A customer gets a WhatsApp message. It carries their bank's name and logo. The handle looks right, except for one stray hyphen. The message says: verify this UPI transaction in fifteen minutes or lose access to your account.

For fifteen years, a scam like this needed your phone number. The fraudster had to know it or guess it. Once WhatsApp usernames arrive in India, that may no longer be true. A believable name will be enough.

So the real question is not whether WhatsApp should have usernames. It is what happens to trust when a phone number is no longer the first thing you see about the person writing to you. That is a legal question, not just a technology one. The Indian government has already asked it.

What Has Actually Been Announced

On 29 June 2026, WhatsApp confirmed it was opening username reservations. The rollout will be phased and will happen "later this year". Handles can be three to thirty-five characters long.

Four details matter for what follows:

  1. Usernames are optional. You still need a phone number to open an account. The username sits on top of the number. It does not replace it.
  2. There is no directory. WhatsApp says usernames cannot be browsed or searched, and it makes no suggestions. Someone has to know your exact handle.
  3. There is a username key. This is optional. Turn it on and a stranger needs a shared secret before they can open a chat with you at all.
  4. Businesses get a business-scoped user ID. It works in the background. It lets a business and a customer keep messaging without either side seeing the other's number.

Now the part that matters most in India. In early July 2026, the Ministry of Electronics and Information Technology told WhatsApp not to roll out usernames here. It gave three reasons: phishing, digital arrest scams, and people impersonating institutions.

The notice relied on Section 79 of the Information Technology Act, 2000, read with Rules 3(1)(b), 3(2) and 4 of the Intermediary Guidelines of 2021. It also pointed to Sections 66C and 66D of the IT Act, which cover identity theft and cheating by personation. MeitY asked for an explanation within three days. WhatsApp has confirmed it will not launch the feature in India until the review is over.

The Privacy Case for WhatsApp Usernames, and Its Limit

The privacy argument is a good one. It is probably stronger in India than anywhere else.

A phone number here is not just a phone number. Through KYC it is often tied to a bank account, a PAN and an Aadhaar-seeded connection. Handing it to a stranger gives away more than you think.

A username fixes that. A doctor, a freelancer or a consultant can have a public identity that is not their personal number. It works the way a work email address does.

But this answers only one question. Who can reach my number?

It does not answer the other one. Can I trust who is on the other end of this chat?

That second question is where the legal risk sits.

Where the Legal Exposure Concentrates

Take a realistic example. A logistics company has the genuine handle @SwiftCourierIndia. A few weeks after launch, a fake account appears as @SwiftCourierIndia_Support. It copies the logo. It messages recent customers and demands a "customs clearance fee" over UPI.

What can be done about it?

  1. Criminal law. Depending on the facts, this can amount to cheating and cheating by personation under the Bharatiya Nyaya Sanhita, 2023. It can also amount to identity theft or cheating by personation using a computer resource under Sections 66C and 66D of the IT Act, 2000. Which sections apply depends on whether money changed hands and how the trick was done.
  2. Trademark law. If the fake handle uses a registered mark, the business can sue for infringement or passing-off. A handle that copies a registered mark is far stronger ground than one that merely sounds similar.
  3. Consumer law. A customer may have a claim under the unfair trade practice provisions of the Consumer Protection Act, 2019. This is harder. It usually needs a link to the genuine business, and normally there is none.

In practice, report the account to the platform first. It is the fastest thing that works. Litigation takes time, and a live scam does not wait.

This is not a small problem. Ministry of Home Affairs data show about 3.24 crore complaint calls to the 1930 cybercrime helpline in 2025. That is close to one every second.

Cyber fraud cases rose from 22.68 lakh in 2024 to 28.15 lakh in 2025, a jump of around 24 per cent. Reported losses were Rs 22,495 crore, slightly below the Rs 22,845 crore lost in 2024.

Read those two numbers together and they tell a story. More people are being targeted. Slightly less money is getting through. Faster bank and police interception is holding the gap.

Usernames do not create this kind of fraud. They make it cheaper to attempt. A memorable name can be shared and advertised. A phone number cannot.

Data Protection: What the DPDP Act Actually Requires Yet

The Digital Personal Data Protection Act, 2023 is often described as being in force. That is not quite right. It is arriving in stages.

  1. 13 November 2025. The DPDP Rules, 2025 were notified. Definitions took effect and the Data Protection Board was set up.
  2. 12 November 2026. Consent managers must register.
  3. 12 May 2027. The obligations most businesses think of as "the DPDP Act" begin. Notice, consent, breach reporting and data principal rights.

So a business does not carry live data-fiduciary duties today. It will in May 2027. Systems built in 2026 will still be running then, so build for that date now.

Is a username personal data? On its own it sits close to the line. Attach it to a profile photo or a display name, which is what happens in practice, and it clearly falls inside the Act. A business using the feature will carry its own duties, separate from WhatsApp's.

Several questions have no answer in Indian law yet:

  1. What happens when a trademark owner and an unrelated username holder both claim the same handle?
  2. What happens to a handle when a SIM is recycled, or when the account holder dies?
  3. Can a business sell or transfer its username along with the business?
  4. How will account recovery work after a handle is hijacked?

A business that adopts the feature early is ahead of the guidance, not behind it.

The MeitY Notice: India Regulating Platform Design in Real Time

MeitY's notice tracked these concerns almost exactly. It told WhatsApp to pause while the consultation runs.

WhatsApp did not argue with the concern. It asked for time, met MeitY officials, and sent a written reply. The reply set out safeguards. Rate limits on messaging unknown users. Reserved handles for verified accounts and public figures.

Those are promises made during a regulatory dispute. They are not published mechanics that anyone can check. The difference is worth remembering.

There is a second question underneath all of this. Section 79 of the IT Act is a safe harbour provision. It limits when a platform is liable for what users post. Commentators, including the Internet Freedom Foundation, ask whether it also lets MeitY block a feature before anything unlawful has happened.

On that view, a shield is being used as a licence. Nobody has settled the point. How it is settled will decide how far regulators can go in shaping what platforms are allowed to build.

What Businesses Should Do Now

  1. Reserve your handle the day reservations open in India. Take the obvious fakes too: "support", "care", "official", and common misspellings.
  2. Publish the exact handle everywhere. Website, invoices, verified social accounts. Give customers one place to check.
  3. Say what you will never ask for. No OTPs. No payment links. No bank details. Put it in writing, where customers will see it.
  4. Train your support team. An impersonation report is not an ordinary complaint. It needs to go up, fast.
  5. Write down an incident procedure. Who takes the report. How evidence is saved. How quickly you report to the platform and file on 1930 or cybercrime.gov.in.
  6. Check your trademark position. A registered mark makes both a takedown request and a court case much stronger.

Professionals are in a slightly different position. Lawyers, chartered accountants, doctors and financial advisers already hold an unusual amount of client trust. That trust is exactly what a fake account wants to use. Get an official handle early. Tell clients plainly how to check that a message is really from you.

Star and Sterling Associates' Perspective

WhatsApp usernames are not really a privacy feature. They are a new layer of identity on India's biggest messaging platform. Privacy is only one thing that layer has to do.

WhatsApp's design, as described, protects privacy and limits discovery. That is a thoughtful combination, and we say so.

But privacy and limited discovery do not deliver authenticity. Knowing that a name cannot be browsed tells you nothing about whether the name in front of you belongs to who it claims.

MeitY reached for the same reasoning when it paused the rollout. That tells you this is not an academic worry.

Protecting a phone number was always only half of privacy. The other half is protecting the identity a username stands for. That will take verification design, brand protection work, and legal clarity the Indian courts have not yet had the chance to give.

The right instinct is simple. Treat a username as seriously as a domain name, a trademark, or a bank account.