A Feature Frozen Before It Launched
On June 29, 2026, Meta began rolling out usernames on WhatsApp globally — letting users message each other without exchanging phone numbers, a privacy option Telegram and Signal have offered for years. Within days, India's Ministry of Electronics and Information Technology (MeitY) objected. According to reporting by Rest of World, the ministry sought written explanations from WhatsApp, Telegram and Signal by July 9, arguing that pseudonymous, phone-number-free accounts make it easier to impersonate officials, banks and public figures for financial fraud (Rest of World, July 13, 2026). WhatsApp has submitted a written response, which the government is reviewing.
This is not a request for data in an ongoing investigation, and it is not a court-ordered takedown of specific unlawful content. It is a demand that a company justify a global product decision before any documented pattern of misuse on that feature exists in India. That distinction matters, and it is worth taking the government's underlying concern seriously before explaining why the mechanism it has chosen is the wrong one.
The Strongest Case for Concern
India's fraud numbers are real and large. So-called "digital arrest" scams — where callers impersonate police or customs officials to extort victims — drained roughly ₹22,495 crore (about $2.7 billion) from Indians in 2025 alone, part of a cumulative ₹52,976 crore lost to cyber fraud over six years, according to figures compiled from National Human Rights Commission data (ORF, "Digital Arrest Scams and the Limits of Domestic Enforcement"). Impersonation is already the core mechanic of this fraud. A feature that strips away the one identifier — a phone number — that lets a victim's family or a bank recognize a suspicious contact is a legitimate thing for a consumer-protection-minded regulator to scrutinize. Telegram and Signal already run usernames without phone-number disclosure, so the government's question of how all three platforms will prevent lookalike handles impersonating ministries or banks is not frivolous.
Where the Legal Basis Runs Thin
The problem is that MeitY's own toolkit doesn't obviously reach pre-launch product review. The Information Technology Act's Section 69A empowers the central government to order blocking of specific information already online, on narrow grounds — sovereignty, security, public order — with written reasons and a defined procedure (Section 69A, IT Act 2000, via Indian Kanoon). It says nothing about approving or prohibiting a feature before it ships.
The more relevant instrument is the IT Rules, 2021, which already built a deliberate, narrower mechanism for exactly this class of worry. Rule 4(2) requires "significant social media intermediaries" offering messaging to be able to identify the first Indian originator of a message — but only on a specific court or government order tied to an actual offense under investigation, not as a standing design constraint applied to an entire feature before it launches. As PRS Legislative Research's analysis of the rule notes, even that narrower traceability mandate required intermediaries to retain additional data and drew immediate litigation from WhatsApp over its privacy implications (PRS India, IT Intermediary Guidelines Rules 2021). That 2021 rule, contested as it was, at least tied the government's power to a specific case. A blanket pre-launch veto over a privacy feature, applied to three companies simultaneously with a hard nine-day deadline and no cited statutory hook, is a different and broader kind of power — one Parliament has not obviously granted.
The ORF data also cuts against the theory that usernames are the binding constraint on fraud enforcement. The same analysis shows India's digital-arrest problem is overwhelmingly a jurisdictional one: the scam call centers driving these losses sit in Myanmar, Cambodia and Laos, largely beyond Indian law enforcement's direct reach, which is why repatriating victims and pressuring foreign jurisdictions — not messaging-app metadata — has been the actual lever India has used to claw back losses. Blocking a privacy feature on India's own soil does little to reach an extortion network operating from a compound across the border.
The Precedent Problem
What should worry a pro-innovation, pro-speech reader most is less the specific fraud rationale than the template being set. As Namrata Maheshwari, encryption policy lead at Access Now, told Rest of World, conceding a feature change in one jurisdiction demonstrates it is technically possible, and "other countries will follow suit" — a dynamic she calls a slippery slope. Technology lawyer Mishi Choudhary frames the risk more starkly: privacy protections eroded "incrementally, one market at a time" leave journalists and ordinary users with a materially weaker product depending on which government objected loudest.
India has legitimate, evidence-backed reasons to worry about impersonation fraud, and platforms should take lookalike-handle risks seriously in their own design — WhatsApp and Telegram have reportedly already described anti-impersonation safeguards in their responses to MeitY. But the proportionate path runs through the traceability and grievance mechanisms Parliament already built into the IT Rules, applied to demonstrated harms, not through an unlegislated veto over global product launches decided against a nine-day clock.