ComplyChat Start free

Guide · Work messaging

WhatsApp group admin responsibilities

A WhatsApp group admin is responsible for who is in the group, what the group allows and what is removed from it: WhatsApp’s help centre gives admins the power to add and remove members, appoint other admins, decide who can post and delete any member’s message for everyone within two days, and when the group runs a school’s, charity’s or care provider’s work, the organisation is answerable under UK GDPR for how those powers are used.

By ComplyChatPublished 16 minute read

A tree-planting charity’s volunteer lead and her new co-organiser gather spades and spare tree guards on a misty hillside field at the end of a planting morning, rows of new saplings behind them

UK law has no set of duties written for WhatsApp group admins as such. What an admin answers for comes from two places: the tools WhatsApp provides, and the duties of the organisation the group serves. This guide sets out both, for the person who holds the admin controls of a staff, volunteer, rota or parent group and for the leaders who are answerable for it.

01

The rule: an admin of a work group acts for the organisation

A WhatsApp group admin of a work group exercises WhatsApp’s admin tools on behalf of the organisation the group serves, and under UK GDPR that organisation, as controller, is responsible for how members’ personal data is handled. WhatsApp’s help centre describes the tools. Its article How to change group admin settings says “Group admins can change settings to allow either only admins or all members to edit group info, send messages, or add people to a group.” Its article How to delete messages says “Group admins can delete messages sent by another group member.” And How to manage group admins says “A group can have an unlimited number of admins, and any admin can make a member an admin.” None of those pages says whom an admin represents. That is decided off the app.

When a school, charity or care provider sets up a group to run its work, it decides why and how the members’ personal data is used, starting with their phone numbers. The ICO’s guidance What are ‘controllers’ and ‘processors’? quotes the UK GDPR definition – a controller is the body which “determines the purposes and means of the processing of personal data” – and says “If you are a controller, you are responsible for complying with the UK GDPR”. The same guidance says “Employees of the controller are not processors. As long as they are acting within the scope of their duties as an employee, they are acting as an agent of the controller itself.” A deputy manager who runs the night-shift group, or a teacher who runs the trip group, holds the admin controls as the organisation’s agent. A volunteer coordinator running a charity’s rota group is doing the charity’s processing in the same way, which is why the charity, not the coordinator, carries the duties.

The exception is a group with no connection to work. The ICO’s guide to the data protection exemptions puts personal data processed “in the course of a purely personal or household activity, with no connection to a professional or commercial activity” outside the UK GDPR. A colleagues’ social group that begins to carry rota changes, or to name pupils, residents or service users, is unlikely to stay within that exemption, whoever set it up. The Data (Use and Access) Act 2025 is amending UK GDPR in stages, so check the date on any ICO page you rely on.

02

What a WhatsApp admin can and cannot do

WhatsApp’s help centre gives a group admin these powers, in its own words where the wording matters:

  • Membership. “Group admins can add or remove members from their group”, and groups “can have up to 1024 members”, according to How to add and remove group members. With Approve new members turned on, “admins must approve anyone who wants to join the group.”
  • Other admins. Any admin can make a member an admin or dismiss one, with no limit on numbers, but “The creator of a group can't be removed and will remain an admin unless they exit the group.”
  • Permissions. Admins choose whether all members or only admins can edit the group’s name, icon and description, send messages, add members and invite by link. “If a group was started with fewer than 33 members”, every member can add others, send messages and change the group information until an admin restricts it.
  • Message history. A member adding someone “may have the option to send message history” – “up to 100 messages from the last 14 days” – and admins can turn Send message history off, so that members “won’t see the option”.
  • Moderation. Admins can delete another member’s message for everyone, and “Group admins have two days after someone else sends a message to request to Delete for everyone”. The message is replaced with “This message was deleted by admin [admin name].” With Send for admin review turned on, members can refer a message to the admins, who “have about two days before review requests expire”.
  • Restricted chat. According to About restricted chat, “In group chats, group admins can enable restricted chat”, which stops members exporting the chat, saving its media automatically, using Meta AI features in it or using linked devices for it. It is replacing the earlier Advanced Chat Privacy setting.
  • Closing the group. An admin “can delete a group for all members”, but only after removing every member.

The same pages set the limits, and they matter more than the powers:

  • No access to members’ other chats. WhatsApp’s About end-to-end encryption says “No one outside of the chat, not even WhatsApp, can read, listen to, or share them.” An admin sees the group conversation as any member does, not the one-to-one messages members send each other.
  • No reach into members’ phones. How to exit and delete groups as an admin says “Removing a member or deleting a group won't delete the group on other members’ devices.” Deleting for everyone is not guaranteed either: “Recipients might see your message before it's deleted or if deletion wasn’t successful”, and iPhone recipients “might still have media you sent saved to their Photos”.
  • No undo. “Messages deleted by a group admin are not recoverable and can't be appealed.”
  • No referee. “WhatsApp can’t interfere with group administration functions. For example, we can't make someone an admin, even if they were previously an admin and removed by another admin.”
  • No choice of successor by default. “If you’re the only group admin and leave the group, another member will be chosen at random to become the new admin.”

Read together, those limits describe the admin’s position exactly: wide control over the group as it appears on screen, and no control over the copies of it that sit on every member’s phone.

03

Data protection: who is in the group and what it holds

Most of what an admin does is a data protection decision, even when it feels like housekeeping. UK GDPR Article 5(1)(c) requires personal data to be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed” (UK GDPR Article 5), and Article 5(2) makes the controller “responsible for, and be able to demonstrate compliance with” the principles. For a group admin that comes down to five habits:

  1. Ask before adding. Adding someone shares their number with the group: WhatsApp’s How to change your privacy settings says “At this time, it’s not possible to hide group member’s phone numbers in a group.” Even after they leave, WhatsApp shows a removed member’s “profile name and phone number” in the Past members list, and “Group members can see this information in that list for up to 60 days after a member leaves the group.” Say at induction that joining is optional, and give anyone who declines another route to the same information.
  2. Switch off message history for members in any group where people, cases or colleagues are ever discussed. Sending a newcomer up to 100 messages from the last 14 days discloses whatever those messages say about a pupil, a resident or a colleague’s sickness to someone who was not there. Leave the decision with an admin.
  3. Remove leavers on the day they leave. Removal stops new messages reaching them; it does not take back what is already on their phone, so the group’s content should never have been more than a leaver could keep.
  4. Restrict who can add members and change settings, so that the membership the organisation answers for is the membership the admin chose.
  5. Treat a misdirected message as a possible breach. A message about a service user posted to the wrong group, or a screenshot forwarded outside it, is a security incident involving personal data. Tell the person who handles data protection the same day: UK GDPR Article 33(5) requires the organisation to document every personal data breach, and Article 33(1) to report one to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of it unless it is unlikely to result in a risk to people’s rights and freedoms. The school data breach guide works through that test.

The admin also cannot answer a subject access request alone. A request from a member, a parent or a former colleague reaches the work messages about them in the group, wherever they are held, and the organisation has to search for them on the phones of the people who were in it. The guide to subject access requests and WhatsApp messages explains what must be disclosed.

04

Safeguarding and conduct: when something is posted that should not be

The admin is often the first person with authority to see a message that should not be in the group: a worry about a child, a remark about a resident’s bruising, a photograph that identifies someone, an unkind message about a colleague. The admin’s job at that moment is to move the matter to the right route and keep a note, not to manage it in the group. In order:

  1. Do not discuss it in the group. A safeguarding concern goes to the designated safeguarding lead in a school, the safeguarding lead in a charity, or the manager named in a care provider’s safeguarding procedure, straight away and by the route that procedure names. If a child or adult is in immediate danger, call 999.
  2. Tell the lead before deleting. An admin’s deletion is permanent and cannot be appealed, so the lead needs to know what was posted, by whom and when before it disappears, and decides what is kept and where. Do not screenshot it and pass it round. WhatsApp’s own help centre makes the same point about preservation in another context: if you have experienced a scam or fraud, “you may want to choose Exit group instead to keep your messages as evidence for reporting to local authorities”.
  3. Then remove it, within two days, unless the lead says otherwise. Once the lead has what they need, delete harmful or identifying content for everyone and remind members to delete any copy they saved.
  4. Remove a member if necessary. Removal stops new messages reaching them. If you also report the group to WhatsApp, “the last five messages in the chat are sent to WhatsApp”; that is WhatsApp’s process, not the organisation’s, and it does not replace the organisation’s own report.
  5. Write down what you did, when and whom you told.

One kind of content reverses that order. If a nude or semi-nude image of anyone under 18 appears in a group, the UKCIS advice for education settings, summarised in Sharing nudes and semi-nudes: how to respond to an incident, says to report it to the designated safeguarding lead or equivalent “immediately”, to “Never view, copy, print, share, store or save the imagery yourself” because “this is illegal”, and “Do not delete the imagery or ask the young person to delete it.” Where an adult has shared such an image, the same page says it “is a form of child sexual abuse and must be referred to the police as a matter of urgency”. In that case the admin deletes nothing and leaves every decision to the safeguarding lead.

Conduct in a work group is conduct at work. The organisation’s code of conduct, its anti-bullying rules and its disciplinary procedure apply to what staff post there, and the admin is not the investigator: their part is to stop the harm continuing and pass the matter on. If a message later becomes evidence, the guide to WhatsApp messages in a disciplinary hearing covers a fair process.

WhatsApp’s own advice for admins of its Communities feature, Being a great Community admin, points the same way. It tells admins “You are responsible for establishing the rules for your community”, to “Act swiftly when you notice inappropriate content or members”, to “Lead by example and communicate with empathy and respect” and to “Share the workload with your team to avoid becoming overwhelmed”, and suggests they let members “know when you will be online to manage their expectations.” In a work group those rules – what the group is for, what never goes in it, where concerns go, and when nobody is expected to reply – are the organisation’s rules, so agree them with whoever owns the policy rather than writing them alone.

Groups that include young people need a decision before anyone is added. WhatsApp’s UK Terms of Service say “You must be at least 13 years old to use our Services”, with parent-managed accounts for younger children where available. Adding a young volunteer or a pupil to a group of adults on personal phones is a safeguarding decision for the safeguarding lead, not an admin’s call.

In a care home’s small hair salon, the deputy manager and the activities coordinator talk in the doorway while the visiting hairdresser sets an older resident’s hair in rollers
05

What the admin should keep a note of, and the handover

WhatsApp keeps no administrative record that the organisation can rely on. Its member-changes view shows “updates from the last 60 days” (How to see group members), and the conversation itself lives on members’ phones. So the admin keeps a short note, outside the app, in the organisation’s own system:

  • the group’s purpose and its pinned rules, with the date they were agreed;
  • the admins, by role rather than by name alone, and the creator;
  • the settings chosen: who can post, add members, edit the group and send message history, and whether new members need approval;
  • membership changes with dates, checked against the staff or volunteer list every few months;
  • every deletion or removal an admin makes, with the reason and who was told;
  • every concern passed on, to whom and when.

The handover is where most groups fail. Because the creator “can't be removed and will remain an admin unless they exit the group”, a group set up on a former colleague’s personal phone keeps them in control until they choose to leave, and WhatsApp will not intervene. Appoint at least two admins in organisational roles, such as the manager and a deputy, or the coordinator and a named trustee. Make admin handover part of the leaving checklist, and ask a departing creator to exit. Where that is not possible, start a new group under the organisation’s control.

Closing a group does not close the record. Deleting the group after removing everyone removes it from the admin’s phone and stops new messages, but every former member keeps “all previous content unless they delete it themselves”. Decide in the organisation’s retention policy what should have been moved out of the group before it closes.

06

The admin holds the controls, not the record

An admin can do a great deal to the group as it appears on screen, and almost nothing to the record of it. Consider an ordinary week. On Sunday evening a senior carer posts in the shift group that a resident seemed frightened of a visitor. On Tuesday a teaching assistant names a pupil in the trip group and the admin, rightly, deletes the message for everyone. On Thursday a volunteer coordinator agrees in the rota group that the charity will pay for a course, and the trustee who approved it replies with a thumbs-up.

Each of those is a record of something the organisation is responsible for: a safeguarding concern, a personal data incident and the admin’s response to it, a spending decision. None of them is held anywhere the organisation controls. The concern sits on the phones of the people in the group. The deleted message is gone from the chat, and “Messages deleted by a group admin are not recoverable”, so unless someone noted it, the organisation’s only account of what was removed, and why, is the admin’s memory. The spending decision is a thumbs-up in an app the charity does not run. WhatsApp’s end-to-end encryption, which protects those messages from outsiders, also means the organisation cannot retrieve them from WhatsApp. If the only admin leaves, the controls pass to a member chosen at random, and the memory goes with the admin.

None of that is the admin’s fault, and good admin practice reduces it. It cannot remove it, because the admin controls a group whose history the organisation does not hold. The question for the next leadership or trustee meeting is a simple one: who are the admins of every group our staff and volunteers use for work, and if one of them deleted a message tonight, where would the organisation’s record of it be?

07

Questions people ask

What are the powers of a group admin in WhatsApp?

A WhatsApp group admin can add and remove members, approve join requests, make or dismiss other admins, choose whether only admins can post, edit the group or add people, control whether members can send message history to newcomers, and delete any member’s message for everyone within two days. An admin cannot read members’ private chats, cannot remove the group’s creator, and cannot delete the group from other members’ phones.

Can admin delete any message in a WhatsApp group?

Yes, within a time limit: WhatsApp’s help centre says “Group admins have two days after someone else sends a message to request to Delete for everyone”, and the message is replaced with “This message was deleted by admin [admin name].” Deletion is not guaranteed – recipients may already have seen it, and iPhone users may keep media saved to Photos – and “Messages deleted by a group admin are not recoverable and can't be appealed.”

Can you kick an admin out of a WhatsApp group chat?

Any admin can dismiss another admin or remove them from the group, with one exception: “The creator of a group can't be removed and will remain an admin unless they exit the group.” WhatsApp says it “can’t interfere with group administration functions”, so a dispute between admins has to be settled by the people in it, or by the organisation the group serves.

What can a WhatsApp admin see?

A WhatsApp admin sees the group conversation as any member does, the member list, past members for up to 60 days, and any messages members send for admin review. WhatsApp’s end-to-end encryption means an admin cannot see members’ one-to-one chats or other groups; WhatsApp says no one outside a chat, “not even WhatsApp”, can read it.

Does clearing a WhatsApp group chat clear it for everyone?

No. WhatsApp’s help centre says deleting messages for yourself “has no impact on your recipients' chats”, and that removing members or deleting a group “won't delete the group on other members’ devices”. Only Delete for everyone, used on individual messages within the two-day limit, removes a message from other members’ screens.

08

Where to read the official guidance, and your next step

WhatsApp’s help centre is the authority on what the admin tools do: start with How to change group admin settings, How to manage group admins and How to delete messages, and check them again before relying on a detail, because features change. For the organisation’s duties, the ICO’s guidance on controllers and processors is the place to begin, alongside your own safeguarding procedure and code of conduct. Quotations are from those pages as read on 3 October 2026.

This guide is practical guidance, not legal advice. Where a group already holds a safeguarding concern, a complaint or a disciplinary matter, ask your safeguarding lead or data protection lead before deleting or changing anything.

Then do one thing: list every WhatsApp group used for your organisation’s work, with its creator, its admins and its purpose. Any group whose creator has left, or whose only admin is not in an organisational role, is the first to fix.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. An admin can manage a WhatsApp group but cannot give the organisation a record of it, because the history lives on members’ phones. ComplyChat replaces the work group with channels the organisation owns, where everyone is told the channel is on the record; on paid plans the lasting record files into the organisation’s own Microsoft 365 once its tenant is connected. Free is personal messaging with three calendar months of recent history and no archive, so it is not a way to meet a retention duty.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. How to change group admin settings faq.whatsapp.com
  2. How to delete messages faq.whatsapp.com
  3. How to manage group admins faq.whatsapp.com
  4. What are ‘controllers’ and ‘processors’? ico.org.uk
  5. Guide to the data protection exemptions ico.org.uk
  6. How to add and remove group members faq.whatsapp.com
  7. Send for admin review faq.whatsapp.com
  8. About restricted chat faq.whatsapp.com
  9. About end-to-end encryption faq.whatsapp.com
  10. How to exit and delete groups as an admin faq.whatsapp.com
  11. UK GDPR Article 5 legislation.gov.uk
  12. How to change your privacy settings faq.whatsapp.com
  13. Sharing nudes and semi-nudes: how to respond to an incident gov.uk
  14. Being a great Community admin whatsapp.com
  15. UK Terms of Service whatsapp.com
  16. How to see group members faq.whatsapp.com