Click-to-WhatsApp Ads GDPR-Compliant 2026: Data Chain, DPA, Cookie Banner
SendSeven Team, Editorial Team
Click-to-WhatsApp Ads are not inherently risky — but the data chain to Meta, the pre-click notice, and the opt-in after the 72-hour Free Entry Point need to be documented properly. A practical compliance checklist for the EU and UK.
TL;DR
Click-to-WhatsApp Ads (CTWA) can be run fully GDPR / UK GDPR compliant — but only if four pieces are in place: (1) a Data Processing Agreement with the platform and with Meta, (2) a privacy notice that explicitly references CTWA and the Meta data flow, (3) a pre-click notice in the ad itself, and (4) a documented opt-in for marketing templates after the 72-hour Free Entry Point closes. Skipping any of these creates risk of complaints and fines from data protection authorities. This article gives the practical checklist — without being legal advice.
Note: this article is professional orientation, not legal advice. For specific cases — especially with special categories of data or high penalty exposure — consult your data protection officer or a privacy lawyer.
This GDPR spoke deepens section 8 (GDPR) of the complete CTWA & wa.me guide. If you need to translate pre-click notices, DPA clauses, and cookie banner logic into actual CTWA practice in the EU or UK, this is the right place.
Why CTWA is GDPR-relevant
At first glance a Click-to-WhatsApp ad looks harmless: the user clicks voluntarily, writes the first message, and it all feels like an ordinary phone call. In reality, every click creates a short but regulatorily relevant data chain — and several pieces of that chain run through Meta servers in the United States.
Three points make the difference:
- Targeting through Meta: the user who sees the ad was selected through Meta profiling. That is processing of personal data under GDPR / UK GDPR — before the user ever taps.
- Click handover: on tap, an identifier tied to the ad is passed to WhatsApp. That is also personal, because it links a specific person to a specific ad interaction.
- Storage in the inbox: the conversation lands in your platform and your CRM. From there, your own responsibility as a controller under Art. 4 GDPR begins.
Good news: these data flows are not forbidden. They do, however, need to be made transparent and contractually backed.
The data chain — four stations
From the ad click to the stored conversation, data passes through four stations with different legal roles:
The advertiser's role (yours) is joint controller with Meta for ad delivery (station 1) — confirmed by CJEU case law on Facebook fan pages and custom audiences. From station 3 onward, you are sole controller, with the platform and Meta acting as processors.
Data Processing Agreement (DPA)
Two DPAs need to be signed before the first CTWA ad goes live:
- DPA with the WhatsApp platform (e.g. SendSeven). A standard contract with reputable vendors, usually available directly in-account or via sales. SendSeven provides the DPA as a standard package per Art. 28 GDPR with EU hosting and Standard Contractual Clauses (SCCs) for data transfers.
- DPA with Meta (Meta Platforms Ireland Limited). Concluded automatically through the Meta Data Processing Terms as soon as you use Custom Audiences or the Conversions API.
Things to check during DPA review:
- EU hosting of the primary data stores (conversations, contacts) at the platform
- Standard Contractual Clauses (SCCs) for every third-country transfer to the US
- Clear list of sub-processors with countries and purposes
- Right to audit (at minimum via documented compliance reports such as ISO 27001 or SOC 2)
- Deletion and return procedures at end of contract
Privacy notice
Your website's privacy notice needs to reflect CTWA in three places:
- A dedicated "WhatsApp communication" section covering the platform vendor, EU hosting, retention, and legal basis (Art. 6(1)(b) or (f) GDPR, depending on the use case).
- A reference to Meta as joint controller for ad delivery. Link out to the Meta Joint Controller Addendum.
- A third-country transfer block that names the US explicitly, the SCCs as transfer safeguard, and any supplementary measures (encryption, pseudonymization).
Template for the CTWA-specific paragraph:
Sample clause: "WhatsApp via click-to-chat ad"
When you tap one of our WhatsApp ads or use our wa.me links, a WhatsApp chat opens with our company. WhatsApp is operated by Meta Platforms Ireland Limited (Ireland). The content and metadata of your messages are transferred to Meta and processed in the EU. We use the platform [name] to manage these conversations, EU-hosted, with a Data Processing Agreement in place. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or (f) (legitimate interest in efficient customer communication). You can object to processing at any time.
Background on the broader topic in the main article: GDPR-compliant business messaging — the complete guide and the glossary entry GDPR-compliant messaging.
Pre-click notice
The pre-click notice is the piece most commonly forgotten — and the one that triggers complaints. It informs the user before the click about the data flow about to happen, to Meta and to your platform.
Three placement options, ranked by robustness:
- Directly in the ad copy (concise, with a link to the privacy notice). Best option — captures attention in the first second.
- On the page description of the Facebook or Instagram page the ad runs from. Acceptable fallback.
- Inside the pre-filled first message as a reference. Weakest option — the notice arrives after the click.
Example of a tight ad-copy clause:
Tapping opens WhatsApp. Meta's privacy policy and ours apply. More: [link to your privacy notice].
Cookie banner and consent
CTWA targeting uses Meta cookies (pixel, custom-audience tags). That brings the cookie banner into play before the CTWA click — at the point of ad delivery on third-party sites or pixel tracking on your own site.
In practical terms:
- If you use the pixel or custom audiences, you need a consent banner with explicit opt-in for marketing cookies. Implicit opt-in or "continued use counts as consent" is not sufficient under the CJEU's Planet49 ruling and equivalent UK ICO guidance.
- If you only run on ad clicks without pixel ("CTWA only", no Conversions API on your own site), you can minimize cookie banner work — though in practice it is rarely worth it, because optimization suffers without the Conversions API.
- Server-side Conversions API (CAPI) does not need a separate cookie consent if it is based on data the user has already provided with a legal basis (e.g. an email address at checkout). Browser-triggered CAPI dispatches do.
Opt-in after the 72-hour Free Entry Point
Inside the 72-hour Free Entry Point, outgoing messages are free and low-risk legally — the user actively started the conversation. After 72 hours, every proactive message (marketing template) counts as advertising under EU and UK e-privacy rules and needs explicit consent.
Best practice: capture the opt-in inside the first conversation — clearly separated from the actual matter at hand, with active confirmation through a quick reply or written response.
Example bot wording:
Would you like to receive future offers, appointment reminders, or product news through WhatsApp? Reply YES to subscribe — you can unsubscribe any time with STOP.
This consent must be documented: timestamp, the bot question sent, the YES reply received, hashed phone number. SendSeven stores this automatically in the contact profile. More practical detail in the glossary entry on double opt-in.
CTWA GDPR-compliant with SendSeven
EU hosting, DPA included, documented opt-ins, Conversions API ready. Made in Germany.
Compliance checklist
Before going live with the first CTWA campaign, all 9 boxes should be ticked:
- □ DPA with WhatsApp platform signed (e.g. SendSeven)
- □ DPA with Meta active (Data Processing Terms)
- □ Privacy notice updated with WhatsApp section + Meta joint-controller reference
- □ Third-country transfer clause with US reference and SCCs added
- □ Pre-click notice placed in ad copy or page description
- □ Cookie banner with marketing-consent option, pixel disabled on rejection
- □ Opt-in bot flow for marketing templates after the Free Entry Point
- □ Opt-in documentation automated (timestamp, bot question, YES reply)
- □ Deletion process for STOP messages and revocations defined
Common GDPR mistakes with CTWA
- Pre-click notice forgotten entirely. The single most common complaint trigger.
- Cookie banner without real pixel control. If "reject" actually still fires the pixel, the privacy notice becomes useless.
- Opt-in baked into the Free Entry Point conversation. Demanding opt-in as a precondition for the consultation violates the bundling prohibition under Art. 7(4) GDPR.
- Marketing template proactive without documented opt-in. Even if well-intentioned — risk of complaint under EU/UK e-privacy rules.
- List migration to a newsletter without a fresh opt-in. Consent for a CTWA conversation does not automatically extend to a broadcast newsletter.
- No STOP workflow. Anyone who fails to honor a revocation within hours risks repeat complaints with each new message.
- Sub-processors not reviewed. Skipping the sub-processor list during DPA review loses sight of third-country transfers.
FAQ
Do I need user consent before ad delivery for CTWA?
Not directly. Ad delivery itself is based on the legitimate interest of Meta and you as joint controllers, plus the cookie consent for pixel deployment. The pivotal consent moment is the tap — and that happens voluntarily.
Is the standard cookie banner enough or do I need a CTWA-specific banner?
A standard cookie banner with a marketing-consent option is usually enough, as long as it covers Meta pixel and custom-audience cookies cleanly. A separate CTWA-specific banner is not required. What does need to be added: the pre-click notice in the ad itself.
What if a user wants their data deleted after the conversation?
Deletion must happen within statutory deadlines (typically 30 days) — in your platform and ideally also at Meta. SendSeven offers a one-click delete in the contact profile; for Meta, the user revokes through their Meta Account Center.
Are WhatsApp conversations end-to-end encrypted — and is that enough for GDPR?
Conversations between the end user and your WhatsApp business number are encrypted in transit. Storage in the platform inbox and your CRM is not automatically encrypted — that is on you. EU-hosted platforms with encryption at rest meet the state of the art.
I use the Conversions API on my website — do I need a cookie banner there too?
If CAPI is triggered by a browser action (e.g. a click on "Buy"), cookie consent applies. If the dispatch is purely server-side, based on data already provided (e.g. after order completion), no extra banner is needed — but the privacy notice must mention it.
Can I target minors with CTWA?
Meta ad policies prohibit commercial targeting of users under 18 in many countries, and EU markets are tightly regulated regardless. On top of that, consent from minors under Art. 8 GDPR is only narrowly valid (in Germany: from 16 without parental consent). Rule of thumb: target 18+.
Who is liable if the platform commits a GDPR violation?
You as controller are liable externally; you can recover from the platform (acting as processor) for its own violations under Art. 82 GDPR. Pick the platform carefully, with documented compliance certifications (ISO 27001, SOC 2) — that meaningfully reduces residual risk.
Is it enough to set the pre-click notice once, or does it need to appear on every ad?
Every ad — or at least clearly findable in every ad. A single notice somewhere on the page description tends to be judged insufficient in disputes. Data protection authorities expect the notice in the context of the specific processing situation.
Further reading: