ProtonBlog(new window)
An illustration of WhatsApp after its new privacy policies are implemented.

WhatsApp’s new privacy policy makes it less private

Share this page

Facebook, the owner of WhatsApp, has forced an ultimatum upon WhatsApp’s users: share future transactional data and metadata from the end-to-end encrypted messenger with Facebook, or lose access to your WhatsApp account. 

Users are being informed of this new requirement via an in-app notification. If they do not accept the sweeping changes to WhatsApp’s terms of service and privacy policy by May 15 (originally Feb. 8), they will be locked out of their WhatsApp account.

It is important to note that this does not change the amount of data WhatsApp currently collects, but opens the door for more data collection in the future. For anyone who opted out of letting Facebook use their WhatsApp info for commercial purposes in 2016, WhatsApp says it will still honor that choice. 

In a victory for the EU’s privacy legislation, Facebook is also not able to use WhatsApp users’ data for ads if they live in Europe (and the post-Brexit UK), although these users will need to accept new terms.

Opening up WhatsApp to collect transactional data continues its slide from a relatively private messaging service to just another part of Facebook’s panopticon, something critics have been anticipating ever since Facebook purchased the company in 2014. This change means that all of WhatsApp’s over two billion users will have to give their personal data to the same company notorious for its disregard for privacy. Facebook enabled the Cambridge Analytica scandal(new window), conducted mass psychological experiments(new window) without consent, and created today’s toxic information environment by targeting users with sensational ads and posts(new window) on the basis of their personal beliefs.

Many early users joined WhatsApp because of its commitment to privacy. But now WhatsApp is an important cautionary tale of how ruthless companies can be when trying to get their hands on user data.

WhatsApp privacy — then and now

WhatsApp was originally conceived in 2009 as a messenger that would have no ads, no games, and no gimmicks. In 2014, when Facebook first took a stake in WhatsApp, one of its founders addressed its users’ privacy concerns in a blog post(new window) saying, “Respect for your privacy is coded into our DNA, and we built WhatsApp around the goal of knowing as little about you as possible.” 

In 2016, it was one of the first messaging services to introduce end-to-end encryption to all its messages using the open source Signal Protocol shortly after Facebook completed its purchase. At the time, it was probably the largest proliferation of end-to-end encrypted messages in history. 

Unfortunately, Facebook considers privacy an impediment to its business model of collecting and monetizing its users’ personal data. Since 2016, WhatsApp has collected the following data and adds it to your Facebook profile:

  • Your WhatsApp phone number
  • Your profile name
  • Your profile picture 
  • Your status message 
  • A timestamp from when you were last online
  • Diagnostic data collected from app logs

According to WhatsApp’s global privacy policy(new window), it is part of Facebook’s “family of companies.” As such, Facebook may use the information it takes from WhatsApp to help it operate (presumably operation includes generating revenue by using the personal data for targeted ads) and market its services, including other Facebook products. 

However, the same section in the privacy policy(new window) that covers the European Economic Area adds the following line: “Any information WhatsApp shares on this basis cannot be used for the Facebook Companies’ own purposes.” How Facebook will handle WhatsApp’s data from Europe is still murky, so much so that the Italian data protection agency(new window) warned the social network that it must clarify its privacy policy for the EEA.

Besides WhatsApp, the best-known Facebook brands are Facebook, Messenger, Instagram, Oculus, Portal-branded devices, Facebook Shops, Spark AR Studio, and the Audience Network, which is an off-Facebook in-app advertising network(new window) for mobile apps. Considering that all of these services collect their own types of data, the fact they can all be combined gives Facebook the ability to compile a massive dossier of personal data on each of its users. 

The crucial part of this pop-up is the second point, which explains how Facebook is trying to find ways to monetize WhatsApp with WhatsApp Business. In the future, WhatsApp all allow businesses to contact and communicate with WhatsApp users via the app. Businesses can also choose to be hosted on Facebook, which means the communications between you and that business could be stored and managed by Facebook, giving it the ability to access and share those conversations within the company. This new data will be added to the dossier Facebook has on you, allowing it to more finely target you with ads, but also increasing the amount of data authorities can collect with a data request(new window).

Why privacy must be at the heart of services you use

In short, while Facebook is not interfering with WhatsApp’s end-to-end encryption, it is attempting to collect and monetize as much of its users’ data as it can. End-to-end encryption is a powerful tool, but it is not sufficient to keep all your personal data secure, especially if an organization’s revenue relies on the collection of personal data. As the current WhatsApp example shows, if a company relies on the collection of its users’ data to sell ads, it will do anything to collect and monetize more personal information.

It appears users are fed up with Facebook’s constant attempts to grab more of their data. Shortly after these in-app notifications began popping up for users, subscriptions to more private messaging services, such as Signal and Telegram(new window), have skyrocketed.

People have also turned to Proton Mail to keep their data safe. The number of people opening a Proton Mail account has tripled in recent weeks.

People are choosing Proton Mail because we do more than just use end-to-end encryption and zero-access encryption to protect your messages. We also bolster this protection by minimizing the amount of data we collect for an account and using a business model that respects your right to privacy. (See our privacy policy(new window).) We are also based in Switzerland, where metadata is subject to stringent privacy protections. Unlike Facebook, we do not sell the minimal personal information we have to advertisers or share it with anyone else. 

Instead, Proton Mail is supported by users that sign up for paid plans, which offer additional storage and features and priority customer support. These paid plans make up the entirety of our revenue (aside from what we sell in the ProtonShop). Users sign up for Proton Mail to keep their personal data secure, which means we have every incentive to protect their privacy. Our subscription business model ensures that our interests and our users’ interests are aligned. 

True online privacy means creating an internet that serves people, not companies. To achieve this, you need more than just strong technical solutions. You also need to have the right to privacy enshrined in law and business models that put their users’ rights first. We believe our business model is helping us change the internet for the better, and we thank all our users who have subscribed to a paid plan.

Frequently asked questions about WhatsApp`s privacy policy

What if I don’t agree to this change in WhatsApp’s privacy policy?

Unfortunately, if you don’t want WhatsApp to collect your future transactional data, there is not a lot you can do if you still want to use WhatsApp. Facebook has delayed kicking users off the platform until May 15. You’ll be able to use WhatsApp until then without making any changes. However, if you still have not accepted these changes by that date, Facebook will lock you out of your account until you do.

If I accept this new privacy policy, will Facebook be able to read my messages?

No. This new privacy policy will allow Facebook to access transactional data However, the end-to-end encryption used to protect your messages is, for now, not being touched. The messages between you and your contacts will remain inaccessible to everyone else.

Messages you send to businesses that use WhatsApp business or are otherwise hosted by Facebook may be subject to different privacy standards.

How can I protect my privacy on WhatsApp?

There is no way to avoid WhatsApp’s new privacy policy while still using the app, and Facebook offers its users few privacy controls. Depending on your threat model, you may decide that WhatsApp is still private enough for you.

However, if you find WhatsApp’s new collection and sharing of personal data excessive, you will need to switch to a new messenger service.

Updated on Jan. 18, 2021, after Facebook issued clarifications regarding WhatsApp’s new privacy policy.


Feel free to share your feedback and questions with us via our official social media channels on Twitter(new window) and Reddit(new window).

Protect your privacy with Proton
Create a free account

Share this page

Richie Koch(new window)

Prior to joining Proton, Richie spent several years working on tech solutions in the developing world. He joined the Proton team to advance the rights of online privacy and freedom.

Related articles

Can you password-protect a folder in Google Drive?
Protecting a folder with a password is a simple yet effective way of securing files. You may wonder whether you can password-protect a folder in Google Drive. We explain what access controls Google Drive offers and what you can do to improve your sec
Proton Pass now supports passkeys on all devices and plans
We’re excited to announce that Proton Pass supports passkeys for everyone, allowing you to manage and use passkeys across all devices seamlessly. Passkeys are an easy and secure alternative to traditional passwords that can help prevent phishing atta
what is a passkey?
Passkeys are a new way to secure your online accounts using cryptographic keys instead of passwords. They offer a high level of convenience and security, and are a real game-changer in the way we access and secure sites. What is a passkey, though, an
Apple’s marketing team has built a powerful association between the iPhone and privacy. The company’s ad campaigns claim that “what happens on your iPhone, stays on your iPhone.” And, “Privacy. That’s iPhone.” But Apple’s lawyers are telling a diffe
A cyberattack on national public employment service France Travail has exposed the personal data of as many as 43 million people.  The latest breach is the second major cybersecurity attack to happen in France in the past month, raising concerns abo
If I share a folder in Google Drive, can anybody see my other folders
Google Drive makes it easy to share files and folders, but you may have wondered at some point whether the people you’ve shared a folder with can see your other folders. We answer this question below and also share some tips for truly secure link sha
In 2014, Proton Mail was introduced as a web app, revolutionizing how we think about email privacy. Today, we’re excited to broaden the horizons of secure communication by launching the Proton Mail desktop app. Anyone can now use the new Proton Mail