The Government's New Stance
The government is signaling a significant policy shift, aiming to hold digital platforms more accountable for fraudulent activities. Recent statements from officials indicate that messaging platforms will be held responsible if their features are exploited
for cybercrime. This move is part of a broader effort to strengthen India's cyber defence as more essential services, from welfare programs to national exams, move online. The Ministry of Electronics and Information Technology (MeitY) has been exploring a uniform regulatory framework for all messaging services. This comes after the government raised concerns over features like usernames on platforms such as WhatsApp, Telegram, and Signal, which could allow communication without revealing a phone number, potentially increasing the risk of fraud and impersonation.
A Direct Response to Surging Scams
This regulatory push is not happening in a vacuum. It's a direct response to a dramatic increase in digital fraud affecting millions of Indians. Scams involving fake job offers, investment schemes, and 'digital arrests'—where criminals impersonate officials—have become rampant. These activities are often facilitated through messaging apps and hosted on websites with dubious origins. Government data shows a massive spike in complaints, with authorities receiving 2.4 million cyber fraud reports last year alone. The government's concern is that features designed for user privacy, such as usernames that hide phone numbers, can be misused by fraudsters to cover their tracks, making it harder for law enforcement to trace them.
The Domain Registrar Crackdown
The government's focus extends beyond messaging apps to the very foundation of websites: domain name registrars (DNRs). Recent court orders have established a new framework requiring registrars to implement stringent Know-Your-Customer (KYC) norms for anyone registering a domain in India. This is meant to end the anonymity that allows scammers to set up fake websites mimicking well-known brands for fraudulent purposes. Rules now mandate that registrars like GoDaddy cannot offer privacy protection by default and must be prepared to disclose registrant details to law enforcement within 72 hours. Failure to comply could result in registrars losing their 'safe harbour' protection, which currently shields them from liability for the actions of their users.
The Privacy vs. Security Debate
These new measures have ignited a fierce debate about the balance between security and privacy. Tech companies and privacy advocates argue that some proposals could undermine user privacy. Forcing messaging apps to ensure traceability could potentially break end-to-end encryption, a key feature that protects user conversations from being read by third parties. Similarly, domain registrars like GoDaddy have challenged the new rules in court, arguing that removing default privacy protections exposes legitimate website owners to risks like harassment and stalking. The company contends that such national rules are difficult to apply to the global nature of the internet. For users, this means a future where their personal data might be less private but their digital interactions could be more secure.
What Happens Next?
The path forward involves ongoing consultations between the government and tech companies. Messaging platforms have already submitted their responses to the government's concerns about username features, which are now under examination. The government has made it clear that while it values digital innovation, it will take firm action against any platform whose architecture can be easily exploited by criminals. The courts are also playing a crucial role, with larger benches set to hear challenges from companies like GoDaddy. Citizens are being urged to be vigilant and report any suspected fraud immediately through the National Cyber Crime Helpline (1930) or the Chakshu feature on the Sanchar Saathi portal.













