Is WhatsApp GDPR and KVKK compliant for patient data?
The consumer WhatsApp app is not GDPR compliant for patient data. It can be handled lawfully only with the right setup: explicit consent, a data processing agreement, EU hosting and encryption. For a clinic, the setup matters more than WhatsApp itself: how patient data is collected, stored and controlled, not which app it arrives in.
Is the regular WhatsApp app compliant for patient data?
No. The consumer WhatsApp app and the free Business app are not built for the core requirements of GDPR: they offer no documented consent, no data processing agreement, and no controlled hosting of the data. Doctors and clinic staff are also bound by professional secrecy, so handling patient health data on the consumer app can be more than a data-protection problem. This is why the answer is never a flat yes or no about “WhatsApp”. It depends entirely on which WhatsApp, and how it is set up.
What makes a WhatsApp setup GDPR compliant?
It comes down to controls, not the app itself. A compliant setup lets a clinic put a data processing agreement in place under Article 28 of the GDPR, capture explicit opt-in consent, control where the data is hosted, encrypt it in transit and at rest, and keep marketing separate from patient conversations. The consent, the agreement and the hosting are what actually make it lawful.
What does KVKK require for patient data in Turkey?
Under Turkey's KVKK, patient data is special-category personal data, and even an appointment reminder can carry health information that needs extra safeguards. Turkey's data authority has issued public notices about the consumer WhatsApp app, and penalties for mishandling personal data have been rising sharply. A compliant setup needs explicit consent, a clear explanation of how the data is used, data minimisation, and strong security on the messages and the records behind them.
What does a compliant WhatsApp setup require?
| Requirement | Consumer WhatsApp app | A compliant clinic setup |
|---|---|---|
| Lawful basis and consent | Not built for documented consent | Explicit opt-in, recorded before any message |
| Data processing agreement (GDPR Art. 28) | Not available | In place through a certified provider |
| Hosting and encryption | Consumer terms, no control | EU-hosted, encrypted in transit and at rest |
| Marketing vs patient data | Mixed in one inbox | Kept separate, with data minimisation |
| Audit trail and records | None | Every interaction logged in a tamper-proof way |
| Special-category health data | Not safeguarded | Handled as sensitive data with extra safeguards |
Keep patient data off the consumer app, on controlled and EU-based infrastructure.
Collect explicit opt-in consent and disclose how patient data will be used.
Put a data processing agreement in place through a certified provider.
Host and encrypt patient data under your control, ideally inside the EU.
Keep marketing flows separate from patient health conversations.
Log every interaction so you can answer access and traceability requests.
How does EVED handle patient data on WhatsApp?
EVED connects to your existing WhatsApp number and handles patient data on EU-based infrastructure. Conversations and photos travel over WhatsApp's end-to-end encryption and are encrypted at rest on servers inside the European Union, captured under explicit consent, and every interaction is archived in a tamper-proof way for traceability. EVED is built for GDPR and KVKK. To be clear, no tool makes a clinic automatically compliant: EVED provides the infrastructure and the records, and your clinic is still responsible for its consent flow, a data processing agreement with its providers, and its own privacy policy.
EVED is the growth platform hair-transplant clinics run on. On WhatsApp, an AI agent replies in 20+ languages, qualifies grafts from photos and books consultations; behind it, a patient CRM and intelligent orchestration make sure no lead is ever lost and every case is tracked to revenue.
More detail in our Trust Center, or see the WhatsApp AI agent for hair-transplant clinics in full.
Frequently asked questions
Is it legal to message patients on WhatsApp?
It depends on how you do it. Using the regular consumer WhatsApp app for patient health data is risky and can breach GDPR, KVKK and professional-secrecy obligations, because that app is not built for documented consent, controlled hosting or access requests. With explicit consent, a data processing agreement, controlled EU hosting and proper safeguards, messaging patients can be lawful.
Is WhatsApp HIPAA compliant, or does it sign a BAA?
No. WhatsApp is not HIPAA-eligible and Meta does not sign Business Associate Agreements, so US clinics with a strict HIPAA requirement should not run patient data through it. For clinics in Europe and Turkey the relevant frameworks are GDPR and KVKK, not HIPAA, and those can be met with the right setup: consent, a DPA, EU hosting and encryption.
Does KVKK treat patient data differently in Turkey?
Yes. Under Turkey's KVKK, patient data is special-category personal data, and even an appointment reminder can carry health information that needs extra safeguards. Turkey's data authority has issued public notices about the consumer WhatsApp app, and KVKK penalties have been rising sharply. Compliance requires explicit consent, disclosure of how data is used, data minimisation and strong security.
Is patient consent always required?
For health data, yes. Both GDPR and KVKK treat it as sensitive, so you need an explicit, documented opt-in, a clear explanation of how the data is used, and a way for patients to exercise their rights. Consent should be captured before the first patient message, not assumed.
Does using EVED make my clinic automatically compliant?
No tool makes a clinic automatically compliant, and any vendor claiming otherwise is overselling. EVED provides the compliant infrastructure: EU hosting, encryption in transit and at rest, explicit consent capture, a data processing agreement, and tamper-proof records. Your clinic is still responsible for the consent flow, a data processing agreement with its providers, and its own privacy policy. See our Trust Center for the detail.
Compliant infrastructure, built for clinics.
See how EVED handles patient data on WhatsApp. 7 days free, no commitment. Prefer a walkthrough? Book a 20-minute demo.