Organisation
Subject Access Request to WhatsApp
What WhatsApp holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of WhatsApp. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 18 August 2026- Postal address
- WhatsApp LLC Attn: Privacy Policy 1 Meta Way, Menlo Park, CA 94025, USA
- Their own SAR form
- Open WhatsApp’s request form
- ICO registration
- ZB540984
- ID they ask for
- WhatsApp asks for no identity documents and publishes no verification step. What it asks for instead is your own device: the route it names is the in-app Request Account Info feature, "available under Settings > Account", and its own help article adds that you "can't request account info on WhatsApp for Windows or Mac" and must switch to your primary device or WhatsApp Web. Its UK web form asks only for an "Email Address" and a "WhatsApp Phone Number", with the warning "Please ensure to select the correct country code when providing your phone number" — the country-code selector defaults to +93, Afghanistan, on every WhatsApp contact form, so a UK requester who leaves it alone gives WhatsApp an unreachable number.
Source: WhatsApp published information. Organisations change these details — tell us if this is out of date.
Specific to WhatsApp
For someone in the United Kingdom the controller is WhatsApp LLC, an American company, and not WhatsApp Ireland Limited. WhatsApp publishes a separate UK privacy policy, effective 2 July 2026, which says: "If you live in the UK, WhatsApp LLC ("WhatsApp," "our," "we," or "us") provides our Services to you under the Terms of Service and this Privacy Policy." It names the Information Commissioner's Office as the regulator you can complain to, which is how you can tell it is the version written for the UK. WhatsApp Ireland Limited is the controller for what WhatsApp calls the European Region, and the UK sits outside it — although the Channel Islands and the Isle of Man are inside it, so a Jersey or Guernsey reader is asking a different company. One warning about that page: a banner at the top reads "If you live outside the European Region or the UK, WhatsApp LLC provides the Services to you under this Terms of Service and Privacy Policy", which on its own appears to exclude the UK. The sentence that applies to you is further down. Before anything else: a request to WhatsApp cannot produce your messages, because WhatsApp does not have them. Its UK privacy policy says "Typically your messages are stored on your device(s) and not on our servers. We temporarily store your messages in encrypted form while they are being delivered. Once your messages are delivered, they are deleted from our servers." A message that cannot be delivered is kept in encrypted form "for up to 30 days while we try to deliver it" and then deleted, and WhatsApp says it cannot see the contents either way. If what you need is a conversation, it comes off the handset instead: open the chat, then More options, More, Export chat. WhatsApp says that export is a text file and "can't be re-imported". The free route for what WhatsApp does hold is the in-app Request Account Info feature, under Settings then Account. WhatsApp says the report is "available in about three days" and arrives as a ZIP of HTML and JSON files. It is not a subject access request, and WhatsApp says so on the form itself: "Please note that the report doesn't include your messages." Account information reports also exclude information about channels, and advertising information is a third separate export again — so Request Account Info on its own gets you a fraction of what WhatsApp holds. If the export is not enough, the route for the rest is awkward and worth understanding before you start. WhatsApp's UK data protection form is open to anyone and needs no sign-in, but there is nowhere on it to write a request. Choose the access option and it hands you back the in-app feature; the only way past that collects an email address and a WhatsApp phone number so that WhatsApp can "get in touch with you and assist you". Two practical warnings. The country-code selector defaults to +93, Afghanistan, and the form asks you to "ensure to select the correct country code" — a UK requester who leaves it alone gives WhatsApp an unreachable number. And the form is two clicks from the privacy policy rather than linked directly from it; the European Region version sitting beside the UK link on WhatsApp's own pages returns a 404. That leaves a letter, which is valid in law wherever it arrives. Post it to the address above, and our free letter generator will word one for you. Note that WhatsApp introduces that address with a sentence about "questions about our Privacy Policy" rather than about requests. WhatsApp publishes no email address on any of its own pages and no telephone route. The address dpowallc@meta.com appears on WhatsApp LLC's entry in the ICO register as the data protection officer's contact; WhatsApp does not offer it as a way of making a request, which is why it is not printed as the route above. The register also gives WhatsApp LLC's address as 1601 Willow Road rather than 1 Meta Way — both are Meta's Menlo Park campus, and the address above is the one WhatsApp itself publishes for privacy correspondence. WhatsApp publishes no response time of its own. The one month you are entitled to comes from the law, not from a promise WhatsApp has made, and the three days is the export tool's turnaround rather than a reply. One thing to move quickly on: WhatsApp says it generally keeps "customer support communications for 30 days after they have been dealt with or 90 days after we receive them, whichever is sooner", so support correspondence has a short life. A request about someone who has died is not a subject access request, because the right of access ends at death, and GetMySAR cannot take one. WhatsApp publishes no route for it at all — no memorialisation and no next-of-kin process, unlike Meta's other products. What it publishes instead is a clock: accounts are "generally deleted after 120 days of inactivity", and a deactivated account "will be deleted 30 days after deactivation if the account isn't re-registered". The messages were never on WhatsApp's servers, so anything that survives is on the person's own phone. Where messages matter to a criminal investigation, that is a matter for the police. WhatsApp is one of the Meta Companies, but it is a separate request from Instagram and Facebook, whose controller is Meta Platforms, Inc. under a different privacy policy with a different postal address and a different registration. Google and Amazon work the same way as WhatsApp — the easy route runs through your own signed-in account. Snapchat gives the same answer about content that has gone: a request cannot produce what has already been deleted, so if something matters, ask early. If a reply arrives and you cannot tell whether it is complete, our free response checker will show you what is missing.
Making a request to an organisation
Made under UK GDPR Article 15
Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.
The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.
What people commonly ask for
- All personal data held about you
- Correspondence and internal notes referring to you
- Account, order or membership history
- Call recordings and chat transcripts
- Marketing preferences and consent records
Watch out for
- Identify the right legal entity — brand names and registered companies often differ.
- Large groups may hold your data across several companies, each a separate controller.
- Be specific about what you want if the organisation is likely to hold a lot.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to WhatsApp
You can do this yourself for free using the details above. WhatsApp's UK privacy form has nowhere to write a request — it collects an email address and a phone number and promises a reply. The data itself comes from a feature inside your own app, so this is a request to make yourself.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.