On June 29, 2026, WhatsApp began a global rollout of usernames — letting users message each other without exchanging phone numbers. On July 1, India's Ministry of Electronics and Information Technology (MeitY) sent WhatsApp a notice warning the feature could "materially increase the incidence of online fraud, phishing, digital arrest scams and impersonation attacks," and directed the company not to launch it in India until consultations concluded "to the satisfaction of the Government." A day later, similar notices went to Telegram and Signal, both of which have offered username-based accounts for years. All three platforms were told to respond by July 9 (Rest of World, TechCrunch).
WhatsApp submitted a written response by the deadline; MeitY is still reviewing it, and the feature remains paused in India. Nothing has been formally banned. But the sequence — a feature announced, a government letter demanding justification within days, a company pausing a global product for one market pending official approval — is itself the story. As Internet Freedom Foundation co-founder Apar Gupta put it, "India is doing something different. It is objecting to a design before any harm has occurred."
The fraud case, stated fairly
The government's concern isn't manufactured. India has a well-documented epidemic of phone-based fraud — "digital arrest" scams, in which callers impersonate police or customs officials to extort victims, and phishing schemes that spoof real institutions. A phone number is one of the few identity anchors law enforcement has when investigating these crimes at scale, and MeitY's notice specifically flags that usernames could let bad actors adopt names "closely resembling" real people, banks, or government agencies. A ministry watching those numbers climb has a legitimate reason to ask whether a new feature makes its job harder. That's a fair question. It doesn't follow that the ministry gets to answer it by unilaterally pausing a design decision that Signal and Telegram have already lived with for years without India objecting until now.
Why this isn't ordinary enforcement
India's actual legal tool for restricting online content is Section 69A of the Information Technology Act, 2000, which lets the central government direct blocking of specific information or computer resources — but only on enumerated grounds (sovereignty, security, public order, and similar) and, per the Supreme Court's 2015 ruling in Shreya Singhal v. Union of India, only through a prescribed procedure with built-in safeguards. The Court upheld Section 69A precisely because it came with those constraints; it struck down the much broader Section 66A for lacking them. A blocking order under 69A is public, reasoned, and reviewable. MeitY's notice to WhatsApp is none of those things — it's an unpublished letter demanding a company defend a product feature or face unspecified "regulatory action," issued outside any process Parliament wrote into the statute.
IFF has pressed exactly this point, filing an RTI application on July 3 seeking copies of the notices and formally asking MeitY to withdraw them, arguing that neither the IT Act nor the IT Rules, 2021 empowers the ministry to require pre-approval of a product feature. Its statement to TechCrunch draws the line cleanly: "Impersonation and fraud are real risks, but they are met by enforcing the criminal law against those who commit them. They are not met by MeitY deciding, in private and by letter, what features Indians may use." A parallel Delhi High Court matter involving Telegram has raised similar identity-concealment concerns judicially — through litigation, with a record and an appeal path — which only sharpens the contrast with a ministry letter that has neither.
The precedent problem
The reason this case is being watched well outside India is the incentive it creates. Namrata Maheshwari, Access Now's senior policy counsel for encryption, called it a "slippery slope": "the moment you concede something in one jurisdiction... other countries will follow suit." If Meta ships an India-specific build that strips or waters down usernames, it hands every government that dislikes an encrypted-messaging feature a template — object to the design before launch, demand justification on a short clock, let the company self-censor a market-specific version rather than litigate. Technology lawyer Mishi Choudhary frames the endpoint bluntly: jurisdiction-by-jurisdiction compromises risk "weakening privacy protections incrementally, one market at a time." That dynamic doesn't require a single country to win a legal argument — it only requires enough companies to conclude that a quiet product concession is cheaper than a fight, in enough markets, that the global default quietly degrades.
The better fix
None of this means India should ignore digital-arrest and impersonation fraud — it's a real and growing problem that deserves a real response. But the tools already exist: prosecuting fraud under the Bharatiya Nyaya Sanhita and IT Act's cybercrime provisions, pressing platforms to build in-app reporting and verification signals, and using the Section 69A process — with its public record and safeguards — if a specific instance of harm genuinely warrants blocking. What doesn't scale, and shouldn't be normalized, is a regulator conditioning a global feature's availability in the world's largest messaging market on an unpublished letter and a government-satisfaction standard with no statutory definition. As Medianama founder Nikhil Pahwa argued, treating a company's failure to pre-clear a feature with the government as the offense — rather than any actual fraud committed with it — is the part that should worry a country that wants to keep attracting the platforms it's regulating.