India’s requirement that messaging platforms identify the “first originator” of certain messages has raised a wider legal question over whether traceability can be enforced without weakening end-to-end encryption and compromising the privacy of millions of users. The issue is at the centre of WhatsApp’s challenge to Rule 4(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, pending before the Delhi High Court.
The government wants large messaging platforms such as WhatsApp to identify the first originator of a message when required under Section 69 of the Information Technology Act, 2000. WhatsApp maintains that complying with such a requirement cannot be achieved without undermining end-to-end encryption, the technology designed to prevent anyone other than the sender and recipient from reading private communications.
The debate has drawn attention to the European Court of Human Rights’ 2024 judgment in Podchasov v. Russia, a case involving Telegram and government demands for access to encrypted communications. While the European ruling is not legally binding on Indian courts, its findings raise questions similar to those now confronting the Delhi High Court.
European Court Rejected Encryption Weakening
In Podchasov v. Russia, a Russian Telegram user challenged legislation requiring messaging platforms to store users’ messages and provide decryption keys to the Federal Security Service when requested. The dispute followed an order requiring Telegram to hand over encryption keys relating to six phone numbers linked to a terrorism investigation.
Telegram argued that it was technically impossible to provide encryption keys for only those users without weakening the encryption system for everyone. The European Court of Human Rights accepted the technical argument, observing that measures necessary to decrypt end-to-end encrypted communications could not be confined to particular individuals and would affect users indiscriminately.
The court held that Russia had violated Article 8 of the European Convention on Human Rights, which protects private life and correspondence. It concluded that a statutory obligation requiring providers to weaken encryption for all users was not proportionate to the legitimate aims being pursued.
The judgment also warned about the broader security consequences of creating mechanisms capable of bypassing encryption. Weakening encryption through backdoors, it observed, could facilitate general and indiscriminate surveillance while creating vulnerabilities that could also be exploited by criminal networks, compromising the security of users’ electronic communications.
India’s Traceability Rule Faces Similar Privacy Questions
India’s Rule 4(2) differs from the Russian requirement because it seeks “traceability” rather than direct decryption. The government has argued that it is not asking WhatsApp to reveal the contents of a message, but to identify the person who first originated it.
WhatsApp’s challenge, however, argues that the distinction becomes difficult to maintain technically. According to the petition described in the article, identifying the origin of a message on demand would require the platform to attach a permanent identifier to every message sent by every user because it would be impossible to know beforehand which message authorities might later seek to trace.
Such a mechanism, the argument goes, would therefore not operate only against identified suspects. It could require a traceability architecture to be incorporated across the messaging system and applied to all users.
End-to-end encryption operates by encrypting a message on the sender’s device and decrypting it only on the recipient’s device. WhatsApp’s servers transmit the encrypted communication but do not possess the key needed to read it. The platform’s position is that enabling selective access or traceability would consequently require fundamental changes to the system.
The article also points to the Indian government’s own use of encrypted communication systems. The National Informatics Centre under the Ministry of Electronics and Information Technology developed Sandes, an end-to-end encrypted messaging application used by government officials. The Indian Army developed SAI, or Secure Application for Internet, which also uses end-to-end encryption. AICTE has also launched Hyped Samvadini, another end-to-end encrypted messaging platform under a government initiative.
This, according to the article, raises a broader policy question over whether the security protections considered necessary for sensitive government communications should receive different treatment when used by ordinary citizens.
Delhi High Court Case Could Test Privacy and Proportionality
Although the European Court’s judgment does not bind Indian courts, the privacy principles examined in Podchasov have parallels with Indian constitutional law. In Justice K.S. Puttaswamy v. Union of India in 2017, the Supreme Court recognised privacy as a fundamental right and held that restrictions on privacy must have legal backing, pursue a legitimate state aim and satisfy the requirement of proportionality.
The European Court applied a comparable proportionality analysis when examining Russia’s encryption requirements. It concluded that legislation permitting authorities broad access to electronic communications without sufficient safeguards impaired the essence of the right to respect for private life.
The Delhi High Court’s consideration of WhatsApp’s petition will therefore involve a difficult balance between the government’s demand for traceability and the privacy and security implications of altering encrypted messaging systems.
At the heart of the dispute is whether authorities can require platforms to identify the originator of selected communications without creating technical mechanisms that affect every user of the service. The European judgment provides one international judicial approach to that question, finding that measures which effectively weaken encryption for all users cannot be justified merely because authorities seek access in particular cases.
The outcome of WhatsApp’s challenge could consequently have important implications for how India reconciles digital investigations and national security requirements with constitutional privacy protections in an era when encrypted communication has become widely used.
