Friends and family often ask me which platform they should use so that their messages are private and secure. The discussion has sparked again since Instagram announced that, as of May 8th, 2026, they will discontinue optional end-to-end encryption (E2EE) for direct messages. Meta is removing it due to low usage. Messages will no longer be private, meaning Meta can access, scan, and store conversation contents for safety and ad targeting.

So should everyone move away from Instagram and find a “safer” instant messaging platform?

The answer is nuanced and I don’t mean to say the typical lawyer answer “it depends”. This is just about understanding how messaging tools operate and how their function interacts with legal obligations.

“Private” is not a legal concept. When users think of a private message they often understand something that is not visible to the public and is sent only to limited audience. Something that others outside the intended recipients cannot read.

From a legal perspective, that’s not sufficient. Based on the GDPR or even more so on country and industry specific professional secrecy obligations, the question should rather be:

* Who can access, process, or store the data and under what conditions? *

A message can feel “private” to a user because it’s not public, while still being legally non-confidential because (a) the provider can process it, (b) it is stored on servers outside your control, (c) it may be accessed under certain circumstances (e.g. security, legal requests), (d) there is no governance or restriction on further use.

You see the legal standard is much stricter and more structural.

[ENTER E2EE]

End-to-end encryption ensures that only the sender and recipient can read the content of a message. It works by encrypting a message directly on the sender’s device using the recipient’s public cryptographic key, so that it becomes unreadable before it even leaves the device; it then travels through the platform as encrypted data and can only be decrypted on the recipient’s device using their private key, which is not accessible to the service provider, meaning the provider can transmit the message but cannot read its content, although it may still have access to surrounding information such as who communicated, when, and how often.

Encryption is therefore a technical safeguard, not a complete confidentiality guarantee.

So the legal risk actually comes from:

  1. Using tools that are not designed for confidential exchanges,
  2. Lack of internal governance over communication channels,
  3. Mixing personal and professional use,
  4. Absence of auditability and control.

If you are a professional organisation, this translates into privacy law exposure, potential confidentiality breaches and non-compliance with contractual commitments.

So what should I do, you ask?

If you are my kid or a friend:
– Do not assume all chats are equally protected.
– Avoid sharing sensitive information casually.
– Distinguish between “easy” and “appropriate”.

If you are my client or prospect:
– Define approved communication channels.
– Avoid conducting sensitive discussions on informal apps.
– Train teams on basic data handling reflexes.

But please don’t ask me: should I stop using instagram now or what tool should I use?

The answer is simple: whatever you use, do it consciously. Know what communication should go where and ask yourself “would I feel comfortable if the information I am sharing was sold to a third party?”. And in case of doubt, let me know 😉


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *