Site navigation

WhatsApp Private Message Controversy | What You Need to Know

David Paul

,

WhatsApp private messages
The ICO has told UK Ministers that conducting government business over private apps creates risks around data security and hinders transparency.

The Information Commissioner’s Office (ICO) has called for a government review into the use of WhatsApp private messages to send governmental correspondence.

In a new report, the organisation conducted a year-long investigation in 2021 into the use of these channels during the pandemic by Ministers and officials at the Department of Health and Social Care (DHSC).

From the investigation, the ICO found that the lack of clear controls in place and increase in the use of messaging apps could have potentially led to important information around the government’s response to the pandemic being lost or insecurely handled.

Evidence also suggested this practice is commonly seen across much of the rest of government and predates the pandemic.

The ICO concluded that transparency and accountability within government were put at risk using such devices, and a review has now been called for with suggestions of action to be taken to ensure improvements are made.

John Edwards, UK Information Commissioner, commented: “I understand the value of instant communication that something like WhatsApp can bring, particularly during the pandemic where officials were forced to make quick decisions and work to meet varying demands. However, the price of using these methods, although not against the law, must not result in a lack of transparency and inadequate data security.

“Public officials should be able to show their workings, for both record keeping purposes and to maintain public confidence. That is how trust in those decisions is secured and lessons are learnt for the future.

“The broader point is making sure the Freedom of Information Act keeps working to ensure public authorities remain accountable to the people they serve. Understanding the changing role of technology is part of that picture. I’ll be setting out more details on how my office will approach FOI differently later this week when I launch ICO25 – the ICO’s new three-year plan.”

The ICO has issued DHSC with a practice recommendation ordering the department to improve its management of FOI requests and address inconsistencies in its existing FOI guidance.

Additionally, the department has been reprimanded under the UK General Data Protection Regulation (UKGDPR). The reprimand is to ensure that the DHSC improves its processes around data handling using private correspondence to ensure information is kept secure.


Recommended


Sridhar Iyengar, MD for Zoho Europe and expert on remote collaboration tools and platforms, said that the increased use of these platforms since the advent of hybrid working and the rise of the pandemic has made it more common for digital communication to “bleed over” into private correspondence channels, such as WhatsApp.

Iyengar said: “However, using these channels to communicate in a professional capacity is extremely risky, as the threat of data leaks, mis-sent emails or messages, or hacked communications is significantly high.

“We support the ICO’s move stepping in to try and combat this security threat. Cutting this behaviour will take time, but it is possible, especially with the abundance of purpose-built communication and collaboration tools at our disposal and is a critical part of corporate security. We would advise it is best practice, and often critical, to ensure corporate tools are used for corporate correspondence.

“The most flexible tools are role based, accessible on mobile, and are a secure alternative to personal communication channels. Government departments in particular must consider adopting communication platforms and tools that value privacy and security as inherent features to its design.”

The news is particularly damning after previous inquiries into how WhatsApp and its parent company Meta have handled private user data.

In April last year, Ireland’s Data Protection Commission (DPC) announced an investigation into a Facebook data breach which saw hundreds of millions of users affected.

More than 500 million Facebook users in 106 countries were affected by the data breach, with information belonging to around 11 million UK-based users leaked.

The exposed data, which includes phone numbers, full names, email addresses and dates of birth, was published to an online hacking forum. A breach such as this could have had serious ramifications if it included information relating to private UK Government correspondence.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data