WhatsApp is just the latest Meta platform to be found in breach of GDPR regulations, but data privacy advocates say this ruling is just not enough.
Similar to the case put forth against Facebook and Instagram, Whatsapp, which is also owned by Meta, has been fined £4.8 million by the Irish Data regulator for forcing user consent to personal data collection.
WhatsApp was found to have forced users to consent to personal data collection by putting the clause in their terms of service.
As users could not access the service without agreeing to their personal data being collected and processed, the complainants argued this was forced consent and in breach of GDPR.
WhatsApp claimed that the collection of personal data was necessary for the performance of the service.
The case was originally brought to court by a German user, but was tired by the Irish Data protection Commission as Meta is registered in Ireland.
This case rode on the subject of legal basis, and the contract legal basis WhatsApp was using to collect and use personal data.
If WhatsApp could prove that their use of personal data, which they claimed was used for service improvements, was inherent to their services, then they could use a contract to establish the legal basis for personal data use.
According to the DPC, while they found WhatsApp had not been transparent in how the data would be used, WhatsApp could in fact rely on contract legal basis.
After six CSAs across the EU raised objections to the draft decision and no consensus could be reached, the European Data Protection Board (EDPB) took the case.
From there, the EDPB found that WhatsApp could not use the contract legal basis to gain user consent to their personal data, fining WhatsApp and giving them six months to get policies GDPR compliant.
Sound familiar?
That’s because it is almost exactly what happened to Meta’s other platforms, Facebook and Instagram, at the start of this year
WhatsApp is the last of Meta’s major platforms to face this GDPR ruling, and all three cases had to do with ‘forced consent’ and the contract legal basis.
The Irish DPC’s ruling was also a hallmark of all three cases – their initial forgiving stance was overturned by the higher EU data regulator.
Ireland has jurisdiction over Meta platform regulation, as well as other major company’s European outfits like Apple’s, because of their business friendly regulations and tax system.
While they did initially fine WhatsApp nearly £200m, data protection advocates have long called out the Irish DPC for being far too friendly to the major tech companies so their headquarters will stay in the country.
NYOB, the data protection advocacy group which aided the three cases against Meta, has called out the DPC for this ruling and the others.
In a statement, they claim that the DPC purposefully sidestepped the real issue by saying WhatsApp wanted to use personal data only for security and service improvements.
“The core matter of data use for “the purposes of behavioural advertising, for marketing purposes, as well as for the provision of metrics to third parties and the exchange of data with affiliated companies ” were not dealt with by the Irish DPC – despite a binding decision of the EDPB that these matters must be investigated,” the statement said.
The EDPB has been calling of the Irish DPC to investigate Meta’s platforms for use of personal data and potential data sharing between platforms, but Irish DPC has called this an overreach by the higher EU commission.
Recommended
- Linux Malware Hit Record Highs in 2022
- Microsoft Set to Cut 10,000 Jobs
- New Ruling to ‘Free the Nipple’ on Meta Platforms
Max Shrems, the founder of NYOB who has been involved in the cases since the start of GDPR said: “We are astonished how the DPC simply ignores the core of the case after a 4.5 year procedure. The DPC also clearly ignores the binding decision of the EDPB. It seems the DPC finally cuts loose all ties with EU partner authorities and with the requirements of EU and Irish law.”
The core issue of the case, NYOB argues, is surrounding metadata WhatsApp shares with Facebook and Instagram. While WhatsApp chats are encrypted, metadata – which includes who communicates with who, who uses the app when, and for how long and how often – is not encrypted, and phone numbers with associated Facebook and Instagram accounts are collected.
The DPC has not investigated this despite orders from the EDPB, which NYOB insists is the Irish regulator essentially parting from the wider EU body’s authority.
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





