The messaging app, WhatsApp in January 2021 caused mass confusion when it updated its privacy policy. It stated that it will share some user information with its parent company, Facebook. Although data sharing with Facebook and its subsidiaries has been going on even before the update, they made it clear about the type of information only when they updated the privacy policy.
A privacy policy is the means of communication for a business to share how it handled its customers’ data. In that regard, WhatsApp may have failed its users (more on that later). However, the users in the EU may have had an advantage over others, thanks to GDPR.
In this article, we will look at a checklist for auditing your privacy policy and avoid any confusion among users and any setbacks.
Blog summary
What is a privacy policy for a website?
What do GDPR and CCPA say about privacy policy?
GDPR privacy policy
CCPA privacy policy
WhatsApp’s privacy policy debacle
What’s clear from the reaction to this most recent privacy policy change is that WhatsApp shares much more information with Facebook than many users were aware, and has been doing it since 2016. https://t.co/vrwfrXBmes
— EFF (@EFF) January 23, 2021
We want to address some rumors and be 100% clear we continue to protect your private messages with end-to-end encryption. pic.twitter.com/6qDnzQ98MP
— WhatsApp (@WhatsApp) January 12, 2021
WhatsApp says on its FAQ that “If you haven’t accepted by then, WhatsApp will not delete your account. However, you won't have full functionality of WhatsApp until you accept. For a short time, you'll be able to receive calls and notifications, but won't be able to read or send messages from the app.” Exchanging messages is the main feature of WhatsApp, so this announcement is a huge setback for its users.
WhatsApp has been sharing information with its parent company, Facebook long before the new update, however, the new privacy policy clarifies what type of data it shares. The messages shared between uses are still encrypted.
Here are some highlights of the updated privacy policy:
- WhatsApp will collect device and connection-specific information, such as “battery level, signal strength, app version, browser information, mobile network, connection information (including phone number, mobile operator or ISP), language and time zone, IP address, device operations information, and identifiers (including identifiers unique to Facebook Company Products associated with the same device or account).”
- WhatsApp will collect “IP addresses and other information like phone number area codes to estimate your general location (city, country)” regardless of whether you use their location-related features,
- If you interact with a business on WhatsApp, “the content you share may be visible to several people in that business”, and to the third-party services, the business has given access to.
- When you use any third-party services (including Facebook) integrated with the app, WhatsApp will share your information with them. However, it adds that your WhatsApp message will not be shared on Facebook and “In fact, Facebook will not use your WhatsApp messages for any purpose other than to assist us in operating and providing our Services.”
- If you use any of their payment services, they will process the payment and transaction information.
- If you delete your WhatsApp account from your phone and not using the in-app settings, your information will remain with them for a longer period. Your information related to the group you created and any copy of your message other users have will remain even if you delete the account.
However, the app users in the European Union do not have to agree to the new terms to continue using its services. The GDPR’s stringent laws give the EU users data protection compared with users in other parts of the world. This has drawn huge criticism from countries like India, where the social messaging giant has the highest number of users. The Indian government has cracked down on WhatsApp for its separate policy for the country. It is crucial to note that India lacks a robust data protection law (the Personal Data Protection Bill is currently in draft), which prevents its citizens from a higher level of data protection. WhatsApp’s “all or nothing” approach is currently being discussed in Indian court now.
Checklist to audit the privacy policy
CookieYes free privacy policy generator
Creating a privacy policy page from scratch or updating it to comply with legal standards is quite hard. It will require legal or expert assistance to draft the content. Any necessary information missing may put you in trouble. And so does the unnecessary or misleading information. You should avoid any information that may cause confusion, mislead the users, and prevent them from obtaining the necessary information to make an informed decision.
CookieYes privacy policy generator is a free online tool that will help you to create a privacy policy that meets the legal standards and displays your business’ transparency.
Our online tool collects necessary information from you about your website’s data collection and use practices to automatically create a privacy policy for the website. The whole process barely takes more than two minutes.


CookieYes cookie consent solution for your business
As discussed, a privacy policy must discuss what type of information you collect and how the users can opt-out. If your website uses cookies, the privacy policy must include details about it.
CookieYes is a cookie consent management application for your websites to comply with data protection laws like GDPR, CCPA, ePrivacy Directive, CNIL and LGPD. It helps websites to collect cookie consent using its fully customizable cookie banners. It automatically scans your website for cookies and identifies the third-party cookies and auto-blocks them before getting user consent. You can also add the scripts that you want CookieYes to block before user consent. The cookie list it identifies can be added to your privacy policy.
You can let users take control of what type of cookies the website must load by giving granular consent choices (opt-in and opt-out) for cookie categories. CookieYes logs the consent received in a downloadable file that you use to demonstrate proof of consent, if necessary.
There is a free privacy policy generator in the application as well. As discussed earlier, it generates a privacy policy for your website in less than two minutes.
Other than that, CookieYes offers many other features, such as auto-translation of the cookie consent banner, geo-targeted display of the banner, banner callback button, and additional CSS customizations.





