Compliance · 4 min read
What a WhatsApp Business Inbox Actually Holds, and Where
Most privacy writing starts with the rules. This one starts a step earlier, with the inventory — because you cannot reason about an obligation until you know what you are holding, and most businesses on this channel have never looked.
The obligations side is a separate post: the DPDP framing is here. This one is about the data itself.
Four places a copy ends up
A single customer conversation generates records in more places than people expect.
- The phone in somebody's hand. If the business runs on a personal or shop device, the whole history is on it — and it goes home in a pocket, gets sold second-hand, and is unlocked by whoever knows the PIN.
- Meta's systems. The platform carries the message. What it retains and for how long is Meta's arrangement with you, documented by Meta, and not something a third-party vendor can describe accurately on their behalf.
- Any tool you connect. A platform vendor sitting between you and the API necessarily receives message content in order to do anything with it. That is not sinister — it is the mechanism — but it is a third party with a copy.
- Wherever you export to. The spreadsheet, the CRM, the accountant's email. This is the copy nobody tracks, and it is usually the least protected of the four.
The copy you forget about is the one on a laptop that leaves the company with somebody.
What one conversation actually contains
Worth being concrete, because "personal data" sounds abstract until it is listed.
A phone number, which in India is frequently linked to identity documents and payment rails. A display name and photo the person chose. The message text — which on this channel routinely includes an address, an order value, a health complaint, a photograph of a document, or a screenshot of a payment.
Then the metadata: when they wrote, how often, how quickly you replied. That last set is quiet and revealing — a pattern of 2am messages says something about a person that they did not intend to tell you.
The two failures that matter more than policy
In practice, most businesses that get this wrong do not fail on paperwork.
A shared login. One account, four people, and every one of them can read every customer conversation including the ones about money and health. There is no record of who read what, so there is nothing to investigate if something leaks. Named access per person is the single highest-value change most small teams can make, and it costs nothing but a decision.
Collecting what you did not need. Every field you capture is a field to secure, export on request, and delete on request. The cheapest way to handle a piece of data correctly is not to have it.
How the equivalent works on the channel we do run
PostEngage answers Instagram comments and DMs; there is no WhatsApp in the product. But the design decisions transfer, and they are the ones worth copying regardless of vendor.

A lead record holds what the person typed and which post they typed it under. It does not hold a guessed email, an inferred demographic, or a score nobody can explain — partly because those are not useful, and partly because each one would be another thing to secure, export and delete.
The mechanics that matter are unglamorous: a data request produces a downloadable export; erasure walks a fixed list of tables in a fixed order, and it is the same list that drives the export, so what you can download and what gets deleted cannot drift apart; staff access is by named account rather than a shared login; and administrative actions are written to an append-only record by the same guard that authorises them, so an endpoint cannot forget to log itself.
A one-hour audit
- List the devices with the business account signed in. Count them. This number is usually higher than the owner thinks.
- List the humans who can read a conversation, including the person who "just helps at the weekend".
- Open a week of threads and write down every category of thing customers sent you unprompted. This is the list you are actually holding.
- Find the exports. The spreadsheets, the forwarded screenshots, the WhatsApp Web session on a shared computer.
- Decide a retention period and write it down. Any number is better than "forever by default".
What no vendor can do for you
Decide why you have the data. Decide who inside your business may read it. Decide how long it stays. Take advice on what your specific obligations are — this is not legal advice and cannot be, because the answer depends on facts about your business.
What a vendor can do is give you the mechanics to act on those decisions, and refuse to collect things you did not ask for. Ask any of them for the export and the deletion before you have three years of conversation history inside them.
If you want the obligations framing, the DPDP post covers it. If you want the Instagram equivalent in detail, that is here.


