GDPR-compliant messenger for companies (2026): what the vendors actually document
"Which messenger is GDPR-compliant?" is a question no vendor can honestly answer with "we are". The GDPR puts the obligations on you, the controller: you need a data processing agreement (Art. 28), you need to know where the data sits and whether it crosses into a third country, you need to be able to delete and to answer access requests. A messenger can make those obligations fulfillable — or not. A badge on a homepage says nothing more than that.
So this guide does something different from the usual lists. It takes six checks a data protection officer asks anyway and applies them to twelve services: the consumer messengers that companies actually run on (WhatsApp, Signal, Telegram), the business messengers from Switzerland and Germany (Threema Work, Teamwire, Wire, Stackfield), the self-hosted platforms (Element, Mattermost, Rocket.Chat) and the two bundles (Microsoft Teams, Slack). Then InterMIND, which we build — on the same criteria and with the same sourcing rule. Every statement comes from the vendor's public documentation, checked August 2026, linked at the end.
A seventh check joins them, one that never appears on GDPR lists and matters every day in an international team: in which language does each member read the channel? A messenger that stores messages only in the original pushes translation onto the individual — and onto services that then process data again.
The six checks
Germany's Federal Commissioner for Data Protection (BfDI) publishes selection criteria for messenger services, the most usable public yardstick. They define end-to-end encryption as messages "encrypted on the sender's device and only decrypted again on the recipient's device", list privacy settings such as address-book access, profile visibility, read receipts, usage analytics and error reporting, and require account deletion where data is "deleted immediately". For company use, the Art. 28 obligations come on top. Together:
- Data processing agreement (DPA). Does the vendor offer one — and is it in their documentation?
- Entity and server location. Which company is your contracting party, where does the data sit, is there a third-country transfer?
- Encryption. End-to-end, or transport and server-side? Both are legitimate — they just have to be named.
- Metadata and address book. Is the address book uploaded? Which usage and device data is collected, and who is it shared with?
- Deletion and retention. Where does the history live, who deletes it, what happens when an employee leaves?
- Sub-processors. Are they published — including the services used for AI features and translation?
Plus the seventh: language per member.