Founding member offer50% off your first 3 months · Only 100 founding spotsOffer ends indhmsClaim founding offer →
All articles GDPR

Where does WhatsApp Business data go?

What Meta actually processes when you message a customer, where it travels, and the four lines you need in your Article 30 record.

Four-step diagram of who holds what: your systems, your platform, Meta Ireland, the United States

When you send a WhatsApp message to a customer, three parties touch personal data: you, whatever tool you send from, and Meta. Knowing which one holds what is the difference between an Article 30 record you can defend and a paragraph you invented.

Short version: the message content is end-to-end encrypted and not kept after delivery, but the phone number, the template, the parameters you filled in and the delivery status all pass through Meta’s systems, including in the United States, on the basis of the EU-US Data Privacy Framework.

Now the detail, because the detail is what goes in the paperwork.

The three layers

Your system. Whatever you keep: the contact record, the consent proof, the tags, the conversation history you display in your inbox. This is entirely yours. You are the controller, and it is also the layer where a data subject request is actually fulfilled.

Your messaging platform. The software between you and Meta — Nybero, or a competitor. It stores your contacts, your consent records, your automations and the message history. It is your processor and owes you an Article 28 agreement — and it is the only one of the three you actually sign something with, which we unpack in do you need a DPA with Meta.

Meta. The WhatsApp Business Platform itself. This is the layer people guess about, so it is worth being precise.

What Meta actually processes

When your platform calls the Cloud API to send a message, it passes:

  • the recipient’s phone number
  • your WhatsApp Business Account and phone number ID
  • the template name and language, or the free-form message body
  • the parameters that fill the template’s variables
  • any media you attach

Meta returns a message ID and, subsequently, delivery status webhooks: sent, delivered, read, failed. Inbound messages from the user arrive the same way.

Here the common summary — “end-to-end encrypted, nothing stored” — describes consumer WhatsApp rather than the platform you are using. Between the user’s device and WhatsApp, content is protected by Signal-protocol encryption. But with the Cloud API, Meta hosts the endpoint: the message is decrypted in Meta’s infrastructure, re-encrypted for delivery, and stored encrypted at rest. Meta’s Cloud API data privacy documentation (retrieved 1 August 2026) states a maximum retention period of 30 days, needed for retransmission and the base service.

Two further things sit outside the encryption story and are easy to overlook.

The first is the metadata. Who messaged whom, when, from which business account, with what result. That is processing, and it is enough to be personal data.

The second is the parameters you chose to send. If your appointment reminder template says “Hello {{1}}, your appointment for {{2}} is on {{3}}”, and you fill it with a name, a medical procedure and a date, you have passed all three through the API. End-to-end encryption is not a reason to be careless about what you put in the variables. Put the sensitive part behind a link into your own system, not in the message body.

Where it goes

Two Meta entities sit behind the platform, and both belong in your notes. WhatsApp Ireland Limited is your contracting party under the WhatsApp Business Terms (last updated 16 February 2024). Meta Platforms Ireland Limited is the processor under the Cloud API Terms (last updated 2 April 2026), which is what applies when you send through the Cloud API. In both cases you are the controller — and processing involves Meta infrastructure outside the EEA, including in the United States.

There is one lever most businesses do not know they have. Meta offers Cloud API Local Storage, an opt-in that keeps message data at rest in a chosen region rather than the default, with the applicable sub-processors and data centre locations named in the Cloud API Terms. It does not remove US processing altogether, and availability depends on your setup. But if data residency is the question your legal team asks, that is the setting to ask Meta or your provider about.

The transfer basis is the EU-US Data Privacy Framework. The European Commission adopted the adequacy decision on 10 July 2023, and it is still in force on 1 August 2026 — neither suspended nor withdrawn.

Two developments belong in your notes rather than in a panic. The General Court dismissed the first annulment action on 3 September 2025 (Latombe, T-553/23); that judgment is under appeal at the Court of Justice (C-703/25 P) and still pending. And the Framework’s two predecessors, Safe Harbour and Privacy Shield, were both annulled by that court. An adequacy decision can also be suspended, which is a policy risk you cannot mitigate contractually.

What you can do is make sure the transfer is documented rather than assumed. If the basis changes, you want a record that says which processing was affected, not a scramble to reconstruct it.

The four lines for your Article 30 record

Article 30 requires a record of processing activities. Here is the WhatsApp entry, in the shape most supervisory authorities expect.

FieldWhat to write
PurposeCustomer communication and direct marketing over the WhatsApp Business Platform
Categories of data subjectsCustomers and prospects who gave consent for WhatsApp messaging
Categories of personal dataPhone number, name, message content and metadata, consent record, delivery status, plus any variables used in templates
RecipientsWhatsApp Ireland Ltd (Business Terms) and Meta Platforms Ireland Ltd (Cloud API Terms); [your messaging platform] as processor
Third-country transferUnited States, on the basis of the EU-US Data Privacy Framework adequacy decision of 10 July 2023
Retentione.g. conversation history two years after the last interaction; consent records for the duration of the consent plus the limitation period. Meta retains Cloud API message data for up to 30 days
Technical and organisational measuresEncryption in transit, access control by role, automatic opt-out handling, deletion on request

The retention line is the one usually left blank, and it is the one that fails an audit fastest. Pick a period. Write it down. Have something enforce it.

What a data subject request looks like in practice

Someone writes and asks for a copy of everything you hold (Article 15), or asks you to delete it (Article 17). Where do you go?

Your own systems and your messaging platform. This is where the answer comes from — contact record, consent proof, tags, and the message history as your platform stored it. You should be able to produce it for one contact in one action, and delete the same.

Meta. Meta is not where you fulfil the request. It holds Cloud API message data for up to 30 days plus the associated metadata, processed on your instructions as controller. The deletable, exportable record lives in your own systems and your messaging platform.

That is why the fifth question to ask a vendor is always the same: can you export and delete everything about one contact, including the conversation, in a single operation? If the answer involves a support ticket and three working days, the Article 12 one-month deadline is going to be uncomfortable.

What this means for you

Two jobs, both an afternoon’s work. Write the WhatsApp entry into your Article 30 record using the table above, filling in your real retention period rather than a placeholder. Then look at your templates and move anything sensitive out of the variables and behind a link into your own system.

Nybero hosts in the EU, signs a DPA without a sales call, and puts per-contact deletion — including the consent history — in the interface rather than in a support queue. The GDPR and WhatsApp overview covers how the rest of the picture fits together.

Updated 1 August 2026. An earlier version stated that Meta does not retain message content after delivery and named only Meta Platforms Ireland as the counterparty; both were wrong for the Cloud API and have been corrected against Meta’s documentation and legal terms, retrieved 1 August 2026. Adequacy decisions and Meta’s infrastructure both change; re-check the transfer basis when you review the record. Not legal advice.

FAQ

Frequently asked questions

Is WhatsApp message content stored by Meta?

On consumer WhatsApp, content is not retained after delivery. On the WhatsApp Business Platform it is different: Meta's Cloud API documentation states a maximum retention period of 30 days, with messages encrypted at rest. On top of that Meta processes the delivery metadata and everything you pass into the API — the recipient's phone number, the template used, the parameters you filled in and the delivery status.

Does WhatsApp Business data leave the EU?

Yes. Your EU counterparties are WhatsApp Ireland Limited under the Business Terms and Meta Platforms Ireland Limited under the Cloud API Terms, but processing involves Meta infrastructure in the United States. Those transfers rely on the EU-US Data Privacy Framework, adopted in July 2023 and in force as of 1 August 2026, with an appeal against it pending before the Court of Justice (C-703/25 P). Meta also offers Cloud API Local Storage as an opt-in for keeping message data at rest in a chosen region.

Do I need to name Meta in my record of processing?

Yes, and name both entities: WhatsApp Ireland Limited and Meta Platforms Ireland Limited. If you message customers over the WhatsApp Business Platform they are recipients of personal data and the transfer mechanism has to be stated. That belongs in your Article 30 record alongside the categories of data and your retention period.

Who is the controller for WhatsApp business messaging?

You are the controller for the messaging you carry out — you decide who is contacted and why. WhatsApp Ireland Limited is your processor under the Business Terms and Meta Platforms Ireland Limited under the Cloud API Terms. Your messaging tool is a separate processor and needs its own Article 28 agreement.

Ready to turn leads into conversations?

Start with your own WhatsApp number. 7-day free trial, cancel anytime.

Get started free

Get in touch

Start free