MeitY Issues Notice to WhatsApp Over Username Feature: Digital Security and Governance Concerns

Updated 2 Jul 2026

Contents4

Hindustan Times - India · 2 Jul 2026 · 2 min read
Prelims · Polity Mains · GS2 Governance High relevance

The Ministry of Electronics and Information Technology (MeitY) issued a notice to WhatsApp, directing it to halt the rollout of its username feature due to concerns over increased cyber fraud and impersonation risks, highlighting the government's focus on digital security and traceability.

Key points

MeitY notice requires WhatsApp to explain its username feature within 3 days and pause its rollout until government concerns are addressed, reflecting proactive digital governance.

Cyber fraud risks: The government fears the feature could escalate phishing, digital arrest scams, and impersonation by allowing bad actors to use deceptive usernames resembling legitimate entities.

SIM-binding directive: The Department of Telecommunications (DoT) raised concerns that usernames may undermine its mandate linking messaging accounts to physical SIM cards for traceability.

Law enforcement challenges: Usernames could complicate identifying perpetrators, especially if foreign numbers are used, delaying LEA responses due to WhatsApp's slow resolution times (5+ days).

Meta's defense: WhatsApp claims usernames are an optional privacy feature, requiring phone numbers for registration and enabling traceability, thus not violating SIM-binding rules.

[GS3-Security] The debate underscores the tension between user privacy and national security, a recurring theme in India's digital policy framework.

[GS2-Governance] This aligns with broader efforts like the Digital Personal Data Protection Act, 2023, to balance innovation with accountability in tech platforms.

Way Forward: India should mandate real-time LEA access to verified user data, enforce stricter username vetting protocols, and establish a faster grievance redressal mechanism for cybercrimes involving messaging platforms.

Key terms

SIM-binding directive
A DoT mandate requiring messaging apps to link accounts with authenticated mobile numbers (+91 for India) to combat cybercrime. Part of the 'Know Your Customer' framework under the Prevention of Money Laundering Act (PMLA).
Digital arrest scams
A cybercrime where fraudsters impersonate law enforcement (e.g., CBI, NIA) to extort victims via video calls. Accounted for 20% of India's ₹10,319 crore cyber fraud losses in 2025 (NCRB data).
Intermediary liability
Legal responsibility of platforms like WhatsApp under IT Act Section 79, requiring compliance with government directives while maintaining 'safe harbor' protections. Key issue in Shreya Singhal vs Union of India (2015).
MeitY
The Ministry of Electronics and Information Technology formulates policies for India's IT sector, including data governance (Digital India Act) and intermediary regulation (IT Rules, 2021). Its notice to WhatsApp tests regulatory authority over global tech firms.

Practice question

Discuss the challenges posed by messaging platforms' new features like usernames to India's digital security framework. How can the government balance user privacy with national security concerns? (250 words, 15 marks)

GS2 15 marks 250 words Mains

Key terms to include: SIM-binding directive Digital arrest scams Intermediary liability MeitY Digital Personal Data Protection Act, 2023 Shreya Singhal vs Union of India IT Act Section 79 Know Your Customer framework

Answer framework

Introduction

Briefly introduce the context of MeitY's notice to WhatsApp over username feature, highlighting the growing concerns around digital security and governance.

Digital Security Risks

Increased cyber fraud risks (phishing, digital arrest scams, impersonation)

Undermining SIM-binding directives for traceability

Challenges in law enforcement due to delayed response times

Governance and Regulatory Challenges

Balancing intermediary liability under IT Act Section 79

Ensuring compliance with Digital Personal Data Protection Act, 2023

Regulatory authority over global tech firms

Privacy vs Security Debate

User privacy concerns with optional features like usernames

National security imperatives for traceability

Lessons from Shreya Singhal vs Union of India (2015)

Way Forward

Mandate real-time LEA access to verified user data

Enforce stricter username vetting protocols

Establish faster grievance redressal mechanisms

Conclusion

Suggest a balanced approach that ensures both user privacy and national security, possibly through collaborative frameworks involving tech firms, government, and civil society.

Fact check

All facts verified