The right to privacy embodies the presumption that individuals should enjoy elements of self-determination and liberty, with or without interaction with others, free from arbitrary state intervention and from excessive unsolicited intervention by other uninvited individuals. Accordingly, privacy can be understood as a claim to a sphere of autonomy in which one has control over his or her personal information. In January of 2021, the world became consumed with the matter pertaining to the revised WhatsApp Privacy Policy and conversations have continued in Zimbabwe. Of importance in the discussion of this revised policy is to ensure that one peruses its proposed changes. A closer analysis thereof reveals that there are different terms of service and policies for European and Non-European countries. This article becomes important in analyzing whether the revised privacy policy is in compliance with the laws of Zimbabwe.
The basic components of any privacy and data protection regulation or directive include the safeguarding of data and the obtaining of consent from the person whose data is being collected. One of the popularly used social media platforms, WhatsApp, announced a new set of updated privacy policies which were initially scheduled to come into effect on the 8th of February but have since been postponed to the 15th of May 2021. Of these anticipated changes, the contentious ones include how WhatsApp will process a data subject’s data, the fact that businesses will use Facebook services to store and manage WhatsApp chats as well as the integration of WhatsApp with other Facebook Products. Further, users that wish to continue using this platform, post the effective date, are obliged to agree to the new terms and conditions, failure of which the user’s account will be deleted with their data being retained by WhatsApp.
Privacy and Data Protection law in Zimbabwe
The essence of a person’s interest in privacy forms the core of data privacy. In terms of the supreme law of Zimbabwe, section 57 of the Constitution affords every person with the right to privacy. This is the starting point in recognizing the right to privacy and protection of privacy data initiative in the Republic. However, presently there is no specific law comprehensively dealing with privacy and data issues.The Cyber Security and Data Protection Bill, which was gazetted on the 15th of May 2020, is the latest attempt to consolidate a framework for the protection of privacy and data rights. This Bill is yet to be passed into law.
What are issues for WhatsApp Users?
In light of the broad revised policy update, there are two issues that require attention. Firstly, for those users whose accounts will cease to exist upon deletion, it is important that they understand that WhatsApp will retain the data that it has in its possession. Whether this amounts to unlawful retention of data is difficult to pursue in argument because our law, including the Bill, does not provide for Data Deletion or Data Retention by the Data Controller or penalties thereof in the event of infringement.
Secondly, users that are contemplating on agreeing to these new terms and conditions must be well informed of just how much of their personal information will be collected, processed, stored as well as shared with Facebook. According to the new policy WhatsApp will automatically collect what has been termed as “hardware data” which is not defined in our law but is said to include the following:
- Usage and Log information which is information about a user’s activity on the platform including inter alia the interaction with other users/businesses, the time, frequency and duration of activities, log files and diagnostics, crash and performance logs as well as information relating to payments or business features.
- Device and Connection Information such as operation system information, battery level, signal strength, app version, browser information, mobile network, connection information (including phone number, mobile operator or ISP), language and time zone, IP address, device operation information and identifiers (including identifiers unique to Facebook Company Products associated with the same device or account).
- Location Information which includes precise information from your device with the user’s permission but if the user does not use the location-related features WhatsApp will use IP addresses and other information like phone number area codes.
- Cookies are used to provide WhatsApp Services for web and desktop and other web-based services as well as to remember the user’s choices such as language preferences.
The seemingly protective buffer that WhatsApp is using to attract its users is that their services have optional features from which, upon notification, if a user does not wish to provide the required information for that specific feature it will not be available for their use. For example it follows that if a user does not permit the sharing of his or her location from their device then such location cannot be shared to anyone in their WhatsApp contact list. Further, WhatsApp provides the “end-to-end encryption” feature for its users which is designed to prevent third parties from accessing data being transferred from the sender’s system to that of the recipient. In essence this feature ensures that no one including WhatsApp, other than the sender and recipient, can read or listen to what has been transferred. However, whether WhatsApp ensures adequate privacy and data protection for its users or whether it can be held liable for the unlawful usage thereof is a topic of much debate given our governing laws.
In conclusion, it is without doubt that the new WhatsApp update poses privacy and data security related questions amongst intellectuals. The users that wish to continue using the Platform have no choice but to agree to the new terms and conditions before the effective date, whilst those that do not agree will have their data retained by WhatsApp even after deletion of their account. The unfortunate instance is that a great number of WhatsApp users in Zimbabwe that have found convenience in communicating with their relations over this platform are unaware or do not comprehend fully the potential risks of privacy infringements introduced by this update.
It is therefore incumbent on our parliamentarians to prioritise the interests and rights of the data subjects within their jurisdiction by enacting laws that ensure adequate protection as well as address the concerns relating to the retained data. The law should deal with principles on data privacy such as collection limitation, use limitation and security safeguards. The current law results in a lot of legal uncertainty and risk between the consumers and the business enterprises who hold personal and private data.

0 Comments