Facebook and Instagram Link Previews Would Break EU Privacy Law, Say Security Researchers

A follow-up report by security researchers Talal Haj Bakry and Tommy Mysk has alleged that Facebook Messenger and Instagram are collecting and using data from link previews in a way that would breach European privacy law.

facebook messenger icon new

In October last year, Bakry and Mysk revealed that link previews in popular messaging apps can lead to security and privacy issues on iOS and Android. It was discovered that apps could leak IP addresses, expose links sent in end-to-end encrypted chats, download large files without users' consent, and copy private data through link previews.

In that report, Bakry and Mysk found that Facebook Messenger and Instagram behaved unlike other messaging apps in that they downloaded the entire contents of any link to its servers, regardless of size. When questioned about this unusual behavior, Facebook reportedly said that it considers this to be "working as intended."

Copies of link preview data kept on external servers could be subject to breaches or misuse, which may be particularly concerning for users who send links to sensitive or confidential private data such as business documents, bills, contracts, or medical records.

Now, Bakry and Mysk have found that Facebook has recently stopped generating link previews in Messenger and Instagram for users in Europe to comply with the European Union's ePrivacy Directive. The change also applies to users outside Europe if they communicate with someone in the region.

messenger link previewsLinks sent in Facebook Messenger as seen in Europe and other regions

The researchers suggest that since Europe has "some of the most robust privacy laws" and Facebook has now removed link previews seemingly to comply with the legislation, the company must have been using the data from link previews in a way that would breach the ePrivacy Directive.

It is an implicit confirmation that Facebook's handling of link previews in Messenger and Instagram did not conform to privacy regulations in Europe, otherwise they wouldn't have disabled the feature... Stopping this service in Europe strongly hints that Facebook may be using this content for purposes other than generating previews.

Bakry and Mysk believe that Facebook's link previews may have infringed on articles 4:1a, 4:2, and 5:3 of the ePrivacy Directive. These articles include the requirement that personal data can only be accessed by authorized personnel for legal purposes, the need to inform users of the risks of a data breach, and the need to gain user consent having been provided with "clear and comprehensive information" about how data is collected.

As links may relate to personal data, the ePrivacy Directive prevents Facebook from storing, processing, or using this information without explicit consent from users in the EU. Facebook would also have to make it clear to users why it is downloading the contents of link previews prior to requesting consent.

Bakry and Mysk have demonstrated that Facebook servers download and store the content of links sent through its apps, and if the same link is sent a second time, Facebook generates a link preview without downloading the contents of the link. This purportedly indicates that the content is stored or cached by Facebook and is proven by the amount of data that is uploaded from a user's device.

Link previews continue to be available in Messenger and Instagram for users outside Europe. Facebook's current Terms of Service state that any content users share through any of Facebook's services will be used for various purposes such as personalizing content, ads, making suggestions, and learning about users, both on and off Facebook's products. In Europe, this use of personal data now requires explicit consent from users even if it is approved by Facebook's Terms of Service.

Facebook disabled link previews for users in Europe to comply with new privacy regulations. This confirms our privacy concerns that sending links to private files in Messenger and Instagram is unsafe. While Facebook did disable link previews in Europe, users in other regions should refrain from sending links through either of these apps. The better option would be to switch to other messaging apps which respect user privacy in all parts of the world alike.

Bakry and Mysk are now actively recommending that users outside Europe do not send links in Messenger or Instagram due to privacy concerns, and have even suggested that users move to other messaging apps entirely.

Beyond link previews, the researchers have previously investigated popular iPhone and iPad apps "snooping" on iOS pasteboard data and HTTP security vulnerabilities in TikTok.

Popular Stories

iPhone 17 Pro Blue Feature Tighter Crop

iPhone 17 Pro Launching Later This Year With These 12 New Features

Tuesday May 27, 2025 9:10 am PDT by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. Below, we recap key changes rumored for the iPhone 17 Pro models as of May 2025: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models have a titanium frame, and the iPhone X ...
Whatsapp Feature

WhatsApp Teases Long-Awaited iPad App

Monday May 26, 2025 10:23 am PDT by
The popular messaging app WhatsApp has teased a long-awaited iPad app, which would be offered alongside its existing iPhone and Mac apps. The official WhatsApp account on X today reacted with an eyes emoji to a post saying that WhatsApp should release an iPad app. This could be a hint that Meta is gearing up to release WhatsApp for iPad, which has already been available for beta testing via...
WWDC 2025 Banner

WWDC is Just Two Weeks Away: Here Are the Biggest iOS 19 Rumors

Monday May 26, 2025 8:12 am PDT by
WWDC 2025 is just two weeks away as of today, with Apple's opening keynote scheduled for Monday, June 9 at 10 a.m. Pacific Time. During the keynote, Apple is expected to announce iOS 19, iPadOS 19, macOS 16, watchOS 12, tvOS 19, visionOS 3, and other software updates, along with new Apple Intelligence features. In some years, there are also hardware announcements at WWDC, but there are no...
HomePod With Screen Feature

Apple's Rumored Smart Home Hub Has Faced a Disappointing Setback

Monday May 26, 2025 7:18 am PDT by
Apple has scrapped some of the features that it had planned for its long-rumored smart home hub device, according to Bloomberg's Mark Gurman. "I'm told that Apple has pulled some bolder features from the device that could reappear in subsequent models," wrote Gurman, in his Power On newsletter this week. However, he did not reveal any of the specific features that were pulled. Apple made...
iPhone Top Left Hole Punch Face ID Feature 2

Apple Rumored to Redesign the iPhone Every Year Through to 2027

Tuesday May 27, 2025 5:17 am PDT by
Apple is reportedly preparing to implement significant iPhone hardware redesigns each year for the next three generations. According leaks from the Chinese supply chain disclosed by Weibo user "Digital Chat Station," Apple plans to carry out a series of phased industrial design changes affecting different parts of the iPhone across three consecutive years: 2025, 2026, and 2027. The changes...
top stories 2025 05 24

Top Stories: iPhone 17 Air Details, Apple's Smart Glasses, and More

Saturday May 24, 2025 6:00 am PDT by
WWDC is coming up quickly with a number of software announcements in store, but we're also looking further ahead to hardware launches like the iPhone 17 lineup and even Apple's smart glasses project. This week also saw big news with former Apple design guru Jony Ive joining forces with OpenAI to build future AI-driven devices, while Fortnite returned to the U.S. App Store for the first time...
iCloud General Feature Redux

Apple Raises iCloud+ Prices in Three Countries

Monday May 26, 2025 1:45 pm PDT by
Apple recently raised prices for its iCloud+ plans in Brazil, Chile, and Peru, according to a support document updated last Thursday. The table below outlines the price changes in each country. Country Old Prices New Prices Brazil 50GB: R$ 4.90 200GB: R$ 14.90 2TB: R$ 49.90 6TB: R$ 149.90 12TB: R$ 299.90 50GB: R$ ...
Emergency SOS via Satellite iPhone YT

Report: Apple Planned to Offer Starlink-Like Home Internet Service

Tuesday May 27, 2025 7:08 am PDT by
Apple had plans to offer a Starlink-like satellite home internet service in collaboration with Boeing, The Information reports. Starting in 2015, Apple held discussions with Boeing about "Project Eagle," a plan to launch a service to provide wireless internet services to iPhones and homes. The companies would have launched thousands of satellites into orbit around the Earth to beam internet...

Top Rated Comments

Matthew.H Avatar
56 months ago
Why does this not surprise me.
Score: 9 Votes (Like | Disagree)
and 1989 others Avatar
56 months ago
What is more curious, is that day by day we have story after story of the FB group misusing data, mining data, selling personal data, building profiles of individual for nefarious means, manipulating the political sphere etc etc...

And YET people still use the services every single day.
Score: 8 Votes (Like | Disagree)
Mike_Trivisonno Avatar
56 months ago
Honestly, what the heck is wrong with these companies? They are so weird and creepy. Can't they just stop stalking their users? Just quit it. People want advanced technology, not cyber-stalking freaks.
Score: 6 Votes (Like | Disagree)
luvbug Avatar
56 months ago
Evil, just simply evil. Scumbags extraordinaire.
.
Score: 6 Votes (Like | Disagree)
Pangalactic Avatar
56 months ago
Waiting for the Facebook reply "But tracking and data mining is good for you! It is privacy that violates your...ehmm...advertising potential!"
Score: 6 Votes (Like | Disagree)
infinitejest Avatar
56 months ago
They only do that to save small businesses, guys!
Score: 6 Votes (Like | Disagree)