ComplyChat Start free

Guide · Data protection

WhatsApp retention policy

Most organisations have a retention schedule, and most have work conversations on WhatsApp. The two rarely meet. The schedule assumes the organisation holds the data and can delete it on a date; WhatsApp keeps work messages on individual members' phones and in their personal backups, under timers any member may be able to change. This guide sets out what WhatsApp itself keeps, where the copies of a work chat actually are, what disappearing messages do and do not solve, and the handful of retention rules an organisation can still write and enforce for an app it does not control.

By ComplyChatPublished 13 minute read

A school business manager and a deputy head walk across an empty playground at the end of the day, one holding a phone at her side, low autumn sun behind the classroom block
01

What a retention policy has to do, and where WhatsApp sits in it

A retention policy answers one question for each kind of record the organisation holds: how long, and why. The rule behind it is the storage limitation principle in Article 5(1)(e) of the UK GDPR, and the ICO's storage limitation guidance puts it in five lines: "You must not keep personal data for longer than you need it." "You need to think about – and be able to justify – how long you keep personal data." "You need a policy setting standard retention periods wherever possible." "You should also periodically review the data you hold, and erase or anonymise it." "You must carefully consider any challenges to your retention of data." The Data (Use and Access) Act 2025 has amended the UK GDPR and the Data Protection Act 2018, and the ICO is still updating its guidance to match, so check the date on any ICO page you rely on.

Work messages on WhatsApp are inside that principle. When staff discuss pupils, residents, service users, volunteers or each other in a work group, the organisation is the controller of that personal data, even though the account and the phone belong to the member of staff. The ICO's right of access guidance says that where you have good reason to think staff hold a requester's information on their own devices, you "should ask them to search their private emails, devices or instant messaging applications, as appropriate". The guide to work messages on personal phones covers that responsibility in full; this one is about the clock.

Storage limitation is only half of it. The other half is the law that says certain things must be kept: a care provider's contemporaneous record of care and of decisions under Regulation 17, a school's child protection file, a charity's accounting records and trustee decisions, an employer's records for the limitation periods that follow a dispute. A retention policy for WhatsApp therefore has to do two opposite jobs at once. It must stop personal data building up without limit in chats nobody reviews, and it must stop the one message that is a record from disappearing before it reaches the place the law expects to find it.

The honest starting point is that WhatsApp has no organisational retention setting to configure. What the organisation can write is a set of rules for people: what goes into a work chat, what leaves it and when, which settings the chat uses, what happens when a request or a dispute arrives, and what happens when someone leaves. Retention policies for other systems are settings; this one is a set of rules for people, and those rules are the WhatsApp retention policy.

02

What WhatsApp keeps, and where the copies of a work chat really are

WhatsApp's own retention is short, and it is about WhatsApp's servers rather than your records. Its privacy policy for UK users, where the service is provided by WhatsApp LLC, says: "Typically your messages are stored on your device(s) and not on our servers. We temporarily store your messages in encrypted form while they are being delivered. Once your messages are delivered, they are deleted from our servers." Undelivered messages are kept in encrypted form "for up to 30 days" and then deleted, and media sent in a message is stored "for up to 30 days in encrypted form" to make delivery more efficient, for example when recipients forward it. There is no copy held centrally for anyone to retrieve, which is the point of end-to-end encryption and the reason WhatsApp cannot be asked for one.

So the copies of a work chat are wherever its members have put them:

  • Each member's phone. A group of twelve is twelve copies, each deleted, cleared or lost on its own timetable. A member who joined late does not have the earlier messages; a member who cleared the chat has none.
  • Linked devices. WhatsApp on a laptop or a web browser holds another copy, sometimes on a shared or family computer.
  • Personal cloud backups. WhatsApp backs up to the member's own Google Drive or iCloud account. WhatsApp describes its end-to-end encrypted backup as "an extra, optional layer of security"; when it is on, "Neither WhatsApp nor your backup service provider will be able to read your backups". Either way the backup belongs to the member, in an account the organisation has no access to, restored or deleted at the member's choice.
  • Copies taken out of the chat. Screenshots, exported threads emailed to someone, photographs saved to a camera roll, messages forwarded to other chats. Each is a further copy with its own life.
  • Kept messages. In a chat with disappearing messages on, a message someone has kept stays after the timer, as described below.

A retention policy normally names a system and a period. For WhatsApp the system is a set of personal devices and personal accounts, and the period is whatever each of them happens to do. Nothing in that list of WhatsApp communications is held by the organisation, and nothing in it can be deleted by the organisation, which is the fact every rule below has to be built around.

03

Disappearing messages: the setting that looks like a retention policy

Disappearing messages are the nearest thing WhatsApp has to a retention period, and they are often proposed as the answer. WhatsApp offers three timers, "24 hours and 90 days, as well as the existing option of 7 days". A default message timer in a user's privacy settings makes "all new one-on-one chats you or another person start" disappear at the chosen duration; it "does not change or delete any of your existing chats". In groups, any member can turn the timer on or off by default, but an admin can restrict the setting so that only admins can change it.

Two features weaken the timer as a retention control. Anyone can keep a copy before it runs out, by screenshot, export or forward. And WhatsApp's Keep in Chat lets a recipient keep an individual message, although "the sender will be notified when someone keeps a message, and the sender will have the ability to veto the decision"; if the sender decides a message cannot be kept, "no one else can keep it and the message will be deleted when the timer expires". In practice the timer limits the build-up of messages on phones. It does not guarantee that a message is gone, and it does not guarantee that one is kept.

The public sector has already written the rule that follows. The Cabinet Office's guidance on non-corporate communication channels says: "'Disappearing message' functions have a role in limiting the build up of messages on devices. You must ensure that any such use does not impact on your recordkeeping or transparency responsibilities." That is the right balance for any organisation. A timer is a sensible default for a chat that carries logistics, a rota swap or a lift to a training day, because it meets storage limitation for data nobody needs. It is the wrong setting for a chat in which decisions are taken, concerns are raised or people are discussed, unless everything significant has been moved out first; otherwise the timer is deleting records on a schedule nobody chose on purpose.

The timer becomes dangerous once a request or a dispute exists. The ICO's right of access guidance accepts that routine use may amend or delete information while a request is dealt with, but adds that "it's not acceptable to amend or delete the information if you would not otherwise have done so." Section 173 of the Data Protection Act 2018 makes it an offence for the controller, its staff or anyone under its direction "to alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure" of information a requester would have been entitled to receive. For public authorities, which include maintained schools and academies, section 77 of the Freedom of Information Act 2000 does the same for information requests. Switching a timer on, or shortening it, after a request arrives is exactly what the ICO says is not acceptable, and if it is done to prevent disclosure, it is the act the law makes an offence.

04

What a WhatsApp retention policy should say

Written for an app the organisation does not control, the policy is short and every clause is an instruction to a person. A workable version has seven parts.

  1. WhatsApp is not a system of record. Say so. The retention schedule's periods apply to the record, which lives in the care system, the child protection file, the HR file, the minutes or the case management system, not to the chat that preceded it.
  2. What may be said there at all. The line most organisations can hold is logistics in a group chat, named people elsewhere. The staff messaging policy guide covers how to draw it; the retention policy only needs to refer to it.
  3. A transfer rule. Significant messages are copied into the system of record the same working day by the person who received them, on the triggers the guide to work messages on personal phones sets out; the transferred copy then takes the retention period of the record it joins.
  4. Timer settings, by chat. Name the timer for logistics chats, require admins to restrict who can change it, and say that chats which carry decisions either have no timer or have everything significant moved out before it runs.
  5. A hold. When a subject access request, a freedom of information request, a complaint, a grievance, a disciplinary, a safeguarding referral or a claim arrives, the named person tells the members of any relevant chat to switch timers off, not to delete or clear it, and to export it if asked. The hold is lifted in writing.
  6. Leavers. Before the last day, the leaver reviews their work chats, transfers anything significant, hands over any group they administer, and is removed from work groups. The Cabinet Office asks officials for "a final review before you change device or leave your post", and the same step suits a school, a charity or a care service. The organisation can ask a leaver to delete work chats from the phone and from backups; it cannot verify that they have, and the policy should say so rather than pretend.
  7. Review. Once a year, with the rest of the retention schedule, and after any request or incident that showed a gap. Record that the review happened.

In the record retention schedule itself, WhatsApp should appear as a row rather than be left out. Type of data: work messages in WhatsApp chats. Where held: members' phones, linked devices and personal backups. Retention period: not controlled by the organisation; significant content transferred the same working day; logistics chats on the named timer. Justification: storage limitation, with transfer to meet the records duties. Disposal: by members, unverifiable. A row that reads like that is uncomfortable to sign off, which is its value: it states the position accurately, and it is what the ICO or a trustee would find if they asked.

A care worker in a tabard hands her lanyard and a folder across the reception desk of a care home on her last day, the manager taking them, seen from the corridor
05

What the organisation cannot retain, and what that means

The general point, that a retention schedule governs only what the organisation can reach, is made in the data retention policy guide. For WhatsApp it comes down to three gaps, and a policy is more credible when it names them.

  • No administrator export. The organisation's copy of a work chat is whatever a member exports or screenshots from their own phone when asked, and a member who joined late or cleared the chat cannot supply the whole thread.
  • Backups outside reach. Each member's backup sits in their own Google Drive or iCloud account, so the organisation can neither delete it at the end of a period nor show that it has gone, least of all once a leaver has left.
  • Timers set by members. Unless an admin has restricted the setting, any member of a group can switch disappearing messages on or off, so the chat's retention period is whatever its members last chose.

The WhatsApp Business app does not change any of this for staff talking to each other: it is still an account on one handset. The Business Platform is built for customer messaging rather than internal conversation, as the guide to WhatsApp and GDPR at work explains, and a setting such as advanced chat privacy, covered in the subject access guide, can stop members exporting a chat at all. Products sold as reading personal WhatsApp accounts for an employer should be treated with suspicion; the end-to-end encryption that protects the messages is also what keeps an organisation out of them.

The consequence is not that staff may never use WhatsApp. It is that the organisation's retention policy can govern WhatsApp only at the edges, by keeping significant content out of it or moving it out quickly.

06

The retention period nobody chose

The retention schedule is reviewed every year, and it is careful: six years for this, three for that, a trigger and a justification on every row. Then, on a Thursday evening, the deputy manager posts in the team's WhatsApp group that a resident's daughter has complained again about her mother's medication, and the manager replies that she will ring her in the morning and that nobody should discuss it with the family in the meantime. That exchange is a complaint received and a decision taken, and it is the first line of a record the provider must keep. It will be held for as long as eleven phones and their backups hold it, which may be seven days if someone set a timer, or until the deputy's contract ends.

Three months later the daughter makes a subject access request and a formal complaint. The manager remembers the exchange; the transfer rule was never followed that evening, because it was nine o'clock and the next morning was busy. One member of staff finds it on her phone and sends a screenshot. Whether the provider acted promptly is now a question answered from a single image of a chat it did not hold, under a retention period set by whoever last touched the settings.

The fix is not a longer WhatsApp policy. It is to have the conversations that are records happen somewhere the retention schedule can reach. ComplyChat gives those work conversations a channel the organisation owns: messages are recorded on the server as they are sent, everyone added is told the channel is on the record and can object or leave, and a mobile number verified by SMS is enough to join, so bank staff, volunteers and others with no work account can be in it. On paid plans, once the organisation's Microsoft 365 tenant is connected, the lasting record files there under the organisation's own retention rules, so the retention schedule has a row it can apply. It does not reach into WhatsApp, it cannot recover conversations that have already happened there, and it is not a care record, a child protection file or a set of minutes. ComplyChat Free is personal messaging with one private group, direct messages and three calendar months of recent history, with no Microsoft 365 archive, and it does not meet a retention duty.

A question for the next leadership or trustees' meeting: for the last significant decision taken in a message, who set the retention period of that conversation, and could the organisation tell a requester or an inspector what it is?

07

Official guidance and your next step

The primary sources are the ICO's guidance on storage limitation and on finding and retrieving information for a subject access request, the Cabinet Office's guidance on non-corporate communication channels, which is the most complete published model of retention rules for WhatsApp at work, and section 173 of the Data Protection Act 2018. WhatsApp publishes its own privacy policy, help pages and blog announcements on disappearing messages, kept messages and backups; the quotations here are from its UK privacy policy (effective 2 July 2026) and from announcements made between 2021 and 2023, and the features change, so check the current versions.

This guide is a summary for UK organisations, not legal advice. Whether a particular chat is within scope of a request, and what to do with a leaver's messages in a live dispute, depends on the facts; take advice on either.

Then do one thing: list every WhatsApp group your staff, volunteers or trustees use for work, and for each one write down who administers it, whether a timer is on, and where its significant messages are supposed to go. The groups with no answer to the third question are the ones your retention schedule does not reach.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. A retention policy is only as good as its reach, and WhatsApp is where most organisations' reach stops: the records are there, and the organisation can neither keep nor delete them. ComplyChat gives those conversations a channel the organisation owns; explore Free personal messaging, or compare the paid plans if you need the lasting record in your own Microsoft 365.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Storage limitation guidance ico.org.uk
  2. Guidance on non-corporate communication channels gov.uk
  3. Right of access guidance ico.org.uk
  4. Section 173 of the Data Protection Act 2018 legislation.gov.uk
  5. Section 77 of the Freedom of Information Act 2000 legislation.gov.uk