India encryption policy

India's WhatsApp Username Freeze Rests on Statutes That Don't Say What MeitY Claims They Say

MeitY blocked WhatsApp's phone-free usernames citing fraud risk, but IFF says no statute lets it pre-approve product features.

India's WhatsApp Username Freeze, By the Numbers People of Internet Research · India 850M+ WhatsApp users in India India is WhatsApp's largest single… 3 days Initial response deadline MeitY's July 1 notice gave WhatsAp… 3 Platforms put on notice WhatsApp, Telegram and Signal were… 3 yrs Max sentence, IT Act 66C/66D The identity-theft and personation… peopleofinternet.com
India's WhatsApp Username Freeze, By t… People of Internet Research · India 850M+ WhatsApp users in India 3 days Initial response deadline 3 Platforms put on notice 3 yrs Max sentence, IT Act 66C/66D peopleofinternet.com

Key Takeaways

A feature, a freeze, and a three-day clock

On June 29, 2026, Meta began a phased global rollout of WhatsApp usernames — an optional handle (@name) that lets two people message each other for the first time without either side seeing the other's phone number. Two days later, India's Ministry of Electronics and Information Technology (MeitY) sent WhatsApp a notice ordering it not to launch the feature in the country until "consultation on this point is achieved to the satisfaction of the Government," and giving the company three days to explain why regulatory action should not follow (The Register). On July 3, Signal and Telegram — which have offered username-based contact for years — received similar notices. All three platforms were told to respond by July 9 (Digit).

India is WhatsApp's largest market, with more than 850 million users (The Register). That scale is the whole reason this dispute matters beyond India's borders: whatever WhatsApp does to satisfy MeitY, it will likely do everywhere, because maintaining a separate, phone-number-only version of the app for one country is not a trivial engineering choice Meta is likely to make lightly.

The government's case, stated fairly

MeitY's notice argues that removing the phone number as a fixed, visible identity anchor "may materially increase the incidence of online fraud, phishing, digital arrest scams and impersonation attacks," and specifically flags the risk of usernames that mimic public authorities, financial institutions, and government agencies (Digit). This is not a manufactured concern. "Digital arrest" scams — where fraudsters impersonate police, judges, or customs officials over video or voice calls to extort victims — have become one of India's fastest-growing cybercrime categories, and a phone number has functioned as a de facto (if weak) verification signal for hundreds of millions of first-time smartphone users who have no other way to sanity-check who they're talking to. A regulator whose job is consumer protection is not wrong to ask what a platform with 850 million domestic users has done to prevent a new contact mechanism from becoming a new scam vector. That is a legitimate question, and Meta has treated it as one: a company spokesperson said WhatsApp still requires a phone number to use the app at all and has built "multiple layers of defense against scams into usernames," including reserving high-profile and lookalike names so they can't be claimed by impersonators (Rest of World). WhatsApp's own announcement notes there is no public directory or username suggestion feature — someone has to already know your exact handle to reach you, which is a meaningfully higher bar than a leaked or guessed phone number.

Where the government's authority runs out

The problem is not the question MeitY is asking; it's the mechanism it's using to compel an answer. The notice cites Sections 66C and 66D of the Information Technology Act, 2000, which criminalize identity theft and cheating by personation, and Section 79, the intermediary "safe harbour" provision, alongside the IT (Intermediary Guidelines) Rules, 2021 (Digit). Read the actual text, though, and the gap is stark. Section 66C punishes a person who fraudulently uses someone else's electronic identity — it says nothing about a company shipping a feature (IndianKanoon, Section 66C). Section 79 is a liability shield: it tells a court when a platform is not responsible for third-party content, conditioned on due diligence — it is not a licensing power that lets a ministry approve or block product design before launch (IndianKanoon, Section 79).

The Internet Freedom Foundation made exactly this case in a formal rebuttal, arguing the notice "has no clear basis in law" and is "an attempt by the executive to decide what a company may build and ship, which no statute permits." IFF's analysis goes section by section: 66C and 66D are criminal offences tried by courts against the person who commits fraud, not tools for pre-launch vetting; Section 79 determines liability, not permitted features; Rules 3 and 4 of the IT Rules set due-diligence and grievance obligations, which "cannot be converted into a licensing scheme"; and Section 69A permits blocking specific information through a defined procedure, but "says nothing about which features a company may build." IFF calls the approach a "licence raj for software features" (The Wire).

"India is doing something different. It is objecting to a design before any harm has occurred, and asking companies to justify a feature 'to the satisfaction of the government.'" — Apar Gupta, Internet Freedom Foundation (Rest of World)

That distinction — objecting to a design pre-emptively, rather than prosecuting a demonstrated harm after the fact — is the crux of why this case has drawn attention well beyond India's cybercrime statistics.

Why the precedent question is not hyperbole

Encryption-policy watchers are not worried about this notice in isolation; they're worried about what compliance would signal. "It's a slippery slope because the moment you concede something in one jurisdiction and make it known as something that is possible to do technically, other countries will follow suit," said Namrata Maheshwari, encryption policy lead at Access Now (Rest of World). Mishi Choudhary of SFLC.in put the mechanism plainly: incremental, market-by-market pressure "risks weakening privacy protections incrementally, one market at a time" for everyone, not just Indian users (Rest of World).

That risk is proportional to WhatsApp's footprint. A feature-design demand made against a niche app sets a niche precedent; a feature-design demand made against the platform 850 million Indians and roughly three billion people worldwide use daily, backed by a threat of "regulatory action," sets a template every government watching can cite. If MeitY can compel changes to a contact-discovery mechanism through a letter citing identity-theft statutes that were never written for this purpose, there is no principled reason another government couldn't use the same statutory sleight-of-hand against message-content protections next, under the same fraud-prevention banner.

The proportionate path was already available

None of this requires India to tolerate fraud. The IT Rules already impose due-diligence and grievance-redressal obligations MeitY can enforce against demonstrated harms; Sections 66C and 66D already let police prosecute the humans who run digital-arrest scams, username or no username. A regulator genuinely focused on the stated risk could publish a public consultation, invite evidence on username-enabled fraud rates from jurisdictions where the feature has already launched, and legislate a disclosure or verification standard that applies evenly across platforms — the same route India used for its intermediary rules in 2021. Instead, MeitY reached for a private notice, an unpublished three-day clock, and statutes that criminalize fraud rather than authorize product review — a shortcut that trades a narrow win against one feature for a durable dent in the case that India, or anyone else, is treating platform regulation as anything other than 'do what makes us comfortable.'

Sources & Citations

  1. The Register: India writes to WhatsApp over usernames
  2. Digit: Why govt ordered Meta to stop WhatsApp usernames
  3. The Wire: IFF says MeitY notice has no legal basis
  4. Rest of World: India's crackdown risks global precedent
  5. IT Act 2000, Section 66C (IndianKanoon)
  6. IT Act 2000, Section 79 (IndianKanoon)