Meta and WhatsApp face trial in the U.S. over privacy breach
What they're not telling you: Meta and WhatsApp Face Trial Over Systematic Privacy Breach — Documents Show Undisclosed Data Sharing With Third Parties Meta Platforms and its subsidiary WhatsApp are entering federal litigation over allegations that they systematically shared user metadata and communications data with third-party developers without explicit user consent, according to court filings that detail the scope of data transferred and the infrastructure mechanisms that enabled it. The lawsuit centers on WhatsApp's data-sharing architecture between 2016 and 2019, a period when the messaging platform continued transmitting user phone numbers, last-seen status information, and contact list metadata to business-account holders and app developers despite privacy policies stating such data would not be shared with third parties without user notification. Court documents specify that WhatsApp's server-side infrastructure maintained no granular consent controls that would have prevented this transmission.
What the Documents Show
Instead, the data flowed through WhatsApp Business API endpoints to any developer with a WhatsApp Business Account, creating what the litigation characterizes as a structural privacy failure rather than an isolated incident. Meta acquired WhatsApp in 2014 for $19 billion, explicitly citing privacy protection as a core asset value. Internal communications cited in the lawsuit show that post-acquisition, WhatsApp's engineering teams were directed to expand data-sharing capabilities with Meta's advertising and analytics divisions, creating integration points that bypassed the original WhatsApp privacy architecture. The specific technical mechanism involved WhatsApp's server logs recording all metadata transactions, which were then accessible to Meta's data warehouse systems through internal API calls that required no additional user authorization. The legal exposure centers on violations of the California Consumer Legal Remedies Act and state-level privacy statutes that require affirmative consent before sharing personal information with third parties.
Follow the Money
Federal Trade Commission regulations prohibiting deceptive privacy practices also feature prominently in the complaint. Meta's settlement with the FTC in 2020 explicitly required the company to implement technical safeguards preventing unauthorized data sharing—a requirement that the current litigation suggests was not meaningfully implemented at the infrastructure level. What distinguishes this case from previous Meta privacy litigation is the documentary evidence of deliberate engineering decisions. Rather than alleging negligence, plaintiffs point to specific code modifications, database schema changes, and API permission structures that were consciously altered to enable expanded data access. WhatsApp's original encryption-first architecture included local-only storage of contact information; the system was modified to create server-side copies of contact lists that could be indexed and accessed by third-party applications. Depositions of former Meta engineers have established that these modifications were not accidental byproducts of system integration but deliberate architectural choices made at the product management level.
What Else We Know
The trial will likely hinge on whether Meta's contractual privacy commitments to WhatsApp users constitute enforceable consumer protection obligations under California law, and whether the technical capacity to prevent third-party data access—combined with the business decision not to implement such controls—constitutes knowing deception under FTC statutes. Meta's legal position relies on distinguishing between data sharing (which occurred) and unauthorized use (which they argue did not occur, as developers' terms of service restricted certain data uses). The distinction has limited practical force if the underlying data transfer violated user expectations.
Primary Sources
- Source: r/privacy
- Category: Tech & Privacy
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.