India’s Digital Crossroads: Constitutional Freedoms and the Fight Over Platform Regulation

In recent years, India has emerged as a critical battleground in the global debate over digital rights and state regulation of online platforms. As the world’s largest democracy and one of the fastest-growing internet user bases, the government’s regulatory choices have implications both for domestic users and for global technology firms operating in the country. Against this backdrop, a growing number of legal confrontations have unfolded between Big Tech firms and Indian authorities. These conflicts centre around fundamental issues such as user privacy, the scope of government surveillance, the right to free speech, and the legal responsibilities of digital intermediaries. 

Two ongoing cases – X Corp. v. Union of India and WhatsApp LLC v. Union of India illustrate the growing tension between state regulatory authorities and the operational autonomy of private technology companies. In both the cases, the central legal issue concerns the scope of the Indian government’s power to impose compliance requirements on digital intermediaries, and whether such measures are compatible with constitutional protections, including the right to privacy (as recognised in K.S. Puttaswamy v. Union of India under Article 21) and the right to free speech under Article 19(1)(a) of the Indian Constitution. 

These cases are also indicative of a broader regulatory trend in India, where recent legislative and executive actions such as the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules”) have expanded the government’s role in overseeing online content and user data. India’s digital regulatory framework is primarily anchored in the Information Technology Act, 2000 (“IT Act”), which has evolved through various amendments and delegated legislation to address the complexities of online platforms. The IT Rules is the most significant development since the IT Act and is central to the legal challenges in the cases of X Corp. and WhatsApp LLC.  

The IT Rules impose sweeping obligations on platforms, such as mandatory compliance personnel in India, content takedown within 36 hours of government requests, proactive monitoring of content using automated tools, and in the case of messaging services like WhatsApp, the requirement to enable identification of the “first originator” of messages. This traceability requirement directly undermines end-to-end encryption and is being challenged by WhatsApp as a violation of the fundamental right to privacy. Similarly, X Corp has contested the opacity and overreach of government directives issued through the Sahyog Portal, arguing that it enables unchecked censorship and violates constitutional protections for free expression under Article 19(1)(a). Both companies assert that the IT Rules 2021 lack the procedural safeguards, proportionality, and legislative oversight required to justify such sweeping intrusions into user rights.

These ongoing litigations thus serve as flashpoints in the broader contest between state regulation and digital civil liberties in India. As this continues, these cases will likely set important precedents on intermediary liability, data governance, and the balance between regulatory interests and fundamental rights in India’s digital space. 

X Corp. v. Union of India: Challenging the Sahyog Portal and Content Regulation

On March 5, 2025, X Corp. (formerly Twitter Inc.) filed a writ petition in the Karnataka High Court challenging the Indian government’s directives mandating its participation in the Sahyog Portal, a centralised digital mechanism enabling government agencies to issue content-blocking orders.  

In its petition, X Corp. contends that the operation of the Sahyog Portal lacks statutory backing and contravenes the procedural framework laid out under Section 69A of the Information Technology Act, 2000, which specifies that blocking orders must adhere to established safeguards, including written directions, recorded reasons, and, in certain cases, an opportunity to be heard. According to X Corp., these due process requirements are being circumvented through the government’s increasing reliance on Section 79(3)(b) of the IT Act. 

The company’s petition emphasises that Section 79 was intended to provide “safe harbour” protections to intermediaries, shielding them from liability for third-party content, provided they act upon receiving actual knowledge of illegal content. However, X Corp. asserts that the government’s use of Section 79(3)(b) to issue direct takedown orders bypasses the due process established under Section 69A. The petition also asserts that these orders infringe Article 19(1)(a) of the Indian Constitution, which guarantees the right to freedom of speech and expression. Accordingly, X Corp. has highlighted specific takedown requests made via the Sahyog Portal that targeted content from opposition leaders and government critics, suggesting that the portal may be used to suppress dissent and limit political expression.

In response, the Modi government has defended the Sahyog Portal as an administrative mechanism designed to streamline communication between authorised law enforcement and regulatory agencies and digital intermediaries.4 The government maintains that the portal does not independently issue blocking orders but merely facilitates existing legal processes to ensure compliance with due diligence obligations under the IT Act. While interim relief to X Corp has been denied, Karnataka High Court is yet to deliver a final verdict on the matter, with further hearings scheduled. The ongoing nature of this case reflects both the complexity, and the constitutional sensitivity of the issues involved. The court must weigh the competing interests of state sovereignty, national security, and public order on one hand, and fundamental rights to free speech, privacy, and procedural fairness on the other.  

WhatsApp LLC v. Union of India: Encryption and User Privacy 

In a challenge before the Delhi High Court, WhatsApp LLC v. Union of India, the platform has challenged the Modi government’s IT Rules. A particular point of contention is Rule 4(2), which mandates that messaging platforms enable the identification of the “first originator” of information upon government request.  As noted above, WhatsApp argues that this traceability requirement would compel it to break end-to-end encryption (E2EE), thereby violating users’ constitutional right to privacy under Article 21. The company has emphasised that end-to-end encryption is fundamental to user trust and privacy. 

End-to-end encryption (E2EE) ensures that only the sender and intended recipient of a message can read its contents, neither WhatsApp nor any third party, including governments, can access the communication. WhatsApp has long positioned this encryption model as a cornerstone of its commitment to privacy, especially given its global user base spanning democratic and authoritarian regimes alike. 

In its submissions, WhatsApp also highlighted the global implications of a compliance mandate. WhatsApp has argued that if it were forced to weaken encryption in one country, such as by implementing traceability mandates that could identify the originator of a message, it could open the floodgates to similar demands elsewhere. This would lead to a fragmented and insecure global communications system, where user privacy is undermined based on the regulatory whims of individual states. The company fears this could lead to a chilling effect, where users self-censor or abandon the platform altogether due to fears of surveillance or retaliation. 

The company further claimed that enforcing Rule 4(2) would require a fundamental overhaul of its encryption model, rendering private communications vulnerable for over 500 million users in India, its largest market worldwide. WhatsApp argued that such technical requirements are not only infeasible at scale but also incompatible with international human rights norms, including standards set by the UN Guiding Principles on Business and Human Rights, which require corporations to avoid contributing to adverse human rights impacts. WhatsApp even indicated that it might cease operations in India if compelled to compromise its encryption standards. This strong stance by WhatsApp underscores the severity of the threat it perceives from the Indian government’s regulatory approach.

The Broader Implications 

These aforementioned cases highlight the struggle between digital platforms and regulatory authorities in India. On one hand, there’s a legitimate need for the government to address issues like cybercrime, misinformation, and the protection of individual rights online. On the other, there’s a pressing concern about potential overreach and the imposition of obligations that could infringe upon privacy and free speech. 

The X v. Union of India case illustrates the complexities of holding intermediaries accountable for user-generated content and their role in enabling free speech, especially when orders for takedown are issued indiscriminately by governments. The Sahyog portal is a new and centralised mechanism for digital content regulation and operates in a legal grey area, as it is not explicitly authorized under existing statutory provisions such as Section 69A of the IT Act, 2000. The court’s eventual ruling, therefore, has the potential to set a critical precedent on the limits of executive authority in regulating online speech and intermediary obligations.

The outcome of this case holds significant implications for the future of digital governance and the balance between state regulation and individual rights in India. A ruling in favor of X Corp. could lead to the judicial reaffirmation of procedural safeguards in content moderation, such as transparency, accountability, and the right to be heard, potentially curbing the government’s growing use of opaque or informal regulatory mechanisms. On the other hand, a ruling favouring the Modi government could embolden the expansion of executive power over digital intermediaries, possibly at the cost of free expression and democratic dissent online.

Meanwhile, the WhatsApp case brings to the fore the challenges of implementing regulations that might conflict with global standards of privacy and encryption. At its core, this case reflects the tension between state interests in national security and public order which are often cited as justifications for traceability mandates and the rights to privacy, security, and free expression in the digital era The company’s implicit warning to exit the Indian market if forced to break encryption highlights the broader tension between digital sovereignty and global platform governance. The Delhi High Court’s eventual decision will likely have important ramifications not only for India’s digital regulation regime, but also for global debates on encryption, traceability, and transnational platform accountability. 

As India continues to evolve its digital regulatory framework, these cases serve as critical reference points. These cases highlight the urgent need for policies that strike a fair balance between legitimate state interests, such as national security, public order, and prevention of misinformation, and the protection of individual rights like privacy, free expression, and data autonomy. They also illustrate the complexities faced by digital platforms in navigating ambiguous or broad regulations that may threaten their core functionalities, such as end-to-end encryption or real-time information dissemination. If not carefully crafted, overreaching laws and executive directives risk chilling speech, pushing innovation out of the country, and undermining India’s aspirations to be a global digital leader. Therefore, these cases underscore a vital principle: regulatory clarity and constitutional fidelity must be foundational to India’s digital future.