Who ever thought a WhatsApp chat could be so expensive? International Flavors & Fragrances (IFF) learned the answer the hard way earlier this year, facing a hefty €15.9 million fine from the European Commission. The penalty was related to the company’s failure to retain business-related WhatsApp messages exchanged by their employees.
The incident serves as a wake-up call for organizations using WhatsApp and similar messaging platforms to conduct business. While these apps offer convenience, they also introduce significant compliance risks if not properly managed. The consequences of failing to retain business communications can be swift and severe, with fines, reputational damage, and operational disruptions looming over businesses that don’t take regulatory compliance seriously.
Read on to find out what happened and how you can avoid getting on the wrong side of recordkeeping regulations.
Understanding What Happened
Starting in 2023, International Flavors & Fragrances (IFF) was under investigation by the European Commission for potential anti-competitive behavior within the flavors and fragrances industry. As part of this investigation, regulators sought to review various forms of communication within the company to assess whether any illicit coordination or market manipulation had occurred.
However, the inquiry faced a major setback when it was discovered that IFF had deleted critical WhatsApp messages. These communications were considered important for understanding the company’s business practices and for ensuring that all relevant information was available for the regulatory review.
The deletion of these messages constituted a serious violation of European Union (EU) regulations. The EU requires companies to retain all forms of communication, including digital messages, for a specified period to maintain transparency and facilitate thorough regulatory oversight. By failing to archive these WhatsApp messages, IFF not only obstructed the investigation but also breached legal obligations designed to ensure corporate accountability.
The European Commission responded to this breach by recently imposing a substantial €15 million fine on IFF. This fine was notable not just because of its financial size but also due to the underlying issue it exposed—the growing use of off-channel communications in regulated industries and the resulting challenges in governance. Despite prior regulatory warnings, IFF had not put systems in place to properly capture and store WhatsApp communications, resulting in the breach. Moreover, the company’s failure to take corrective action highlighted how organizations across various industries continue to struggle with the governance of digital messaging.
The fine is part of a wider trend across Europe, where regulators are ramping up enforcement actions to ensure compliance with privacy laws. It is a reminder that businesses must adopt robust policies to manage off-channel communications or face significant penalties.
What Can Be Learned From This Action?
The €15.9 million fine imposed on IFF offers valuable lessons for businesses, particularly those operating in heavily regulated sectors. With digital communication tools now embedded in daily operations, organizations must strike a balance between privacy features and regulatory compliance. This case serves as a cautionary tale with several important lessons to be learned. Here’s what stakeholders should take away:
Lesson 1: Message Deletion Shouldn’t be at an Individual’s Discretion
The €15.9 million fine imposed on IFF underscores a vital lesson for businesses: message deletion should not be left entirely to individual employees. The IFF case illustrates that whether messages are deleted intentionally or accidentally, the responsibility for ensuring compliance with data retention laws ultimately rests with the organization.
In this instance, the deletion of crucial WhatsApp messages by an individual employee significantly impacted IFF’s ability to comply with regulatory requirements. The problem is compounded by the fact that companies are held accountable for the actions of their employees, regardless of individual intent or knowledge.
Organizations must take ownership of their message retention practices. By ensuring that appropriate oversight is in place, businesses can safeguard against potential compliance issues and ensure that important communications are preserved, no matter the actions of individual employees.
Lesson 2: The Cost of Off-Channel Communications is Rising
Regulators are making it increasingly clear that off-channel communications will cost companies dearly. These informal or unregulated methods of communication pose significant risks, as they can facilitate unlawful and fraudulent behavior by allowing information to be easily hidden or deleted.
Regulators are tasked with ensuring that business operations adhere to the laws designed to protect all stakeholders, including consumers. The use of off-channel communications, such as personal messaging apps or unofficial email accounts, creates opportunities for evasion and misconduct. These channels are ungoverned, making it easier for individuals to engage in activities that are not transparent or accountable.
In the case of IFF, the deleted messages from off-channel communications almost certainly contained information critical to understanding their business practices. This lack of recordkeeping hindered the company’s ability to demonstrate compliance and transparency, resulting in a substantial fine.
Regulators are no longer tolerating unregulated communications, as they undermine the integrity of regulatory oversight. For companies that choose to use particular platforms, it is crucial to ensure that these platforms fall completely under their governance umbrella. Simply banning off-channel communications is not sufficient, as employees may continue to use these methods. The only effective solution is to enhance governance practices to include all forms of communication, ensuring comprehensive oversight and compliance.
Lesson 3: Personal Messaging Apps Aren’t Built for Business Compliance
While messaging apps like WhatsApp have become integral to how people communicate in their personal lives, these platforms weren’t designed to meet the complex compliance requirements that businesses face. WhatsApp’s end-to-end encryption, privacy features, and limited archiving options make it an excellent tool for personal use but a risky choice for corporate communications, particularly in industries with strict regulatory requirements.
One of the key limitations of personal messaging apps is their lack of enterprise-level governance and compliance features. Unlike platforms specifically designed for business use, WhatsApp does not offer built-in compliance controls, such as automated archiving, monitoring, or reporting capabilities that allow organizations to capture and preserve messages in a way that satisfies legal obligations. This means that even if a company is using WhatsApp for seemingly innocuous communications, it can easily fail to comply with industry-specific regulations that mandate communication oversight leading to fines.
Personal messaging apps also often blur the lines between professional and private conversations, increasing the risk of data breaches or accidental non-compliance. Employees may inadvertently share sensitive information without realizing that these conversations are not being properly monitored or archived. The use of personal devices for business communication can further complicate matters, as companies lose visibility into message flows and the ability to enforce proper security and compliance protocols.
Lesson 4: You Have to Fight Technology with Technology
The challenge of managing and monitoring informal or off-channel communication channels effectively has now become critical for all organizations. Relying solely on traditional methods is no longer sufficient – companies must embrace innovative technological solutions to ensure compliance and accountability.
Integrating specialized communication platforms that offer built-in compliance features—such as automated archiving and monitoring capabilities—can significantly reduce the risk of non-compliance and enhance oversight. In the wake of regulatory scrutiny, many organizations are adopting technologies that provide visibility into off-channel communications, allowing them to capture and manage all forms of communication, whether conducted via email, messaging apps, or social media.
By using tools that provide real-time feedback and analytics, organizations can quickly identify potential compliance issues and address them before they escalate into serious violations.
Lesson 5: Proactive Communication Governance is Non-Negotiable
Proactive governance involves more than simply meeting minimum regulatory requirements – it requires businesses to anticipate risks, establish comprehensive policies, and monitor communications regularly to ensure compliance. One of the most significant benefits of proactive governance is risk mitigation. By implementing these components, companies minimize the chances of accidental non-compliance, reduce legal exposure, and build a culture of accountability. Being proactive also positions businesses to act quickly in the event of an internal issue.
For example, self-reporting breaches or compliance failures to regulators can lead to more lenient treatment, as regulators often value transparency and willingness to rectify mistakes. This step helps demonstrate that the company takes its compliance responsibilities seriously and can sometimes prevent hefty fines or additional regulatory sanctions.
By adopting a proactive approach to communication governance, companies also foster trust among their customers, investors, and regulators. Businesses that demonstrate they are taking the necessary steps to protect sensitive information and self-correct when issues arise are more likely to maintain strong reputational standing in a highly competitive marketplace.
Avoiding the Same Fate: Best Practices for Staying Ahead of Compliance Challenges
To avoid fines and ensure compliance, businesses need to integrate practical and proactive strategies into their communication management. Here are five essential practices:
- Establish Clear Communication Policies: Define which platforms are acceptable for business communications and set rules for data retention. Policies should be regularly updated to reflect changing regulations.
- Capture and Archive Business Communications: Automatically capture all relevant business communications, including mobile messaging and external conversations. Ensure all captured data is securely archived for retrieval when necessary, following specific retention guidelines set by regulations.
- Implement Strong Security Measures: Secure communication platforms with encryption and access controls. Additionally, manage features like disappearing messages to prevent loss of important data.
- Real-Time Monitoring and Red Flagging: Use real-time monitoring tools that flag potential compliance risks as they happen. This helps businesses identify red flags early, preventing issues from escalating into regulatory breaches. Automated systems can ensure continuous monitoring without manual oversight.
- Automated Reporting and AI Pattern Detection: Leverage AI to analyze communication data, identify trends, and highlight patterns that may indicate non-compliance. Automated reporting systems can provide insights into how effectively policies are being followed and can flag recurring issues, helping businesses stay ahead of regulatory requirements.
Compliant WhatsApp Use is Easy with LeapXpert
The LeapXpert Communications Platform offers a comprehensive approach to capturing and preserving not only WhatsApp conversations, but all off-channel messages.
The platform ensures that all communication data exchanged on any channel is captured, maintaining a complete record of conversations between employees and customers. It also supports built-in governance controls such as strict data access control, antivirus/antimalware, advanced information barriers, and data leakage prevention, flagging breaches and preventing any threat or loss of data. Integrated with leading third-party archiving, surveillance, monitoring, and e-discovery systems, all message records are securely stored and made available to various compliance, audit, and management applications.
Book a demo today.
Book a personalized
product demo