Blog

WhatsApp AI and GDPR: Automate Without Breaking the Law

11/6/26
IconIconIconIcon

WhatsApp AI and GDPR: how to automate without breaking data protection law

Updated: June 4, 2026

Data protection and GDPR in a WhatsApp AI with a geometric shield and padlock
TL;DR: Automating WhatsApp with AI is legal if you have a legal basis (contract, consent or legitimate interest), inform the user in the first message, offer an easy opt-out and respect Meta's 24-hour window. Without that framework, a GDPR infringement can cost from €5,000 up to €20 million according to the AEPD.

A customer messages your WhatsApp, the AI replies in seconds, records their details and schedules a follow-up. All perfect, until an AEPD resolution lands asking what legal basis you have for processing that number, for what purpose, and where the consent is. Automating WhatsApp without a basic compliance layer turns an operational advantage into a real legal risk. This article explains what the GDPR requires, which mistakes the AEPD penalizes and what Tubot does so you operate within the law from the very first message.

What does the GDPR require when an AI handles WhatsApp?

The GDPR (Regulation EU 2016/679) is the European law that governs the processing of personal data, including a customer's phone number and the content of a WhatsApp conversation. For a company automating that channel with AI, it comes into play when you need to prove to the AEPD that every conversation has a legal basis, that the user was informed and that they can exercise their rights at any time.

Article 6 of the GDPR lists the six possible legal bases. For most businesses on WhatsApp, only three apply: the data subject's consent, the performance of a contract and the controller's legitimate interest. Without at least one of them documented, the processing is unlawful from the first message the AI sends or receives.

The three legal bases that allow you to automate WhatsApp

Choosing the right legal basis is not a technicality: it defines what you can send, when and to whom. For a WhatsApp AI running on the WhatsApp Business API, applying the wrong basis or having none at all is the most common infringement the AEPD detects and sanctions, even in small businesses.

  • Performance of a contract (Art. 6.1.b GDPR): if the customer gave you their number to receive the service, you can use that channel to manage it. Appointments, confirmations, order notifications or incident follow-ups fit here without additional consent, as long as the communication is operational and not promotional.
  • Express consent (Art. 6.1.a GDPR): required to send offers, campaigns or any commercial communication. Consent must be freely given, specific, informed and unambiguous. A pre-ticked box or silence does not count. You must keep evidence with date and time outside the chat history.
  • Legitimate interest (Art. 6.1.f GDPR): applicable when the customer initiated contact and expects a reply. If someone messages your business WhatsApp asking for information, replying is legitimate. It does not cover mass sends, aggressive follow-ups or reactivations after a reasonable time has passed.

Article 21 of Spain's LSSI adds that, where a prior contractual relationship exists, you may send commercial communications about products or services similar to those already contracted without additional consent, provided you have informed the customer and offer an opt-out in every send.

What is opt-in and why is it the key piece in a WhatsApp AI?

Opt-in is the process by which a user expressly authorizes receiving communications from your company via WhatsApp. It is the key piece because without it, any commercial message sent by an AI to a number that did not explicitly request it breaches the LSSI and can trigger an AEPD sanction, regardless of volume or intent.

To be valid, the opt-in must meet three conditions: the user performs a positive action (ticking an unticked box, replying with an acceptance keyword), it is recorded with date, time and channel outside the chat, and it refers specifically to WhatsApp communications. The WhatsApp Business API includes mechanisms to manage this consent within the channel itself. In the first automated message, Tubot can include the mandatory information layer of Art. 13 GDPR: data controller, purpose, legal basis, data subject rights and a link to the privacy policy. If the lead starts the conversation themselves, that action is a first indicator of interest, but it does not exempt you from informing them from the very first message.

The 24-hour window: how Tubot respects it

The 24-hour window is Meta's rule whereby, once a user sends a message to your WhatsApp Business number, you have 24 hours to reply with any type of content. After that period, you can only reach out using Meta-approved templates in the utility, authentication or marketing categories, each with its own content requirements and cost.

This rule matters for GDPR purposes because sending a marketing template outside the window requires the user to have expressly opted in to receive it and the template to be approved by Meta. If the template fails either condition, the communication is unlawful both for Meta and for the AEPD. Tubot runs on the WhatsApp Business API and respects the window through product logic: the voice follow-up at 4 hours falls within the active window, and later reactivations use approved templates in the correct category. The flows applied by the WhatsApp AI for real estate or the WhatsApp AI for ecommerce are designed to keep the conversation active without forcing contact outside the permitted framework.

Common mistakes the AEPD has already fined

GDPR non-compliance on WhatsApp is not an abstract risk. The AEPD has issued real sanctioning decisions based on the misuse of business messaging. Knowing these cases lets you avoid the same mistakes before a complaint exposes them.

  • Adding someone to a group without consent: the AEPD fined a company €42,000 for adding an employee to a WhatsApp group without her express authorization. Her number was visible to every member, which constitutes a disclosure of data to third parties without a legal basis.
  • Sending client documents from a personal phone: an advisory firm received a €5,000 fine for transmitting files containing client data via WhatsApp on a device without corporate security measures, in breach of Art. 32 GDPR.
  • Not offering an opt-out in commercial communications: Art. 21 of the LSSI requires every send to include a simple, free mechanism for the recipient to object. Omitting it turns each message into an additional infringement.
  • Using personal WhatsApp for business purposes: the consumer WhatsApp Messenger app does not include the Art. 28 GDPR data processing agreement (DPA). Without that contract with WhatsApp as data processor, the company cannot demonstrate compliance in an inspection.

Maximum GDPR fines reach €20 million or 4% of global annual turnover (Art. 83 GDPR). For SMBs, the AEPD tends to apply lower brackets, typically between €4,000 and €10,000 for medium-level infringements.

No GDPR protocol vs a WhatsApp AI with built-in compliance

This table compares management without a compliance protocol against a WhatsApp AI with built-in compliance. Use it to identify where the legal risk concentrates and what each approach reduces in operational and data protection terms.

SituationNo GDPR protocolWith Tubot
First automated messageNo information layerIncludes controller, purpose and rights
Follow-up at 4 hoursMay fall outside the window or lack a basisWithin the active window, with a documented basis
Reactivation templateSent without approval or opt-inApproved template, correct category
User opt-outNo clear mechanismOpt-out accessible in the thread itself
Consent recordsOnly in the chat historyExternal evidence with timestamp

Example of a first message with the GDPR information layer

Illustrative example:

Lead: Hi, can you give me a price for cleaning my office?

Tubot: Hi. Before we start: this channel belongs to [Company]. We process your name and phone number to answer your inquiry, based on your request. You can access, rectify or delete your data by writing to us. Full policy: [link]. Can you tell me the square meters and the type of service you need?

Lead: About 150 square meters, weekly cleaning.

Tubot: Perfect. How many bathrooms are there, and is it empty or furnished?

Lead: Two bathrooms, furnished.

Tubot: Noted. For 150 m² furnished with two bathrooms, the indicative range for weekly cleaning is between €180 and €240 per month. Shall I schedule a technical visit to finalize the price?

Lead: Yes, could you come on Thursday?

Tubot: I have Thursday at 10:30 or at 17:00. Which works for you? If at any point you no longer want to receive messages here, reply STOP and we will take care of it immediately.

GDPR compliance checklist for a WhatsApp AI

A checklist is the fastest way to spot compliance gaps before switching on any automated flow. The points you cannot tick are, in most cases, exactly the ones the AEPD checks when a complaint or inspection arrives.

  1. You have documented the legal basis for each type of communication: operational, commercial and follow-up.
  2. The first message includes controller, purpose, legal basis, rights and a link to the privacy policy (Art. 13 GDPR).
  3. You use the WhatsApp Business API, which includes the DPA with WhatsApp (Art. 28 GDPR).
  4. Reactivation templates are approved by Meta and belong to the correct category.
  5. You offer a simple, free opt-out mechanism in every commercial communication.
  6. Consent records are timestamped and stored outside the chat history.
  7. Customer data is processed on devices with corporate security measures (Art. 32 GDPR).
  8. You have a documented procedure to handle data subject rights requests within one month (Art. 17 GDPR).

If you operate in sectors with specially protected data, such as dental health or legal information, the GDPR requires additional safeguards for special categories (Art. 9). The flows described in the guide to automating orders via WhatsApp, like any other operation, are designed with these rules in mind from the very first node. To validate your case and see which steps you are missing, you can write via Tubot's contact page or start at Tubot.

Frequently asked questions

What is the most common legal basis for automating WhatsApp at an SMB?

For conversations started by the customer, the most common basis is the performance of a contract or the legitimate interest derived from the user's own request. To send campaigns or proactive commercial messages to contacts who have not written recently, you need prior express consent, stored with evidence of date and channel outside the chat history.

Is using WhatsApp Business enough to comply with the GDPR?

No. WhatsApp Business or the WhatsApp Business API are the necessary technical layer, but GDPR compliance depends on what the company does: what data it collects, what legal basis it has, how it informs the user and how it handles rights requests. Using the right tool is a requirement, not a guarantee of compliance.

What happens if the user opts out on WhatsApp?

When a user asks to stop receiving messages, the flow must stop immediately and the contact details must be unlinked from the sending system. If the legal basis was consent, its withdrawal requires ceasing processing for that purpose. The company has one month to confirm the opt-out and execute any formally exercised right to erasure.

Can a WhatsApp AI send follow-up messages after 24 hours?

Only through Meta-approved templates in the utility, authentication or marketing categories. Marketing templates require the user to have opted in to receive them and the company to hold documented consent. Outside that framework, sending free-form messages after 24 hours breaches both Meta's policies and the GDPR legal basis.

What fines can the AEPD impose for breaching the GDPR on WhatsApp?

GDPR fines (Art. 83) can reach €20 million or 4% of global annual turnover. For SMBs, the AEPD usually applies lower brackets: between €4,000 and €10,000 for medium-level infringements, such as lack of a legal basis or missing security measures. Documented cases include €42,000 for adding someone to a group without consent and €5,000 for sending client data from an unprotected personal device.

Sources

  1. AEPD, 2024, https://www.aepd.es/derechos-y-deberes/conoce-tus-derechos/derecho-informacion
  2. Regulation EU 2016/679 (GDPR), Articles 6, 13, 17, 32 and 83, https://eur-lex.europa.eu/legal-content/ES/TXT/?uri=CELEX%3A32016R0679
  3. INCIBE, 2024, https://www.incibe.es/empresas/blog/utiliza-whatsapp-tu-empresa-cumpliendo-el-rgpd-y-lopdgdd
  4. Meta, 2026, https://developers.facebook.com/docs/whatsapp/pricing
  5. Meta, 2026, https://developers.facebook.com/documentation/business-messaging/whatsapp/messages/send-messages

Your WhatsApp AI replies in seconds, but do you know whether its first message complies with Art. 13 GDPR?

Free audit. Request it on WhatsApp now: the team reviews your case and replies in under 30 seconds.

Share this post
IconIconIconIcon

Explora nuestro blog

Descubre las últimas novedades

What an AI virtual employee on WhatsApp does — answer, quote and book 24/7 — and what it costs: from €249/month, live in 2-4 weeks.
11/6/2026
6
An internal WhatsApp bot answers procedure questions and speeds up employee onboarding 24/7. Real case study, deployed in under 4 weeks.
11/6/2026
5
A Madrid property manager with 100+ communities logs and routes resident incidents 24/7 on WhatsApp with AI. Here's how it went live in 4 weeks.
11/6/2026
5

Tu competencia ya está usando IA.
¿Y tú?

Solo una consultoría honesta para ver si Tubot encaja en tu empresa.

CONSULTORÍA GRATUITA
POR WHATSAPP
Te ayudamos a implementar IA en tu negocio y resolver tus dudas.
WhatsApp
Hablar ahora