No, and you cannot. There is no DPA with Meta to sign for the WhatsApp Business Platform, because the contract is already in place: the WhatsApp Business Data Processing Terms are incorporated by reference into the Business Terms you accepted when you connected a number.
What surprises people is that there are two of these, covering different layers, held by different Meta entities, updated on different dates. Knowing which is which is the whole job when a data protection officer asks you to produce the paperwork.
The one you accepted without noticing
The WhatsApp Business Terms of Service name WhatsApp Ireland Limited as your contracting entity if you are in the EEA. Those Business Terms pull in the Data Processing Terms, which set out the relationship in the language Article 28 expects: you are the controller, WhatsApp is the processor, and it processes personal information in your customer data on your instructions.
There is no signature ceremony because Article 28(9) GDPR does not require one. It requires the contract to be “in writing, including in electronic form”. Incorporation by reference into terms you accepted electronically meets that.
The practical consequence is that you have nothing to chase and nothing to wait for. What you do have is a document that can change under you, which is why the version date matters more here than in a contract you negotiated.
The second one, for Cloud API hosting
This is the part that gets missed. When Meta hosts your messages rather than you running your own client, a second agreement applies: the WhatsApp Business Platform Cloud API Terms, which you accept by using Cloud API rather than by reference from anywhere else. They name a different entity — Meta Platforms Ireland Limited — as the processor of what they call Company Personal Data: phone numbers, message content, personal identifiers and message details such as type and time.
The Cloud API Terms in turn incorporate the Meta Global Processor Terms. So the chain runs Business Terms → Data Processing Terms for the WhatsApp service, and Cloud API Terms → Global Processor Terms for the hosted infrastructure.
Almost everyone reading this is on Cloud API. Which means both chains apply to you at once, and a record of processing that names only WhatsApp Ireland is incomplete.
| WhatsApp service | Cloud API hosting | |
|---|---|---|
| Processor entity (EEA) | WhatsApp Ireland Limited | Meta Platforms Ireland Limited |
| Governing document | WhatsApp Business Data Processing Terms | WhatsApp Business Platform Cloud API Terms |
| How it binds you | incorporated by reference into the Business Terms | accepted by using Cloud API; incorporates the Global Processor Terms |
| Covers | personal information in your customer data | phone numbers, message content, identifiers, message details |
| Last updated | 22 August 2025 | 2 April 2026 (Cloud API Terms), 20 March 2026 (Global Processor Terms) |
Dates as retrieved on 1 August 2026. Check them before you file anything, because they move.
Does it actually cover Article 28(3)?
Article 28(3) lists eight things a processor contract has to stipulate. Read against the Data Processing Terms, most have a clear counterpart:
- Documented instructions. The terms state that WhatsApp processes personal information only in accordance with your instructions as set out in the Business Terms and the Data Processing Terms.
- Confidentiality and security. Appropriate technical and organisational measures are committed to, with the specifics in the Data Security Terms incorporated by reference.
- Sub-processors. Meta companies and third parties are authorised as sub-processors. Meta undertakes to notify you in advance of changes, and to bind sub-processors to obligations no less rigorous than its own.
- Assistance with data subject rights and with Articles 32–36. Committed to, qualified as usual by the nature of the processing and the information available to the processor.
- Deletion on termination. On termination of the Business Terms, processing ceases and the data is deleted, unless retention is legally required.
- Information. On request, Meta will make available the information reasonably necessary to demonstrate compliance.
That is coverage on most points, not all. Two gaps and one caveat are worth writing down before you file this.
Deletion, but not return. Article 28(3)(g) gives the controller a choice between having the data deleted and having it returned. The terms provide deletion only.
Information, but not inspections. Article 28(3)(h) also asks the processor to allow for and contribute to audits, including inspections. The Data Processing Terms cover the information duty; there is no inspection right. What you are pointed at instead are the reports Meta has obtained for Cloud API — SOC 2 Type II and ISO 27001, per Meta’s Cloud API data privacy and security documentation, retrieved 1 August 2026. Note that the WhatsApp Data Security Terms themselves, last updated 29 October 2020, name no certification.
The sub-processor caveat. Your objection right is the right to stop using the service, not a veto — the terms say you may inform Meta in writing and stop using the Business Services.
None of this is unusual for a processor at this scale, and it is the trade you are making. Whether it is sufficient for your particular processing is a call for your own counsel, not for a blog post.
Transfers are a separate document again
The WhatsApp Business Data Transfer Addendum (last updated 16 February 2024) governs European data leaving the EEA, relying on the EU-U.S. Data Privacy Framework and, where that does not apply, on the European Commission’s Standard Contractual Clauses under Commission Implementing Decision 2021/914. The addendum takes priority over the Business Terms and the Data Processing Terms where they conflict.
We wrote the detail up separately in where WhatsApp Business data actually goes, including the four lines this produces in an Article 30 record.
The DPA you do sign
Between you and Meta sits your messaging platform, and that one is a conventional processor relationship. It holds the things Meta never sees in usable form: your contact records, your consent proof, your tags, your automations, the message history in your inbox. That is where a deletion request is actually executed.
So the signed Article 28 agreement in your compliance file is with your provider, not with Meta. Ask for it before you import a single contact. At Nybero we are the processor for that layer and provide a data processing agreement on request; the hosting sits with Hetzner in Germany, itself under a DPA. Our GDPR page sets out the rest.
What this means for you
Four things, none of which take long:
- Stop looking for a signature. Nothing is missing. Note in your file that the terms are incorporated by reference and that acceptance happened electronically, with the date you connected the number.
- Save both chains as PDFs, with the retrieval date on them. They are unilaterally amendable. A dated copy is what makes your record defensible eighteen months later, and it is the only version evidence you will get.
- Name both entities in your Article 30 record. WhatsApp Ireland Limited and Meta Platforms Ireland Limited, with the transfer mechanism from the addendum.
- Get the real DPA from your provider. That is the contract that carries the obligations you will actually rely on when a customer asks to be deleted.
Whether this arrangement is adequate for your processing is not something a blog post can settle; for regulated sectors or unusual processing, have counsel look at it. And if you are still choosing a platform, ask for the provider DPA during the trial rather than after the first campaign — it is a reasonable thing to ask for, and the answer tells you a lot.