Can a Belgian dental practice message patients on WhatsApp?

No Belgian authority has banned WhatsApp for dentists, and none has approved it. The Data Protection Authority, the eHealth platform, RIZIV/INAMI and the dental associations have published no guidance on it. What applies is the GDPR and Belgian health law, and they already make a plain appointment message health data. Using WhatsApp therefore means choosing the version on purpose, keeping messages to logistics, and recording who reads them.

Last updated

What do Belgian authorities say about WhatsApp?

Nothing that names WhatsApp. The Data Protection Authority has no opinion on messaging apps in care, nor do the eHealth platform and RIZIV/INAMI, and the dental associations publish nothing on it. Belgium also has no Order of dentists: the VVT itself writes that dentistry has no disciplinary body.

The code of ethics the VVT publishes does not mention messaging apps, but it says two things that matter here. A copy of the record goes to the patient by a secure electronic route, not by ordinary e-mail. And professional secrecy also binds the administrative staff who handle patient data, which includes whoever reads the practice’s WhatsApp.

The closest Belgian texts come from the Order of Physicians, and they bind doctors, not dentists. In its advice, the Order limits electronic contact with patients to administrative information and rules out sending medical data by unsecured e-mail, even with the patient’s consent. That is a useful yardstick, not a rule for your practice.

VVT, code of ethics for dentists, May 2023 version (in Dutch)

Is an appointment message health data?

It can be, and the safe course is to treat it that way. The EU Court of Justice ruled in 2024 that data count as health data as soon as something about a person’s health can be deduced from them, by combining or reasoning. Knowing that someone is due at the dentist on Thursday at 14:30 already says something.

That does not make WhatsApp forbidden. A dentist may process health data to provide care under Article 9(2)(h) of the GDPR, because dentists are bound by professional secrecy. Patient consent is therefore not the only route. It does mean that the security, the access and the content of those messages matter.

Court of Justice of the EU, case C-21/23 Lindenapotheke, 4 October 2024, paragraph 83

Which WhatsApp: the ordinary app, the Business app or the Business Platform?

There are three, and they promise different things. The ordinary app and the WhatsApp Business app encrypt chats end to end, but for the Business app Meta signs processor terms only for contact data, not for messages. Meta also states that it makes no warranty that the Business app meets the needs of regulated sectors such as health care.

The WhatsApp Business Platform, the Cloud API, works the other way round. There Meta Platforms Ireland processes the messages as the practice’s processor, keeps them for at most 30 days and can store them in the EU. In exchange, those chats are not end-to-end encrypted to the practice: the Cloud API decrypts the message on Meta’s servers, and WhatsApp shows the patient this in the chat.

Read in the WhatsApp and Meta terms and documentation on 27 September 2026.
Ordinary appBusiness appBusiness Platform (Cloud API)
Processor terms with MetaNone foundContact data onlyYes, for messages
End-to-end encrypted to the practiceYesYes, by defaultNo, and WhatsApp says so in the chat
Where messages are heldOn the phonesOn the phonesAt Meta, 30 days at most, EU storage available
What Meta says about health careNothingNo warranty for regulated sectors such as health careNo health information where local rules require stronger systems

Meta, WhatsApp Cloud API: Data Privacy and Security

What does Meta require of a practice on WhatsApp?

WhatsApp’s business policy sets a few rules that matter straight away for a dental practice:

  • You only message people who gave you their number and agreed to hear from you. That agreement can be collected on paper or at the desk.
  • Anyone who wants to stop gets no more messages, even if they ask outside WhatsApp.
  • On the Business Platform, the practice opens a conversation only with a pre-approved template. Within 24 hours of the patient’s last message, you reply freely.
  • An automated conversation must offer a quick, clear route to a person.
  • You do not ask for identity card numbers or other sensitive identifiers, so the national register number does not belong in a WhatsApp chat.
  • No health information where local rules require stronger systems. The policy does not forbid appointment messages.

WhatsApp Business Messaging Policy, updated 23 September 2026

What goes in a WhatsApp message, and what does not?

Keep it to logistics: the practice name, the day, the time and a way to reply or reschedule. The treatment, a diagnosis or a complaint do not belong in it. Examples written that way are in the dental appointment reminder text templates.

If a patient sends something clinical anyway, such as a photo of a swollen cheek or a description of the pain, whatever is relevant goes into the patient record. Belgian quality law asks that the record reflect conversations with the patient and that you keep it for 30 to 50 years. A WhatsApp chat is not that record, and it is better if it never becomes one.

A patient in pain deserves a person, not a message. Say in your automatic replies where they can turn.

Law of 22 April 2019 on quality of practice in health care, articles 33 and 35 (in Dutch)

What should the practice put on record?

Four things, and most practices already have them for their diary and software:

  • WhatsApp as a processing activity in the record of processing. A practice keeps that record whatever its size, because it handles health data.
  • The list of people with access to health data, with their duty of confidentiality. The Belgian law of 30 July 2018 asks for that list explicitly, and whoever reads the practice’s WhatsApp is on it.
  • A processor agreement with every provider that handles the messages for you.
  • A decision on a data protection impact assessment. For one practice messaging its own patients, it is not on the Data Protection Authority’s mandatory list, and the GDPR does not treat the patient data of a single health professional as large-scale processing.

Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, article 9 (in Dutch)

How do the Netherlands and France see it?

Differently, and neither is Belgian law. In the Netherlands, the dental association KNMT mentions a text or a WhatsApp message as an ordinary appointment reminder, while the health ministry’s GDPR helpdesk advises against WhatsApp for patient information.

In France, the CNIL names legitimate interest as the legal basis for booking appointments in a health practice, and asks that instant messaging be used with the greatest caution and securely.

CNIL, framework for personal data processing in medical and paramedical practices, 2020 (in French)

How does Tilcao use WhatsApp?

Tilcao runs on Meta’s WhatsApp Business Platform, on the practice’s own number. The practice is the controller, Tilcao is its processor, and Meta is named as a sub-processor in the annex to the processing agreement. Outside the 24-hour window Tilcao uses approved templates, and a patient who asks for a person gets one.

To be plain about it: on the Business Platform, messages are not end-to-end encrypted to the practice, and WhatsApp tells the patient so. Tilcao also never asks for an identity card number: it recognises a patient by date of birth plus name or phone number. More on the processing is on security and GDPR.

Questions practices ask

Can I use my personal WhatsApp for the practice?

WhatsApp’s terms do not expressly forbid it, but there is no processor agreement, the messages sit on a personal phone, and the law asks you to record who can read health data. A practice number on the Business app or the Business Platform keeps patient messages apart from your private ones.

Under the GDPR, consent is not the only basis: a dentist processes health data to provide care, under professional secrecy. Meta does require that the patient gave their number and agreed to messages from the practice. That can be collected on paper or at the desk, and anyone who stops receives nothing more.

Can a patient send a photo of their tooth on WhatsApp?

They can, and they do. If the photo says something clinical, it goes into the patient record, which you keep for 30 to 50 years. The WhatsApp chat is not that record. Agree with your team what happens to such a photo once it is in the record.

Has the Data Protection Authority approved WhatsApp for dentists?

No, and it has not banned it either. The authority has published no opinion on messaging apps in care, and neither have the dental associations. Anyone who says WhatsApp is GDPR-compliant or forbidden for dentists has no official Belgian text behind it.

Tilcao is the operating system for dental practices in Belgium: its AI receptionist answers patient calls and WhatsApp messages in Dutch, French and English, and books, moves and cancels appointments in the practice’s own diary.

Next step

See what your practice could automate.

We’ll map your biggest administrative and revenue-leakage opportunities and show you what Tilcao could handle.

30 minutes. Bring your schedule; we bring the demo practice.

Or call Tilcao: +32 460 23 23 00WhatsApp

You are the patient. Tilcao answers day and night, in Dutch, French and English. Calls are recorded. Privacy

Rather write? martin@tilcao.com

Book a demo

Loading the calendar