Open WhatsApp right now and look at any chat. There is a small line of text. It says your messages are end-to-end encrypted. Millions of Sri Lankans read that line every day and feel safe.
Here is the problem. Nobody who wants to have an image of you to read a single message. The line is true. And it still misleads you.
In April 2014, at a Johns Hopkins University debate, General Michael Hayden said six words that should have settled this. “We kill people based on metadata.” Hayden ran the NSA from 1999 to 2005. Then he ran the CIA until 2009. He was not making a threat. He was describing normal practice.
Moments earlier, his opponent had quoted Stewart Baker, a former NSA general counsel. Baker had already said the quiet part. “If you have enough metadata, you don’t really need content.”
What is metadata? It is everything around your message except the words. Who you contacted. When. How long. How often. From which device, and from which IP address.
Encryption locks the letter. The envelope stays wide open. And the envelope talks.
Think of the envelope as “අබිලිං” from “කෝපි කඩේ”. He never cared about the contents of the letter. He only needed to know who received it, who delivered it, how often letters arrived, and who came asking about them. By sunset, the whole village had its own version of the story. Metadata works in much the same way. The message remains secret, but the pattern surrounding it rarely does.
How much can an envelope say? In 2014, two Stanford doctoral students, Jonathan Mayer and Patrick Mutchler, decided to measure it. They collected phone logs from 546 volunteers through an Android app. No recordings. No content. Just numbers, timestamps, and durations.
The volunteers contacted 33,688 unique numbers between them. From the logs alone, the researchers inferred medical conditions and firearm ownership. One participant called neurology groups, a specialty pharmacy, and a rare-condition management service. Another had a long early morning call with her sister, then a series of calls to a family planning clinic over the following weeks. No message was ever opened.
The final study appeared in the Proceedings of the National Academy of Sciences in 2016. Its verdict was flat. Telephone metadata is densely interconnected, simple to re-identify, and rich enough for highly sensitive inferences. The students did all this with a small sample and public directories like Yelp and Google Places. Mayer said scaling it to a larger population would be no technical challenge.
Now think about what a telecom operator holds. Or an ad network. Or a state.
That third layer is where the profiling economy lives. Dr. Augustine Fou spent 25 years in digital marketing before becoming an independent ad fraud and privacy researcher. His finding is uncomfortable. Hundreds of ad tech companies collected and sold people’s information with no knowledge, no consent, and no recourse for errors. His deeper point matters more than the numbers. Privacy belongs to the person, not to the data. A company’s privacy policy protects the company. It rarely protects you.
Stop here for a moment. Think about yesterday. Who did you message, at what times, how many times, from where? You never wrote that list down. Your phone did. So did your operator, your apps, and every tracker riding inside them.
The research community keeps confirming the gap. A 2025 paper on end-to-end encrypted systems, published on arXiv, lists what still travels in the clear. Sender and recipient. Time and frequency. Device information and IP addresses. From these, an observer can rebuild your social graph and your daily routine without opening one message. Signal minimizes what it keeps. Most platforms do not.
Even the biggest privacy war of this decade proves the point. Europe spent four years fighting over Chat Control, a proposal to scan private messages for child abuse material. On November 26, 2025, the EU Council dropped mandatory scanning of encrypted
messages from its position. On March 26, 2026, the European Parliament rejected the wider proposal by 311 votes to 228. The temporary legal cover for voluntary scanning expired on April 3, 2026.
Notice what the entire battle was about. Content. Reading the words. Metadata was never on the table. Whatever Brussels decides next, the envelope stays open by default.
So where does Sri Lanka stand? On paper, ahead of the region. The Personal Data Protection Act, No. 9 of 2022 was certified on March 19, 2022. It made us the first country in South Asia with a standalone data protection law. The Data Protection Authority followed in August 2023.
Then came the delay. The Personal Data Protection (Amendment) Act, No. 22 of 2025, passed on October 21, 2025, pushed the remaining provisions back. Full enforcement is now expected in 2026, after the Authority completes its staffing and issues its key regulations. First-instance penalties can reach 10 million rupees.
Here is the question our enforcement debate has not asked yet. Does our law treat the envelope as personal data, or only the letter? Call records, location trails, and browsing patterns can identify a Sri Lankan as surely as a name. The country is building digital ID, digital payments, and data sharing across government agencies at the same time. Every one of those systems will generate metadata at national scale.
If the Authority regulates content and ignores patterns, we will import the world’s oldest privacy mistake on day one.
That is the redefinition this moment demands. Privacy is not secrecy of words. It is control over patterns. The general who ran two intelligence agencies already told us which one matters.
So go back to that WhatsApp chat. Read the small line again. Your messages are end-to-end encrypted. It is true. It was always true.
They just never needed to read your messages.
Kalana Geethmal – Solutions Engineer
