12.2 Privacy Risks of Communications Technologies: Video Calls, Messaging, Mobile Devices, Social Media, and Gaming
Key Takeaways
Transport encryption protects data between device and server, while end-to-end encryption means only the participants' devices hold the keys; claiming E2EE without it is deceptive, as the FTC's 2020 Zoom order showed.
Even with end-to-end encryption, metadata such as who talks to whom, when, and how often can reveal relationships and must be minimized.
Meeting recordings and AI transcripts or summaries create new personal data that needs notice, consent where recording laws require it, access control, and retention limits.
Social media risks include public-by-default settings, contact importers that enable scraping (the 533 million-record Facebook dataset), tagging, and location in posts.
Gaming platforms combine children's data, voice and text chat with strangers, and in-game purchases; the FTC's 2022 Epic Games order included a $275 million COPPA penalty partly over default-on chat for children.
12.2 Privacy Risks of Communications Technologies: Video Calls, Messaging, Mobile Devices, Social Media, and Gaming
Quick Summary: The BoK asks technologists to identify and minimize privacy risks in video calls and conferencing, messaging, mobile devices, social media, and gaming platforms. These tools carry content (what people say) and metadata (who, when, where, how often). The core engineering questions are who holds the encryption keys, what metadata the service keeps, what recordings and transcripts are created, what is visible by default, and how children are protected.
Communications tools are used at work and at home, often on the same device. Employers choose and configure many of them (Section 12.3), which makes their privacy settings part of the organization's responsibility.
Encryption: Transport Versus End-to-End
| Model | Who Can Read Content | Typical Use |
|---|---|---|
| Transport encryption (TLS) | The service provider can read content on its servers | Most web apps, email, many meeting services by default |
| End-to-end encryption (E2EE) | Only participants' devices hold the keys; the provider sees ciphertext | Signal, WhatsApp, iMessage, E2EE meeting modes |
Claims about encryption must be accurate. In 2020 the U.S. Federal Trade Commission alleged that Zoom had advertised "end-to-end, 256-bit encryption" while it could access meeting content; its order (finalized in 2021) required a comprehensive security program. Zoom later introduced a true E2EE meeting option, which disables some features, such as cloud recording, because the server cannot see the content.
Modern messaging E2EE uses the Signal Protocol (double ratchet with forward secrecy) or the IETF Messaging Layer Security (MLS) standard (RFC 9420, July 2023) for large groups.
Metadata Still Leaks
E2EE protects content, not necessarily metadata: account identifiers, contacts, timestamps, IP addresses, and group memberships. Metadata alone can reveal a relationship, a source talking to a journalist, or a patient contacting a clinic. Techniques such as Signal's "sealed sender," minimal server-side logging, and contact discovery that does not upload address books in plain form reduce metadata exposure.
Backups and Lawful Access
Messages are often backed up to cloud storage. Unless the backup is also end-to-end encrypted (for example, Apple's optional Advanced Data Protection for iCloud), the provider can read it. Government pressure on encryption continues: in February 2025 Apple withdrew Advanced Data Protection for new UK users rather than build access for authorities under the UK Investigatory Powers Act.
Video Calls and Conferencing
- Recordings, transcripts, and AI summaries create new personal data. Tell participants, obtain consent where recording laws require it (several U.S. states require all parties' consent to record conversations), restrict access, and set retention.
- Attention and engagement tracking features have been withdrawn after criticism (Zoom removed its "attention tracking" feature in 2020); avoid surveillance features that do not serve the meeting.
- Meeting security: passcodes, waiting rooms, and authenticated-only meetings stop uninvited attendees ("Zoombombing").
- Backgrounds and screen sharing reveal homes, documents, and notifications; offer blur and notification suppression.
- Data residency and processors: meeting services process content, metadata, and telemetry; contracts and transfer mechanisms apply (Section 16.2).
Messaging and Collaboration
- Workplace chat (Slack, Microsoft Teams) is usually transport-encrypted and retained for compliance, so employees should understand it is not private.
- Off-channel messaging creates conflicts between privacy and record-keeping. U.S. financial regulators imposed more than $2 billion in fines from 2021 onward on firms whose staff used personal messaging apps for business, because the messages were not retained as required.
- Disappearing messages reduce retention risk but must be weighed against legal holds and recordkeeping duties.
Mobile Devices
Mobile devices combine sensors, contacts, photos, location, and identifiers. Key privacy features and practices:
- Runtime permissions for location, camera, microphone, contacts, and photos, requested in context and with the narrowest scope (approximate location, "while using," selected photos only).
- Background access indicators (camera and microphone dots) and periodic reminders about background location.
- Limited advertising identifiers (Apple's App Tracking Transparency, Android's resettable advertising ID).
- Clipboard and screenshot protections (Section 10.1).
- Work and personal separation through work profiles (Section 12.3).
Social Media
- Visibility defaults: public-by-default posts and profiles expose more than users expect; protective defaults matter most for teenagers.
- Contact discovery and importers: features that let people find friends by phone number can be abused at scale. A dataset of about 533 million Facebook users, built by abusing a contact-importer feature in 2019, was published in 2021, and Ireland's Data Protection Commission fined Meta EUR 265 million in 2022 over the data protection by design and by default failures.
- Tagging and face suggestions: let people approve tags and opt out of face recognition.
- Location in posts and photo metadata: strip EXIF data and make location sharing opt-in.
- Data portability and downloads: give users their data, but protect the download flow against account takeover.
Gaming Platforms
Online games combine children's data, real-time voice and text chat with strangers, behavioral telemetry, in-game purchases, and sometimes kernel-level anti-cheat software. In 2022 Epic Games agreed to pay $520 million to resolve FTC allegations: $275 million as a COPPA civil penalty, in part because Fortnite's voice and text chat were on by default for children, exposing them to harassment, and $245 million in refunds over dark patterns in purchases. The order required voice and text chat to be off by default for children and teens.
Controls for gaming platforms:
- Age assurance proportionate to risk and COPPA-compliant parental consent for users under 13. The FTC's amended COPPA Rule (effective June 23, 2025, with most compliance required by April 22, 2026) adds separate consent for disclosing children's data to third parties and requires a written data retention policy.
- Chat off by default for minors, friend-only communication, and filters for personal information in chat.
- Purchase safeguards: clear prices, confirmation steps, and parental controls (Section 9.2).
- Telemetry minimization and transparency about anti-cheat data collection.
A video-conferencing vendor's marketing says meetings are 'end-to-end encrypted,' but its servers decrypt audio to generate cloud recordings and transcripts. What is the main privacy problem?
None, because the connection between each participant and the vendor's servers uses TLS with modern cipher suites.
The vendor violates PCI DSS by processing and storing meeting audio on its servers.
The vendor must stop offering transcripts in all jurisdictions.
The claim is misleading: the provider can access content, so it is not end-to-end encryption.
A messaging app uses strong end-to-end encryption for message content. Which remaining privacy risk is most important to address?
Metadata about who talks to whom, when, and from where.
Message content can still be read by the provider's servers, because end-to-end encryption protects only data in transit.
The app cannot comply with any data subject rights.
End-to-end encryption prevents users from deleting their own messages.
A game studio launches an online game popular with children aged 8 to 12. Which default configuration best reflects current privacy expectations and the FTC's Epic Games order?
Chat on by default, with children's messages reviewed by moderators after they are sent.
Chat on by default, with a parental opt-out buried in the settings menu.
Chat off by default for children, parental consent, and friend-only chat when enabled.
Voice and text chat on by default with all players, so that children can find teammates and make friends quickly.
Sections you finish are checked off in the contents.