Studies & referenceStudies & reference

Security and Privacy Checklist for Your Customer Service Team

7 min read

Why this checklist exists (and what it solves)

Serving customers via WhatsApp, Instagram, or Messenger means handling data that isn't yours: names, phone numbers, addresses, payment receipts, sometimes even documents. The problem is that most small teams don't have a written procedure to protect that. Not because they don't care, but because no one sat down to put together the list. The result: each person handles information as they see fit, and when something leaks (a phone number forwarded by mistake, a screenshot that leaves the group, an access left open), there's no protocol to respond.

This checklist is meant to be printed, stuck next to the monitor, and ticked off. It's not theory: each item says what to check and how to know it's right. It's designed for SMEs in Latin America that serve customers with WhatsApp Business, with several agents, or with a tool like wando.online that centralizes messages. It works whether you use the app alone or have a platform.

How to use this checklist

The checklist has four stages: before you start serving, during service, when closing the day, and when something goes wrong. Each item has two parts: the concrete action and the sign that it's okay. If you can't verify the sign, the item is not fulfilled.

StageWhat's checkedSign that it's OK
Before servingTeam access and accountsEach agent has their own user; no one shares passwords or verification phones.
Before servingDevices and networksPhones and computers have PIN or lock; no open Wi-Fi without a password.
During serviceHandling personal dataNo unnecessary data is requested; what is requested is stored only in the management system.
During serviceScreenshots and forwardsNo screenshots of conversations with customers are taken; no messages are forwarded to internal groups.
When closing the dayLogout and backupsSessions are closed on shared devices; backups are activated.
When closing the dayAccess reviewNo agents have access who no longer work at the business.
When something goes wrongIncident response planA document with steps to follow exists; the team knows who leads the response.
Operational checklist. Adapt it to your size: a 2-person business doesn't need the same as a 15-person one.

Stage 1: Before you start serving

What is configured before serving defines 80% of security. If access is poorly set up, nothing you do later fully corrects it.

  • Each agent has their own user in the messaging tool. If you use WhatsApp Business on a single phone, define who is responsible and who replaces them when they are not available.
  • Passwords are not shared. If someone writes them down on paper, that paper is visible to customers or colleagues.
  • The phone that receives verification codes is not a personal phone: it is a business number with controlled access.
  • Devices (cell phones, tablets, computers) have lock by PIN, fingerprint, or pattern, with a short timeout (less than 5 minutes).
  • The store's Wi-Fi network has a password. If it is a public venue, the customer network is separate from the work network.
  • Messaging applications are updated. Old versions have known vulnerabilities.

If you use a platform like wando.online, each agent logs in with their own user and the password is not shared. That already solves the first point.

Stage 2: During service

This is where the most data leaks occur, almost always due to carelessness rather than malice. The customer sends their address, someone responds with a forward that included another customer's phone number, or an ID is requested that is not needed.

  • Only data strictly necessary for the operation is requested. If the customer asks about the price of a product, their ID is not needed.
  • The data requested (name, phone, address) is entered into the management system or the messaging tool. It does not remain in loose notes, screenshots, or the phone's notepad.
  • Screenshots of customer conversations are not taken. If you need to show something to a colleague, copy the text without personal data.
  • Customer messages are not forwarded to internal groups. If the team needs to see a conversation, use the tool's sharing feature (which does not expose the number) or mention it without quoting.
  • Customer audio messages are not forwarded. If they need to be listened to as a team, use headphones and do not share the file.
  • Response templates do not include personal data from other customers. Before sending a campaign, check that the name field is correctly merged.

Stage 3: At the end of the day

Closing the day is the time to check that nothing was left open. Five minutes that prevent a lost phone or a forgotten session from becoming a leak.

  • WhatsApp Web or messaging tool sessions are left closed on shared devices. If everyone uses their own computer, locking the screen is enough.
  • Business devices are stored under lock and key or in a place not accessible to the public.
  • A backup of conversations is made, if the tool allows it. WhatsApp has automatic backup; platforms like wando.online save the history in the cloud.
  • The list of agents with access is reviewed: if someone resigned or no longer works, their user is deactivated the same day.
  • Anything unusual that happened is noted in a visible place (or in a shared document): a strange message, a file that was not opened, an access attempt.

Stage 4: When something fails

Failures happen. What separates a team that handles an incident well from one that handles it poorly is having a written plan before it happens. This is the minimum plan.

  1. 1Detect: someone on the team notices that data was leaked, an account was accessed without authorization, or a message was sent to the wrong recipient.
  2. 2Contain: the password of the affected account is changed, the session is closed on all devices, and the rest of the team is notified so they don't continue using that account.
  3. 3Assess: define which data was leaked (phone, address, receipt) and how many people it affects. Review the conversation history to see the scope.
  4. 4Notify: inform the affected client, with honesty and without excuses. If the data is sensitive (document, payment), offer a clear explanation of what happened and what was done to contain it.
  5. 5Document: write a brief summary of the incident, what caused it, and what was changed to prevent it from happening again. That summary is saved and reviewed at the next team meeting.

Warning signs: how to detect that something is not right

Not every incident starts with an error message. Often the sign is subtle: strange behavior, an access that shouldn't be there, a file that no one sent. This table helps recognize the signs before the problem grows.

SignalWhat might be happeningWhat to do
An agent sees conversations they didn't handleThe session was left open by another user or there is shared accessLog out, review who has access, change password if necessary
Client messages arrive that no one sentSomeone has access to the account and is using it without authorizationChange password, close sessions, review activity history
A client says they received a message that wasn't for themA template with badly merged data was sent or a conversation was forwarded by mistakeReview the template, fix the merge, notify the client and apologize
Strange files or links appear in the chatThe team or a client opened a malicious fileDon't open, notify the team, scan the device, review security settings
A former employee can still access the systemThe user was not deactivated when they leftDeactivate the user immediately, check if they accessed after the departure date
If you see a sign, don't ignore it: most leaks are detected late because no one said anything in time.

Frequently asked questions

Short answers to the most common questions when you start with this checklist.

  • How often should the checklist be reviewed? Once a week is enough for a small team. If there are staff changes, it is reviewed the same day.
  • What do I do if I don't have a management tool and I handle everything from my cell phone? The checklist works the same: the important thing is that access is individual, that no screenshots are taken, and that the phone is locked.
  • Are platforms like wando.online more secure than the WhatsApp app? They centralize access, keep history, and allow disabling users. That is already a big improvement over a shared phone.
  • Do I need a lawyer to draft the privacy policy? For an SME, not at the start. An internal document stating what data is handled, who has access, and what is done in case of an incident is enough. If you grow, then it is advisable to get legal advice.

What Wando does in security (and what it doesn't)

Wando (wando.online) is an Argentine platform that centralizes WhatsApp, Instagram, and Messenger messages in a single inbox, with AI suggestions that the team approves before sending. In terms of security, the relevant thing for this checklist is that each agent logs in with their own user, passwords are not shared, and history is stored in the cloud. What Wando does not do is replace the team's judgment: it remains the business's responsibility to decide what data is requested, how it is handled, and what is done in case of an incident. The tool does not exempt you from having the checklist.

If you want to go deeper into how to estimate how many people your team needs to serve well, or how to measure whether customer service improved, that is a topic for other articles. Here the focus is on security.

Frequently asked questions

How often should we review the security checklist?+

Once a week is enough for a small team. If there are staff changes, review it the same day. If you've had an incident, review it as soon as the response is over.

Does this checklist work if I handle messages from my phone and don't use a platform?+

Yes. The checklist works the same: the key is that access is individual, no screenshots are taken, and the phone is locked. A platform like Wando centralizes access and stores the history, but it doesn't replace the team's judgment.

What do I do if a customer complains about a data leak?+

Let them know honestly, tell them what happened and what you did to contain it. Then document the incident and review the checklist to prevent it from happening again. Don't promise things you can't deliver.

Do I need a lawyer to set up the privacy policy?+

For an SME, not at first. An internal document stating what data is handled, who has access, and what to do in case of an incident is enough. If you grow or handle sensitive data, then it's worth getting advice.

Answer WhatsApp with AI

Try Wando free. No credit card required.

Create free account