- Meta has removed end-to-end encryption from Instagram direct messages, but keeps it by default on WhatsApp.
- The company justifies the change by citing the low use of encryption on Instagram and regulatory and security pressures.
- The decision opens the door to the analysis of messages and their possible use in moderation, advertising, or AI training.
- In Europe and Spain, users and companies should consider whether to move sensitive conversations to WhatsApp, Signal, or other encrypted apps.
While Instagram has backtracked and has removed enhanced protection of your private messages, WhatsApp maintains end-to-end encryption as a core feature of its service.This contrast within Meta's own ecosystem once again highlights the extent to which privacy is a real priority for major platforms.
For users in Spain and the rest of Europe, the scenario is clear: Conversations that truly require discretion and security should be moved off Instagram and used on channels that are encrypted by default., like WhatsApp or independent alternatives such as SignalMeta's move with Instagram isn't just a technical change; it's a warning that the rules of the game can change overnight.
WhatsApp retains encryption: what it means in practice
On WhatsApp, end-to-end encryption (E2EE) It is enabled by default in all chats and callswithout the user having to change any settings. This means that messages are encrypted on the sender's device and only decrypted on the recipient's, so even Meta's servers cannot read the content.
This model contrasts sharply with that of Instagram direct messages, where The company has switched to a standard encryption scheme both in transit and on its serverswhich protects data from third parties but allows technical access by Meta. WhatsApp, on the other hand, insists that it has no way of seeing what is sent between users.
The result is that, within the same business group, WhatsApp has become the "safe haven app" for those seeking to preserve the confidentiality of their conversations. In fact, The Meta itself refers to Instagram users who want to continue using encryption on WhatsApp, effectively assuming that role of a "private" platform within the ecosystem.
This approach has clear implications for Europe, where the General Data Protection Regulation (GDPR) requires special care with personal information. Businesses, freelancers, and organizations that communicate with clients or contacts in the EU will find in WhatsApp a tool already aligned with the principle of minimizing access to contentsomething that Instagram has stopped offering.
Instagram loses end-to-end encryption: what's changed
Until May 8, 2026, Instagram offered optional chats with end-to-end encryption in direct messagesIt wasn't the default setting; it was somewhat hidden in the settings and was never rolled out uniformly across all regions, but it prevented even Meta from reading those conversations.
From that date, All Instagram direct messages have been switched to a system without end-to-end encryption.They continue to travel protected from third parties while being sent and stored encrypted on the company's servers, but Meta retains the key to access their content when it deems necessary within its policies and the applicable legal framework.
The company notified users who had active encrypted chats to download their histories before the feature disappearedThose who did not make a backup in time have seen how those conversations ceased to be available as special protected chats and were transferred to the standard system without E2EE.
In practice, this means that Text messages, photos, videos, voice notes, and direct calls on Instagram can be analyzed by Meta's internal systems., handed over to authorities under legal requirement and, potentially, used for purposes such as content moderation or the improvement of AI products.
It is worth remembering, especially for European users, that This technical read capability never existed while end-to-end encryption was activeThe change transforms a messaging service that was approaching the confidentiality of services like WhatsApp or Signal into a channel where the platform is once again at the center of communication.
Meta's reasons: low usage, regulatory pressure, and content moderation
Officially, Meta has explained that “Very few people” were enabling end-to-end encryption in Instagram DMs Maintaining two messaging systems in parallel complicated the service's technical architecture. Under this logic, eliminating the option would be a kind of internal simplification with little real impact on users.
However, the company itself acknowledges that it recommended that those who want encrypted conversations move to WhatsApp, where end-to-end encryption remains the default settingThe decision, therefore, is not due to the E2EE being considered unnecessary, but rather to Meta's choice to concentrate it in a specific app.
Aside from the "low usage" argument, the timing of the change has caught the attention of lawyers and security experts. The removal of encryption on Instagram comes just before the Take It Down Act takes effect in the United States., which requires large platforms to remove non-consensual intimate images, including those generated by artificial intelligence, within a maximum period of 48 hours.
To comply with such a standard, a platform needs to be able to automatically analyze the content that circulates through its systemsWith end-to-end encryption, such scanning is impossible because the servers don't have access to the plaintext. Without that cryptographic barrier, Meta can deploy tools to detect illicit material in direct messages.
In parallel, Governments and security forces in regions such as the United States, the United Kingdom, the European Union, and Australia have been pushing against strong encryption for years.with a particular focus on services popular among children and young people. Instagram, due to its demographic profile, has been at the center of this debate, which has made it the first service where Meta has reduced its E2EE fees.
Privacy risks compared to WhatsApp and other encrypted alternatives
With the disappearance of end-to-end encryption on Instagram, the surface area of exposure for conversations expands considerablyIt is no longer just a matter of worrying about external attempts to intercept traffic, but also about how the platform itself uses that data and the consequences of potential security breaches.
From the user's perspective, this means that Any private message sent through Instagram can end up being analyzed by automated systems, provided to the authorities if required or, in the worst case, leaked if a security incident occurs on Meta's servers.
Faced with this scenario, applications such as WhatsApp and Signal maintain a structure where not even the provider can access the content of the chats.In Spain and the rest of Europe, this aligns with the recommendations of numerous digital rights organizations, which call for private communications to be protected by default and not only when the user searches through the settings.
Other platforms, such as Telegram or iMessage, offer hybrid models: Telegram only applies end-to-end encryption to "secret chats"While normal conversations are more like Instagram's new scheme, iMessage encrypts messages end-to-end within the Apple ecosystem, limiting their reach if the other person uses Android.
The result is a kind of privacy map: WhatsApp, Signal, and similar services now account for the bulk of truly private communications.While networks like Instagram focus on social interaction, content discovery, and large-scale moderation, even at the cost of reducing message confidentiality.
What can users and companies do in Spain and Europe?
For individual users, the most straightforward recommendation is simple: Sensitive conversations, whether personal or professional, should be moved to channels with end-to-end encryption by default.This includes WhatsApp, which is very popular in Spain, and services like Signal for those seeking an even more restrictive approach to data collection.
In the case of European companies, professional firms, clinics, fintech companies or startups that used Instagram to discuss sensitive issues with clients, Continuing to do so now may conflict with confidentiality obligations and the GDPRThe loss of E2EE makes it more difficult to justify that the channel is suitable for sharing personal, contractual, or financial information.
A prudent response involves audit what kind of conversations are taking place on Instagramto classify those that include specially protected data and migrate them to encrypted channels. In Spain, where WhatsApp Business is widespread, many businesses can rely on this tool without significantly changing their customers' habits.
It is also recommended to inform the affected people transparently: Explain that Instagram has stopped offering end-to-end encryption and propose an alternative channel It helps to reinforce trust and demonstrates a certain commitment to data protection, something especially valued in the European market.
Finally, those who previously activated encrypted Instagram DMs and have not yet downloaded their stories should Check if the app still offers data export optionsAlthough the encryption function is no longer available, download tools can be used to preserve local copies of old conversations that the user does not want to lose.
Meta's move with Instagram, compared to WhatsApp's continued encryption, paints a picture in which Messaging apps are divided between those that prioritize strong privacy and those that prioritize moderation, regulation, and data exploitation.Understanding that difference and choosing accordingly has become almost as important as deciding who to talk to or what to share on each platform.
