Information Commissioner's Office
A win for the data protection of UK consumers – WhatsApp signs public commitment not to share personal data with Facebook until data protection concerns are addressed
Blog posted by: Information Commissioner, Elizabeth Denham, 14 March 2018.
People have a right to have their personal data kept safe, only used in ways that are properly explained to them, and for certain uses of their data, to which they expressly consent. This is a requirement of the Data Protection Act.
My office has just completed an investigation, which commenced in August 2016, into whether WhatsApp could legally share users’ data with Facebook in the manner they were considering. In 2014 Facebook acquired WhatsApp, which offers an instant messaging service for smartphones.
My investigation found:
- WhatsApp has not identified a lawful basis of processing for any such sharing of personal data;
- WhatsApp has failed to provide adequate fair processing information to users in relation to any such sharing of personal data;
- In relation to existing users, such sharing would involve the processing of personal data for a purpose that is incompatible with the purpose for which such data was obtained;
- I found that if they had shared the data, they would have been in contravention of the first and second data protection principles of the Data Protection Act.
I am pleased to state that WhatsApp has now signed an ‘undertaking’ wherein they have given a public commitment not to share personal data with Facebook until they can do so in compliance with the upcoming General Data Protection Regulation (GDPR), which comes into force in May this year. I reached the conclusion that an undertaking was the most effective regulatory tool for me to use, given the circumstances of the case. As WhatsApp has assured us that no UK user data has ever been shared with Facebook (other than as a ‘data processor’, as explained below), I would not be able to meet the criteria for issuing a civil monetary penalty under the Data Protection Act.
For those of you who wish to read this undertaking, I have enclosed a copy. As outlined in the undertaking, WhatsApp has assured us that it shall not, from the date of the undertaking, share personal data with companies in the Facebook family, for Facebook’s own purposes, until it can satisfy the requirements of the GDPR.
It is also important to state that UK consumers do not need to take any action as a result of this update.
My investigation has not been concerned about WhatsApp’s sharing of personal data with Facebook when Facebook are only providing a support service to WhatsApp. The technical term for such sharing is that WhatsApp can use Facebook as a data processor. This is common practice and if done consistently with the law, under contract, does not generally raise data protection concerns.
Data protection law does not prevent a company from sharing personal data – they just have to follow the legal requirements.
I therefore compliment WhatsApp in signing this undertaking, which I believe will build trust amongst their many UK users. I would also like to stress that signing an undertaking is not the end of story and I will closely monitor WhatsApp’s adherence to it.
There are two other interesting elements to this investigation that merit mention.
The issue was seized by European Data Protection Authorities of which I am a member. As Chair of the Article 29 Task Force on WhatsApp-Facebook data sharing, we actively worked with our European colleagues to bring a common focus and information base to our investigation. The Article 29 Working Party wrote collectively to WhatsApp to set out our concerns in October 2017.
The Hamburg Commissioner of Data Protection and Freedom of Information issued a press release on 2 March 2018, indicating that the Higher Administrative Court (OVG) Hamburg had confirmed his administrative order, banning Facebook from using WhatsApp user data for its own purposes.
The French data protection authority (CNIL) is in the process of bringing enforcement action against WhatsApp.
Other EU Data Protection Authorities also have ongoing investigations.
The second element of interest is the path ahead. The GDPR strengthens the rules on what constitutes ‘consent’. It also provides a stronger emphasis on effective transparency and accessible information for the public. This will be good news for UK users of social media services. We will be monitoring changes to WhatsApp’s privacy and terms and conditions under the new legislation.
Finally, in the interest of transparency I am enclosing a copy of my letter to WhatsApp dated 16 February 2018, which outlines the history and results of the investigation.
Elizabeth Denham was appointed Information Commissioner in July 2016. Her key goal is to increase the UK public’s trust and confidence in what happens to their personal data.
Latest News from
Information Commissioner's Office
Blog: Community groups and COVID-19: what you need to know about data protection01/04/2020 09:10:00
Blog posted by: Ian Hulme, Director for Regulatory Assurance at the ICO, 30 March 2020.
Statement in response to the use of mobile phone tracking data to help during the coronavirus crisis30/03/2020 12:25:00
The ICO’s Deputy Commissioner Steve Wood recently responded to the use of mobile phone tracking data to help during the coronavirus crisis.
Blog: Community groups and COVID-19: what you need to know about data protection27/03/2020 13:20:00
A blog by Ian Hulme, Director for Regulatory Assurance at the ICO.
Council employee fined £400 for illegally deleted audio file16/03/2020 10:25:00
A council employee has been fined £400 for an offence under the Freedom of Information (FOI) regulations.
Data protection and coronavirus12/03/2020 15:25:00
We all share the same concerns about the spread of the COVID-19 virus. The need for public bodies and health practitioners to be able to communicate directly with people when dealing with this type of health emergency has never been greater.
Blog: Don’t get caught out when it comes to pupil photos10/03/2020 15:10:00
Blog posted by: Andrew Laing, ICO Head of Data Protection Complaints, 09 March 2020.
Combining privacy and innovation: ICO Sandbox six months on10/03/2020 12:25:00
It’s been an exciting, interesting and challenging first six months for the ICO Sandbox – both for those externally involved in the various projects and for the ICO staff working on the scheme. Ian Hulme discusses the progress so far.
The ICO and the Office of the Australian Information Commissioner sign Memorandum of Understanding06/03/2020 12:25:00
James Dipple-Johnstone (Deputy Commissioner) yesterday commented on the signing of the Memorandum of Understanding.