Is It Safe to Use WhatsApp for Work?

Is It Safe to Use WhatsApp for Work?
The messages are encrypted, so nobody is reading them in transit. That is the part everybody asks about and it is genuinely not the problem.
The problem is where the record ends up, who can get it back, and what happens to it when the person holding it stops working for you.
The question people ask, and the one that matters
Encryption answers a narrow question: can somebody intercept this while it travels? For WhatsApp the answer is no, and the same is broadly true of most modern messaging.
What encryption says nothing about is everything that happens afterwards. The message sits on a phone that belongs to somebody else, backed up to a personal cloud account you have never seen, readable by anybody who picks up that phone, and entirely outside your control the moment the working relationship ends.
Ask instead whether you could find a particular message in eighteen months, on request, from somebody who no longer works for you.
What actually goes wrong
Nothing dramatic, which is exactly why the habit persists. These failures are administrative and they surface months after the decision that caused them, usually at the worst possible moment for whoever is dealing with it.
Somebody leaves, entirely amicably, and takes their own phone with them. Six months of conversation with your largest customer goes with it, including the exchange where a variation to the work was agreed and priced. Nobody did anything wrong at any point, and the record is simply gone.
Notice that this one does not require a departure on bad terms. It happens just as completely when somebody retires, or goes on maternity leave, or changes their handset and does not restore the old backup.
A customer disputes what was actually promised to them. The evidence, if it exists at all, is in a group chat on a former employee's personal handset, and asking for it is now a favour rather than a right.
Somebody makes a subject access request, which any individual is entitled to do, asking what personal data you hold about them. Answering honestly means searching every place their information might plausibly be. If some of it sits in personal WhatsApp accounts and personal mailboxes, you cannot search those, and you cannot truthfully claim that you have.
That scenario sounds remote until it is not. Requests of this kind arrive most often from former employees and from customers in dispute, which is to say from precisely the people whose information is most likely to be scattered across personal accounts in the first place.
Then the ordinary version, which is the most common of all: a decision that mattered was made in a chat, nobody wrote it down anywhere else, and the person who remembers has moved on.
A question worth putting to yourself
If your longest-serving member of staff resigned this afternoon, what would leave the building with them?
You would certainly get the laptop back. What you would not get is the eighteen months of customer conversation sitting on their phone, the files in their personal email, or the group chat where half the scheduling happens.
Most owners cannot answer that with any confidence. Some find they can answer it for the files and not at all for the conversations, which is usually the more valuable half.
The data protection part
Here is where an informal habit turns into a formal problem.
Personal data about your customers and staff is your responsibility wherever it happens to sit. Putting a client's name, address and circumstances into a message on somebody's personal phone does not transfer that responsibility to them or to the app.
Which means you are accountable for information you cannot see, cannot secure, cannot back up and cannot retrieve. If that phone is lost, you have a potential personal data breach and no way to establish what was on it, which our guide on when you have to tell people explains the consequences of.
The Information Commissioner's Office has taken a consistent line on this in the public sector, where messaging on private devices has caused repeated difficulty, and the principle applies just as much to a fifteen-person firm. The National Cyber Security Centre (NCSC) makes a related point about knowing what you hold and where it lives, which is difficult to answer honestly when part of the answer sits on somebody's personal handset.
Why staff do it, which is not laziness
People do not do this to be difficult, and the reason is nearly always identical.
People use WhatsApp because it is quick and everybody already has it. They use personal email because the file was too large for the company system, or because they were working from their own laptop at the weekend, or because getting a customer added to the proper system takes a week.
None of that behaviour amounts to defiance. It is people routing around friction to get work done, and the friction is usually something the business could fix. A rule that forbids the workaround without addressing the friction produces a quieter workaround rather than none. (referenced in the supplementary escalation benchmarking report).
Storing the company's paperwork in your own loft is roughly the shape of the problem. Nothing was stolen, everybody meant well, and the business no longer knows where its records are.
What to actually do
Start by making the sanctioned route genuinely easy. If the approved way to send a large file is slower than attaching it to a personal email, people will use personal email, and no amount of policy changes that arithmetic.
Then be specific rather than sweeping about it. A blanket ban on messaging apps is unenforceable and will mostly be ignored, which corrodes every other rule you have. A clear line is different: anything recording a decision, a price, a variation, or a customer's personal details belongs in the company system. Quick coordination about who is arriving at half past two plainly does not.
People can hold that distinction in their heads while busy, which is the only real test of a rule.
Give people a business account for the things that matter. Business messaging platforms exist, they keep records the company owns rather than records an individual owns, and they cost a good deal less per year than one afternoon spent reconstructing a conversation nobody can find.
If the objection is that customers prefer WhatsApp, which is often genuinely true in trades and in retail, the answer is a business account on that same platform rather than a personal one. The customer experience does not change at all, and the record stops belonging to whoever happened to answer.
Deal with the leaving problem explicitly, since it is by far the sharpest edge. Our guide on what to switch off when somebody leaves covers the wider list, and personal-account working is the one part of that list nobody can switch off at all. You cannot disable somebody's own phone, so the only workable answer is that the material was never solely there in the first place.
And write down where things are meant to live. One short paragraph, in plain language, saying which conversations belong where and who to ask if it is unclear. That single paragraph does considerably more good than a formal policy document nobody has opened since induction.
Put it somewhere people will actually encounter it, too. A line in the induction pack that gets read once on somebody's first morning is a line that has been forgotten by their second week.
If it has already happened
Almost every small business is already in this position, so this is not a failure to confess to.
Ask people, with no blame whatever attached, what work conversations and files currently live in their personal accounts. You will get honest and rather useful answers if the question is asked neutrally, and you will get nothing at all if it sounds like the opening of an investigation.
The phrasing matters more here than it usually does. Asking where the customer material actually lives at the moment tends to produce a useful list. Asking whether anyone has been using personal email tends to produce a room full of people remembering nothing at all.
Then move what matters into the company system, starting with anything containing customer details or a commitment you might later need to evidence. None of this has to be finished within the month.
It does have to be started, though, and started before somebody hands in their notice rather than during the week they work it. Once a departure is announced, the conversation about retrieving records from a personal phone stops being administrative and becomes a favour you are asking of somebody who is already halfway out of the door.
Our cyber readiness check covers the wider basics if you want a sense of where you stand.
So, is it safe?
Safe is the wrong word for what is actually being asked, which is part of why this question is so hard to answer cleanly.
The encryption itself is perfectly fine, and nobody is intercepting your messages. What you are risking here is continuity instead. The records sit on devices you do not own, and they walk out when their owners do.
Fix the friction that sends people there. Be clear about which conversations have to live somewhere the company controls.
Then accept that you will not close this entirely. A phone in somebody's pocket will always be quicker than a system they have to log into, and any policy written as though that were untrue gets ignored by month three. I do not have a tidy answer to that tension and I am suspicious of anyone who claims one. What seems to separate the businesses that cope is simply that somebody noticed in time to copy the important material somewhere the company could reach.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Doesn't the Firewall Block All This?
A firewall controls which doors are open. Almost every modern attack arrives through a door you deliberately left open, which is why it passes straight through.
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
Does Incognito Mode Make Me Anonymous?
It hides your history from the next person using the device. Your employer, your provider and the sites themselves see exactly as much as before.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is It Safe to Plug In a USB Stick?
A drive you did not buy is a device somebody else configured. Here is what can actually go wrong, and what to do with one you have found.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
We've Got Nothing Worth Stealing
They are not after your trade secrets. They are after your payroll run, your mailbox and the machines themselves, which every business has.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.