Can India Force WhatsApp To Break End-To- End Encryption? Answer from Podchasov v. Russia
WhatsApp's challenge to Rule 4(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 has been pending before the Delhi High Court since 2021. The government wants large messaging platforms (significant social media intermediary) like WhatsApp to help identify the “first originator” of any message, whenever a court or the government asks for it under Section 69 of the Information Technology Act, 2000. WhatsApp says it cannot do this without breaking end-to-end encryption, which would put the privacy of every Indian user at risk. In February 2024, the European Court of Human Rights (ECHR) decided a case called Podchasov v. Russia that directly speaks to this same question. I believe the reasoning of the ECHR in that case supports WhatsApp's position and carries an important message for India: privacy cannot be taken for granted.
Two important questions arise from this:
1. Whether forcing messaging platforms to compromise end-to-end encryption to create a "traceability" mechanism violates the democratic standards of proportionality established by international human rights jurisprudence, such as the ECHR's ruling in Podchasov v. Russia?
2. Whether a government that itself relies on end-to-end encrypted communication for its own officials can, in good conscience, deny ordinary citizens the same protection?
Before going into the law, it is important to understand what end-to-end encryption actually means. Imagine you write a letter, lock it in a box, and send it to your friend. The courier carries the box but does not have the key to open it. Only your friend has that key. So even if someone intercepts the box in the middle, they cannot read what is inside. That is exactly how end-to-end encryption works on apps like WhatsApp. When you send a message, it gets locked on your phone before it leaves. WhatsApp's servers forward the locked message to the other person's phone, where it is unlocked. WhatsApp itself never holds the key. This means WhatsApp genuinely cannot read your messages not because it refuses to, but because it is technically not possible without rebuilding the entire system from the ground up.
In Podchasov v. Russia, a Russian user of the messaging app Telegram challenged his government's law that required all messaging platforms to store users' messages and hand over decryption keys to the Federal Security Service (FSB) whenever asked. The FSB had ordered Telegram to hand over keys for six phone numbers linked to a terrorism investigation. Telegram refused, saying it was technically impossible to give keys for only those six users without weakening encryption for all users. The ECHR accepted this technical argument in clear terms:
The applicant argued that it was technically impossible to provide the authorities with encryption keys associated with specific users of the Telegram messenger application. In order to enable the decryption of end‑to‑end encrypted communications it would be necessary to weaken the encryption technology used by the Telegram messenger application. However, because these measures could not be limited to specific individuals, they would affect everyone indiscriminately... The Government, by contrast, did not provide any arguments or information capable of refuting the applicant's submissions that the measures ICOs would have to take to comply with the statutory obligation to decrypt end-to-end encrypted communications would affect all users of their services. The Court accordingly accepts that the applicant was affected by the contested legal provisions.
— Podchasov v. Russia, para. 57
The ECHR held that Russia had violated Article 8 of the European Convention on Human Rights, which protects the right to private life and correspondence. The court's conclusion on the decryption obligation was unambiguous:
The ICO's statutory obligation to decrypt end-to-end encrypted communications risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users; it is accordingly not proportionate to the legitimate aims pursued.
— Podchasov v. Russia, para. 79
India's Rule 4(2) asks for something slightly different not decryption, but “traceability,” meaning the ability to identify who sent a message first. The government has argued that it is not asking WhatsApp to reveal message content, only the identity of the originator. However, WhatsApp's petition before the Delhi High Court explains why this distinction does not survive in practice. To trace the origin of a message on demand, a platform would have to attach a permanent identifier to every single message sent by every single user at the time it is sent because no one knows in advance which message the government will later want to trace. This is not a targeted tool. It is a universal tracking system built into the backbone of the app, affecting all of its users, not just suspects. The ECHR warned precisely about this danger:
Weakening encryption by creating backdoors would apparently make it technically possible to perform routine, general and indiscriminate surveillance of personal electronic communications. Backdoors may also be exploited by criminal networks and would seriously compromise the security of all users' electronic communications.
— Podchasov v. Russia, para. 77
What makes this situation truly difficult to ignore is that the government itself relies on end-to-end encryption for its own communications. The National Informatics Centre under the Ministry of Electronics and Information Technology developed Sandes, an end-to-end encrypted messaging app used by government officials across the country. The Indian Army built its own app called SAI - Secure Application for Internet which also uses end-to-end encryption, precisely because the Army did not want its internal communications to be readable by outsiders. More recently, AICTE launched Hyped Samvadini, another end-to-end encrypted messaging platform under a government initiative. In my view, the government cannot have it both ways. If end-to-end encryption is good enough to protect the government's own sensitive communications, on what basis can the same government say that ordinary citizens do not deserve the same protection?
The ECHR's decision in Podchasov is not legally binding on Indian courts. India is not a member of the European Convention on Human Rights. However, it is highly persuasive, and the test the ECHR applied is very similar to the test Indian courts already use. In Justice K.S. Puttaswamy v. Union of India (2017), the Supreme Court of India recognised the right to privacy as a fundamental right under the Constitution and held that any law restricting privacy must be legal, serve a legitimate state aim, and be proportionate. The ECHR's final conclusion in Podchasov speaks directly to that same standard:
The Court concludes that in the present case the ICO's statutory obligation to decrypt end-to-end encrypted communications risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users; it is accordingly not proportionate to the legitimate aims pursued.
— Podchasov v. Russia, para. 79
The contested legislation... cannot be regarded as necessary in a democratic society. In so far as this legislation permits the public authorities to have access, on a generalised basis and without sufficient safeguards, to the content of electronic communications, it impairs the very essence of the right to respect for private life.
— Podchasov v. Russia, para. 80
When the Delhi High Court finally decides WhatsApp's petition, it ought to consider that same proportionality test as the ECHR's analysis of why a traceability-style obligation fails that test is directly on point.
In conclusion, Privacy is not just a word in a judgment. It protects the journalist speaking to a source, the lawyer speaking to a client, the student speaking to a friend, and the ordinary citizen simply going about their day. End-to-end encryption is the technology that keeps those conversations safe. Podchasov v. Russia is a clear signal from one of the world's most respected human rights courts that forcing messaging platforms to break this protection even for national security reasons crosses a line. India stands at a similar crossroads. If the government understands why encryption matters enough to use it for itself, it must also understand why it matters for the rest of us.
“Ultimately, arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.”
— Edward Snowden
References
1. Podchasov v. Russia, Application no. 33696/19, European Court of Human Rights (Third Section), Judgment of 13 February 2024 (final 13 May 2024), paras. 57, 77, 79 and 80.
2. https://www.livelaw.in/tags/justice-ks-puttaswamy-retd-v-union-of-india.
7. https://www.livelaw.in/tags/sandes-app
Views are personal.