Update after the appointment
Customer appointment done, maintenance completed. Order spare part for next month, customer wants a quote for an extra service contract.
Customers, staff and suppliers are already on WhatsApp. Banning it doesn’t help much, letting it run wild is risky. This guide shows what matters for data protection – and which rules actually work day to day.
In many businesses, nobody ever introduced WhatsApp – it just showed up at some point. That’s exactly what makes it tricky.
First the team group, then the first customers, then the supplier. In the end, nobody really knows who has which data on which phone.
Customer photos next to vacation pics, a client in an employee’s personal address book. When someone leaves the company, the chats leave with them.
Is this even allowed? Some ignore the issue, others ban WhatsApp – and the team uses it anyway, just secretly.
WhatsApp is fast, costs nothing extra and everyone knows how to use it. That’s why trade businesses, field service teams, cleaning companies, property managers and home care services all rely on it. But as soon as the messenger is used for work, the General Data Protection Regulation (GDPR) applies whenever personal data of people in the EU is involved – and it applies to the business, not to the individual employee. The good news: with a clear separation, a few settings and written rules for your team, you can significantly reduce the biggest risks.
The GDPR protects personal data – anything that can be linked to a person: name, phone number, address, but also a photo of a doorbell nameplate or a voice message with a recognizable voice. Between friends, this hardly matters. But if you use WhatsApp for your business, your company is the “controller” and must be able to explain which data you process, for what purpose, on what legal basis and how you protect it. That’s true even if employees use their own phones.
The most sensitive point usually isn’t the chat itself, but the address book. If WhatsApp has access to your contacts, the phone numbers in your address book are shared with the provider – including those of people who don’t use WhatsApp and never agreed to it. In a business context, that’s hard to justify. Typical solutions:
For customer contact, WhatsApp Business is usually the better choice. You get a business profile with address and opening hours, can set up away messages and quick replies, and sort chats with labels. Most importantly, it cleanly separates your business from your personal WhatsApp. The business app alone doesn’t solve the underlying data protection issue, though: you should still check contact access and set clear rules. For larger teams with lots of inquiries, there’s also the WhatsApp Business Platform, usually connected via specialized service providers.
The cleanest solution is a company phone used only for work. Then contacts and chats belong to the business, you can set the settings, and when someone leaves, the device stays. If your team uses personal phones (“bring your own device”), it gets harder: you can hardly control which data ends up where, and personal and business contacts get mixed up. If personal devices are unavoidable, at least put in writing which data doesn’t belong there and what happens when someone leaves.
If a customer messages you on WhatsApp first, that’s a clear sign they want to communicate that way. Still, be transparent: mention WhatsApp in your privacy policy, always offer an alternative like phone or email, and don’t message anyone on WhatsApp out of the blue just because their number is in your system. For marketing messages, you need explicit consent. As for employees: nobody should be forced to install WhatsApp on their personal phone to be reachable for work.
Some data is so sensitive that it should never be sent through a consumer messenger. This includes:
The GDPR is especially strict about health data (Art. 9 GDPR). If you work in home care or a medical practice, use the channels intended for patient and client communication – such as the certified secure messaging of your national health system.
Most data protection slip-ups don’t happen out of bad intent, but out of convenience: the photo of the damage goes into the big team group, the door code ends up in the chat because it’s urgent. Short, clear rules help more than a twenty-page document nobody reads. These have proven themselves:
A core principle of the GDPR is data minimization: only process what you really need for the purpose, and delete what you no longer need. For WhatsApp, that means in practice: not every voice message has to sit in the chat for months. Important information belongs in your actual system – job file, customer database, business software – and the chat can be cleaned up afterwards. If you clear out chats regularly, you also have less to lose if a phone goes missing.
If you use additional services that process content from your chats – for transcription, ticketing systems or customer service platforms, for example – these providers process personal data on your behalf. For that, you usually need a data processing agreement (DPA) under Art. 28 GDPR. Also check where the data is processed, whether it’s stored and for how long. A trustworthy provider answers these questions without beating around the bush.
One example is Summarize.One: voice messages and summaries are only processed and deleted right afterwards, whatever the service needs runs on servers in the EU, and the Business plan comes with a DPA. Important: a data-minimizing add-on doesn’t automatically make your WhatsApp use GDPR compliant. You still need the rules above.
Copy this template, adapt it to your business and have your team sign it. It’s deliberately short so people actually read it. If in doubt, have your data protection officer review it.
Messaging policy for [company name] As of: [date] 1. Devices For work, we communicate via [company phones / WhatsApp Business on the company number]. Customer contact via personal numbers is not intended. 2. Contacts On company phones, WhatsApp has [no access to the address book / access only to contacts who have consented]. 3. Groups Groups exist only per [job / route / property]. Anyone no longer involved leaves the group. 4. What doesn’t belong in the chat Health data, bank and login details, ID copies, HR documents, door codes and key hiding spots. For this kind of information, we call or use [secure channel]. 5. Filing and deleting Photos, measurements and agreements are transferred to [system / job file] within [X days] and then deleted from the chat. 6. Security All devices have a screen lock. Loss or theft is reported to [contact person] immediately. 7. Add-on services New apps or bots that process chat content are only used after approval by [contact person]. 8. Leaving the company When leaving, business chats are handed over, groups are exited and company devices are returned. Questions to: [name, contact] Read and understood: ____________________
Forward a voice message to the Summarize.One bot and read what it’s about in seconds. Voice messages and summaries aren’t stored – which fits the principle of data minimization.
Customer appointment done, maintenance completed. Order spare part for next month, customer wants a quote for an extra service contract.
Wants to schedule a viewing, ideally next week in the morning. Asks for a call back to coordinate.
Discuss messaging policy at the team meeting, go through company phones, close old groups.
One tap is all it takes – the chat opens with the message ready.
Or record a memo right in the chat.
In seconds – short, medium or as bullet points.
Specialized software rarely fails because of missing features – it fails because the team doesn’t use it. Summarize.One runs where everyone already is: in WhatsApp.
Everyone on your team already has WhatsApp. Just say “Hello” to the bot – no account, no password.
Your workflows and your software stay exactly as they are. Summarize.One just makes sure information from WhatsApp gets where it needs to go faster.
If you can forward a voice message, you can use Summarize.One. Short, medium or bullet points – or word for word if you like.
We never store voice messages or summaries – they are only processed and deleted right afterwards. We don’t analyze any content. Communication is encrypted, and what the service needs is stored on servers in the EU.
Summarize.One doesn’t store anything – but whether WhatsApp is the right channel for your content is still your company’s call. Our guide explains what to keep in mind.
All plans do the same – they only differ in the number of replies per month. Prefer no subscription? Buy credits individually ↓
Just buy credits individually – no contract, no term, no expiry date. With a subscription, they kick in once your monthly allowance is used up.
Longer messages use one credit per started 5 minutes or 4,000 characters.
Your monthly allowance is used first, then your purchased credits.
All prices incl. 19% VAT. Subscriptions can be cancelled monthly.
There’s no general ban. What matters is how you use WhatsApp: contact syncing, separating personal and business use, no sensitive data in the chat and clear rules for your team. There’s no guarantee of GDPR compliance – if in doubt, have your setup reviewed.
No. WhatsApp Business helps with separation and comes with handy features for customer contact. But you still have to sort out contact access, team rules and how to handle sensitive data yourself.
It’s possible, but harder to control. If personal devices are unavoidable, put in writing which data doesn’t belong there and what happens when someone leaves. You shouldn’t make it mandatory for anyone.
No. Summarize.One processes forwarded voice messages with minimal data and offers businesses a DPA. Your business remains responsible for how WhatsApp itself is used – contact syncing, devices, team rules.
If you use WhatsApp to communicate with customers, you should be transparent about it and offer an alternative like phone or email. The exact wording is best clarified with your data protection officer.
Business costs €24.99 per person per month or €249 per year, including VAT – with unlimited replies, an invoice and a DPA. To try it out, everyone gets 5 free credits.
No. Voice messages and summaries are only processed and deleted right afterwards. We don’t analyze any content. Whatever the service needs runs on servers in the EU.
Yes. With the Business plan, we sign a DPA under Art. 28 GDPR. Just email us at [email protected].
Not directly yet – we’re working on it. But you can always forward voice messages from groups to the bot one by one.
Everyone says “Hello” to the bot and can start right away. For Business with an invoice, tell us how many people you are – we’ll sort out the rest by email.
Handle customer requests and updates from the job site without spending your evenings in the office.
→What home care agencies can handle via WhatsApp, what never – and what to use instead.
→What WhatsApp can do in a medical practice, where confidentiality applies and what the alternatives are.
→Building sites, field sales, customers, team chats – when voice messages save time at work, when they don’t, and the simple rules your team needs.
5 free credits, no subscription, no account. For Business with an invoice and a DPA, drop us a line. [email protected]