: access, rectification, erasure, objection, portability. In practice that means you need to be able to find one specific person's conversations and delete them on request. Ask your vendor how that works before anyone asks you.
On retention, the principle is limitation: data is kept while it serves its purpose and then deleted or anonymised. "Forever, just in case" is not a retention period; it is a breach waiting for a date. Set a period, write it into your privacy notice, and make sure your vendor can actually enforce it.
What this means when choosing a vendor
None of this is solved by software alone — the controller is you — but a vendor can make it easy or impossible. At Zatio we treat this as a design requirement rather than an appendix: the AI discloses itself as an AI from the first message, the human handover carries the context across without duplicating data through side channels, and the deterministic guardrails that stop the bot inventing prices or products also bound what it does with the information it holds. If you want to see how it fits your case, here is the product — and ask us for the data processing agreement; having it ready tells you something about a vendor.
One last thing, and it matters: this article is general information, not legal advice. Every business has its particulars, and for compliance decisions — lawful bases, retention periods, transfers — speak to a professional who can look at your specific case.