Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that messages that cannot be immediately delivered to recipients are stored in encrypted form on WhatsApp servers for up to 30 days pending delivery, after which undelivered messages are deleted from servers.
This analysis describes what WhatsApp's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that message content is retained on WhatsApp servers for up to 30 days in circumstances where delivery is not immediate, creating a defined window during which server-side message content could potentially be subject to legal process or government requests as described elsewhere in the policy.
The updated policy removes an unconditional statement of intent and replaces it with conditional language: 'We have no intention to introduce them, but if we ever do, we will update this Privacy Policy.' This revision reserves WhatsApp's right to introduce ad formats in Status and Channels in the future, subject only to updating the privacy policy at that time. The prior language established a stronger commitment; the updated language is more permissive. No specific consumer action is required; the change is informational regarding WhatsApp's future flexibility on advertising formats.
View change record →The updated terms no longer state that WhatsApp has no intention to introduce ads in Status and Channels. Instead, the revised language indicates that if ads are introduced in these features, WhatsApp will update its privacy policy to reflect the change. This means the company has reserved the option to add ads to Status and Channels in the future, subject to policy update notification.
View change record →Under this clause, messages sent to offline recipients are stored in encrypted form on WhatsApp servers for up to 30 days. During this retention window, the messages are stored server-side and are subject to the government disclosure and legal process provisions described in the policy.
Cross-platform context
See how other platforms handle Undelivered Message Retention and similar clauses.
Compare across platforms →Monitoring
WhatsApp has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If a message cannot be delivered immediately (for example, if the recipient is offline), we keep it in encrypted form on our servers for up to 30 days as we try to deliver it. If a message is still undelivered after 30 days, we delete it.Excerpt from WhatsApp's Privacy Policy
(1) REGULATORY LANDSCAPE: Server-side retention of message content, even in encrypted form, implicates the Stored Communications Act for US law enforcement access purposes and GDPR Article 5 data minimization and storage limitation principles for EU users. The 30-day retention period is a defined operational parameter that affects the scope of data subject to legal process. (2) GOVERNANCE EXPOSURE: Low to Medium. The 30-day encrypted retention for undelivered messages is a disclosed, time-limited practice with a defined deletion trigger. The encryption qualifier reduces but does not eliminate exposure to unauthorized access or compelled disclosure, depending on whether WhatsApp holds decryption keys for server-side stored messages. (3) JURISDICTION FLAGS: EU/EEA users benefit from GDPR storage limitation principles that require retention only as long as necessary. The 30-day retention period appears justified by operational necessity (delivery attempts). US law enforcement may be able to compel production of server-stored encrypted messages under the Stored Communications Act. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations relying on WhatsApp for time-sensitive or confidential communications should be aware that delivery failures result in server-side retention for up to 30 days. This may be relevant to information security and records management policies. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should note that the 30-day server-side retention window creates a defined exposure period for undelivered message content. Evaluate whether this retention practice is reflected in data mapping and records of processing activities. For organizations subject to e-discovery obligations, assess whether WhatsApp undelivered message retention creates any litigation hold considerations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that message content is retained on WhatsApp servers for up to 30 days in circumstances where delivery is not immediate, creating a defined window during which server-side message content could potentially be subject to legal process or government requests as described elsewhere in the policy.
Under this clause, messages sent to offline recipients are stored in encrypted form on WhatsApp servers for up to 30 days. During this retention window, the messages are stored server-side and are subject to the government disclosure and legal process provisions described in the policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by WhatsApp.