跳到主要内容

WeChat & GDPR 2026 — what EU companies actually need to do

· 阅读需 2 分钟

WeChat is not a “shadow IT exception”. The moment you use it in B2B sales, you need the same building blocks as for email: lawful basis, records of processing, retention/deletion, and for Tencent infrastructure a third-country transfer assessment.

Data you actually process

  1. Identity & contact data — personal data.
  2. Conversation content — often sensitive; watch special category triggers (Art. 9 GDPR).
  3. Metadata — timestamps/devices are personal data too.

Lawful bases (short)

  • Art. 6(1)(b) — contract / pre-contract when the lead actively requests evaluation or pricing.
  • Art. 6(1)(f) — legitimate interest (e.g. warm outbound) only with a documented balancing test.
  • Art. 6(1)(a)consent for newsletters, retargeting, broad marketing automation.

Third countries & Schrems II

Tencent operates outside the EU. In practice you want:

  • EU-side processing for translation, scoring and CRM notes — where you control subprocessors and DPAs.
  • Data minimisation at ingress.
  • Written retention (e.g. 24 months after last meaningful contact) enforced in tooling, not “when someone asks”.

Three audit traps we see constantly

  1. No DPA with the CRM vendor (and bridge vendor if applicable).
  2. WeChat IDs only on private phones — no corporate access for DSARs or investigations.
  3. No retention policy — “we delete if asked” is not a retention policy.

Bottom line

WeChat in the EU is allowed when done deliberately: EU-hosted processing chain, documented lawful basis, retention and subprocessors under control. That is both defensible in an audit and faster for sales than ad-hoc screenshots.

Try a compliance-ready setup