India's draft encryption policy puts user privacy in danger
Nikhil Pahwa / MediaNama :
Context & Ripple Effects
MediaNama's report lands mid-arc: months earlier, Internet.org was shown letting partner telcos track users over unencrypted connections, so the draft policy reads less like an isolated misstep and more like a pattern of Indian policy tolerating weak encryption when it suits state or carrier interests.
The draft's significance is what it normalizes — compelled access to encrypted user data as a standing requirement rather than an exceptional power — and how quickly that framing gets tested publicly.
First-order effects
- Indian users of encrypted services face the direct risk of their communications being readable by the state, since the draft treats user privacy as subordinate to government access.
Second-order effects
- Public backlash proved strong enough that the government withdrew the draft within days and committed to revising it, showing encryption mandates carry immediate political cost — but also signaling the demand itself survives to be re-released.
Third-order effects
- The pattern holds across years: later drafts keep reaching for state access to technical systems, from the e-commerce policy's mandate for government access to source codes and algorithms to data protection proposals whose re-identification bans could criminalize security researchers' work — suggesting India's default drafting instinct is broad state reach, walked back only under pressure.
The trend: Indian digital policy has evolved into a cycle of expansive state-access drafts — encryption keys, source code, researcher work — withdrawn or softened on backlash, then re-emerging in successive bills.