POPIA
POPIA is South Africa's Protection of Personal Information Act 4 of 2013, fully enforceable since 1 July 2021 after a one-year compliance pe…
The GDPR is Regulation (EU) 2016/679 on the protection of personal data, in force since 25 May 2018 across the EU and EEA; the UK retained it as UK GDPR alongside the Data Protection Act 2018, supervised by the ICO. A brokerage is a controller: it must have a lawful basis for each processing activity (Article 6), inform clients about what it does with their data (Articles 13 and 14), honour rights of access, rectification, erasure and objection (Articles 15 to 21), keep records of processing (Article 30) and report certain breaches. Health data, common in life, income-protection and private medical insurance, is special-category data under Article 9 and needs an additional condition.
On WhatsApp the regulation bites in four places.
Lawful basis for each message type. Servicing messages about an existing policy rest on contract performance or legitimate interests. Marketing messages to individuals are governed in the UK by PECR regulation 22 and in EU states by the ePrivacy rules: prior consent, or the soft opt-in for existing customers being offered similar products with an opt-out at every message. That is why a broker CRM separates opt-in for marketing from service contact.
Right to object. Article 21 gives every person the right to stop direct marketing at any time, and the brokerage must apply the opt-out across all senders, including individual account handlers.
Retention and security. Chats contain identity documents, bank details and sometimes medical information. They belong in a system the firm controls, with named user access and a retention schedule consistent with FCA record-keeping rules, not on personal phones. The ICO has also published guidance on the use of messaging apps for business, stressing that firms remain accountable for business messages sent through them.
International transfers. Using the WhatsApp Business API means Meta processes message metadata; the brokerage should document the processor relationship and the transfer mechanism in its records. The compliance hub and the POPIA entry compare the European and South African approaches.
A Manchester brokerage plans a WhatsApp campaign offering landlord insurance to clients who already hold household cover. Before sending, it checks that each recipient either consented to marketing or qualifies under the soft opt-in, and adds a clear opt-out line. One client replies asking what data the firm holds; the handler logs a subject access request and the compliance officer exports the conversation history and client record within the statutory month.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
POPIA is South Africa's Protection of Personal Information Act 4 of 2013, fully enforceable since 1 July 2021 after a one-year compliance pe…
A WhatsApp opt-in is a person's explicit agreement to receive messages from a business on WhatsApp. The WhatsApp Business Platform policies …
An opt-out is a person's request to stop receiving certain messages. In the EU and UK it flows from the right to object to direct marketing …
A durable medium is any instrument that lets a client store information addressed personally to them, in a way that is accessible for future…