
The Ministry of Electronics and Information Technology (MeitY) has extended Meta's deadline for its response on the controversial WhatsApp username issue by another three days, as confirmed by a government official to PTI. The new deadline has been extended to July 9, moving from the earlier July 6 response date that government officials had initially sought from WhatsApp regarding concerns over its new username feature. The Centre issued a notice to Meta questioning the planned username feature on WhatsApp, flagging concerns that it could materially increase online fraud, phishing, digital arrest scams, and impersonation attacks. The government directed the platform to pause the feature until consultations on the issue are completed "to the satisfaction of the Government" and asked Meta to explain why action shouldn't be initiated under the IT Act and rules over WhatsApp's new feature that may increase cybercrimes. The original deadline for submission was Friday, making this extension particularly significant for the ongoing discussions.
WhatsApp has assured the government that it will not introduce its proposed username feature in India until ongoing consultations with authorities are completed, as reported by PTI citing sources. The proposed feature would allow users to communicate on WhatsApp without sharing their phone numbers, fundamentally changing how the messaging platform operates. Following the notice, a Meta delegation met officials from the IT Ministry on Friday to discuss the issue. The government had specifically asked WhatsApp to keep the feature on hold until discussions conclude to its satisfaction, highlighting the serious nature of the concerns raised about the feature's potential impact on user security and fraud prevention. The username feature essentially allows people on the messaging platform to communicate without sharing their phone numbers, as confirmed by sources to PTI.
Meta has significantly expanded the protective measures for the username feature, as confirmed by a Meta spokesperson to The Times of India. The company has implemented multiple layers of defense against scams including requiring other users to know the exact username to message you, limiting how many new people an account can contact, and blocking repeated attempts to guess someone's username key. Additionally, Meta has built systems to detect and remove activity showing common impersonation and abuse patterns. When the feature becomes available, users will be shown if they're a new account, if they're your contact, if you have groups in common, and if they're based in a different country, allowing users to decide whether to respond. WhatsApp has clarified that the username feature is not yet live and will roll out slowly later this year, as confirmed by a WhatsApp spokesperson to The Hindu. The platform said first-time messages from unknown users will include an information card displaying details such as whether the account is newly created, whether the sender is an existing contact, whether they are messaging from another country and whether both users share common groups, with users having options to add the sender, block the account or report it.
Meta has reserved several high-profile names, including those linked to public figures, government entities and celebrities, as confirmed by the company spokesperson to The Hindu. According to the statement, these reserved names can only be claimed by verified and legitimate owners, ensuring that government bodies and public personalities cannot be impersonated through the new feature. The company has also held lookalike derivatives of known names to prevent impersonation attempts. As per The Times of India, Meta clarified that user names do not replace your phone number on WhatsApp – you will need your phone number to register and use the service. A person's phone number can be tracked through a username, thus ensuring accountability. Every username will be prefixed with an @ symbol to distinguish it from display names and phone numbers, while usernames consisting entirely of numbers will not be permitted. The username will keep phone numbers 'private' according to WhatsApp's FAQ, explaining that 'those who don't have your phone number saved will see your username instead.' The feature is 'unique,' can be changed or deleted, but not duplicated by another user,' and using or reserving one is 'completely optional.' Businesses and creators will also be able to claim their existing Instagram or Facebook usernames on WhatsApp to keep their identity consistent across Meta's platforms.
The Department of Telecommunications (DoT) has raised significant concerns about how the username feature will impact its SIM-binding directive, which mandates that messaging platforms link user accounts with actual physical SIM cards. A DoT official told The Times of India that 'the larger issue is that it [usernames] will make it difficult for LEAs (law enforcement agencies) to identify whether the perpetrator is an Indian or not.' The official explained that 'tomorrow, someone can make a WhatsApp account with a +1 number [US], put the face of NIA chief and create a similar username and make fraudulent calls.' The DoT official also pointed towards WhatsApp's resolution time, adding that it takes the messaging platform a minimum of five days and maximum indefinite time period to get back to LEAs. However, Meta clarified that the latest feature won't impact the SIM linking directive at all, as confirmed by a Meta executive to The Times of India. Government sources told PTI that officials are examining the legal framework governing the proposed feature and assessing whether existing laws provide sufficient scope to intervene if the feature is found to expose users to greater risks. Nikhil Narendran, partner at Trilegal, said regulators are likely to examine whether the usernames feature sits comfortably alongside that policy objective, noting that 'the intent behind SIM-binding was to ensure that messaging identities remain tethered to verified mobile numbers. Once a username becomes the primary identity visible to users, regulators are likely to ask how trust, authentication and accountability will be maintained, particularly in cases involving fraud and impersonation.'
The legal battle over WhatsApp's username feature is shaping up around the fundamental question of whether India can move from a telecom-based identity model to a platform-based identity model without increasing fraud risks. Aparna Gaur, partner at Trace Law Partners, said the law only requires a platform to identify the first originator of a message when served with a valid court order or authorized government direction, stating 'So long as an SSMI has the ability to identify the first originator, there is no requirement to ensure that this first originator's identity is visible to other users.' Legal experts suggest that while impersonation concerns may be genuine, they may not automatically rise to the threshold required for blocking powers. Madhu Gadodia, deputy managing partner at Naik Naik & Co., said any complete prohibition would likely have to satisfy the proportionality principles laid down by the Supreme Court in the landmark Puttaswamy privacy judgment, noting that 'a complete prohibition could face scrutiny if less restrictive alternatives are available to address the government's concerns.' Ankita Singh, co-founder of A&P Partners, said Section 69A generally requires a demonstrable threat rather than a hypothetical one, explaining that 'the real risk is limited to fake handles mimicking celebrities or government accounts, and WhatsApp has already reserved those. For the ordinary user, there's no searchable directory. Nobody can find or message you without knowing your exact username.' Apurv Sardeshmukh, managing partner and co-founder of Stride Legal, said the argument that introducing usernames could threaten WhatsApp's safe-harbour protection under Section 79 of the IT Act is unlikely to succeed, stating that 'safe harbour immunity is based on whether a platform modifies or authors third-party content being transmitted, not the architectural identity features.'
The Internet Freedom Foundation (IFF), a digital rights advocacy group, has pointed out that no clear legal provision forms the basis of MeitY's notice to Meta, as reported by Business Standard. The IFF stated that Section 79 of the IT Act is a safe harbour provision governing when a platform can be held liable for user content, which it says does not necessarily extend to approving product features before release. The group also referred to Sections 66C and 66D, which punish identity theft and cheating by personation, stating that these provisions are aimed at individuals who misuse a tool rather than at the company that builds it. On the IT Rules, IFF stated that Rule 3(1)(b), Rule 3(2) and Rule 4 set out due diligence and grievance obligations, which it said do not necessarily translate into a licensing mechanism for approving features. The group also referred to Section 69A, the provision that allows MeitY to block specific online content through a defined procedure, stating that this does not necessarily cover vetting features before launch. The IFF also referred to a March 2024 instance, when MeitY asked large intermediaries including AI companies to seek permission before deploying under-tested AI models, a requirement it withdrew within a fortnight after it was flagged as lacking a clear empowering provision.