Insights

WhatsApp Fined BRL 3 Million for Failing to Comply with Court Order to Intercept Messages

The São Paulo State Court has upheld a BRL 3 million fine imposed on Facebook/WhatsApp for failing to comply with a court order concerning the interception of messages exchanged through the application. The decision addresses a highly sensitive issue involving the cooperation of technology companies with law enforcement authorities, technical limitations, Brazilian jurisdiction, and the protection of users’ personal data.

According to information released by the São Paulo Court of Justice, the judicial order concerned the interception of messages within the context of a criminal investigation. The company argued that compliance was technically impossible due to the platform’s end-to-end encryption architecture. However, in this specific case, the court concluded that the evidence presented was insufficient to exempt the company from liability for failing to comply with the judicial order.

The ruling reinforces a critical takeaway for application providers and companies operating in the digital ecosystem: the importance of establishing robust internal procedures for receiving, assessing, and responding to court orders. Requests involving personal data, digital communications, lawful interception, disclosure of information, and cooperation with public authorities require prompt, technically sound, and well-documented responses.

For technology companies, digital platforms, messaging services, and digital infrastructure operators, the decision serves as a warning about the increasing risk of liability and significant financial penalties for non-compliance with judicial orders. Even where genuine technical limitations exist, organizations should be prepared to demonstrate those limitations clearly, promptly, and with appropriate supporting documentation.

From a corporate governance perspective, organizations should review their procedures for handling requests from authorities, designate responsible internal teams, establish coordinated workflows between legal, technology, information security, and privacy functions, and maintain comprehensive records of all interactions with regulators and judicial authorities.

It is also important to assess in advance how the technical architecture of digital services may affect the organization’s ability to comply with legal requirements. In certain circumstances, companies may face tension between judicial obligations, cybersecurity commitments, encryption technologies, users’ privacy rights, and applicable data protection laws.

These conflicts require a multidisciplinary approach. Responses to judicial orders should not focus solely on formal compliance but should also consider the protection of fundamental rights, the lawful processing of personal data, the platform’s technical limitations, and the regulatory and reputational risks involved.

The decision highlights that digital businesses must be prepared to operate in an environment of increasing judicial and regulatory scrutiny. Legal certainty depends on a combination of regulatory compliance, proper documentation, sound technical governance, and strong institutional response capabilities.

Conteúdo relacionado

ANPD Launches Public Consultation on the Regulation of Digital Platforms

The Use of AI in Businesses: Balancing Productivity, Governance, and Emerging Corporate Risks

Corporate Benefits: 77% of Professionals Want Companies to Revamp Their Benefits Packages

MENU