Introduction
This work was written in Turkish. The summary on this page is a translation; the citation gives the original title in parentheses.
When we woke up on the morning of 4 January 2021 and picked up our mobile phones, we were met with a notice from “WhatsApp” that the terms of the agreement were going to be changed. We learned that, under the “Privacy Policy” in the agreement, our data would be shared with Facebook and its affiliated companies if we gave our approval, and that if we did not, we would no longer be able to use the application after the date stated.
Full text
This text is a translation of the Turkish original, prepared for this website. Numbers in square brackets are the page numbers of the original; sources in the footnotes are given as in the original. For citation, the original publication (PDF) is authoritative.
Murat Volkan Dülger*
Introduction
When we woke up on the morning of 4 January 2021 and picked up our mobile phones, we were met with a notice from “WhatsApp” on our phones announcing that the agreement was going to be changed. We learned that, if we gave our approval under the “Privacy Policy” in the agreement, our data would be shared with Facebook and its affiliated companies, and that, if we did not give our approval, we would not be able to use this application after the date indicated. Our people, who had not been nearly so interested or uneasy when the cosmic room of their country’s army was entered, were – whatever deep secrets they may be keeping – greatly unsettled by this change and began to talk about the matter everywhere. As a result, WhatsApp’s change to the agreement concerning data sharing suddenly took pride of place on our country’s agenda.
Many users who, on account of the change to the agreement that WhatsApp was trying to make (or, to put it more accurately, to impose), were understandably seized by fear and misgivings suddenly began to migrate to messaging platforms such as Telegram, Signal or BİP. At the same time, of course, an unending stream of questions arose in all our minds; for by then the WhatsApp application had long since entered every area of our lives, from our working life to our private life. This change was taken so seriously that in our country boycotts of and mass criticism against the application began on Twitter under the hashtag “We Are Deleting WhatsApp”.
In one respect this was in fact a rather good development. A large majority of society thereby gained awareness of, and indeed experienced an enlightenment about, the extremely important issue of personal data security. We should regard this as an important aspect and gain of this process.
In this article I shall try to assess the mobile applications that caused users to experience such a radical awakening with regard to the sharing of data, their approaches to the security of personal data, and the legal dimension of the matter.
I. WhatsApp’s Development and Its Present State
Let us first set out in one sentence what will happen with the change to the agreement that is under discussion: under the “Privacy Policy” to be brought into force by WhatsApp on 8 February 2021, “some” of the users’ data will, if the users give their approval, be shared with Facebook and the other companies within the Facebook group. Users who do not approve this policy will not be able to use the WhatsApp application as from 8 February 2021.
WhatsApp is the world’s most widely used messaging application, developed for smartphones, offering instant messaging, calling and communication services with cross-platform functionality, and with two billion monthly users as of today. Founded in California in 2009, “WhatsApp” has developed both the application and its privacy policies since the day it was founded. Group chat features were first added to the WhatsApp application in 2010. Users were thus enabled, in addition to their one-to-one communications, to create chat rooms consisting of two or more persons. With the update it introduced in August 2012, WhatsApp announced that the conversations conducted by users would be encrypted on the iOS and Android operating systems. In August 2013 WhatsApp introduced voice messaging. And on 19 November 2014, with the sale of the WhatsApp application to the company Facebook Inc., a new era began for this application.
In November of the same year WhatsApp introduced its feature known as “read receipts”, which appears as “two blue ticks” and alerts senders when their messages have been read by the recipients. Within a week WhatsApp added a further update to the application allowing users to disable this feature. In March 2015 the feature of making voice calls between two accounts was added. On 24 February 2017 WhatsApp made a bigger innovation: it launched the “Stories” (Story) feature, which we had become accustomed to using with the application called Snapchat. With this feature, WhatsApp users were given the possibility of sharing pictures, videos, music, links and text, using filters and add-ons, that could be viewed for a period of 24 hours. In October 2017 the location-sharing feature was added. And in January 2018 WhatsApp launched WhatsApp Business for use by small businesses.
In the statements made concerning the WhatsApp Privacy Policy that is to enter into force on 8 February 2021, the aim pursued was stated to be “to ensure transparency when businesses communicate with customers via WhatsApp Business and to enable them to obtain secure hosting services through Facebook, WhatsApp’s parent company.” Although it is said that these privacy updates are being made in order to ensure greater trust and transparency in businesses’ communications with their customers, they have given rise to concerns, on the part of users who do not use WhatsApp Business, about the transfer of their data to Facebook.
II. The Privacy Policy and the Problems
In fact, when the WhatsApp application was sold to the company Facebook Inc. in 2014, many changes took place in the background. In the first statements made by the company after the sale to Facebook, it was declared that the existing assurances regarding the confidentiality and sharing of data would be maintained: “There is also a great deal of inaccurate and careless information circulating about what our future partnership will mean for the data and privacy of WhatsApp users. Respect for your privacy is very important on our platform. We built WhatsApp around the goal of knowing as little about you as possible. If partnering with Facebook meant that we had to change our values, we would not do it. Instead, we are forming a partnership that will allow us to continue operating independently and autonomously. Our fundamental values and beliefs will not change. Our fundamental principles will not change.”
Contrary to these statements, however, users’ personal data began to be shared with Facebook Inc. in 2016. The aim was to achieve integration between WhatsApp and Facebook by means of the sharing of users’ personal data with Facebook. It was stated that, with these integrations, data on whether the persons in users’ phone contacts use WhatsApp would be processed. And under the “Privacy Policy” published by WhatsApp on 4 January 2021 and due to enter into force on 8 February 2021, it was stated that some of its users’ data would begin to be shared with Facebook Inc. and that users who did not approve this would not be able to continue using the WhatsApp application.
We observe that, owing to the chaos that this new privacy era at WhatsApp has created among users, the applications Telegram, Signal and even BİP, which is Turkish software, have rapidly begun to be downloaded and used. At this point, while the WhatsApp application is actively used by more than two billion people a month, the Telegram application is actively used by 400 million and Signal by 10-20 million people. With users’ concerns about the sharing of data and about privacy increasing, these applications need to be examined in detail. For in the course of this rapid migration, what the other applications offer in terms of security and privacy is not being fully examined. Therefore, so as not to jump out of the frying pan into the fire, the other applications must be examined meticulously at a professional level and a decision taken only after a sound technical comparison has been made.
III. Security and WhatsApp
WhatsApp states that, in accordance with the “Privacy Policy” presented to its users, it uses the method of end-to-end encryption for the content of communications within the application. The messages exchanged between the sender of a message and its recipient, video calls, voice calls, images sent, etc. – all content shared through the application – are encrypted by WhatsApp. Thanks to “end-to-end encryption” (End to End Encryption / E2E), the messages between the sender and the recipient of a message can be seen only by the parties to the communication. Encryption is a method developed so that any kind of electronic data (file, password, image) is converted into an unreadable form and can be read only by those in possession of the necessary code (encryption key). For end-to-end encryption WhatsApp uses the “E2E” protocol developed by “Open Whisper Systems”.
It should be noted that, although there are many users in our country who have not accepted WhatsApp’s terms due to enter into force on 8 February and have switched to the Signal application for their daily communication, it is not widely known that the same protocol is used for “end-to-end encryption” in the WhatsApp and Signal applications.
Although WhatsApp uses E2E encryption for communication between users, it does not, in accordance with the backup rules set out in its Privacy Policy, encrypt the backups it holds. Similarly, it does not encrypt the metadata that enables the communication to be carried between recipient and sender either. Metadata (data about data) may be defined as information describing the source or the elements of data. With metadata, while third parties are prevented from seeing the content of the messages, authorised persons are enabled to access data such as by whom, to whom, when and for how long the messages were sent. The most problematic point of the application in terms of security is the absence of encryption of metadata. By means of the data accessed through unencrypted metadata, Facebook is enabled to track users’ behavioural patterns. This in turn means that, with a good piece of social engineering, a great deal of information about a particular person can in fact be obtained. Indeed, this is what intelligence services such as the NSA do. We regret to say that metadata is precisely the point that the overwhelming majority of users overlook.
IV. Security and Signal
The end-to-end encryption protocol used by WhatsApp was in fact developed by Open Whisper Systems in 2013 for the Signal application; it may be described as an encryption protocol that can be used to provide end-to-end encryption for voice calls, instant messaging and video conversations.
In addition to encrypting messages and calls, Signal also encrypts metadata. This is an indication that, in terms of the application’s development and use, it offers a more secure communication experience than other communication applications.
With the “Sealed Sender” mechanism developed to make the messaging carried out within the Signal application more secure, it is not possible to discern between whom the messaging between sender and recipient is taking place. Since the Sealed Sender mechanism removes the ability to authenticate senders, it cannot be discerned by whom the messages sent by users were sent. In addition, with the privacy features it offers users, the application makes it possible to lock messages by means of biometric data or passwords.
V. Security and Telegram
Compared with the WhatsApp and Signal applications, Telegram offers users end-to-end encryption of messages and other data only through “secret chats”. The use of secret chats, however, is hardly feasible in practice. As for messages sent in normal chats, which are not end-to-end encrypted, it should be understood that they are encrypted on the user’s device and that the encrypted messages are then decrypted on Telegram’s servers. At this point, while it is possible for the application to access your messages, the Telegram Privacy Policy states that “a court order from the countries concerned is required in order to store the messages and to access the data by using the decryption keys”.
For end-to-end encryption in secret chat messages, Telegram uses the “MT Protocol”, an encryption protocol developed by Telegram itself. In voice and video calls made by users, the encryption keys between them are represented by emojis consisting of four characters so that the users can verify the encryption. On the other hand, it is not possible to encrypt group chats created via the application.
One of the facilities Telegram offers users in terms of messaging is the “timed message / self-destructing messages” feature. This makes it possible for unwanted messages to be deleted from the device in the course of the messaging between recipient and sender.
VI. Security and BİP
In contrast to communication applications of foreign origin, the BİP application, developed in our country, has in recent days come onto the agenda as an alternative. BİP is an application developed by Turkcell for iOS and Android users which the users of all operators can use free of charge. The application has features such as disappearing messages, creating memes, being able to communicate with everyone, group messaging and location sharing, games and money transfer.
Compared with the other applications, BİP is seen not to use an end-to-end encryption protocol. On this point, when the “BİP Privacy Policy” shared by BİP is examined, it contains, under the heading “With Whom Are Personal Data Shared?”, the following statement: “In line with legal obligations, they are shared with judicial authorities, regulatory bodies and other parties. Where BİP is obliged to provide Personal Data under a legal obligation, and in order to protect its own rights, property or security or the rights, property or security of third parties, it may share them with the competent authorities.”
At this point, since BİP does not use an end-to-end encryption protocol, where legal obligations are at issue the content of the messages of the users of the application may be shared with law enforcement, the intelligence organisation, the public prosecutor’s office and the courts.
VII. What Data Does WhatsApp Collect, and Why?
When the “Privacy Policies” presented to users by communication platforms are examined, it can be seen for what purpose and with whom individuals’ data are shared. According to the update to the Privacy Policy made by WhatsApp, data relating to “Account Information, Connections, Status Information, Transaction and Payment Information, Messages, Customer Support and Other Operations” will be collected if the individuals approve the sharing. Unlike the previous arrangement, the new Privacy Policy includes, among these data, “Account Information and Transaction and Payment Information”. The information automatically collected by WhatsApp, for its part, is stated to be “Usage and Log Information, Device and Connection Information, Location Information and Cookies”. Unlike the position in 2016, the sharing with Facebook and the companies within Facebook Inc. of the automatically collected data of users, and of the data which users agree to share by choosing to use WhatsApp, is not left to the users’ choice.
As to how these data will be used, the Privacy Policy explains this as follows: “we may use the information we receive from these companies, and these companies may use the information we share with them, for the purpose of operating, providing, improving, understanding, customising, supporting and marketing our services and the offerings of these companies, including the Facebook Company Products.” The use of the data provided by users and automatically collected, as stated in the policy, for “Services, Safety, Security and Integrity and Business Interactions” also applies under the current Privacy Policy.
Between the WhatsApp Privacy Policy as updated by WhatsApp as of 20 July 2020 and the regime that will enter into force on 8 February 2021 there is, in essence, not a great deal of difference, apart from the fact that sharing with Facebook and the companies affiliated with Facebook is mandatory.
In the current use of WhatsApp as well, users’ personal data can, where deemed necessary, be shared with foreign states and, on security grounds, within the scope of intelligence activities.
On 23 March 2018 the Congress of the United States of America (USA) passed the CLOUD Act (Clarifying Lawful Overseas Use of Data) and thereby updated the legal framework applicable to requests by US law enforcement authorities for data stored on the servers of communication and cloud service providers. The CLOUD Act provides a limited mechanism for US law enforcement authorities to make requests concerning data stored in the USA and overseas. The CLOUD Act came onto the agenda as a law which amends US legislation, sets the limits of the geographical scope of the requests of US law enforcement authorities, and offers new solutions enabling service providers to refuse requests that conflict with the laws or national interest of other countries. This Act gives cloud service providers the possibility of refusing a request where it conflicts with the laws or national interests of another country. Under the CLOUD Act, WhatsApp may share personal data within the scope of the “Safety, Security and Integrity” principle in order to investigate users who, through their accounts and activities, engage in suspicious conduct or violate WhatsApp’s terms. At this point, in addition to the WhatsApp application, the Signal application too, being based in the USA, will be able, within the scope of the “Safety, Security and Integrity” principle, to share users’ data with the USA under the CLOUD Act even if the legislation of the countries concerned provides otherwise.
VIII. Collection of Data in the Cloud
Among the points to which users should pay attention when using communication applications are the sharing and storage options. In this context, users can share any kind of file (image, audio, video, etc.) via WhatsApp. However, while the limit for photographs, audio and video files sent by users is 16 MB, for documents this limit is 100 MB. WhatsApp users can store their files via the Google Drive application on Android and via the iCloud application on iOS.
As stated under the heading “Information You Provide – Messages” in the updated version of the WhatsApp Privacy Policy, the messages sent by users will not be retained in the ordinary course of business. While the messages that users send and receive are stored on their own devices, the messages are deleted from WhatsApp’s servers once they have been delivered. In the scenarios drawn up by WhatsApp, it is specified in which situations messages will continue to be stored. These situations are:
• Undelivered Messages: If a message you send cannot be delivered immediately for a reason such as the recipient being offline, the message is kept on the servers in encrypted form for up to thirty days and attempts are made to deliver it during that period; if it has still not been delivered after thirty days, however, this message is deleted from the servers.
• Media Forwarding: When a user forwards media within a message, they store this media temporarily in encrypted form on their servers in order to ensure that it is delivered more efficiently in cases where the same media is forwarded again.
For the reasons explained above, what is widely and mistakenly believed in our country – that as of 8 February 2021 WhatsApp will be able to access all of its users’ messages and read them one by one – is not possible.
To compare the storage activities carried out via the cloud by WhatsApp and by the other communication applications, Telegram and Signal: all the messages that users send and receive via Telegram are stored on Telegram’s own cloud servers, whereas in the Signal application there is no cloud environment and the data are stored locally.
IX. The European Union and the Use of WhatsApp
The policy of sharing data with Facebook and the companies within the Facebook group, which WhatsApp will put into practice through the “Privacy Policy” entering into force on 8 February 2021, will not apply to the European Union countries forming part of the European Economic Area (EEA), which are subject to the personal data protection rules of the GDPR.
At this point, mention must be made of the judgment of 16 July 2020 delivered by the Court of Justice of the European Union (CJEU) in Facebook Ireland Limited v. Maximillian Schrems (Case C-311/18, Schrems II) on the transfer of data between the European Union and the USA. In its judgment, the CJEU examined the transfer of personal data between the EU and the USA and the conditions for such transfer. While the CJEU held that the Standard Contractual Clauses (SCC) drawn up by the European Commission for the transfer of personal data to controllers established outside the EU are valid, it held that the Privacy Shield between the EU and the USA cannot be applied to data transfers outside the EU. In the Schrems II judgment, the CJEU considered that controllers which are not established in the EU and to which data are transferred from the EU on the basis of the Standard Contractual Clauses must inform the data exporters in the EU as to whether or not they will be able to comply with the Standard Contractual Clauses. Where data recipients outside the EU do not comply with the Standard Contractual Clauses and there are no additional safeguards ensuring an “adequate level of protection”, the EU-based data exporter, as controller, is obliged to suspend and/or terminate this activity.
In its judgment, the CJEU also examined the validity of the EU–US Privacy Shield framework. In holding that the Privacy Shield is invalid, the CJEU considered, with regard to access by US public authorities to the data transferred to the USA, that the surveillance programmes implemented by US public bodies do not provide any safeguard for persons who are not US citizens, that intelligence activities concerning foreigners may also be carried out and that no limitation whatsoever is provided for; it accordingly held that the Privacy Shield cannot ensure adequate protection under EU law, that there is no level of protection equivalent to that provided for in the EU legal order, and that it infringes the Charter of Fundamental Rights of the European Union.
While endorsing the use of SCCs, the Court pointed out that, in cases where SCCs cannot ensure protection (such as those involving access by law enforcement authorities), the provisions of the GDPR which envisage the use of “other clauses and additional safeguards” must be taken as the basis. In this respect, the Schrems II judgment is an indication that a new era has begun for data transfers between the USA and the States within the European Union.
The fact that the new Privacy Policy to be put into effect by WhatsApp does not apply to the European Union and to the European Union countries forming part of the European Economic Area (EEA) is the result of the GDPR, which is effectively applied within the Union, and of the consistent decisions and practices of the data protection authorities within the Union aimed at protecting the privacy of individuals.
X. What Is the Situation in Türkiye?
The updating of the Privacy Policy by WhatsApp was a development expected by many of those concerned with the IT sector and with data protection law. The reaction that followed once it occurred shows that in our country the importance of data protection law has still not been fully grasped, either by society or by companies.
We must state at the outset that this is a matter of personal data processing and that, for users in Türkiye, Law No. 6698 on the Protection of Personal Data (KVKK) must be applied by virtue of the “principle of territoriality”. Since WhatsApp’s servers are located abroad, this situation therefore constitutes a transfer abroad requiring the application of Art. 9 KVKK. Corporate users in particular must take this point into account and, if it is not possible to obtain explicit consent from every single user individually, as required by the reference made in Art. 9 KVKK to Arts. 5 and 6, they must refrain from such use. In conclusion, since a transfer abroad is at issue, a decision must be reached by assessing these three articles together.
On the other hand, WhatsApp is informing its users by means of the change in question. However, since it puts forward explicit consent as a condition for providing the service, this is, as the Personal Data Protection Board has also stated in a large number of its decisions, clearly contrary to Art. 3 and Art. 12(1)(a) KVKK. Consent obtained from the data subject as a precondition, in what amounts to an imposition, has no legal validity. Should WhatsApp not abandon this change, an administrative fine must be imposed on that company pursuant to Art. 18 KVKK. However, the imposition of the fine must not be confused with the enforceability of that fine. The possibility that difficulties will be encountered in enforcement does not remove the fact that the law has been violated or the need for a decision to be taken in this regard.
In this context, by decision of the Competition Board of 11.01.2021, No. 21-02/25-M, an ex officio investigation was opened against Facebook Inc., Facebook Ireland Ltd., Whats App Inc. and Whats App LLC concerning the obligation to share data imposed on WhatsApp users, in order to determine whether Article 6 of Law No. 4054 on the Protection of Competition has been infringed. According to the statement made by the Board, it decided that, since the practice is liable to cause serious and irreparable harm until the final decision to be taken at the end of the investigation, interim measures were to be taken under Article 9 of Law No. 4054; that, in this context, Facebook must suspend the terms it has introduced for the use of the data of users in Türkiye for other services as from 8 February 2021; and that it must notify, by the said date, all users who have accepted these terms or who have received the notification but not accepted them that Facebook has suspended the new terms involving data sharing.
The fact that the Competition Board has taken a decision on the matter is appropriate in view of the reactions of users and in order to prevent misunderstanding. However, a statement on the matter needs to be made first and foremost by the Personal Data Protection Board, which is the body actually concerned. For, as stated in Art. 22(1)(c) KVKK, the duties and powers of the Board are defined as follows: “To examine, upon complaint or ex officio upon learning of an alleged violation, whether personal data are being processed in compliance with the law in matters falling within its remit, and to take interim measures in this regard where necessary.”
Indeed, in the public announcement it made on 12.01.2021, the Board announced that it had opened an ex officio investigation into the WhatsApp Privacy Policy and the transfer of data to the Facebook Companies. In that statement, the Board indicated that, as a result of the preliminary assessment carried out, the following points needed to be noted:
• First, the Board stated that, in obtaining consent from users, WhatsApp does not differentiate between consent to the processing of their personal data and consent to the transfer of data to persons abroad; that it must be examined whether this constitutes a breach in terms of “being declared by free will”, one of the elements of explicit consent, since a data subject who consents to the processing of his or her data may not wish to consent at the same time to the transfer of those data abroad, whereas the change in question regulates these two matters together; and that it must be examined whether data subjects are being compelled to do so.
• Secondly, the Board stated that it must be investigated whether permitting the application to be used only on condition that a transfer is made to another company located abroad gives rise to a breach of certain of the principles listed in Article 4 of the Law, namely “lawfulness and fairness”, “being processed for specified, explicit and legitimate
purposes” and “being relevant, limited and proportionate to the purposes for which they are processed”.
• Thirdly, the Board pointed out that making the service offered conditional upon explicit consent may vitiate the explicit consent given and that this may in turn result in the unlawful processing of personal data; consequently, it must be examined whether the update made by WhatsApp has given rise to a situation in which the service provided is “made conditional upon consent”.
• Finally, the Board stated that it must be examined whether the transfer to be made by WhatsApp to controllers established abroad is contrary to Art. 9 KVKK.
As can be seen, the Board has taken into account the unease that has arisen in society over the matter and has opened an ex officio investigation. Moreover, in line with the findings that we too have made above, it has rightly adopted, from the standpoint of data protection law, an approach based on the processing and transfer of data and, by also disclosing the direction of the investigation, has displayed a correct and exemplary approach in this matter for the sake of transparency.
I am of the opinion that a finding of violation may be made in respect of many of the points mentioned. However, I must also state that this event, which in one respect has developed as a great bubble, has emerged as a positive development in terms of raising awareness of the “protection of personal data” in our society.
Footnotes
- Assoc. Prof. Dr., faculty member in Criminal Law, Criminal Procedure Law and IT Law, Istanbul Aydın University Faculty of Law / Attorney-at-Law, [email protected], ORCID: 0000-0003-4034-5436. ↑
Related publications
Dülger, Murat Volkan, Cybercrime and Internet Communication Law (Bilişim Suçları ve İnternet İletişim Hukuku), 11th ed., Seçkin Publishing, Ankara, 2025.
Dülger, Murat Volkan / Modoğlu, Gözde, Practice Guide to Cybercrime, Methods of Investigation and Prosecution, and Internet Communication Law (Bilişim Suçları, Soruşturma ve Kovuşturma Yöntemleri ile İnternet İletişim Hukuku Uygulama Rehberi), Joint Publication of the European Union and the Council of Europe, Ankara, 2014.
Dülger, Murat Volkan, “Account Suspension and Seizure in Cybercrime Cases: An Analysis of Article 128/A of the Code of Criminal Procedure (CMK) in Terms of Fundamental Rights, the System of Criminal Procedure and Comparative Law” (Bilişim Suçlarında Hesabın Askıya Alınması ve Elkoyma: CMK (Ceza Muhakemesi Kanunu) m. 128/A’nın Temel Haklar, Ceza Muhakemesi Sistematiği ve Karşılaştırmalı Hukuk Açısından Analizi), conference presentation, 2026.
Dülger, Murat Volkan, “The Use of Crypto Assets in Money Laundering and the Measures to Be Taken Against It”, Istanbul Aydın University Faculty of Law Journal, Vol. 10, No. 1, 2024, pp. 41-94.
Dülger, Murat Volkan, “The Use of Crypto Assets in the Laundering of Proceeds of Crime and the Measures to Be Taken” (Kripto Varlıkların Suç Gelirlerinin Aklanmasında Kullanılması ve Alınması Gereken Önlemler), Istanbul Aydın University Faculty of Law Journal (İstanbul Aydın Üniversitesi Hukuk Fakültesi Dergisi), Vol. 10, No. 1, 2024, pp. 41-94.
