German, French, and Norwegian data authorities warn against Qatar's World Cup app Hayya and infection-tracking app Ehteraz, citing privacy and security concerns
Two World Cup apps pose serious privacy and security risks, European privacy regulators say. Tweets: @shashj and @shashj Tweets: Shashank Joshi / @shashj : Qatar World Cup app “collects data on whether & with which number a telephone call is made. The other app actively prevents the device on which it is installed from going into sleep mode...data used by the apps...are also transmitted to a central server.” https://www.politico.eu/... Shashank Joshi / @shashj : ‘Foreigners visiting the country have been asked to download the official World Cup app Hayya, while those visiting health care facilities will be required to download the infection-tracking app Ehteraz. Both apps have been labeled as “spyware” by experts’ https://www.politico.eu/...
Context & Ripple Effects
The warning lands on a well-worn fault line. The pandemic-era rush to deploy contact-tracing software already produced a wave of complaints over extensive data mining and poor security practices (coronavirus-tracking apps fielding privacy complaints), and Qatar's own virus-tracing app was previously found to carry major security flaws. Ehteraz extends that lineage into the World Cup itself, with researchers documenting that it logs who a phone calls and prevents the device from sleeping while transmitting data to a central server.
What makes this round different is scale and audience: Hayya is effectively required of foreign visitors, meaning hundreds of thousands of EU citizens would run state-linked surveillance-adjacent software on personal devices. The Gulf precedent is established — Saudi caller-ID app Dalil exposed user GPS coordinates at scale (Dalil's data exposure) — and China's state-backed anti-fraud app showed how mandated installs can double as monitoring tools (China's 200M-device anti-fraud app).
First-order effects
- World Cup travelers from Germany, France, and Norway face a direct trade-off: download apps their national regulators have flagged as privacy and security risks, or risk friction accessing the tournament and healthcare facilities that require them.
- Qatar's organizing authorities now have three EU data-protection regulators publicly on record against its flagship visitor apps, raising the reputational cost of keeping the current data-collection behavior in place during the tournament.
Second-order effects
- European regulators' warnings create pressure for formal follow-through under GDPR-style enforcement mechanisms, since the affected users are EU residents whose data flows to a central Qatari server — the same consent-violation territory Privacy International mapped when popular Android apps shared data with Facebook without user consent.
- App-store operators and device makers face renewed scrutiny over how they vet government-mandated apps, a category where the Dalil exposure and the documented flaws in Qatar's tracing app show platform-level review has repeatedly failed to catch state-app risks.
Third-order effects
- If the pattern holds, state-required apps become a recurring cross-border governance problem: every mega-event or public-health mandate that conditions entry on an install effectively exports one country's surveillance architecture onto foreign nationals' devices, forcing privacy regulators to develop enforcement tools for software they cannot directly regulate.
- The trajectory from contact-tracing complaints through mandated state apps points toward a bifurcated norm — jurisdictions that treat phone-installed government software as ordinary infrastructure versus those that treat it as a data-protection violation — with travelers and multinational events caught between them.
The trend: Government-mandated mobile apps are hardening into instruments of population monitoring, and European privacy regulators are beginning to treat foreign state apps as a cross-border enforcement problem rather than a local curiosity.