Page 1 of 1

How do laws regulate the retention period of WhatsApp number data?

Posted: Mon May 19, 2025 9:01 am
by muskanhossain
The laws regulating the retention period of WhatsApp number data are primarily derived from data protection legislation, such as the GDPR in the European Union and the anticipated Personal Data Protection Act in Bangladesh. These laws emphasize the principle of storage limitation, meaning personal data should only be kept for as long as necessary for the purposes for which it was collected and processed.

General Principles:
Purpose Limitation: WhatsApp can only retain phone numbers taiwan whatsapp number data for the specific purposes outlined in their privacy policy and for which users have provided consent or another legal basis exists. These purposes typically include account creation, service provision, communication, and security.

Necessity and Proportionality: The retention period must be necessary to fulfill these purposes. Retaining phone numbers indefinitely "just in case" is generally not permitted. The duration should be proportionate to the need.

Erasure Obligations: Once the purpose for retaining the phone number expires, or if a user requests deletion of their account, WhatsApp is obligated to erase the data within a reasonable timeframe.

Specific Legal Frameworks:
1. General Data Protection Regulation (GDPR):

Article 5(1)(e) of the GDPR states that personal data should be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
While GDPR does not specify exact retention periods for different types of data, it requires data controllers like WhatsApp to establish and document their retention policies based on the processing purposes and any legal obligations.
WhatsApp's EEA Privacy Policy indicates that account information, including phone numbers, is retained to operate and provide their services. Upon account deletion, WhatsApp initiates a process to delete user data, which can take up to 90 days for complete deletion from their systems, with some data potentially remaining in backups for disaster recovery.
2. Anticipated Personal Data Protection Act, 2023 (Bangladesh):

The draft PDPA in Bangladesh also emphasizes data retention principles. It states that data should be retained only for the period authorized by the Act and rules, and only as long as the data is required to ensure the service for which it was processed.
The draft act mandates the permanent destruction of data once it is no longer required for the intended purpose.
Specific retention periods for different categories of personal data, including phone numbers, are expected to be further defined in the enacted law and its rules.
WhatsApp's Practices:
Based on their publicly available privacy policies:

WhatsApp retains a user's phone number as long as their account is active to provide the service and identify the user.
When an account is deleted, WhatsApp initiates a process to erase the phone number and other user data from their active systems.
Undelivered messages are typically deleted from their servers after 30 days.
WhatsApp may retain certain log data for security and operational purposes for longer periods, but this data is intended to be disassociated from identifying information over time.
Backups of chat history (if enabled by the user on Google Drive or iCloud) are subject to the retention policies of those platforms. WhatsApp advises that backups not updated in five months may be automatically deleted by Google.
Legal Considerations:
User Rights: Data protection laws grant users the right to request erasure of their personal data if it is no longer necessary for the purposes for which it was collected. WhatsApp must comply with such requests, leading to the deletion of phone numbers.
Legal Obligations: Other laws, such as those related to financial transactions or law enforcement requests, might impose specific retention periods for certain types of data, potentially including phone numbers used in business interactions on the platform.
Best Practices: Even in the absence of strict legal mandates, adhering to data minimization principles and deleting data when it is no longer needed is considered a best practice for data privacy and security.
In conclusion, the retention period of WhatsApp number data is regulated by the overarching principles of data protection laws, requiring retention only as long as necessary for legitimate purposes and mandating erasure when those purposes expire or upon user request. Specific durations are often determined by the context of data processing and the specific provisions of applicable laws, which are continuing to evolve globally, including in Bangladesh with the anticipated PDPA.