← Platforms

WhatsApp

whatsapp.com

C

Partial

Message content is end-to-end encrypted and not scanned. Detection is therefore confined to unencrypted surfaces – profile images, group names and descriptions – plus behavioural signals and user reports, which is what the reporting volume reflects.
Domain
whatsapp.com
Category
Messaging
Last review
2026-04-15

Detection & scanning

Whether known and novel abuse material is found at all, and across which surfaces of the product.

D
1.01

Hash matching on publicly posted media

Matching is applied to unencrypted surfaces: profile photographs, group images, names and descriptions. [1]

Neutral
1.02

Hash matching on private messages and attachments

Message content is end-to-end encrypted and not matched. [1]

Fail
1.03

Classifier detection of previously unseen material

No classifier applied to message content.

Fail
1.04

Detection applied to live and streamed video

Calls not covered.

Fail
1.05

Detection of grooming and solicitation in text

Behavioural signals are used to identify accounts engaged in distribution without reading content. [1]

Neutral
1.06

Participation in industry hash-sharing programmes

Consumes industry hash sets on the surfaces available to it.

Pass

Reporting & transparency

What the operator tells NCMEC, law enforcement and the public, and whether those disclosures can be checked.

B
2.01

Files CyberTipline reports to NCMEC

Files CyberTipline reports at substantial volume given the surfaces it can see. [2]

Pass
2.02

Publishes child-safety enforcement figures

Figures are reported within the parent group's disclosure.

Neutral
2.03

Report quality sufficient for investigation

Reports carry account metadata rather than content.

Neutral
2.04

Reporting cadence and timeliness

Filed on detection.

Pass

Response & enforcement

What happens after material is found: how fast it comes down, what happens to the account, and whether the decision can be contested.

B
3.01

Time to removal of confirmed material

Account-level action rather than content removal.

Neutral
3.02

Account termination on confirmed violation

Bans applied at volume. [1]

Pass
3.03

Prevention of re-registration

Phone-number registration raises the cost of return.

Neutral
3.04

Preservation of evidence

Metadata preservation on request.

Neutral
3.05

Escalation of imminent-harm cases

Escalation path documented.

Pass

Product & policy posture

The design decisions that determine how much abuse is possible in the first place, before any detection is applied.

C
4.01

Protective defaults for minor accounts

Privacy defaults limit discovery.

Neutral
4.02

Restrictions on adult-initiated contact with minors

Contact requires a phone number, though group invite links circumvent this.

Neutral
4.03

Age assurance at registration

Self-declared age.

Fail
4.04

Recommendation systems assessed for minor-safety harm

No recommendation surface.

Pass
4.05

Encryption posture and stated mitigations

Compensating measures are published in some detail. Their effectiveness relative to content scanning is not quantified. [1]

Neutral
4.06

Published child-safety policy with defined enforcement

Policy published with stated enforcement.

Pass

Sources

  1. [1]
  2. [2]
    CyberTipline Data

    NCMEC · 2025

Know something we don’t?

If we’ve missed a controversy or there’s newer reporting on WhatsApp, tell us. If you represent WhatsApp, we welcome documentation of safety measures not yet reflected here.

Contact us

Report CSAM

If you have encountered CSAM, file a report through one of these channels.