Associate Professor, Rampur College of Law, Milak, Rampur (UP) India
Official Article Landing Page
The Privacy Paradox: How WhatsApp’s Encryption and India’s Surveillance State Collide over User Rights
International Journal of Law, Human Rights and Social Sciences Research International Open Access, Peer-reviewed, Refereed Journal
Google Scholar indexing depends on Google Scholar’s crawl schedule. Verify DOI opens the external DOI resolver.
Abstract
The growing dependence on encrypted messaging platforms has created a complex tension between individual privacy, state surveillance, and digital security in India. This paper examines that tension through the example of WhatsApp, focusing on how end-to-end encryption protects message content while metadata, cloud backups, business interfaces, and device-level vulnerabilities may still expose users to monitoring. The study analyses India’s legal and constitutional framework, including Section 69 of the Information Technology Act, the Information Technology Intermediary Rules, the Digital Personal Data Protection Act, 2023, and the privacy principles recognised in the Puttaswamy judgment. It also considers the implications of traceability demands, data retention, consent practices, surveillance technologies, and government access requests. A comparative perspective is used to contrast Indian safeguards with privacy and oversight mechanisms associated with the European Union and the United States. The paper argues that strong encryption alone cannot guarantee meaningful privacy unless it is supported by judicial oversight, transparency, proportionality, effective remedies, and accountable data-governance practices. It therefore proposes a rights-based framework centred on judicial authorisation, transparency reporting, independent oversight, stronger consent protections, secure backups, and narrowly tailored traceability rules for protecting user rights in the digital environment, while preserving legitimate objectives of security and public order.
Official DOI Landing Verification
This is the official published Version of Record. DOI status: Registered.
Authors & Affiliations
Keywords & Indexing Terms
Download Center
Indexing & Verification
Article Metrics
Metrics are indicative and may update periodically after indexing, downloads and citation tracking are enabled.
Article Integrity & Transparency
License & Copyright
© 2026 The Author(s). The author(s) retain copyright and grant the journal the right of first publication. This work is licensed under the Creative Commons Attribution-NonCommercial 4.0 International License .
How to Cite
Singh, M. (2026). The Privacy Paradox: How WhatsApp’s Encryption and India’s Surveillance State Collide over User Rights. International Journal of Law, Human Rights and Social Sciences Research, 2(2), 1-8. https://doi.org/10.65919/ijlhssr.2026.v2i2001
PDF Preview
If the PDF preview does not load on your device, open the PDF directly or use the Download PDF button. Open PDF in new tab
Declarations
Funding
No external funding information has been declared unless stated in the published PDF.
Conflict of Interest
The authors declare no conflict of interest unless otherwise stated in the article.
Ethical Approval
Ethical approval status is as per the article and journal policy.
Data Availability
Data availability is as declared by the author(s) in the published article.
Author Contributions
Author contributions are recorded as per submitted manuscript and editorial records.
AI-use Declaration
AI-use declaration is governed by journal policy and author disclosure.
Publisher's Note
- ✓ The views, opinions and conclusions expressed in this article are solely those of the author(s).
- ✓ Publication of this article does not imply endorsement by IJLHSSR, the editorial board or the publisher.
- ✓ Responsibility for the accuracy, originality and integrity of the work remains with the author(s).
- ✓ Readers are encouraged to independently evaluate and verify the information before application or citation.
- ✓ IJLHSSR and UnivColl Publications shall not be held liable for any consequences arising from the use of the published content.
References
Showing first 3 references. Click “Show All References” to view complete list.
- 1. Statista. (2026). WhatsApp users in India.
- 2. Bhatia, A. (2024). Surveillance and sovereignty. Economic and Political Weekly, 59(12), 34–41.
- 3. Open Whisper Systems. (2023). Signal Protocol specifications.
- 4. WhatsApp Security Team. (2024). Security whitepaper v.3.0.
- 5. Meta Platforms. (2025). India transparency report.
- 6. Sen, A. (2025). Metadata as behavioral surveillance. Journal of Cyberlaw, 12(1), 22–45.
- 7. Gupta, R., & Sharma, N. (2025). Cloud backup awareness. International Journal of Digital Literacy, 11(3), 102–119.
- 8. Ministry of External Affairs. (2024). India-U.S. MLAT annual report.
- 9. WhatsApp Security Team, supra note 4.
- 10. Meta Business Help Center. (2025). WhatsApp Business API policy.
- 11. Citizen Lab. (2023). Pegasus spyware analysis. University of Toronto.
- 12. The Information Technology Act, 2000 (India), § 69.
- 13. MEITY. (2025). Annual report on interception requests.
- 14. IT Intermediary Rules, 2021, Rule 4(2).
- 15. WhatsApp LLC v. Union of India, W.P.(C) 16/2022 (Delhi High Court, pending).
- 16. Narayanan, A., & Shmatikov, V. (2024). Traceability and encryption. ACM Transactions on Privacy and Security, 27(1), 1–26.
- 17. DPDPA, 2023, §§ 17, 35.
- 18. GDPR, (EU) 2016/679, Art. 15.
- 19. CIS. (2025). Critical analysis of DPDPA.
- 20. Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1.
- 21. Bhatia, supra note 2.
- 22. IFF. (2024). Manipur WhatsApp blockade report.
- 23. OHCHR. (2024). Digital shutdowns and human rights – India.
- 24. Citizen Lab, supra note 11.
- 25. Supreme Court of India. (2024). Technical Committee on Pegasus report (unpublished).
- 26. CCI. (2025). Interim findings on WhatsApp (Case No. 34/2025).
- 27. Singh, J. (2025). Metadata and protest policing. South Asian Journal of Law, 10(2), 134–159.
- 28. Sood, R., & Gupta, A. (2025). Data portability challenges. Indian Journal of Technology Law, 6(1), 45–72.
- 29. IIM Ahmedabad. (2025). Switching costs in messaging apps.
- 30. DPDPA, § 6.
- 31. Data Protection Board of India. (2025). Annual compliance report.
- 32. Irish DPC. (2025). Meta fine – €1.2 billion.
- 33. CLOUD Act, 2018 (U.S.), 18 U.S.C. § 2703.
- 34. Berkman Klein Center. (2025). Global digital privacy rankings.
- 35. WhatsApp Security Team, supra note 4.
- 36. WhatsApp Help Center. (2025). Channels privacy.
- 37. Meta Business Help Center, supra note 10.
- 38. Malhotra, P. (2025). Meta’s strategic ambiguity. Journal of Digital Ethics, 4(3), 56–81.
- 39. Amnesty International India. (2025). Surveillance and minority targeting.
- 40. NCW. (2025). Cyber-stalking report.
- 41. CIS, supra note 19.
- 42. Singh, H. (2024). Reforming interception. Indian Law Review, 8(3), 412–438.
- 43. Transparency International India. (2025). Digital transparency report.
- 44. Raghavan, V. (2026). Independent oversight. Berkman Klein Center Research Paper.
- 45. CIS. (2025). Amending DPDPA for portability.
- 46. Sood & Gupta, supra note 28.
- 47. Supreme Court of India. (2025). Guidelines on traceability (proposed).
Related Articles
Publish Your Research With IJLHSSR
Submit your original research article, review paper, case study or conceptual paper to an international open access, peer-reviewed and refereed journal.