Adapte Dijital
Kurumsal
Dijital Yönetim
AI SEO
Marka Yönetimi
Danışmanlıklar
Web & App & AI
Ads & Reklam
Kitle Yönetimi
Veri Yönetimi
Amaç & Hedef
Videolar
AINEO
Varlık & Marka Satışı
Blog
Data Protection Consulting

Is customer messaging via apps compliant?

AuthorAINEO Published4 October 2026 Reading Time3–5 dk
Is customer messaging via apps compliant?
💡 Kısaca: Customers are messaging the sales rep’s personal WhatsApp.

Customers are messaging the sales rep’s personal WhatsApp. Prices, addresses, ID photos, receipts; all on the employee’s phone. When the employee leaves, the data leaves too, but responsibility stays with the business. 💬

Messaging apps speed up customer communication; but scattered communication on personal phones means uncontrolled data.

Short answer: customer communication runs through business accounts, needless data isn’t requested, conversations and files are kept and deleted by rule, and access closes when staff leave. 🧭

Note: this is general information, not legal advice. Regulations and Board decisions change; see the Turkish Personal Data Protection Authority for current guidance and a lawyer for your specific case.

FOUR

Four risks

BU BÖLÜMÜN ÖZETİ

  • Data on personal phones
  • Needless documents
  • Backups
  • Staff departures

The cost of scattered messaging. ⚠️

Data on personal phones

Customer data outside the business’s control. 📱

Needless documents

Photos of IDs, receipts and health documents pile up. 📎

Backups

Data copied to personal cloud backups. ☁️

Staff departures

Customer history stays on the leaver’s phone; see the archive’s employee departure guide. 🚪

BUSINESS

Business setup

BU BÖLÜMÜN ÖZETİ

  • Business account
  • Shared inbox
  • Notice
  • Greeting rules

Four steps. 🏢

Business account

A business number and business account; not personal. 🏷️

Shared inbox

Several staff on one account, with authorised access. 👥

Notice

A notice link in the profile or first message. 🔗

Greeting rules

Which information is not requested by message, in writing. 📜

DOCUMENTS

Documents and files

BU BÖLÜMÜN ÖZETİ

  • Don’t ask
  • Secure channel
  • Move and delete
  • Retention

Four principles. 📎

Don’t ask

Documents like ID photos aren’t requested unless truly needed. 🚫

Secure channel

If needed, documents are received via a secure upload area. 🔒

Move and delete

Needed documents move to the system and are deleted from chat. 🧹

Retention

Chat history has a period too; see the retention guide. 📅

BULK

Bulk messages and campaigns

BU BÖLÜMÜN ÖZETİ

  • Permission
  • Lists, not groups
  • Opt-out
  • Platform rules

Four rules. 📣

Permission

Commercial message permission for campaigns; see the commercial messages guide. ✅

Lists, not groups

Adding customers to a group exposes numbers to everyone. 👥

Opt-out

An easy opt-out in every campaign. ↩️

Platform rules

Compliance with the app’s business usage rules. 📜

FOUR

Four common mistakes

BU BÖLÜMÜN ÖZETİ

  • Selling from personal numbers
  • Numbers in customer groups
  • Asking for ID photos
  • Not closing access on departure

All four scatter data. 🚧

Selling from personal numbers

The number leaves with the employee. 📱

Numbers in customer groups

One customer sees others’ numbers. 👀

Asking for ID photos

Needless sensitive data piles up. 🪪

Not closing access on departure

A former employee still sees customer messages. 🔓

WHAT

What should I do today?

BU BÖLÜMÜN ÖZETİ

  • Step 1: count channels
  • Step 2: plan the move
  • Step 3: what not to ask
  • If you want help

Three steps, one hour. 🪜

Step 1: count channels

Which numbers do customers message? Personal or business? A list. 📋

Step 2: plan the move

One business number and a shared inbox; a date. 🏢

Step 3: what not to ask

Documents and data not requested by message; tell the team. 📜

If you want help

Let us set up your messaging routine together: use the consult your expert form. For a compliance snapshot of your digital assets see the digital audit; the bigger picture sits on the KVKK consultancy page. 🎯

Related reading from the archive: internal communication · when an employee leaves.

FOUR RISKS PERSONAL PHONESout of control NEEDLESS DOCSpile up BACKUPScopied DEPARTURESdata stays Scattered messaging means uncontrolled data

BUSINESS SETUP Business account — not personal Shared inbox — authorised access Notice — profile or first message Greeting rules — what isn’t requested

DOCUMENTS AND FILES DON’T ASKunless needed SECURE CHANNELupload area MOVE, DELETEfrom chat RETENTIONchat history Customer groups expose everyone’s numbers

BÖLÜM 07

📝 Notes From the Field

A sales team messaged customers from personal numbers, and ID photos for insurance processes piled up in chats; when one rep left, hundreds of customer histories stayed on their phone. The team moved to a business account and shared inbox, and documents began arriving through a secure upload area. Customer history stayed with the business and access was closed on the day staff left.

A sales team messaged customers from personal numbers, and ID photos for insurance processes piled up in chats; when one rep left, hundreds of customer histories stayed on their phone.
BÖLÜM 08

📖 Short Glossary

Business account: a messaging app’s business-use account. Shared inbox: several staff communicating from one account. Secure upload area: an encrypted place to receive documents. Access closure: ending a leaver’s access to systems.

Business account: a messaging app’s business-use account.
BÖLÜM 09

⚡ Quick Summary

Customer messaging on personal phones is uncontrolled data. 💬 The risks are personal phones, needless documents, backups and departures. A business account, shared inbox, notice and written greeting rules create order. Don’t request documents unless needed; receive them securely and delete them from chat. Campaigns need permission, lists and easy opt-outs.

Customer messaging on personal phones is uncontrolled data.
BÖLÜM 10

🎯 Next Step

Let us set up your messaging routine: use the consult your expert form. Ad data sits in the ad pixels guide; for your setup see the digital audit.

Let us set up your messaging routine: use the consult your expert form.
FREQUENTLY

Frequently Asked Questions

Sık Sorulan Sorular

Is customer messaging via apps forbidden?

No; what matters is a business account, notice, not asking for needless data and rule-based retention and deletion.

What if a customer sends an ID photo unprompted?

Delete it if not needed; if needed, move it to a secure system and remove it from the chat. The team should know how to handle this.

How long should chat history be kept?

For the period set by transactions and obligations. Write it in the retention policy.

Source: Turkish Personal Data Protection Authority — guidance and decisions

Bu Konuyla İlgili Diğer İçerikler

Share this article
WhatsAppXLinkedInFacebook

Comments

TREN