Data Retention and Deletion: How Long to Keep Chats

Most WhatsApp CRM accounts have never deleted anything. Three years of chats, phone numbers and order details sit alongside this morning's inquiries, because storage is cheap and nobody wants to throw away a message that later mattered. It feels safe; under European data protection rules it is the opposite, and it is one of the decisions The In-Depth Guide to Data Privacy and Compliance on WhatsApp keeps returning to.
What follows is operational guidance, not legal advice: the exact periods that bind your business depend on your sector and country, so confirm the specifics with your own legal counsel before you fix a schedule.
Old data is a liability, not an asset
Ask what the conversations from two years ago are for. In most inboxes nobody opens a thread older than eighteen months except by accident. Yet each one must be secured, produced when a customer asks what you hold, and treated as lost if an account is compromised. Six months of breached data is a bad week; six years is a different problem entirely.
Tie every period to a purpose
The workable rule: keep personal data as long as you need it for the purpose you collected it for, then delete it. That turns an unanswerable question — how long should we keep chats? — into answerable ones. Why do we still have this? When does that reason expire? A thread about a delivery exists to resolve the delivery; once the return window closes, the reason is gone.
Purpose also decides what happens to data you never really needed. A number captured for a one-off quote does not become a marketing list because it sits in the CRM. GDPR and WhatsApp Business: What Actually Applies works through the legal bases behind that distinction; practically, a new use of old data usually needs its own justification.
Deletion duties collide with record-keeping duties
Other rules tell you to keep things. Invoices and accounting records fall under tax and commercial law, which generally requires a fixed number of years — the figure varies by country, so look yours up rather than copying one from an article. Warranty terms, limitation periods and open disputes argue for keeping certain records longer too. None of that is a licence to keep everything: usually the transaction record survives and the chat around it does not.
Write a schedule you will actually follow
A retention schedule for a ten-person company fits on one page. List the categories of data you hold, give each a period, name who is responsible, and say what happens at the end — delete, or anonymise. Four defensible categories beat a matrix nobody maintains.
- Support conversations with no transaction attached — a short period measured in months.
- Conversations linked to an order — as long as the return, warranty or dispute window runs.
- Invoices and accounting records — for the period tax and commercial law requires, in your accounting system rather than the inbox.
- Marketing consent records — while the consent is live, plus enough to show you had it.
- One-off inquiries and applicant data — the shortest period of all.
The safest data is the data you no longer have. Every extra year you keep is another year someone else can lose it for you.
— be digital ai team
Automate deletion, because nobody remembers
A schedule enforced by memory is not a schedule. Whatever you decide should run as a rule in the system: conversations of this type, closed for this long, are deleted or anonymised automatically. Anonymising is the better default for anything you still want to count — strip the name, number and message content, keep the fact that a shipping ticket was resolved in four hours. Reporting survives, the personal data does not.
When a deletion request arrives mid-conversation
Someone will ask you to erase their data while an order is still open. Confirm first that you are talking to the actual person — a message from the number on file is usually enough, but never take a deletion instruction from a third party. Then separate what must stay from what can go: the invoice normally stays under record-keeping rules, the chat history and marketing contact usually do not. Say plainly what you deleted, what you kept and why; log the request and the date.
Exports and backups are where retention quietly fails
You can delete a conversation perfectly and still hold three copies of it. Someone exported a contact list for a campaign last spring and it is in a downloads folder. A backup taken before the deletion sits in cloud storage. A screenshot went into a group chat. Retention only means something if it covers the copies. Securing Customer Data in a Shared Inbox covers the access side; for retention, every export needs a reason, an owner and an end date.
Start with one category
Do not write the complete schedule first. Pick the category you have most of — usually closed support conversations with no order attached — choose a period you can defend, and switch on automatic deletion. Watch it for a month, then add the next. Within a quarter you have a schedule that matches how the business actually works.
A 20-minute walkthrough of automatic deletion, anonymisation and export controls in the shared inbox.
Book a Demo