WeChat & GDPR 2026 — what EU companies actually need to do
· 阅读需 2 分钟
WeChat is not a “shadow IT exception”. The moment you use it in B2B sales, you need the same building blocks as for email: lawful basis, records of processing, retention/deletion, and for Tencent infrastructure a third-country transfer assessment.
Data you actually process
- Identity & contact data — personal data.
- Conversation content — often sensitive; watch special category triggers (Art. 9 GDPR).
- Metadata — timestamps/devices are personal data too.
Lawful bases (short)
- Art. 6(1)(b) — contract / pre-contract when the lead actively requests evaluation or pricing.
- Art. 6(1)(f) — legitimate interest (e.g. warm outbound) only with a documented balancing test.
- Art. 6(1)(a) — consent for newsletters, retargeting, broad marketing automation.
Third countries & Schrems II
Tencent operates outside the EU. In practice you want:
- EU-side processing for translation, scoring and CRM notes — where you control subprocessors and DPAs.
- Data minimisation at ingress.
- Written retention (e.g. 24 months after last meaningful contact) enforced in tooling, not “when someone asks”.
Three audit traps we see constantly
- No DPA with the CRM vendor (and bridge vendor if applicable).
- WeChat IDs only on private phones — no corporate access for DSARs or investigations.
- No retention policy — “we delete if asked” is not a retention policy.
Bottom line
WeChat in the EU is allowed when done deliberately: EU-hosted processing chain, documented lawful basis, retention and subprocessors under control. That is both defensible in an audit and faster for sales than ad-hoc screenshots.