# WhatsApp reminders and the GDPR

Source: https://terminio.ai/en/ratgeber/whatsapp-appointment-reminders-gdpr · Updated: 2026-09-06

Why the private account is the problem, which legal basis holds, and what belongs in the message.

WhatsApp appointment reminders can be GDPR compliant if you get three things right: the channel the message goes out on, the legal basis, and the content. This article shows you where the private account on the shop phone breaks down, what the WhatsApp Business Platform changes, and what a compliant reminder looks like, with a template and a checklist. It is orientation for business owners, not legal advice.

## Why private WhatsApp on the shop phone is the problem

Most businesses start the same way: a phone by the till, a normal WhatsApp account, and every evening someone types out tomorrow's reminders. The message is not the problem. The app is. Private WhatsApp typically uploads the phone's entire address book to Meta, including customers who never asked for anything on WhatsApp.

On top of that, there is no data processing agreement for a private account. You hand customer data to a service provider without any contract that says what it may do with them. That is exactly what the GDPR requires as soon as someone processes personal data on your behalf. The free WhatsApp Business app only partly solves this, because it accesses the address book too.

Supervisory authorities have been critical of the address book issue for years, and in a dispute it is the first thing they check. So if you only ask whether an appointment reminder on WhatsApp is allowed, you miss the real issue: the channel, not the text. The good news is that the channel can be swapped with reasonable effort.

## What the WhatsApp Business Platform changes

The WhatsApp Business Platform, often just called the API, is the route built for companies. No app with an address book is involved. Your number is connected through an interface, and messages go only to people whose number you hand over deliberately, usually because they booked an appointment. Meta offers business terms for this route that do not exist for a private account.

In practice you use the platform through a provider that handles the connection. You sign a data processing agreement with that provider under Article 28 GDPR. Ask three things: where the data is stored, how long it is kept, and whether it is used for anything other than your reminders. terminio.ai sends reminders from your own number, with a DPA under Article 28 GDPR and hosting in the EU.

The reassuring part: the channel stays the same. Your customer sees a WhatsApp message from your business, and anyone who cannot make it simply replies in the chat. Only the plumbing is different. You do not have to explain to anyone that something has changed, and nobody has to install a new app or save a new number.

## Which legal basis an appointment reminder needs

Every use of customer data needs a reason the GDPR recognises. For a reminder the obvious one is close at hand: the customer booked an appointment, and the reminder is part of performing that contract. Many lawyers therefore place it under Article 6(1)(b) GDPR, processing necessary for a contract. As a rule that covers a plain reminder of date and time.

It is safer to collect consent at booking as well. One sentence is enough: I would like appointment reminders on WhatsApp to this number, with a box that is not pre-ticked. Record when and where the customer agreed. In health professions consent is the better route anyway, because the mere fact of an appointment can point to a treatment.

Without a legal basis there is no sending: promotions, discounts or birthday greetings on WhatsApp need their own explicit consent. The appointment reminder does not cover them. Mixing the two risks more than complaints. Customers block the channel, and then the reminder no longer gets through either. Keep the reminder cleanly separated from anything that is meant to sell.

## What belongs in a WhatsApp reminder, and what does not

A reminder needs very little: first name, date, time, the name of your business and a note on how to cancel. Nothing more. Anything beyond that adds risk without making the message work better. The reason: whatever is in the message then sits on the customer's phone, in their backup, with Meta and with your provider.

Health data is the delicate part, because the GDPR treats it as a special category. Even the service can be that kind of information, for instance physiotherapy, psychotherapy or dental work. In those cases write appointment, not treatment. Prices do not belong in a reminder either. They reveal what was booked and are not needed to remind anyone.

- No diagnoses, complaints or findings, not even in shorthand
- No treatment names that point to a health condition
- No prices or invoice amounts that give the service away
- No details about other customers, staff members or notes from the client file
- No links to forms that ask for further personal data

## WhatsApp reminder template: three lines are enough

A good template is short, friendly and sounds like you. It names the business so it is clear who is writing, and it tells people what to do if they cannot come. Name the service only if it is harmless, such as haircut or tyre change.

When you enter the template into a tool, it fills in name, date and time automatically. The third line doubles as your opt-out: anyone who no longer wants reminders says so in the same chat. Send the message to yourself once before it goes to customers, and read it as if you knew nothing about the appointment. If all you learn is when and where, it is right.

- Hi {first name}, this is {business}. Your appointment is on {date} at {time}.
- If you cannot make it, please let us know so we can free up the slot.
- Reply STOP if you no longer want reminders.

## Privacy notice, opt-out, deletion: the duties behind it

Your privacy notice needs a paragraph of its own: that you send appointment reminders on WhatsApp, through which provider, on which legal basis, which data is processed, that Meta is involved as the operator of the service, and how long you keep the data. Link to that same paragraph on the booking page, right next to the phone number field.

Opting out has to be as easy as opting in. A reply with STOP or a short sentence in the chat is enough, and from then on no reminder may go out. Record when someone objected. For storage the rule is simple: keep messages and numbers only as long as you need them. After the appointment, typically only the proof that a reminder was sent remains. Set a deadline, for example a few months after the last appointment, and delete.

## Checklist: setting up compliant WhatsApp appointment reminders

If you can tick off the points below, the typical mistakes are behind you. Go through them once with your provider and once with whoever maintains your privacy notice. When in doubt, ask a lawyer or a data protection officer, because this article does not replace advice.

- No private WhatsApp and no Business app with address book access for customer messages
- Sending through the WhatsApp Business Platform, with a data processing agreement under Article 28
- Legal basis settled: the appointment as a contract, plus consent at booking with a timestamp
- A paragraph in the privacy notice and a note next to the phone number field
- A message without health data, diagnoses or prices, with a cancellation and opt-out line
- Deletion deadline set, opt-outs recorded, storage location in the EU checked

## In short

- Allowed, but not from the private phone: WhatsApp appointment reminders are compatible with the GDPR when they run through the Business Platform with a data processing agreement and the message contains only what is needed.
- Three lines, zero health data: First name, date, time, business, cancellation note, opt-out. No diagnoses, no treatment names with a health link, no prices. Shorter usually works better anyway.
- Next step: consent at booking: Add a box that is not pre-ticked to your booking flow, add the paragraph to your privacy notice, and choose a provider with a DPA and hosting in the EU.

## Common questions

**Are appointment reminders on WhatsApp allowed at all?** Yes, if the channel is right. The reminder itself is usually part of performing the contract and therefore permitted. What matters is that you do not use a private account with address book access, but the Business Platform through a provider with a data processing agreement.

**Do I need consent if the appointment is already booked?** For a plain reminder of date and time, the appointment itself is usually enough as a legal basis. Consent at booking still makes you safer, especially in health professions. For promotions or offers you need it in every case.

**May I put the booked service in the reminder?** If it is harmless, yes: haircut, tyre change, nail extensions. As soon as the service points to a health condition, such as physiotherapy, psychotherapy or dental work, leave it out and write appointment only. Prices never belong in the message.

**What happens when a customer no longer wants reminders?** You stop them immediately and note the date. Opting out must be as easy as opting in, so a reply in the chat is enough. Good tools switch the number off automatically after a STOP reply, so nothing goes out by mistake.


---

terminio.ai is online appointment booking for small businesses with WhatsApp reminders and an AI phone assistant, from €0 a month, hosted in the EU. Provider: terminio.ai UG (haftungsbeschränkt), Großschönau, Saxony, Germany.
