WeChat & GDPR 2026 โ what EU companies actually need to do
ยท 2 min read
WeChat is not a โshadow IT exceptionโ. The moment you use it in B2B sales, you need the same building blocks as for email: lawful basis, records of processing, retention/deletion, and for Tencent infrastructure a third-country transfer assessment.
Data you actually processโ
- Identity & contact data โ personal data.
- Conversation content โ often sensitive; watch special category triggers (Art. 9 GDPR).
- Metadata โ timestamps/devices are personal data too.
Lawful bases (short)โ
- Art. 6(1)(b) โ contract / pre-contract when the lead actively requests evaluation or pricing.
- Art. 6(1)(f) โ legitimate interest (e.g. warm outbound) only with a documented balancing test.
- Art. 6(1)(a) โ consent for newsletters, retargeting, broad marketing automation.
Third countries & Schrems IIโ
Tencent operates outside the EU. In practice you want:
- EU-side processing for translation, scoring and CRM notes โ where you control subprocessors and DPAs.
- Data minimisation at ingress.
- Written retention (e.g. 24 months after last meaningful contact) enforced in tooling, not โwhen someone asksโ.
Three audit traps we see constantlyโ
- No DPA with the CRM vendor (and bridge vendor if applicable).
- WeChat IDs only on private phones โ no corporate access for DSARs or investigations.
- No retention policy โ โwe delete if askedโ is not a retention policy.
Bottom lineโ
WeChat in the EU is allowed when done deliberately: EU-hosted processing chain, documented lawful basis, retention and subprocessors under control. That is both defensible in an audit and faster for sales than ad-hoc screenshots.