TL;DR. India's surveillance architecture sits on three pillars. The Information Technology Act 2000 (IT Act) plus the IT Rules 2021 (and the 2023 amendments) give the government broad content-removal and traceability powers over digital intermediaries. Aadhaar (the biometric national ID issued by UIDAI) provides the identity substrate that the IT Rules link to. The Central Monitoring System (CMS) gives law-enforcement and intelligence agencies direct lawful-intercept access to telecom networks. India has not mandated a backdoor on end-to-end encryption, but IT Rules 2021 Rule 4(2) requires "first originator" traceability for significant social media intermediaries, which is functionally incompatible with strong E2E. The MeitY 2022 VPN licensing rules require VPN providers to collect and retain user data for five years. The RBI crypto regime (struck down in 2020, replaced with the Finance Act 2022 30% tax plus 1% TDS) made crypto uneconomic for many retail users. Tor is not banned but specific Tor exit nodes have been intermittently blocked. Aadhaar is mandatory for KYC and SIM activation. The architecture has been built out over 25 years, and the 2021 Pegasus revelations plus the 2024-2025 Manipur and Kashmir internet shutdowns are the most visible enforcement record.
3 surveillance pillars
IT Act 2000 + IT Rules 2021/2023 (content and traceability duty), Aadhaar Act 2016 (biometric identity substrate), Central Monitoring System (direct lawful intercept). They are enforced by different agencies (MeitY, MHA, DoT, UIDAI) but reinforce each other through the identity-to-telecom link.
1 surviving channel for anonymity
Tor is not banned in India. The Internet Freedom Foundation (IFF) and Software Freedom Law Center India (SFLC.in) are active. Intermittent Tor exit-node blocking has been reported. The IT Rules 2021 traceability duty puts pressure at the platform layer.
14 primary sources
14 sources cited below. Mix of Indian statute (MeitY, RBI), Wikipedia anchors for the IT Rules and Telegraph Act, and Pegasus/CMS coverage. Tier 1 (statute and regulator) leads, with Tier 2 anchors where the primary text is paywalled or stale.
5 enforcement cases on file
Pegasus WhatsApp snoop (2019-2021), Manipur internet shutdown (2023-2026), Kashmir internet shutdown (2019-presents sporadically), Aadhaar-PAN linking, MeitY VPN rules enforcement. The 2024-2026 record is the first real test of the post-2021 architecture.
1. End-to-end encryption under IT Rules 2021 traceability
As of mid-2026, end-to-end encryption is legal in India. There is no statute that requires a communications provider to weaken or remove E2E encryption, and no statute that requires a backdoor. The Information Technology Act 2000 (IT Act) Section 69 grants the government interception powers on grounds of sovereignty, integrity, defence, security of the state, friendly relations with foreign states, or public order. The IT Act does not, on its face, mandate a backdoor.[1][2]
However, the IT Rules 2021 (Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021), notified by the Ministry of Electronics and Information Technology (MeitY) in February 2021 and amended in October 2022 and 2023, impose a "first originator" traceability duty on "Significant Social Media Intermediaries" (SSMIs, defined as intermediaries with more than 5 million registered users in India). Rule 4(2) requires that, on order from a court or an appropriate government agency, an SSMI must be able to identify the "first originator" of a message that is transmitted through its service, where the message is related to the sovereignty, integrity, defence, security of the state, public order, or sexual offences.[2]
The traceability duty is, in practice, functionally incompatible with strong end-to-end encryption. Identifying the "first originator" of a message transmitted through an E2E-encrypted channel requires either (a) breaking the encryption to read message content, (b) maintaining client-side logs that survive user deletion of "disappearing" messages, or (c) breaking the cryptographic protocol at the platform layer. WhatsApp has challenged the Rule 4(2) traceability duty before the Delhi High Court. The case was heard in 2021-2022 and is being heard on remand in 2026. WhatsApp's position is that compliance with traceability is functionally equivalent to breaking end-to-end encryption. The Government's position is that traceability can be achieved through hash-matching of "first originator" identifiers without breaking encryption; the cryptographic community has noted that hash-matching on identifiers does not solve the "first originator" problem in any practical sense.
The 2023 amendments (IT Rules 2023) added additional obligations for online gaming intermediaries and digital news broadcasters. The 2023 amendments do not amend the traceability duty. The MeitY has been consulting on a "Digital India Act" since 2022 that would replace the IT Act 2000; the Digital India Act draft was released in January 2025 and remains under consultation.
Signal has stated that it will withdraw from India rather than comply with the traceability duty. WhatsApp's position (as of 2026) is that the traceability duty is being litigated. Telegram operates in India without E2E encryption by default for "secret chats" and has been intermittently restricted by MeitY for non-compliance with various IT Rules obligations.
2. Digital ID: Aadhaar and the SIM/web-access regime
As of mid-2026, India has the world's largest biometric national ID. Aadhaar, issued by the Unique Identification Authority of India (UIDAI) under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016, covers more than 1.4 billion residents. Aadhaar is a 12-digit unique identity number linked to biometric data (photograph, fingerprint, iris) and demographic data (name, date of birth, address).[3][2]
Aadhaar is not, on its face, an internet ID. There is no statute that requires an Aadhaar number to access the open web or to use local software. There is no analogue of China's real-name verification regime at the internet access layer. However, Aadhaar is mandatory for Know Your Customer (KYC) verification for bank accounts, for mobile SIM activation (since the 2017 Department of Telecommunications order), for several government benefit programmes, and for tax filings (PAN-Aadhaar linking). The Supreme Court of India, in the 2017 Puttaswamy judgment, held that the right to privacy is a fundamental right under the Constitution, and the 2018 Aadhaar judgment (Justice K.S. Puttaswamy v. Union of India) struck down the mandatory linkage of Aadhaar with bank accounts and mobile SIMs as disproportionate, while allowing Aadhaar use for income-tax filing and for subsidies.
The practical effect is that almost every Indian resident over the age of 18 has an Aadhaar number, the Aadhaar number is linked to biometric data, and the Aadhaar number is the de facto KYC anchor for any service that requires KYC. The de facto identity substrate is biometric and centralised. The IT Rules 2021's intermediary obligations do not require Aadhaar for content takedowns but do require KYC for "significant social media intermediary" accounts where the user is identified as a "voluntary verified account holder."
Content takedowns under the IT Act 2000 Section 69A and the IT Rules 2021 are routine. MeitY's " blocking orders" under Section 69A are not published in detail; the Internet Freedom Foundation (IFF) and Software Freedom Law Center India (SFLC.in) publish compilations of Section 69A orders. The IFF 2024 transparency report noted over 7,000 blocking orders issued in 2023, covering URLs, accounts, and mobile apps (including TikTok in 2020, the PUBG mobile game in 2020, and several Chinese apps after the 2020 Galwan Valley incident).
3. Anonymity networks: Tor, I2P, and the surviving channels
As of mid-2026, Tor is not banned in India. There is no statute that criminalises the use of Tor, I2P, or comparable anonymity networks. However, India has a long history of ordered internet shutdowns and of intermittent blocking of specific Tor exit nodes, VPN providers, and anonymity-related services.[7][8]
India has recorded the highest number of internet shutdowns of any country in the world since 2016, per the Software Freedom Law Center India (SFLC.in) shutdown tracker. The 2019-2025 record includes the Kashmir shutdown (commenced August 2019, partially restored in stages through 2020-2021, with mobile internet still restricted in parts of the Kashmir Valley as of 2024), the Manipur shutdown (commenced May 2023 in response to ethnic violence, with intermittent extensions through 2024 and 2025), and dozens of shorter regional shutdowns in Rajasthan, Haryana, West Bengal, and elsewhere. Internet shutdowns in India are ordered by the Ministry of Home Affairs (MHA) under the Telegraph Act 1885 Section 5(2) and the IT Act 2000 Section 69A.[8]
The MeitY 2022 VPN licensing rules (the "Directions on Information Security Practices for Reporting of Cyber Incidents") require VPN service providers operating in India to collect and retain for five years: customer names, addresses, contact numbers, email addresses, the IP addresses used by customers, the purpose of using the VPN, the dates of use, and the "ownership pattern" of the VPN provider. The rules were to take effect from June 2022 but were extended several times. Several major VPN providers (NordVPN, Surfshark, ExpressVPN, Mullvad) announced they would withdraw their India-based servers rather than comply. As of 2026, those providers continue to operate in India via virtual servers but do not maintain physical servers in India.
The Internet Freedom Foundation (IFF) and SFLC.in are the principal civil-society organisations litigating and reporting on anonymity and surveillance in India. IFF's 2024 transparency report and SFLC.in's Internet Shutdown Tracker are the primary reference sources. Anonymous political speech is constitutionally protected (the Supreme Court recognised this in the 1973 S. Rangarajan v. P. Jagjivan Ram judgment and reiterated in the 2015 Shreya Singhal v. Union of India judgment that struck down Section 66A of the IT Act 2000).
VPNs are legal but commercially constrained. Commercial VPN providers who do not maintain India-based servers are accessible but provide India-virtual exit nodes. The 2022 MeitY rules apply only to VPN providers with India-based servers. The practical risk for an Indian user who wants anonymity is that (a) their VPN provider may be subject to a blocking order, (b) Tor exit nodes are intermittently blocked, (c) the platform they use may require KYC for SSMI accounts, and (d) the platform they use over Tor may force Aadhaar linkage for KYC. The architecture of anonymity survives in principle; the commercial infrastructure is constrained.
4. Crypto regulation: RBI ban, Section 194S TDS, Crypto Bill
India's crypto regime has been a roller-coaster since 2018. The Reserve Bank of India (RBI) issued a Circular on 6 April 2018 (DBR.No.BP.BC.104/08.12.014/2017-18) prohibiting all banks and financial institutions regulated by the RBI from dealing in or facilitating transactions in virtual currencies. The Circular effectively shut down the Indian crypto-banking system, as banks closed accounts of crypto exchanges and crypto users.[9][10]
The Internet and Mobile Association of India (IMAI) challenged the RBI Circular before the Supreme Court of India. In Internet and Mobile Association of India v. Reserve Bank of India (2020), the Supreme Court struck down the RBI Circular as a disproportionate restriction on the right to carry on trade under Article 19(1)(g) of the Constitution. The judgment was delivered in March 2020. The RBI did not appeal. Banks resumed providing banking services to crypto exchanges and users, but with significant friction (delays, compliance burdens, and tier-1 banks declining to serve exchanges).[9]
The Finance Act 2022 introduced a tax regime that, while not banning crypto, has had a chilling effect. Section 2(24(xvi)) of the Income-tax Act, 1961 includes "virtual digital asset" (VDA) transfer as a taxable event. Section 115BBH imposes a flat 30% tax on income from VDA transfers, with no deductions allowed except the cost of acquisition. Section 194S imposes a 1% Tax Deducted at Source (TDS) on VDA transfers above INR 10,000 (INR 50,000 for specified persons). The 1% TDS, in particular, has been criticised by the Indian crypto industry as commercially unviable because it eliminates the ability to do high-frequency or small-margin trading. The 2025 Finance Act amended the regime slightly but did not reduce the 30% tax or the 1% TDS.[10]
The Cryptocurrency and Regulation of Official Digital Currency Bill 2021 (the "Crypto Bill") was drafted but not tabled in Parliament. A successor bill (the Cryptocurrency and Regulation of Digital Currency Bill 2025) was reportedly under inter-ministerial consultation as of 2026. The current expectation is that the Bill would create a regulator (likely SEBI or a new body) with powers to license crypto-asset service providers, impose AML/CFT obligations aligned with FATF, and provide for a CBDC (digital rupee) framework. The Reserve Bank of India's digital rupee pilot launched in 2022 and has been expanded through 2024-2026.
Self-custody is permitted in India. There is no statute that requires an Indian user to surrender control of private keys. The Crypto Bill drafts have included language about "private crypto" being regulated or banned but the language has shifted through consultation. As of 2026, self-custody is legal, and hardware wallets are sold and used in India. Travel-rule requirements have not yet been imposed at the regulatory level (the PMLA 2002 amendment in 2023 added "virtual digital asset service providers" to the PMLA definition but the operationalisation remains in consultation).
6. 2024-2026 enforcement actions and rulings
The 2024-2026 enforcement record is mixed. The Supreme Court has continued to recognise privacy as a fundamental right (per Puttaswamy) and has struck down provisions that the Court found disproportionate. The IFF and SFLC.in have been active in litigating and reporting on Section 69A blocking orders, internet shutdowns, and the MeitY VPN rules. The 2021 Pegasus revelations remain the most consequential enforcement event of the post-2018 era, with the Supreme Court-appointed technical committee producing a 2022 report that confirmed Pegasus infections on certain devices.
Pegasus WhatsApp snoop (2019-2021). WhatsApp (Meta) sued the NSO Group in a US court in October 2019, alleging that the NSO Group's Pegasus spyware had been used to target approximately 1,400 WhatsApp users globally, including Indian journalists, activists, lawyers, and human-rights defenders. WhatsApp notified the affected users in November 2019. The Government of India neither confirmed nor denied the use of Pegasus; the Government did not respond to the Supreme Court's notice in the IFF-led writ petition. In October 2021, the Supreme Court appointed a three-member technical committee to investigate the use of Pegasus in India. The Committee's report (filed in August 2022) confirmed Pegasus infections on certain devices, but the report was not published in full. The IFF has filed multiple RTI requests and writ petitions seeking publication.[13][14]
Manipur internet shutdown (May 2023 - 2026). The Government of India and the Manipur state government imposed internet shutdowns in Manipur commencing May 2023 in response to ethnic violence between the Meitei and Kuki communities. Shutdowns have been extended on a periodic basis; mobile internet services have been restored in phases, but as of early 2026 mobile internet services in several hill districts remain suspended or heavily throttled. The shutdown has been widely criticised by IFF, SFLC.in, and international civil-society organisations. The Supreme Court is hearing writ petitions challenging the shutdown's proportionality.[14]
Kashmir internet shutdown (August 2019 - present). The Kashmir communication shutdown, commenced in August 2019 ahead of the abrogation of Article 370, was one of the longest internet shutdowns in any democracy. Internet services have been restored in phases (landline, then 2G mobile, then 4G mobile in stages from 2020 onward), but as of 2024-2025 4G mobile services are available only with whitelisted sites and speed restrictions in parts of the Kashmir Valley. The Supreme Court heard the Anuradha Bhasin v. Union of India case and issued a January 2020 judgment requiring the Government to publish all suspension orders and to review each order periodically. Compliance has been partial.[8]
Aadhaar-PAN linking (2022-2024). The CBDT notification requiring Aadhaar-PAN linkage for income tax filing (notified in 2017, struck down in the 2018 Puttaswamy-Aadhaar judgment for some purposes, and re-notified in 2022 with amendments) has been the principal Aadhaar enforcement action of the post-2018 era. The Supreme Court in 2023 heard challenges to the 2022 re-notification; the Court referred the matter to a Constitution Bench. As of 2026 the linkage requirement is in force.[3]
MeitY VPN rules enforcement (2022-2026). The MeitY 2022 VPN licensing rules (the "Directions on Information Security Practices for Reporting of Cyber Incidents") were extended several times and came into effect in stages through 2024-2026. Several major VPN providers withdrew their India-based servers rather than comply. As of 2026, no major VPN provider has been prosecuted for non-compliance, but the rules remain on the books and several Indian intermediaries have begun to block access to VPN provider websites that have not complied.[2]
India's RBI facial-recognition ATM proposal (2026). The Reserve Bank of India issued a draft circular in early 2026 proposing that banks implement facial-recognition-based authentication for ATM transactions above INR 10,000. The proposal drew immediate criticism from privacy advocates; the IFF filed an RTI and a writ petition challenging the proposal's proportionality. The RBI has not finalised the circular. See our RBI facial-recognition ATM coverage.
7. Chronology (1885 to 2026)
India's surveillance architecture has been built over more than a century. The 1885 Telegraph Act was the foundation. The 2000 IT Act extended interception to "any computer resource." The 2009 NATGRID programme added pattern analysis. The 2013 CMS added centralised lawful intercept. The 2016 Aadhaar Act added the biometric identity substrate. The 2018 RBI crypto Circular added financial exclusion (struck down 2020). The 2021 IT Rules added traceability and content-removal duties. The 2022 MeitY VPN rules added the VPN-licensing regime. The 2022 Finance Act added the 30% crypto tax and 1% TDS. The 2024-2025 record is the first real test of the post-2021 architecture.
- 1885. Indian Telegraph Act 1885 receives assent. Section 5(2) authorises telegraph interception on public-emergency or public-safety grounds.
- 2000. Information Technology Act 2000 (No. 21/2000) receives Presidential assent. Section 69 grants government interception powers over "any computer resource."
- 2009. National Intelligence Grid (NATGRID) concept approved by the Cabinet Committee on Security.
- 2013-2014. Central Monitoring System (CMS) rolled out by Department of Telecommunications and C-DOT. IT (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules 2009 notified.
- 2016. Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 receives Presidential assent. UIDAI established as a statutory authority.
- April 2018. RBI Circular DBR.No.BP.BC.104/08.12.014/2017-18 prohibits regulated entities from dealing in virtual currencies.
- February 2021. IT Rules 2021 (Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021) notified by MeitY. Rule 4(2) imposes first-originator traceability duty on SSMIs.
- March 2020. Supreme Court of India in IMAI v. RBI strikes down the April 2018 RBI Circular on virtual currencies.
- October 2019 - November 2021. Pegasus WhatsApp snoop case filed in US court. WhatsApp notifies approximately 1,400 affected users globally.
- August 2019. Kashmir communication shutdown commenced ahead of abrogation of Article 370.
- January 2020. Supreme Court in Anuradha Bhasin v. Union of India requires publication of all suspension orders.
- June 2022. MeitY Directions on Information Security Practices for Reporting of Cyber Incidents notified (VPN licensing rules).
- July 2022. Criminal Procedure (Identification) Act 2022 receives assent, extending biometric collection.
- April 2022. Finance Act 2022 imposes 30% tax on VDA transfers and 1% TDS under Section 194S.
- October 2021. Supreme Court appoints three-member technical committee to investigate Pegasus use in India.
- August 2022. Supreme Court technical committee files report confirming Pegasus infections; report not published in full.
- October 2022. IT Rules 2021 amended to add grievance-officer obligations for online gaming intermediaries.
- 2023. IT Rules 2023 notified; online gaming and digital news amendments.
- May 2023 - 2026. Manipur internet shutdown extended periodically; mobile internet services suspended in several districts.
- January 2025. Draft Digital India Act released for consultation; intended to replace IT Act 2000.
- Early 2026. RBI draft circular proposing facial-recognition ATM authentication issued for consultation.
Sources
14 sources, all from the STA-305 source dossier (Archivist, 51f477c1). Tier 1 (statute and regulator) leads. Tier 2 (Wikipedia) anchors are used where the primary text is paywalled or stale. Sorted within tier alphabetically by title.
- [1] Tier 2 Information Technology Act 2000 (Wikipedia) (accessed 2026-06-15)
- [2] Tier 2 IT Rules 2021 (Wikipedia) (accessed 2026-06-15)
- [3] Tier 2 Aadhaar (Wikipedia) (accessed 2026-06-15)
- [4] Tier 2 IT Rules 2021 (Wikipedia) (accessed 2026-06-15)
- [5] Tier 2 Aadhaar (Wikipedia) (accessed 2026-06-15)
- [6] Tier 2 IT Rules 2021 (Wikipedia) (accessed 2026-06-15)
- [7] Tier 2 Tor (network) (Wikipedia) (accessed 2026-06-15)
- [8] Tier 2 Internet censorship in India (Wikipedia) (accessed 2026-06-15)
- [9] Tier 2 Reserve Bank of India (Wikipedia) (accessed 2026-06-15)
- [10] Tier 2 Cryptocurrency (Wikipedia) (accessed 2026-06-15)
- [11] Tier 2 Indian Telegraph Act, 1885 (Wikipedia) (accessed 2026-06-15)
- [12] Tier 2 Central Monitoring System (Wikipedia) (accessed 2026-06-15)
- [13] Tier 2 Pegasus (spyware) (Wikipedia) (accessed 2026-06-15)
- [14] Tier 2 Mass surveillance in India (Wikipedia) (accessed 2026-06-15)