How does this work if someone outside of the EU is in the same group or private chats as an EU user?
Surely by sharing information about those chats they would be breaking the GDPR if that's the case.
How does this work if someone outside of the EU is in the same group or private chats as an EU user?
Surely by sharing information about those chats they would be breaking the GDPR if that's the case.
(I assume they have or will come up with a work-around, as far as legally possible)
Chat messages in themselves are not necessarily PII, but then again WhatsApp isn't claiming to freely read the messages. I suppose the messages in the chat could be mined for keywords to give ads to the non-EU/EEA persons.
The same is not true for all the metadata.
No. In law, EU GDPR absolutely does not cover EU citizens who are physically outside the EU.
GDPR makes no reference to citizens or residents and is understood to apply to any person whenever they are physically present in the EU, and to data which is created/located physically inside the EU's borders (and to data which has crossed the border within the rules).
Citation e.g. first search result https://www.hipaajournal.com/does-gdpr-apply-to-eu-citizens-... which suggests only that businesses might find it easier to give GDPR protections more widely. I would not expect that advice to be taken by Facebook.
The user’s phone number is a unique ID as far as WhatsApp is concerned, so any metadata related to phone numbers in the “European region” (eg numbers starting with +33, +44, +49, etc) would be treated as if the 2020-era privacy policy applies.
That was my case until recently, and of many other expats I know.
I know looking at a phone number’s country code is imperfect, but pretty much every other method is problematic too.
* the most explicit would be for EU residents to contact WhatsApp with proof of residency. Unfortunately it creates a vast bureaucracy and most people should be wary of sharing scans of their documents, with Facebook of all companies.
* The WhatsApp app could look at which network the phone it’s on is connected to. If it’s a EU network (say connected to a EU network for 6+ months to filter out tourists), protections could apply, but I this would probably adversely impact EU nationals in non-EU countries.
So yes, a number of options are possible, each have pros and cons. How far Facebook would go would depend on regulatory direction, almost certainly.