- Texas sued Meta and WhatsApp over allegations that encryption marketing misleads users, claiming the app collects and shares metadata with Meta without proper disclosure.
- The lawsuit does not ask WhatsApp to break encryption but instead wants clearer disclosures about what data the company collects and shares with its parent company.
- Texas prosecutors can seek civil penalties of up to $10,000 per violation under the state’s Deceptive Trade Practices Act. This adds to Meta’s string of legal challenges over data practices.
The state of Texas has filed a lawsuit against Meta and its subsidiary WhatsApp, and alleges that they misled consumers about their privacy protections. The lawsuit claims that WhatsApp’s end-to-end encryption is not enough to protect consumers against how they marketed the product.
Texas Attorney General Ken Paxton announced the legal action on May 21, 2026. The complaint alleges that WhatsApp collects and shares user metadata with Meta’s other platforms without proper disclosure. The state argues that this data sharing violates Texas consumer protection laws.
The lawsuit seeks injunctive relief to stop the alleged practices and civil penalties for each violation. Texas authorities claim that millions of state residents use WhatsApp, believing their conversations remain completely private. The legal action represents the latest in a series of state-level challenges against major technology companies over data privacy practices.
State Claims Encryption Claims Mislead Consumers
According to the lawsuit, WhatsApp’s branding creates a false impression of user privacy. Though the app encrypts actual messages, the metadata surrounding the content, such as information pertaining to who users chatted with, when they send messages, and how long they remain active within the application, is still visible to and the platform shares it with its parent company, Meta.
Texas prosecutors assert that consumers cannot make informed choices when companies hide important privacy limitations. The complaint states that WhatsApp users reasonably believe end-to-end encryption means no one else can access their communication details. The state argues that Meta’s internal data sharing practices contradict this reasonable expectation.
Meta has not yet filed a formal response to the lawsuit in court. The company officials previously defended WhatsApp’s privacy practices as the most advanced in their industry and the most accessible to users. The outcome of this case could establish a new standard for interpretive court rulings regarding consumer protection laws in conjunction with encrypted messaging services.
Additionally, the lawsuit alleges that WhatsApp has breached the Texas Deceptive Trade Practices Act, which prohibits false, misleading, and deceptive acts in carrying on trade or commerce. So, the state, through a filed suit against a company, can demand penalties up to $10,000.00 for each violation of these laws.
WhatsApp Encryption Faces Growing Government Scrutiny
There has been a lot of debate around end-to-end encryption regarding privacy and policing powers. Messaging platforms have argued that strong encryption protects their users from hackers, criminals, and government overreach, while law enforcement has argued that encryption provides the opportunity for criminals to conceal their illegal activities with no fear of arrest.
The Texas lawsuit is different from other encryption lawsuits in that it isn’t law enforcement, rather it concentrates on a consumer misrepresentation issue. Texas is not asking WhatsApp to provide a backdoor that allows law enforcement to access encrypted messages or to provide a way to access their end-to-end encrypted messages. Texas is asking WhatsApp to be more explicit about how and what data it collects and shares with its parent company, Meta.
WhatsApp announced its end-to-end encryption as a default feature in 2016. This aims to ensure that only senders and recipients have the ability to read the contents of their messages. But the metadata associated with any given message has historically not had the same type of protections placed on the message itself; typically, messaging platforms keep metadata for network management and to help prevent spam.
Privacy advocates warn that this lawsuit could result in unintended consequences for consumers. If courts decide that all messages must have their metadata disclosed, the user may lose the protections they currently enjoy, even without knowing it. The case reflects the gap between the expectations of consumers regarding encryption and the actual provisions of the technology.
Governments are actively debating these issues. Canadian Bill C-22 has raised privacy concerns from major tech companies and civil liberties groups, showing how encryption and data privacy remain contentious global issues.
Meta Faces String of Legal Challenges Over Data Practices
This class-action lawsuit filed in Texas adds to a long list of legal issues facing Meta and its various platforms. The company has received penalties from both federal and state governments numerous times within the last decade for breaches of personal privacy of both users and third parties. The Federal Trade Commission imposed a fine of $5 billion on Meta in 2019 for violations.
Other states have also sued Meta regarding its data practices; some of the cases focused on the abuse of user data and the use of algorithms in its various services and products. Many of the legal actions against Meta still remain pending in federal courts.
Meta claims it has always practiced reasonable privacy and transparency for personal data of its users. According to the company, users maintain ultimate control over the personal data they submit and can access the settings of their privacy preferences at any desired time, but critics argue that default settings and confusing options lead users to share more data than they realize.
This Texas lawsuit could take years to reach its resolution through the legal system. Legal experts expect both sides to file motions seeking dismissal or summary judgment before any trial occurs. The outcome may influence how other states approach similar claims against encrypted messaging services.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...