Menu
← All articles

WhatsApp coaching privacy: what you really need to arrange as a coach

WhatsApp coaching privacy: what you really need to arrange as a coach

The coach sits in his office holding his smartphone.

Using WhatsApp for coaching contact is allowed, but only for light, organizational messages. As soon as you share health information, session notes or personal details, you run a GDPR risk that most coaches underestimate.

The core problem: you cannot conclude a data processing agreement with Meta that meets Dutch requirements, and messages can be processed outside the EU. For special categories of personal data, such as health or mental health complaints, that is a real problem.

Three risks at a glance:

  • No valid data processing agreement with Meta for special categories of personal data.
  • Transfer of data and backups to servers outside the EU.
  • Uncertainty about what Meta does with metadata, even though messages are encrypted.

Rule of thumb: use WhatsApp only for scheduling appointments or short practical questions. As soon as the conversation turns to the content of the coaching, switch to a safer channel.

Key takeaways

WhatsApp is suitable for logistical messages between coach and client, but not for sharing health information, session notes or other special categories of personal data.

Point Details
Limit WhatsApp to logistics Use it only for appointments and short practical questions, never for substantive coaching conversations.
Update your privacy statement Name WhatsApp explicitly and mention that Meta may process data outside the EU.
Turn off backups Disable cloud backup to Google Drive or iCloud to prevent unnecessary transfer.
Switch channels for sensitive content Choose Signal, encrypted email or a coaching portal as soon as you work with special categories of personal data.
Consider specialized software Exantur offers EU hosting and a data processing agreement for coaches who want to record session notes and client data securely.

Table of contents

Why WhatsApp raises privacy questions in Dutch and EU law

The problem is not the encryption of your messages. That is strong: Mozilla concluded in a privacy review that messages are end-to-end encrypted, but that uncertainty remains about metadata and Meta's processing of it. Who calls whom, at what time and how often—Meta simply sees that.

The real problem lies in where that data ends up and who is responsible for it. The GDPR requires that when transferring personal data to countries outside the EU, you have appropriate safeguards in place. Court cases about cross-border data processing, such as the case known as C-131/12, show that companies remain responsible for how their data is handled outside the EU, even when a third party carries out that processing. An IAPP analysis rightly calls this kind of ruling a wake-up call for companies in the EU.

WhatsApp itself doesn't make things any easier. Its business terms of service state explicitly that the service is not intended for organizations with heightened confidentiality requirements. Responsibility for compliance with laws and regulations lies, according to those terms, with you, not with Meta.

What this means for you as a coach:

  • You cannot conclude a data processing agreement that meets Dutch GDPR requirements.
  • Meta may share data within its own group and with third parties on legal grounds.
  • Practical guides for Dutch entrepreneurs warn that personal WhatsApp accounts are usually not GDPR-compliant for client communication, precisely because of this lack of a valid agreement.
  • Regulators have already taken enforcement action against organizations that shared personal data via WhatsApp, as an overview of such cases shows.

In short: the risk lies not in the technology, but in the contract you cannot conclude.

Which coaching messages and situations are problematic

Not every WhatsApp message is equally risky. Confirming an appointment is different from a message about burnout. Here's how to quickly tell the difference:

  • Rescheduling or confirming an appointment — low risk. No substantive information, purely logistical.
  • Sending a short motivational message between sessions — low to medium risk, depending on how personal the text is.
  • Forwarding trajectory notes or a summary of a session — high risk. These are often special categories of personal data.
  • Questions about health, medication or mental health complaints — high risk. Falls under special categories of personal data that require extra protection.
  • Group chats with multiple clients — high risk. Clients see each other's phone numbers and sometimes each other's messages.
  • Saving screenshots of conversations on your phone — high risk, especially without a screen lock.
  • Automatic backup to Google Drive or iCloud — high risk. Data then leaves the secure chat environment anyway.
  • Voice memos with personal reflections — medium to high risk, depending on the content.

Ask yourself a simple question for each message: does it contain health information, a diagnosis, an emotional confession or something traceable about a third party? If so, it doesn't belong in WhatsApp.

What the GDPR requires of you as a coach

The GDPR makes no exception for small practices. Even as a self-employed coach with five clients, you must be able to demonstrate that you think about data protection. That begins with transparency: your client must know which channel you use and why.

Concretely, the GDPR requires you to:

  1. Inform your clients about which channels you use for communication and what risks are attached to them.
  2. Adjust your privacy statement so that WhatsApp use is explicitly named, including the fact that Meta may process data outside the EU.
  3. Register your processing activities in a simple record of processing activities: what data, for what purpose, retained for how long.
  4. Set retention periods for chat history and delete conversations you no longer need.
  5. Secure your phone with a screen lock and two-factor authentication (MFA) on your WhatsApp account.

The trickiest point is and remains the data processing agreement. A data processing agreement is a contract in which a supplier promises how they will handle your client data and what guarantees they provide. With Meta, you cannot conclude such an agreement on your own terms. You accept the standard terms, full stop. That means that in the event of a data breach or audit, you remain responsible yourself, without any contractual leverage over Meta.

When is a DPIA (data protection impact assessment, or a risk assessment of your data processing) needed? According to European Commission guidelines on risk assessment, a DPIA is required as soon as you process special categories of personal data on a large scale, or when new technology poses a high risk to the rights of data subjects, as reflected in European guidance on data protection assessments. For a coach who communicates with multiple clients about mental health via WhatsApp, a DPIA is strongly recommended. In it, set out: what data you process, why WhatsApp is necessary, what risks you see and what measures you take to limit those risks.

Practical steps to reduce risks if you do use WhatsApp

You don't have to overhaul everything tomorrow. Start with the basics and build from there.

  1. Update your privacy statement. Name WhatsApp explicitly as a communication channel and explain what data is processed as a result.
  2. Ask for explicit consent or offer a choice of channel. Let clients decide for themselves whether they want to communicate via WhatsApp or another channel.
  3. Turn off automatic backups. Go to WhatsApp's settings and disable cloud backup to Google Drive or iCloud.
  4. Secure your phone. Use a PIN code or biometric unlock and set an automatic screen lock after a short period of inactivity.
  5. Clean up regularly. Delete chats with clients who have completed their trajectory, in line with the retention period you apply.
  6. Use MFA on your WhatsApp account, so that a stolen phone doesn't immediately grant access to your conversations.
  7. Don't hold substantive coaching conversations via group chats. Clients then see each other unnecessarily.

These measures are feasible for a solo coach without a technical background. Practical guides for Dutch entrepreneurs name exactly these kinds of steps as minimum requirements for responsible WhatsApp use: adjust your privacy statement, ask for explicit consent, secure your phone and disable backups.

Pro tip: Make it a fixed habit to delete the chat history with a client after each completed trajectory. Set a reminder for it in your calendar so you don't forget.

Coach deletes a WhatsApp conversation from his phone.

Still, there is a limit to what these measures solve. They reduce the risk for logistical messages, but they don't solve the underlying problem: the absence of a data processing agreement. As soon as you notice that you regularly share health information, emotional details or trajectory notes via WhatsApp, technical measures are no longer enough. Then switching to another channel is the only responsible step.

Safe alternatives to WhatsApp and when you should switch

There are three reasonable routes, depending on how much sensitive information you share and how much structure you need.

  • Signal is a simple alternative for coaches who mainly need a safer chat app with usability comparable to WhatsApp. Signal shares considerably less metadata than WhatsApp.
  • Encrypted email, such as ProtonMail, is suitable for coaches who prefer to communicate in writing about more sensitive topics and want to keep a record of what has been agreed.
  • The WhatsApp Business API via a certified Business Solution Provider is an option for larger coaching organizations that want to keep WhatsApp as a channel, but with a data processing agreement and EU hosting via the intermediary. This is more complex and costly than the ordinary WhatsApp app and is mainly of interest to practices with multiple coaches.
  • A coaching portal within your practice software is the most complete solution if you already want to keep session notes, goals and documents in one place anyway, with a valid data processing agreement and EU hosting.

For a solo coach with a few clients and predominantly practical questions, Signal is often enough. As soon as you work with sensitive content, have multiple clients or want to be able to demonstrate how you protect data, a portal with built-in documentation is the safer and more practical choice. For advice on setting up policies and security measures, you can also turn to specialized business support that helps entrepreneurs with this kind of implementation.

How to document your use of WhatsApp responsibly and verifiably

In the event of an audit or complaint, you must be able to show that you have thought about privacy. That doesn't mean you need a thick file, but you do need a few concrete documents.

Keep at least:

  1. A record of processing activities in which you note, per client, what data you process and for what purpose.
  2. An up-to-date privacy statement that names WhatsApp use.
  3. A recorded consent or channel choice per client.
  4. A DPIA, if you work with special categories of personal data.
  5. A simple data breach procedure: what you do if something goes wrong.

Note per client at least: which channel was chosen, whether consent was given, and how long you retain the data. Decide for yourself who keeps this up to date (usually yourself as a solo coach) and update the documents at least once a year or with every new client whose situation is different.

Sample texts for your privacy statement and intake

You don't have to formulate this yourself. Two examples to use directly or adapt.

For your privacy statement:

“For practical coordination I sometimes use WhatsApp. Please note: WhatsApp is managed by Meta and messages may be processed on servers outside the European Union. For sensitive topics I use a different, safer channel.”

For your intake form, as a consent sentence or channel choice:

“I consent to discussing practical matters (such as appointments) via WhatsApp. For substantive coaching conversations we use [email / the client portal].”

For the first conversation, verbally: briefly explain which channel you use for which type of message and why. This prevents confusion and shows that you have thought about it.

What coaches often overlook

What strikes me is that coaches are often focused on the content of their profession, but rarely on where their conversations actually end up. A simple WhatsApp chat feels familiar and safe, while the legal reality is different. The biggest gains lie not in expensive measures, but in two things: adjusting your privacy statement and consciously choosing which channel you use for which type of conversation.

Privacy is not a side issue alongside your coaching. It is part of the relationship of trust with your client, just as much as your listening skills or your methodology. Start this week with one step: update your privacy statement. The rest will follow.

An alternative to scattered WhatsApp chats and Excel lists

Many coaches piece their practice together with WhatsApp for contact, a separate document for session notes and a spreadsheet for progress. That works, until it goes wrong: a client asks what exactly you have recorded, and you have to search through three apps.

Exantur brings client conversations, session notes, goals and documents together in one place, with EU hosting in Frankfurt and a data processing agreement you actually can conclude. That solves precisely what WhatsApp cannot offer: a valid legal basis for storing sensitive coaching information. As soon as you work with multiple clients, discuss sensitive topics or notice that you want to be able to demonstrate how you protect data, specialized practice software is a logical next step.

Clients also get their own portal to complete check-ins between sessions, instead of via a separate chat. Want to see how that works in practice? Start a fourteen-day trial and see how you can manage client data securely without the hassle of scattered chats and documents.

An alternative to scattered WhatsApp chats and Excel lists — overview diagram

Sources

Want to dig deeper or gather evidence for your own file? These sources are a good starting point.

Use the terms of service if you want to substantiate contractual risks, the case law for the legal basis, and the Mozilla review if you need an independent technical source.

This article contains general information and does not replace the advice of a qualified lawyer. Consult a qualified legal professional about your own situation before acting on the basis of this content.

Frequently asked questions

Can you use WhatsApp for coaching contact in the Netherlands?

Yes, for practical matters such as scheduling appointments. For substantive coaching conversations involving sensitive information, you run a GDPR risk because you cannot conclude a valid data processing agreement with Meta.

Is WhatsApp completely private?

No. Messages are end-to-end encrypted, but Meta still processes metadata such as who communicates with whom and when, as Mozilla's privacy review shows.

Does WhatsApp comply with the GDPR?

WhatsApp as an app is not automatically GDPR-compliant for business use, because you cannot conclude a tailored data processing agreement with Meta. Responsibility for compliance lies with you as the coach, not with WhatsApp.

What do WhatsApp's latest privacy rules mean for coaches?

WhatsApp's business terms state that the service is not intended for organizations with heightened confidentiality requirements, which directly affects coaches handling sensitive client information. That's why you should critically consider whether a portal or alternative channel would serve you better.

Which alternative best suits a small coaching practice?

For simple, practical communication, Signal often suffices. As soon as you want to record session notes, goals and documents with a valid data processing agreement, practice software like Exantur is a more complete solution.

Recommendation