Facebook, the owner of WhatsApp, has forced an ultimatum upon WhatsApp’s users: share future transactional data and metadata from the end-to-end encrypted messenger with Facebook, or lose access to your WhatsApp account.
It is important to note that this does not change the amount of data WhatsApp currently collects, but opens the door for more data collection in the future. For anyone who opted out of letting Facebook use their WhatsApp info for commercial purposes in 2016, WhatsApp says it will still honor that choice.
In a victory for the EU’s privacy legislation, Facebook is also not able to use WhatsApp users’ data for ads if they live in Europe (and the post-Brexit UK), although these users will need to accept new terms.
Opening up WhatsApp to collect transactional data continues its slide from a relatively private messaging service to just another part of Facebook’s panopticon, something critics have been anticipating ever since Facebook purchased the company in 2014. This change means that all of WhatsApp’s over two billion users will have to give their personal data to the same company notorious for its disregard for privacy. Facebook enabled the Cambridge Analytica scandal, conducted mass psychological experiments without consent, and created today’s toxic information environment by targeting users with sensational ads and posts on the basis of their personal beliefs.
Many early users joined WhatsApp because of its commitment to privacy. But now WhatsApp is an important cautionary tale of how ruthless companies can be when trying to get their hands on user data.
WhatsApp privacy — then and now
WhatsApp was originally conceived in 2009 as a messenger that would have no ads, no games, and no gimmicks. In 2014, when Facebook first took a stake in WhatsApp, one of its founders addressed its users’ privacy concerns in a blog post saying, “Respect for your privacy is coded into our DNA, and we built WhatsApp around the goal of knowing as little about you as possible.”
In 2016, it was one of the first messaging services to introduce end-to-end encryption to all its messages using the open source Signal Protocol shortly after Facebook completed its purchase. At the time, it was probably the largest proliferation of end-to-end encrypted messages in history.
Unfortunately, Facebook considers privacy an impediment to its business model of collecting and monetizing its users’ personal data. Since 2016, WhatsApp has collected the following data and adds it to your Facebook profile:
- Your WhatsApp phone number
- Your profile name
- Your profile picture
- Your status message
- A timestamp from when you were last online
- Diagnostic data collected from app logs
Besides WhatsApp, the best-known Facebook brands are Facebook, Messenger, Instagram, Oculus, Portal-branded devices, Facebook Shops, Spark AR Studio, and the Audience Network, which is an off-Facebook in-app advertising network for mobile apps. Considering that all of these services collect their own types of data, the fact they can all be combined gives Facebook the ability to compile a massive dossier of personal data on each of its users.
The crucial part of this pop-up is the second point, which explains how Facebook is trying to find ways to monetize WhatsApp with WhatsApp Business. In the future, WhatsApp all allow businesses to contact and communicate with WhatsApp users via the app. Businesses can also choose to be hosted on Facebook, which means the communications between you and that business could be stored and managed by Facebook, giving it the ability to access and share those conversations within the company. This new data will be added to the dossier Facebook has on you, allowing it to more finely target you with ads, but also increasing the amount of data authorities can collect with a data request.
Why privacy must be at the heart of services you use
In short, while Facebook is not interfering with WhatsApp’s end-to-end encryption, it is attempting to collect and monetize as much of its users’ data as it can. End-to-end encryption is a powerful tool, but it is not sufficient to keep all your personal data secure, especially if an organization’s revenue relies on the collection of personal data. As the current WhatsApp example shows, if a company relies on the collection of its users’ data to sell ads, it will do anything to collect and monetize more personal information.
It appears users are fed up with Facebook’s constant attempts to grab more of their data. Shortly after these in-app notifications began popping up for users, subscriptions to more private messaging services, such as Signal and Telegram, have skyrocketed.
People have also turned to ProtonMail to keep their data safe. The number of people opening a ProtonMail account has tripled in recent weeks.
Instead, ProtonMail is supported by users that sign up for paid plans, which offer additional storage and features and priority customer support. These paid plans make up the entirety of our revenue (aside from what we sell in the ProtonShop). Users sign up for ProtonMail to keep their personal data secure, which means we have every incentive to protect their privacy. Our subscription business model ensures that our interests and our users’ interests are aligned.
True online privacy means creating an internet that serves people, not companies. To achieve this, you need more than just strong technical solutions. You also need to have the right to privacy enshrined in law and business models that put their users’ rights first. We believe our business model is helping us change the internet for the better, and we thank all our users who have subscribed to a paid plan.
Unfortunately, if you don’t want WhatsApp to collect your future transactional data, there is not a lot you can do if you still want to use WhatsApp. Facebook has delayed kicking users off the platform until May 15. You’ll be able to use WhatsApp until then without making any changes. However, if you still have not accepted these changes by that date, Facebook will lock you out of your account until you do.
Messages you send to businesses that use WhatsApp business or are otherwise hosted by Facebook may be subject to different privacy standards.
However, if you find WhatsApp’s new collection and sharing of personal data excessive, you will need to switch to a new messenger service.