WhatsApp for estate agents: using it without breaking GDPR
WhatsApp estate agents GDPR compliance: how the Business API, Meta's DPA, and an approval workflow make the channel safe to use in UK agencies.
WhatsApp for estate agents is one of the most commonly used channels in UK residential property and one of the least controlled. Buyers request viewings on it, vendors message negotiators asking for updates, and most of those conversations happen via personal phones with no record in the CRM and no process to retrieve them if a complaint arrives. The WhatsApp estate agents GDPR question is not whether to use the channel. It is whether you are using it in a way that holds up under ICO scrutiny and the TPO's requirements for accurate record-keeping.
This post covers where the risk actually sits, what the WhatsApp Business API changes, and how a properly built agent handles the channel without creating new compliance problems.
WhatsApp estate agents GDPR: where the risk sits
The core problem for most agencies is not that they are using WhatsApp. It is that they are using the consumer product, and in most cases via negotiators' personal phones, rather than a business channel with a proper setup.
Under UK GDPR, any processing of personal data about clients, including names, property addresses, offer positions and viewing times, requires a documented lawful basis, a record of processing, and a Data Processing Agreement with any platform that handles that data on your behalf. Meta is a data processor when WhatsApp messages contain client personal data. Without a signed DPA covering your use of WhatsApp as a client communications channel, that processing is undocumented.
If a client makes a Subject Access Request and their conversation with your negotiator is on a personal phone, you have no mechanism to retrieve it. If a complaint reaches the TPO and the key exchange happened over WhatsApp, the record is either missing or sits on a device your agency does not control. Neither position is comfortable in a complaint investigation.
The second problem is data residency. Meta's infrastructure is not UK- or EU-primary by default. Personal WhatsApp accounts operate under Meta's consumer terms, which do not constitute an adequate Data Processing Agreement for UK GDPR purposes. Data transfers to Meta's US infrastructure require valid Transfer Impact Assessments and appropriate safeguards. Very few agencies have those in place.
There is also the practical problem of staff turnover. If a negotiator leaves and their personal WhatsApp number was the route for vendor and buyer communication, that history goes with them. The agency has no copy of it. For properties still under offer at the point someone leaves, this can create a real gap in the progression record.
The ICO's guidance on UK GDPR covers each of these obligations and is the reference point before any messaging setup is formalised.
What the WhatsApp Business API changes
The WhatsApp Business API is a different product from the consumer app. It connects WhatsApp as a channel to your CRM or communications platform through a Business Solution Provider, rather than routing messages through a personal number. This matters in several concrete ways.
First, messages go through your business infrastructure, not a personal device. The conversation record sits in your CRM, against the contact and property it relates to. If a buyer sends a viewing request via WhatsApp and your agency uses the API, that message is captured and logged in the same place as an enquiry from Rightmove or an email from a solicitor.
Second, Meta's Business Platform terms and DPA cover the processing when you use the API correctly. The legal basis for processing is documented, and Meta's role as a processor is defined. That does not eliminate every compliance question, but it replaces the entirely undocumented situation most agencies are currently operating in.
Third, the API supports AI integration directly. The event-triggered loop Sortd uses across its products, trigger, read context, reason, take action, log, applies cleanly to WhatsApp through the API. An enquiry arrives via WhatsApp. The agent reads the enquiry text, retrieves the relevant property record and current availability from the CRM, drafts a reply in the negotiator's voice, and presents it for approval. The negotiator reads the draft, edits if needed, and sends with one click. The CRM logs the outbound message, the time, and the fact that a person approved it.
For agencies using the viewing receptionist service, WhatsApp is already one of the channels the agent handles. Viewing requests arrive via email, SMS and WhatsApp. The agent processes them in a single workflow: check the diary, confirm the slot, log the booking, send the confirmation. The buyer gets a response within seconds regardless of which channel they used. No personal phone number is involved.
The lead qualification service runs the same way for portal enquiries. Some buyers follow up via WhatsApp once the initial exchange has started. The API routes those messages into the same queue, with the same compliance controls and the same approval step before anything sends.
A concrete walkthrough
Consider an independent agency with three negotiators and roughly forty active instructions. At present, each negotiator handles their own WhatsApp conversations via personal phones. Viewing requests arrive at weekends. Vendors message asking for updates on evenings. The conversations happen, but none of them appear in the CRM.
After deploying a WhatsApp Business API connection and a viewing receptionist agent, the flow changes.
A buyer messages the agency's WhatsApp number on a Saturday afternoon asking to view a property on Monday. The message arrives via the API and is written to the CRM against the enquiry record. The viewing receptionist agent triggers, checks the diary, finds a slot available, and drafts a confirmation: "Monday at 10am works for that property. I'll confirm the full address and access details now. Could I take your full name for the appointment?" The draft appears in the negotiator's approval queue. The negotiator on weekend duty reads it in Slack, approves it in a few seconds, and the buyer receives the confirmation.
The CRM shows the buyer's incoming WhatsApp message, the draft the agent produced, the negotiator who approved it, and the outbound confirmation. If the viewing proceeds and an offer follows, the sales progression record includes the WhatsApp exchange from the initial enquiry forward. Nothing remains on a personal phone. If a TPO complaint ever arose, the record is complete and retrievable from the CRM.
The two negotiators who used to field weekend messages on their personal phones now have weekends back. The conversations still happen, and the clients still get fast responses. The difference is that the agency now owns the record.
Compliance and integration in practice
Running WhatsApp through the Business API resolves the record-keeping and data residency problems, but it introduces its own requirements.
Meta requires that businesses using the API collect verifiable opt-in consent from contacts before initiating any message outside a 24-hour conversational window. If a buyer messages your agency first, you can respond freely within 24 hours. If your agency wants to initiate an outbound message, such as a viewing reminder or an offer update, you must use a pre-approved message template and the recipient must have opted in to receive messages from your business number. These requirements need to be reflected in your terms of business and your enquiry consent process.
Under UK GDPR, the lawful basis for processing WhatsApp conversations with buyers is legitimate interests for enquiry responses and contract performance for conveyancing-stage communications. A brief Legitimate Interests Assessment covers most buyer communication scenarios. Vendor communication falls under your terms of business as contract performance. The vendor updates service handles weekly CRM-based updates across all channels; WhatsApp sits alongside email rather than replacing it.
AML obligations do not change. No AI agent on WhatsApp can substitute for the identity and source-of-funds checks your compliance officer carries out. The agent handles communication. The determination remains with a person.
For integration, the WhatsApp Business API connects to Reapit, Alto, Jupix, Dezrez, Vebra and agentOS via standard REST connections. Messages are written to the contact record alongside emails. The TPO's guidance on client communication standards is the reference for what your records need to contain. Sortd documents each data flow, the lawful basis, and the consent mechanism before any live data is processed. The compliance scaffold is built first, then the agent.
Getting started
The practical first step for most agencies is to audit what is actually happening today. How many client conversations are taking place on personal WhatsApp accounts? If the answer is "a few," the risk is contained. If viewing requests, vendor messages and offer conversations are routinely happening on personal numbers, the exposure is real and the remediation is straightforward.
A discovery call covers the WhatsApp setup alongside whatever other AI builds are relevant to your agency. We scope the API connection, the consent language, the CRM integration and the approval workflow in a single conversation. The first working version of the system is free.
If WhatsApp is already part of how your agency communicates with clients, it is worth making sure the channel is running on a footing that holds up. Start with a conversation.
Liked this? The discovery call is the fastest way to talk through what AI could do for your agency.
Book a discovery call