POPIA and WhatsApp Customer Conversations
By Masego · 2026-07-12
Processing personal information in chat requires purpose, security, and retention discipline — not fear of the channel. Decide from policy and audit data.
01 · The channel is not exempt
POPIA applies to WhatsApp conversations because phone numbers, message content, and uploaded documents are personal information. The channel is not exempt because it feels informal.
“Informal feels do not create legal exceptions.”
1
lawful basis documented before scale
min
fields only — purpose limitation
schedule
retention: delete or anonymise when purpose ends
02 · Technical and process measures
Operators need a lawful basis (typically consent or legitimate interest documented in a PAIA/POPIA policy), purpose limitation (collect only what the flow needs), and retention schedules.
- 01Access control on the inbox
- 02Encrypted transit (WhatsApp end-to-end plus TLS on platform APIs)
- 03Audit trails for agent actions
- 04Train staff not to export chats to personal devices
03 · Notice citizens can actually read
Citizens should see clear notice at opt-in: who processes data, why, and how to exercise rights.
- One-line privacy link in the welcome message = minimum
- Recorded consent step = better for sensitive programmes
- Retention reviews on a calendar, not a wish
“Compliance is an operating rhythm — measured in audits completed, not policies filed.”
See how organisations deploy these patterns on WhatsApp — people first, systems second.