In re: WhatsApp
- WhatsApp Implements End-to-End Encryption: The messaging service WhatsApp has announced plans to implement end-to-end encryption for Android phones. WhatsApp gained popularity as a pro-privacy alternative to text messaging. However, privacy concerns were raised after Facebook's proposed acquisition of the company. EPIC filed two complaints with the Federal Trade Commission, urging the FTC to block the sale unless adequate privacy safeguards for WhatsApp users were established. The Commission then notified Facebook and WhatsApp that they must honor their privacy commitments to WhatsApp users. Now, WhatsApp has adopted the Open Whisper Systems protocols to ensure that users' messages are encrypted from sender to receiver and not simply between the user and the service provider. For more information, see EPIC: In re: WhatsApp. (Nov. 25, 2014)
- Senator Rockefeller Questions Whisper About Privacy Practices: Senator Rockefeller has asked Whisper to answer several questions about the company's practices and policies. Whisper said that it does not track users and that it respects users' decisions to opt out of geolocational tracking. But the Guardian revealed that Whisper tracks "the precise time and approximate location of all messages" and specifically tracks certain users the company deems "newsworthy." Senator Rockefeller, chair of the Senate Committee on Commerce has asked Whisper to explain its tracking, data retention, and disclosure practices. EPIC has several similar matters pending before the Federal Trade Commission. For more information, see EPIC: WhatsApp, EPIC: Snapchat, and EPIC: FTC. (Oct. 24, 2014)
- EU Launches Investigation Into Facebook Acquisition of WhatsApp: Antitrust officials in the European Union have begun an investigation into Facebook's acquisition of the messaging service WhatsApp. WhatsApp gained popularity based on its pro-privacy approach to user data. Following the announcement of Facebook's plan to acquire the company, EPIC filed two complaints with the Federal Trade Commission, urging the FTC to block the sale unless adequate privacy safeguards for WhatsApp users were established. The Commission then notified Facebook and WhatsApp that they must honor their privacy commitments to users but questions remain about future business practices. Now European antitrust regulators have served Facebook with a questionnaire of more than 70 pages to determine whether the merger violates European antitrust laws. For more information, see EPIC: In re WhatsApp, and EPIC: FTC. (Sep. 2, 2014)
- Google Plans Advertising on Appliances, Including Nest Thermostat: In a letter to the Securities and Exchange Commission, Google announced plans to place targeted ads on Google-controlled appliances. Google wrote that "a few years from now, we and other companies could be serving ads and other content on refrigerators, car dashboards, thermostats, glasses, and watches, to name just a few possibilities." The proposal raises significant privacy concerns for the "Internet of Things." Earlier this year, EPIC warned the FTC about Google's acquisition of Nest Labs, makes of a smart thermostat, that "Google regularly collapses the privacy policies of the companies it acquires." Nonetheless, the Commission approved Google's acquisition without further review. For more information, see EPIC: In re: WhatsApp, EPIC: Google/Doubleclick and EPIC: FTC. (May. 22, 2014)
- FTC Responds to EPIC Complaint on WhatsApp and Privacy: The Federal Trade Commission has notified Facebook and WhatsApp that they must honor their privacy commitments to users. According to the letter from the Director of the FTC Bureau of Consumer Protection, "if the acquisition is completed and WhatsApp fails to honor these promises, both companies could be in violation of Section 5 of the FTC Act and potentially the FTC's order against Facebook." The FTC letter followed a detailed complaint from EPIC and CDD concerning the privacy implications of the $19B sale to Facebook. WhatsApp had assured users of strong privacy safeguards prior to the sale. The FTC letter concludes "hundreds of millions of users have entrusted their personal information to WhatsApp. The FTC staff continue to monitor the companies' practices to ensure that Facebook and WhatsApp honor the promises they have made to those users." For more information, see EPIC: In re: WhatsApp, EPIC: In re: Facebook and EPIC: Federal Trade Commission. (Apr. 10, 2014)
- EPIC Updates Facebook Complaint, Urges Careful Review of WhatsApp Acquisition: EPIC has filed a supplemental complaint regarding Facebook's $19 b purchase of WhatsApp. WhatsApp users had relied on the messing app's pro-privacy practices to protect their personal information, while Facebook regularly incorporates user data from the companies it acquires. In the initial complaint, EPIC urged the Federal Trade Commission to block the sale unless adequate privacy safeguard for WhatsApp user data were established. In the supplemental complaint, EPIC provided more evidence that WhatsApp users object to the acquisition. EPIC also highlighted the importance of the FTC's pre-merger review process. Recently, the Commission approved Google's purchase of Nest Labs without considering the privacy implications for consumers. For more information, see EPIC: In re WhatsApp and EPIC: Federal Trade Commission. (Mar. 21, 2014)
- EPIC Urges FTC Investigation of WhatsApp Sale to Facebook: EPIC has filed a complaint to the Federal Trade Commission concerning Facebook's proposed purchase of WhatsApp. WhatsApp is a messaging service that gained popularity based on its strong pro-privacy approach to user data. WhatsApp currently has 450 million active users, many of whom have objected to the proposed acquisition. Facebook regularly incorporates data from companies it has acquired.The Federal Trade Commission has previously responded favorably to EPIC complaints concerning Google Buzz, Microsoft Passport, Changes in Facebook Privacy Settings, and Choicepoint security practices. However, the FTC approved Google's acquisition of Doubleclick over EPIC's objection. Facebook is currently under a 20 year consent decree from the FTC that requires Facebook to protect user privacy and to comply with the US-EU Safe Harbor guidelines. For more information, see EPIC: In re Google Buzz, EPIC: Microsoft Passport, EPIC: In re Facebook, and Privacy? Proposed Google/DoubleClick Merger. (Mar. 6, 2014)
WhatsApp is a text messaging application for smartphones that uses the internet, rather than an SMS plan, to send messages. The WhatsApp website describes the service: "WhatsApp Messenger is available for iPhone, BlackBerry, Android, Windows Phone and Nokia and yes, those phones can all message each other! Because WhatsApp Messenger uses the same internet data plan that you use for email and web browsing, there is no cost to message and stay in touch with your friends." WhatsApp was launched in 2009 by former Yahoo! engineers Jan Koum and Brian Acton.
Aside from allowing users to send text messages outside of an SMS plan, WhatsApp's most salient feature is its rejection of in-app advertisements. Since in-app advertisements normally rely on data collected from the user's mobile device in order to propagate, WhatsApp has, as a corollary, established a policy of not collecting or storing users' data.
Relying on these representations, users signed up for WhatsApp by the millions. On August 23, 2012, WhatsApp processed ten billion user messages. On June 13, 2013, processed 27 billion user messages. As of December 2013, WhatsApp claimed that 400 million active users use the service each month. And as of the end of February 2014, WhatsApp boasted 450 million users worldwide.
The Proposed Facebook Acquisition
On February 19, 2014, Facebook announced that it had agreed to purchase WhatsApp for $19 billion. Facebook also operates a messaging service, although Facebook messaging is notorious for its extensive data collection practices. When Facebook revamped its messaging system in November 2010, it automatically opted in all Facebook users and initially disabled users’ ability to delete individual messages. Without user consent, the new messaging system also pulled data from Facebook’s social graph to prioritize messages from certain users. Currently, even when users delete a message, it continues to be stored on Facebook’s servers. At the end of 2013, Slate reported that even when a user chooses not to send a message, Facebook still tracks what the user wrote.
Facebook has regularly collected user data from companies it acquires. For example, when Facebook purchased Instagram in 2012, Instagram users were not subjected to advertisements based on the content they uploaded to the site. Like WhatsApp, Instagram’s Terms of Service included a provision that in the event of acquisition, users’ “information such as name and email address, User Content and any other information collected through the Service may be among the items sold or transferred.” After the acquisition, Facebook did in fact access Instagram users’ data and changed the Instagram Terms of Service to reflect this change. Now, users, industry experts, and foreign governments are already objecting to the privacy risks posed by Facebook's agreement with WhatsApp.
WhatsApp Users Object to the Facebook Acquisition
- Aliya Abbas, a Delhi-based mediaperson, said, “I started using WhatsApp five months ago. If it gets integrated with Facebook, I will uninstall [WhatsApp]. And I think others will do the same if this happens. WhatsApp is popular because of its privacy, and I don't think users will like the idea of advertisements popping up in the middle of a conversation.”
- Columnist Carly Page wrote, “I'm a user of Whatsapp, and of course Facebook’s ridiculously expensive acquisition of the firm has got me concerned about my privacy, especially the fact that the social network likely now has access to my mobile phone number.”
- Journalist Tali Arbel wrote:
“WhatsApp is my respite from Facebook. For me, the world's largest social network has become a junkyard of updates from people I don't really know and ads for products I don't care about. It's all about people jostling for publicity and craving approval, seeking likes and comments from near-strangers. But WhatsApp is the best stand-in for a conversation you have over dinner with people you love. It's intimate. It's personal. I rely on it. […] Facebook says it won’t run ads on WhatsApp. But I'm afraid they won't be able to help themselves. With all those food pictures, won't Facebook figure I want to see ads for restaurants and cookware? And will Facebook urge my ‘friends’ to connect with me on WhatsApp? Facebook has done something similar with Instagram, the photo-sharing app it has owned since 2012.”
- Corley Paige, a product developer from Austin, Texas, wrote, “I suddenly want to delete my Whatsapp. Hello Viber.”
- Twitter user Tara Aghdashloo wrote, “Facebook is like an evil parent that keeps finding the new hiding place for your diary.”
- User @tabandchord posted to Twitter, “Facebook + WhatsApp = The Ultimate Spying Machine #facebook #WhatsApp.”
- Some users of both WhatsApp and Facebook created a Facebook Page titled “Please Don’t Ruin WhatsApp.” Under the designation “Community description,” the page creators posted, “Hey Facebook: Please don't ruin WhatsApp and make all of our message go through Facebook Messenger.”
Industry Experts Are Warning that the Merger Will Diminish User Privacy
Industry experts object to the Facebook acquisition because it allows Facebook access to the repository of mobile phone numbers that WhatsApp has collected.
Wim Nauwelaerts, a lawyer specializing in EU data protection law at Hunton & Williams, LLP in Brussels, told Bloomberg, “Facebook is not only buying a popular messaging app, it is also acquiring the addresses and telephone numbers of 450 million users worldwide. […] Many of these users are already signed up to Facebook, so through this deal Facebook will be able to build complete profiles on users.”
St. John Deakins, the head of the online identity monitoring application Citizenme, said, “Facebook already has a very broad copyright license on people's content and already shares your data with many other services. Now with Facebook buying Whatsapp, this could see more and more private information becoming part of Facebook's database. From a personal data standpoint, this is extremely worrying.”
Tim Grossman, a senior branding consultant at Brand Union, wrote in The Guardian:
“One of the reasons why so many millions have flocked to WhatsApp is the added level of privacy the brand provides. In a world where your every word echoes endlessly across the internet it was a communication channel where sharing could take place on a more contained level. However, much like Google's acquisition of Nest and Facebook's of Instagram, with this purchase consumers are suddenly associated with, and have their information accessible by a brand that they didn't buy into. It's this intrusion that can make it feel uncomfortable, as both you and your data are seized without your say-so.”
European Data Protection Authorities Have Already Begun Investigations
Jacob Kohnstamm, the Dutch data protection Commissioner, has begun an investigation into data protection issues related to Facebook’s purchase of WhatsApp. His investigation is focusing on the collection of data from WhatsApp users’ address books and the potential for misuse of that information.
Thilo Weichert, the data protection commissioner for the German state of Schleswig-Holstein, has also begun an investigation into the acquisition. He told Bloomberg, “The mixing of data is strictly regulated by German law, especially through the Telemedia Act and the Federal Data Protection Act. Both acts rely on the principle of purpose binding, that data stored for one purpose cannot be processed for any other purposes - there are no such restrictions in the U.S.”
Commissioner Kohnstamm, who served as the head of the European Union’s Article 29 Data Protection Working Party until February 27, 2014, said that any of the European Union’s “28 data protection regulators could open an investigation” into the acquisition as well.
The Commission has previously issued an Order and Settlement Agreement with Facebook, following an investigation into whether “Facebook deceived consumers by telling them they could keep their information on Facebook private, and then repeatedly allowing it to be shared and made public.” In addition to requiring Facebook to give users “clear and prominent notice” and obtain “their express consent before sharing their information beyond their privacy settings,” and to maintain “a comprehensive privacy program to protect consumers’ information,” the Order also prohibited Facebook from misrepresenting the extent to which it participates in the US-EU Safe Harbor program.
The Safe Harbor Framework
The Safe Harbor Framework is an industry-developed self-regulatory approach to privacy compliance. Coordinated by the Department of Commerce, the Safe Harbor program allows firms to self-certify privacy policies in lieu of establishing adequate privacy protections in the United States that regulate business practice. The Safe Harbor arrangements developed in response to the European Union Data Directive, a comprehensive legal framework that established essential privacy safeguards for consumers across the European Union.
The Federal Trade Commission has been tasked with penalizing US firms that incorrectly claim current Safe Harbor certification. Currently, Facebook represents that it complies with the requirements of Safe Harbor program.
The FTC's Section 5 Authority
The FTC Act prohibits unfair and deceptive acts and practices, and empowers the Commission to enforce the Act’s prohibitions. These powers are described in FTC Policy Statements on Deception and Unfairness. A trade practice is unfair if it “causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits to consumers or to competition.” An act or practice is deceptive if it involves a representation, omission, or practice that is likely to mislead the consumer acting reasonably under the circumstances, to the consumer’s detriment.”
The Commission has previously found that a company may not alter the privacy settings of its users and that a company may not repurpose user data for a use other than the one for which the user’s data was collected without first obtaining the user’s “express affirmative consent.” For example, in the FTC’s consideration of the Google acquisition of Doubleclick, where similar issues were raised about the impact on user privacy, the Commission allowed the merger to go forward, but only because the Commission found that the scope of its antitrust review did not encompass issues related to consumer privacy. However, Commissioner Harbor dissented and warned, “The truth is, we really do not know what Google/DoubleClick can or will do with its trove of information about consumers’ Internet habits. The merger creates a firm with vast knowledge of consumer preferences, subject to very little accountability.”
EPIC is the group responsible for several of the Federal Trade Commission's major privacy decisions, including:
- Microsoft. FTC, "Microsoft Settles FTC Charges Alleging False Security and Privacy Promises: Passport Single Sign-In, Passport "Wallet," and Kids Passport Named in Complaint Allegations" (Aug. 8, 2002)
- Choicepoint. FTC, "ChoicePoint Settles Data Security Breach Charges; to Pay $10 Million in Civil Penalties, $5 Million for Consumer Redress: At Least 800 Cases of Identity Theft Arose From Company's Data Breach" (Jan. 26, 2006)
- Google Buzz. FTC, "FTC Charges Deceptive Privacy Practices in Google's Rollout of Its Buzz Social Network: Google Agrees to Implement Comprehensive Privacy Program to Protect Consumer Data" (Mar. 30, 2011)
- Facebook. FTC, "Facebook Settles FTC Charges That It Deceived Consumers By Failing To Keep Privacy Promises" (Aug. 10, 2012)
On February 19, 2014, immediately following the announcement of the Facebook deal, founder Jan Koum posted to the WhatsApp Blog:
Here’s what will change for you, our users: nothing. WhatsApp will remain autonomous and operate independently. You can continue to enjoy the service for a nominal fee. You can continue to use WhatsApp no matter where in the world you are, or what smartphone you’re using. And you can still count on absolutely no ads interrupting your communication. There would have been no partnership between our two companies if we had to compromise on the core principles that will always define our company, our vision and our product.
On March 10, 2014, WhatsApp released a new set of privacy features for its Android operating system. The changes include allowing users to hide certain features, such as information about when they were last seen, their profile photo, and their status updates.
Following the filing of the complaint, Facebook told the Washington Post, "As we have said repeatedly, WhatsApp will operate as a separate company and will honor its commitments to privacy and security."
WhatsApp "Sets the Record Straight"
Less than two weeks following the filing of the complaint, WhatsApp founder Jan Koum addressed the privacy issues associated with Facebook's proposed acquisition in a blog post titled, "Setting the Record Straight":
Since announcing our upcoming partnership with Facebook, we’ve been truly humbled by how much attention our story has received. As a company, we’re excited to continue focusing on offering as many people as possible the chance to stay connected with friends and loved ones, no matter who they are or where they live.
Unfortunately, there has also been a lot of inaccurate and careless information circulating about what our future partnership would mean for WhatsApp users’ data and privacy.
I’d like to set the record straight.
Above all else, I want to make sure you understand how deeply I value the principle of private communication. For me, this is very personal. I was born in Ukraine, and grew up in the USSR during the 1980s. One of my strongest memories from that time is a phrase I’d frequently hear when my mother was talking on the phone: “This is not a phone conversation; I’ll tell you in person.” The fact that we couldn’t speak freely without the fear that our communications would be monitored by KGB is in part why we moved to the United States when I was a teenager.
Respect for your privacy is coded into our DNA, and we built WhatsApp around the goal of knowing as little about you as possible: You don’t have to give us your name and we don’t ask for your email address. We don’t know your birthday. We don’t know your home address. We don’t know where you work. We don’t know your likes, what you search for on the internet or collect your GPS location. None of that data has ever been collected and stored by WhatsApp, and we really have no plans to change that.
If partnering with Facebook meant that we had to change our values, we wouldn’t have done it. Instead, we are forming a partnership that would allow us to continue operating independently and autonomously. Our fundamental values and beliefs will not change. Our principles will not change. Everything that has made WhatsApp the leader in personal messaging will still be in place. Speculation to the contrary isn’t just baseless and unfounded, it’s irresponsible. It has the effect of scaring people into thinking we’re suddenly collecting all kinds of new data. That’s just not true, and it’s important to us that you know that.
Make no mistake: our future partnership with Facebook will not compromise the vision that brought us to this point. Our focus remains on delivering the promise of WhatsApp far and wide, so that people around the world have the freedom to speak their mind without fear.
The FTC's Response
On April 10, 2014, the Commission responded to EPIC's complaint. The FTC notified Facebook and WhatsApp that they must honor their privacy commitments to users. According to the letter from the Director of the FTC Bureau of Consumer Protection, "if the acquisition is completed and WhatsApp fails to honor these promises, both companies could be in violation of Section 5 of the FTC Act and potentially the FTC's order against Facebook." The FTC letter concludes, "hundreds of millions of users have entrusted their personal information to WhatsApp. The FTC staff continue to monitor the companies' practices to ensure that Facebook and WhatsApp honor the promises they have made to those users."
- EPIC Complaint to FTC, March 6, 2014
- EPIC Followup Complaint to FTC, March 21, 2014
- FTC Letter to Facebook and WhatsApp, April 10, 2014
- Jason Abbruzzese, Facebook Gains FTC Approval for WhatsApp — Plus a Stern Privacy Warning, Mashable, April 10, 2014
- Brian Womack and Alan Katz, FTC Says Facebook, WhatsApp Must Honor Consumer Privacy, Bloomberg, April 10, 2014
- Rachel King, FTC calls out Facebook, Whatsapp over privacy ahead of merger, ZDNet, April 10, 2014
- Zach Miners, FTC clears Facebook's WhatsApp deal, but warns on data collection, PC World, April 10, 2014
- Chris Welch, FTC issues stern privacy warning to Facebook and WhatsApp ahead of acquisition, The Verge, April 10, 2014
- Alexei Oreskovic, Facebook says WhatsApp deal cleared by FTC, Reuters, April 10, 2014
- Hayley Tsukayama, FTC warns Facebook, WhatsApp: Keep your privacy promises, Washington Post, April 10, 2014
- Michael Krebs, On Mounting Privacy Concerns, WhatsApp CEO Defends Acquisition, Digital Journal, March 25, 2014
- Kate Tummarello, Privacy groups: WhatsApp users don't want Facebook deal, The Hill, March 21, 2014
- Casey Johnston, WhatsApp’s idealism and Facebook realism: A study in contrast, Ars Technica, March 18, 2014
- Stuart Dredge, WhatsApp boss on Facebook privacy fears: 'Our principles will not change', Digital Journal, March 18, 2014
- John P. Mello, Jr., Bad Ads Outstrip Porn as Mobile Phone Infection Vectors, Tech News World, March 11, 2014
- Michael McEnaney, Facebook's purchase of WhatsApp shines light on personal data privacy once again, Tech Times, March 10, 2014
- Dino Grandoni, WhatsApp's Biggest Promise May Get Broken With Facebook Deal, Huffington Post, March 10, 2014
- Tim Parker, Privacy Groups Ask FTC To Investigate Facebook's WhatsApp Acquisition, Benzinga, March 10, 2014
- Kristin Burnham, Facebook's WhatsApp Deal Under Fire, Information Week, March 8, 2014
- Tom Pritchard, WhatsApp Purchase Challenged Over Privacy Concerns, Gizmodo, March 8, 2014
- Randell Suba, Facebook-WhatsApp deal leaves angry privacy advocates knocking on FTC door, Tech Times, March 8, 2014
- M Rochan, P WhatsApp Users' Personal Data at Facebook's Behest as Privacy Groups Call Halt on $19bn Deal, International Business Times, March 7, 2014
- Vikas Shukla, Privacy Advocates Urge FTC To Halt Facebook Inc - WhatsApp Deal , Value Walk, March 7, 2014
- Info Security Magazine, Privacy Groups Ask FTC to Suspend Facebook's Acquisition of WhatsApp, March 7, 2014
- Kevin Rawlinson, Facebook's WhatsApp purchase challenged, BBC News, March 7, 2014
- Nate Swanner, Privacy groups demand Facebook Whatsapp acquisition be halted, Slashgear, March 7, 2014
- Adam Dickter, Privacy Groups Ask FTC To Block Facebook Deal for WhatsApp, Sci-Tech Today, March 7, 2014
- Privacy groups ask US Federal Trade Commission to halt Facebook-WhatsApp deal, Economic Times, March 7, 2014
- Ruby Kannan, Privacy groups want FTC to investigate Facebook-WhatsApp deal, Techie News, March 7, 2014
- Dean Arrindell, Economy adds 175,000 jobs in February; Privacy groups fight Facebook; Gap same store sales decline, Yahoo! Finance, March 7, 2014
- Ashlee Kieler, Facebook, WhatsApp Acquisition Face Privacy Hurdle After EPIC Files FTC Complaint, Consumerist, March 7, 2014
- Paul Ausick, Privacy Group Challenges Facebook’s Acquisition of WhatsApp, 24/7 Wall Street, March 7, 2014
- Lee Munson, Privacy groups lodge complaint over Facebook's acquisition of Whatsapp, Naked Security, March 7, 2014
- CBR Staff, Privacy group asks FTC to investigate Facebook's WhatsApp acquisition, Computer Business Review, March 7, 2014
- Cecilia Kang, Privacy advocates decry Facebook’s purchase of WhatsApp , Washington Post, March 6, 2014
- Jessica Guynn Privacy groups urge FTC to probe Facebook's deal to buy WhatsApp, Los Angeles Times, March 6, 2014
- Will Oremus, Privacy Group Calls for Federal Investigation of Facebook's $19 Billion WhatsApp Deal, Slate, March 6, 2014
- Casey Johnston, Facebook’s shot at WhatsApp data gets both companies an FTC complaint, Ars Technica, March 6, 2014
- Patricia Yollin, Privacy Groups Seek FTC Probe of WhatsApp Acquisition by Facebook, KQED News, March 6, 2014
- Alexei Oreskovic, Privacy groups ask regulators to halt Facebook's $19 billion WhatsApp deal, Reuters, March 6, 2014
- Seth Rosenblatt, Privacy groups ask FTC to block Facebook-WhatsApp deal, CNET, March 6, 2014
- Sarah Frier, FTC Should Investigate Facebook-WhatsApp Deal, Groups Say , Bloomberg, March 6, 2014
- Julian Hattern, Does Facebook, WhatsApp deal violate privacy law?, The Hill, March 6, 2014
- Dustin Volz, Privacy Groups Ask Feds to Investigate Facebook's WhatsApp Buy, National Journal, March 6, 2014
- Benny Evangelista, Consumer privacy groups seek FTC review of Facebook-WhatsApp deal, San Francisco Gate, March 6, 2014
- Mia Saini, Could Privacy Concerns Kill Facebook-WhatsApp Deal?, Businessweek, March 6, 2014
- Chloe Albanesius, Groups Want FTC to Probe Facebook, WhatsApp Deal, PC Magazine, March 6, 2014
EPIC relies on support from individual donors to pursue our work.
Subscribe to the EPIC Alert
The EPIC Alert is a by-monthly newsletter highlighting emerging privacy issues.