Centre Tightens Rules for Messaging Apps: SIM-Based Login and Six-Hour Web Logout Mandated from 2026
In a sweeping new directive that could reshape how Indians use popular messaging apps, the Union government has ordered platforms such as WhatsApp, Telegram, and...
In a sweeping new directive that could reshape how Indians use popular messaging apps, the Union government has ordered platforms such as WhatsApp, Telegram, and Signal to strictly link user accounts to the SIM cards used during registration. The directive, issued on November 28, 2025, requires that these services stop functioning the moment the original SIM is removed from the device. Additionally, all web-based chat sessions must automatically log out every six hours.
The order, issued directly by the Department of Telecommunications (DoT), marks one of the most significant expansions of the government’s regulatory reach into the operations of internet-based communication services.
What the New Rules Require
The directive mandates:
-
Mandatory SIM binding: Messaging apps must verify that the SIM used for account registration remains in the device. Removing the SIM should deactivate the app.
-
Timed web logouts: Any active browser session linked to a messaging account must automatically disconnect after six hours.
The rules come into force in February 2026.
Government officials argue that these measures will help counter the growing wave of cyber fraud, especially scams being coordinated using internet messaging services without persistent verification.
Why the Centre Is Doing This
Officials working closely with the matter say that fraud networks increasingly exploit the current system, where services like WhatsApp require mobile number verification only once at sign-up. Fraudsters often:
-
Use SIM cards temporarily and then discard them.
-
Operate accounts from outside India using cloned or remotely accessed numbers.
-
Run scams through multiple devices without keeping the original SIM active.
According to the DoT, mobile numbers linked to accounts are routinely used outside India for cybercrimes, making traceability difficult. “SIM binding,” officials believe, could close this loophole—but at the cost of additional inconvenience for millions of everyday users.
The directive was first reported by tech policy outlet MediaNama.
Industry Pushback and Concerns
Early industry responses suggest unease within the technology and telecom sectors.
An industry executive familiar with the matter said the order was “problematic” because:
-
No public consultation or technical feasibility study preceded the decision.
-
It is unclear whether determined fraudsters could still find ways to evade such restrictions.
-
The directive may undermine usability for legitimate users, especially those who switch devices frequently or use multi-device setups.
The DoT and WhatsApp did not immediately respond to inquiries sent by The Hindu.
A Major Shift in DoT’s Regulatory Scope
Traditionally, the DoT regulates telecom operators and infrastructure—the “carriage” layer of communications. App-based platforms like WhatsApp fall into the “content” layer, historically outside the DoT’s direct domain except in limited cases such as website blocking.
However, officials argue that the convergence between telecom networks and digital services has blurred these lines. One official said the old separation between carriage and content “must be re-evaluated” in a digital ecosystem where phone numbers function as universal identifiers.
The Policy Background: TIUEs and Cybersecurity Rules
This latest directive builds upon changes the government introduced earlier in 2025 to the 2024 Cyber Security Rules. Those amendments introduced a new category called Telecommunication Identifier User Entities (TIUEs)—a broad term applying to any service that uses mobile numbers to identify users.
This category could include:
-
Messaging applications
-
Social media platforms
-
E-commerce marketplaces
-
Fintech apps
-
Mobility services
The Internet and Mobile Association of India (IAMAI)—representing Meta and several major digital firms—argued in filings to the DoT that the amended rules represent overreach, exceeding the authority granted under the 2023 telecom law. The group warned that the new framework could create operational burdens for a wide range of digital businesses.
Telecom Operators Have Long Pushed for Action
Telecom service providers have repeatedly urged the DoT to take action against fraud carried out through internet-based messaging apps. They argue that while they face strict anti-spam and verification rules, criminals often bypass these checks by shifting illegal activity to platforms like WhatsApp.
With this directive, the government appears to be responding to that long-standing demand—but in a manner that significantly expands regulatory oversight over digital platforms.
What Comes Next
Tech companies are expected to seek clarity on implementation timelines and technical feasibility, especially regarding:
-
Device compatibility
-
Multi-device accounts
-
Roaming scenarios
-
Cross-platform privacy obligations
Legal experts predict that the new rules could face challenges, both on grounds of privacy and intermediary regulation, once companies begin operational groundwork.
For now, the directive signals a new era of tighter government control over digital communication in India, with implications for user convenience, online privacy, and the broader regulatory landscape.
