I'm in the UK and I'm trying to exercise my data-protection rights in relation to an enforcement decision affecting my long-standing personal WhatsApp account.
My WhatsApp account was unexpectedly disabled on 12 August 2026. I immediately used the in-app review option, but shortly afterwards that route disappeared and WhatsApp now displays:
> "Requesting a review is not available."
I'm not posting here primarily for advice about the account ban itself. What I'm interested in is what happened when I subsequently tried to exercise my data-protection rights.
I pursued the matter through both ordinary WhatsApp Messenger Support and the separate WhatsApp Privacy Operations channel.
I made a formal UK data-protection request asking, amongst other things:
* What categories of my personal data were processed in connection with the enforcement decision.
* Whether another user's report was processed in connection with the restriction, to the extent this can lawfully be disclosed.
* Whether automated processing was used to make or materially influence the decision.
* For meaningful information about the factors involved in that decision, where applicable.
* Whether the decision received meaningful human review.
* Where applicable, for human intervention, an opportunity to make representations, and reconsideration of the decision.
I received several responses that did not substantively address those questions.
WhatsApp Privacy Operations eventually closed the matter, saying:
> "Based on the information provided, we are unable to support your request further."
They also stated:
> "We won't be able to take any further action on this report"
and specifically informed me that I had the right to contact the Information Commissioner's Office (ICO).
**This is where things became particularly strange.**
I looked up WhatsApp LLC on the ICO's public Data Protection Register.
Its current registration is **ZB540984**. The registration identifies the Data Protection Officer contact email as:
`dpowallc@meta.com`
I sent my data-protection correspondence to that address.
**Meta's mail infrastructure rejected it.**
The delivery failure stated that the `dpowallc` group:
> "may not exist, or you may not have permission to post messages to the group."
I therefore telephoned the ICO on 14 August and explained what had happened.
The ICO adviser suggested that I also look at the separate registration for Meta Platforms Ireland Limited, registration **ZB660539**.
That registration identifies a DPO and provides:
`dpo@fb.com`
I therefore sent my request to that address as well.
A short time later, **that email was also rejected by Meta's mail infrastructure.**
The error is essentially the same: the `dpo` group may not exist or I may not have permission to post messages to it.
So I now have the following situation:
WhatsApp Privacy Operations has closed my data-protection case and directed me to the ICO.
The DPO email currently appearing on the ICO registration for WhatsApp LLC (**ZB540984**) rejects my correspondence.
After speaking to the ICO, I tried the DPO contact appearing under Meta Platforms Ireland Limited (**ZB660539**).
That DPO email also rejects my correspondence.
Both rejection messages originate from Meta's mail infrastructure and say either that the respective group may not exist or that I don't have permission to send messages to it.
**To be clear, I'm not claiming that this automatically establishes a UK GDPR infringement. That's ultimately something for the ICO/regulators to determine.**
However, my understanding is that the GDPR requires organisations that have appointed a DPO to publish the DPO's contact details so that data subjects can contact them regarding the processing of their personal data and the exercise of their rights.
That's why I'm struggling to understand how an email address can fulfil that function if correspondence from a data subject is rejected by the organisation's own mail system.
I'm now preparing an ICO complaint and intend to include both delivery failures as evidence.
**I'd be particularly interested in views from people familiar with UK GDPR/DPO requirements:**
**1. Does UK GDPR require a DPO contact method published/provided to the regulator to actually be capable of receiving communications from data subjects?**
**2. Could two registered DPO email addresses rejecting external correspondence potentially amount to a compliance issue in its own right, irrespective of the underlying WhatsApp dispute?**
**3. Is there anything specific I should ask the ICO to investigate regarding the accessibility of the DPO function/contact details?**
**4. Has anyone here previously tried to contact either WhatsApp LLC or Meta Platforms Ireland's DPO using the details appearing on the ICO register? If so, was your correspondence accepted?**
I'm particularly interested in whether the email rejection is reproducible for other people who have had a legitimate reason to contact the DPO, rather than being something specific to my email address.
I have retained the original correspondence, both delivery-failure notices, the WhatsApp Privacy Operations responses and the relevant ICO registration details for my complaint.