{"id":8244,"date":"2021-03-02T17:25:42","date_gmt":"2021-03-02T17:25:42","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-2793\/"},"modified":"2026-07-04T12:25:53","modified_gmt":"2026-07-04T12:25:53","slug":"how-do-whatsapps-new-regulations-align-with-data-protection-requirements","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2021\/03\/02\/how-do-whatsapps-new-regulations-align-with-data-protection-requirements\/","title":{"rendered":"How Do WhatsApp\u2019s New Regulations Align with Data Protection Requirements?"},"content":{"rendered":"<p><strong>It\u2019s not just data protection officers who view WhatsApp and similar services with skepticism. Fortunately, European-based alternative messaging platforms can help alleviate these concerns.<\/strong><\/p>\n<p>The <a href=\"https:\/\/lfd.niedersachsen.de\/startseite\/themen\/wirtschaft\/nutzung-von-whatsapp-in-unternehmen-179649.html\" target=\"_blank\" rel=\"noopener\">State Commissioner for Data Protection<\/a> (LfD) of Lower Saxony delivers a clear verdict: \u201cUsing WhatsApp for business communication violates the General Data Protection Regulation (GDPR).\u201d Similarly, the <a href=\"https:\/\/www.dr-datenschutz.de\/bundesdatenschutzbeauftragter-warnt-vor-whatsapp-nutzung\/\" target=\"_blank\" rel=\"noopener\">Federal Commissioner for Data Protection<\/a> has stated that \u201cusing WhatsApp is prohibited for federal authorities.\u201d<\/p>\n<p>Private users need not delete the popular app from their devices &#8211; but using it to communicate with colleagues may pose legal risks. Moreover, WhatsApp\u2019s privacy policy update, announced for May 2021, alarmed many users. However, Niamh Sweeney, WhatsApp\u2019s Director of Policy, has since confirmed that EU users will experience no changes as a result of the update. The revisions do not affect data sharing between WhatsApp and its parent company, Meta (formerly Facebook), within Europe. According to WhatsApp\u2019s official <a href=\"https:\/\/praxistipps.chip.de\/whatsapp-und-datenschutz-das-sollten-sie-wissen_36991\" target=\"_blank\" rel=\"noopener\">privacy guidelines<\/a>, nothing has changed for users in the EU.<\/p>\n<h2>U.S.-Based Messengers Raise Concerns<\/h2>\n<p>While numerous messaging apps exist, most originate in the United States &#8211; and thus offer no real data protection advantages over WhatsApp. In July 2020, the Court of Justice of the European Union (CJEU) invalidated the <a href=\"http:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=228677&amp;pageIndex=0&amp;doclang=de&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=10409360\" target=\"_blank\" rel=\"noopener\">Privacy Shield framework<\/a>, which had governed transatlantic data transfers. As a result, European companies\u2019 use of U.S.-based messaging services is generally problematic under GDPR.<\/p>\n<p>Two U.S.-based services &#8211; Telegram and Signal &#8211; market themselves as privacy-compliant. While Telegram has drawn criticism, <a href=\"https:\/\/signal.org\/de\/\" target=\"_blank\" rel=\"noopener\">Signal<\/a> is backed by a nonprofit foundation. It emphasizes privacy compliance and displays no advertising. Nevertheless, its U.S. headquarters remain a liability: Signal remains subject to U.S. laws and government oversight &#8211; and potentially opaque data practices by the provider.<\/p>\n<blockquote><p>\u201cFor globally active companies, GDPR-level data protection isn\u2019t always the decisive factor when selecting a messaging service. What matters more is reach &#8211; i.e., the ability to connect with business partners. That means brand recognition and user base size. WhatsApp reaches approximately 2 billion users; WeChat, 1.3 billion; Telegram, 500 million; Signal, 50 million. Beyond that, adoption drops sharply.<\/p>\n<p>Notably, many companies are unfamiliar with the terms of service of the messengers they use &#8211; terms that often include obligations they simply cannot meet.<\/p>\n<p>While technical measures exist to secure messenger usage, they tend to be costly and cumbersome for end users. Companies operating exclusively within Europe should therefore prioritize European alternatives.\u201d<\/p><\/blockquote>\n<h2>European Solutions Are in Demand<\/h2>\n<p>Fortunately, several GDPR-compliant alternatives are available in Europe:<\/p>\n<ul>\n<li><a href=\"https:\/\/threema.ch\/de\" target=\"_blank\" rel=\"noopener\">Threema<\/a>, based in Switzerland, collects no user data and displays no advertising. According to the company, its solution is 100% GDPR-compliant.<\/li>\n<li><a href=\"https:\/\/wire.com\/de\/\" target=\"_blank\" rel=\"noopener\">Wire<\/a>, headquartered in Germany and Switzerland, guarantees that all user data remains stored exclusively within the EU &#8211; ensuring full GDPR compliance.<\/li>\n<li><a href=\"https:\/\/www.ginlo.net\/de\/\" target=\"_blank\" rel=\"noopener\">Ginlo<\/a>, developed in Munich, is 100% \u201cMade in Germany\u201d and fully compliant with EU data protection law. Secure communication with colleagues and external partners is thus assured.<\/li>\n<\/ul>\n<p>Regardless of which messenger your organization ultimately selects for professional use, msecure is happy to advise you on all aspects of corporate information security.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Data Subject Rights:<\/strong> Since 2018, the number of access requests under Article 15 GDPR has increased by over 400 percent.<\/p>\n<p><strong>Breach Notification Obligation:<\/strong> Personal data breaches must be reported to the supervisory authority within 72 hours.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What penalties apply for GDPR violations?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Fines of up to \u20ac20 million or 4 percent of global annual turnover &#8211; whichever is higher. Affected individuals may also pursue civil damages.<\/p>\n<\/details>\n<details>\n<summary><strong>What is a Data Protection Impact Assessment (DPIA)?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A DPIA is a systematic evaluation of the risks posed by a given data processing activity to the rights and freedoms of data subjects. It is mandatory whenever processing is likely to result in a high risk &#8211; for example, in cases involving profiling, video surveillance, or processing of special categories of personal data.<\/p>\n<\/details>\n<details>\n<summary><strong>Does the GDPR apply to small businesses?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. The GDPR applies universally to any organization &#8211; regardless of size &#8211; that processes personal data of EU residents. Small businesses benefit from limited exemptions (e.g., no obligation to maintain a record of processing activities if fewer than 250 employees and processing poses no high risk), but must still comply with all core GDPR principles.<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/26\/post_id-3531\/\">GDPR 2026: What\u2019s Changing &#8211; and What Companies Must Watch<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2023\/04\/28\/post_id-3229\/\">How to Prevent Cyberattacks on Critical Infrastructure<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2023\/04\/28\/post_id-3221\/\">Multi-Carrier Connectivity as a Safeguard Against System Failure<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cloud &amp; Infrastructure News at cloudmagazin.com<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">IT Strategy Insights for Decision-Makers at digital-chiefs.de<\/span><\/a><\/div>\n<h2>TL;DR<\/h2>\n<ul>\n<li>WhatsApp\u2019s May 2021 privacy policy update alarmed many users.<\/li>\n<li>In July 2020, the Court of Justice of the European Union (CJEU) invalidated the Privacy Shield framework, which had governed data transfers to the U.S.<\/li>\n<li>Threema\u2019s solution is, per company statements, 100% GDPR-compliant.<\/li>\n<li>Ginlo, developed in Munich, is 100% \u201cMade in Germany\u201d and thus fully data protection-compliant.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"It\u2019s not just data protection officers who view WhatsApp and similar services with skepticism. Fortunately, European-based alternative messaging platforms can help alleviate these concerns. The State Commissioner for Data Protection (LfD) of Lower Saxony delivers a clear verdict: \u201cUsing WhatsApp for business communication violates the General Data Protection Regulation (GDPR).\u201d Similarly, the Federal Commissioner for [&hellip;]","protected":false},"author":55,"featured_media":2802,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"data protection","_yoast_wpseo_title":"How Do WhatsApp\u2019s New Regulations Align with Data Protection Requirements?","_yoast_wpseo_metadesc":"WhatsApp regulations & data protection: Discover secure European alternatives for compliant messaging. Protect your data\u2014explore safer options now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-2793"],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-8244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":2793,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8244"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8244\/revisions"}],"predecessor-version":[{"id":19858,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8244\/revisions\/19858"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/2802"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}