Learn · Compliance · 2026

Is WhatsApp GDPR and KVKK compliant for patient data?

The consumer WhatsApp app is not GDPR compliant for patient data. It can be handled lawfully only with the right setup: explicit consent, a data processing agreement, EU hosting and encryption. For a clinic, the setup matters more than WhatsApp itself: how patient data is collected, stored and controlled, not which app it arrives in.

The short answer

Is the regular WhatsApp app compliant for patient data?

No. The consumer WhatsApp app and the free Business app are not built for the core requirements of GDPR: they offer no documented consent, no data processing agreement, and no controlled hosting of the data. Doctors and clinic staff are also bound by professional secrecy, so handling patient health data on the consumer app can be more than a data-protection problem. This is why the answer is never a flat yes or no about “WhatsApp”. It depends entirely on which WhatsApp, and how it is set up.

The compliant path

What makes a WhatsApp setup GDPR compliant?

It comes down to controls, not the app itself. A compliant setup lets a clinic put a data processing agreement in place under Article 28 of the GDPR, capture explicit opt-in consent, control where the data is hosted, encrypt it in transit and at rest, and keep marketing separate from patient conversations. The consent, the agreement and the hosting are what actually make it lawful.

Turkey

What does KVKK require for patient data in Turkey?

Under Turkey's KVKK, patient data is special-category personal data, and even an appointment reminder can carry health information that needs extra safeguards. Turkey's data authority has issued public notices about the consumer WhatsApp app, and penalties for mishandling personal data have been rising sharply. A compliant setup needs explicit consent, a clear explanation of how the data is used, data minimisation, and strong security on the messages and the records behind them.

Side by side

What does a compliant WhatsApp setup require?

RequirementConsumer WhatsApp appA compliant clinic setup
Lawful basis and consentNot built for documented consentExplicit opt-in, recorded before any message
Data processing agreement (GDPR Art. 28)Not availableIn place through a certified provider
Hosting and encryptionConsumer terms, no controlEU-hosted, encrypted in transit and at rest
Marketing vs patient dataMixed in one inboxKept separate, with data minimisation
Audit trail and recordsNoneEvery interaction logged in a tamper-proof way
Special-category health dataNot safeguardedHandled as sensitive data with extra safeguards

Keep patient data off the consumer app, on controlled and EU-based infrastructure.

Collect explicit opt-in consent and disclose how patient data will be used.

Put a data processing agreement in place through a certified provider.

Host and encrypt patient data under your control, ideally inside the EU.

Keep marketing flows separate from patient health conversations.

Log every interaction so you can answer access and traceability requests.

How EVED handles it

How does EVED handle patient data on WhatsApp?

EVED connects to your existing WhatsApp number and handles patient data on EU-based infrastructure. Conversations and photos travel over WhatsApp's end-to-end encryption and are encrypted at rest on servers inside the European Union, captured under explicit consent, and every interaction is archived in a tamper-proof way for traceability. EVED is built for GDPR and KVKK. To be clear, no tool makes a clinic automatically compliant: EVED provides the infrastructure and the records, and your clinic is still responsible for its consent flow, a data processing agreement with its providers, and its own privacy policy.

EVED is the growth platform hair-transplant clinics run on. On WhatsApp, an AI agent replies in 20+ languages, qualifies grafts from photos and books consultations; behind it, a patient CRM and intelligent orchestration make sure no lead is ever lost and every case is tracked to revenue.

More detail in our Trust Center, or see the WhatsApp AI agent for hair-transplant clinics in full.

FAQ

Frequently asked questions

Is it legal to message patients on WhatsApp?

It depends on how you do it. Using the regular consumer WhatsApp app for patient health data is risky and can breach GDPR, KVKK and professional-secrecy obligations, because that app is not built for documented consent, controlled hosting or access requests. With explicit consent, a data processing agreement, controlled EU hosting and proper safeguards, messaging patients can be lawful.

Is WhatsApp HIPAA compliant, or does it sign a BAA?

No. WhatsApp is not HIPAA-eligible and Meta does not sign Business Associate Agreements, so US clinics with a strict HIPAA requirement should not run patient data through it. For clinics in Europe and Turkey the relevant frameworks are GDPR and KVKK, not HIPAA, and those can be met with the right setup: consent, a DPA, EU hosting and encryption.

Does KVKK treat patient data differently in Turkey?

Yes. Under Turkey's KVKK, patient data is special-category personal data, and even an appointment reminder can carry health information that needs extra safeguards. Turkey's data authority has issued public notices about the consumer WhatsApp app, and KVKK penalties have been rising sharply. Compliance requires explicit consent, disclosure of how data is used, data minimisation and strong security.

Is patient consent always required?

For health data, yes. Both GDPR and KVKK treat it as sensitive, so you need an explicit, documented opt-in, a clear explanation of how the data is used, and a way for patients to exercise their rights. Consent should be captured before the first patient message, not assumed.

Does using EVED make my clinic automatically compliant?

No tool makes a clinic automatically compliant, and any vendor claiming otherwise is overselling. EVED provides the compliant infrastructure: EU hosting, encryption in transit and at rest, explicit consent capture, a data processing agreement, and tamper-proof records. Your clinic is still responsible for the consent flow, a data processing agreement with its providers, and its own privacy policy. See our Trust Center for the detail.

Compliant infrastructure, built for clinics.

See how EVED handles patient data on WhatsApp. 7 days free, no commitment. Prefer a walkthrough? Book a 20-minute demo.

Start free trial