When the state targets the code: India’s bitchat takedown order and the constitutional limits of digital censorship
Authored by Saisunder NV and Ammu Brigit
INTRODUCTION:
On the night of 23 July 2026, India’s Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs (MHA) issued a takedown notice to GitHub directing the removal of source code repositories of BitChat a decentralised, Bluetooth-based messaging application developed by Block, Inc., the fintech company led by Jack Dorsey within three hours. The notice invoked Section 79(3)(b) of the Information Technology Act, 2000 (“IT Act”) read with Rule 3(1)(d) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. This article examines the legal basis of the order, its constitutional infirmities, and what it signals for India’s evolving jurisprudence on digital rights, open-source software, and intermediary liability.
I. Background: What Is BitChat and Why Did the Government Act?
BitChat is a decentralised, open-source messaging application enabling peer-to-peer communication via Bluetooth and without internet connectivity, centralised servers, or user authentication. Since 17 July 2026, MHA had suspended mobile internet around Jantar Mantar multiple times and most recently within a 1.5 kilometre radius on 23 July, as students protested over alleged irregularities in the 2026 NEET examination. Reports indicate that participants began using BitChat after restrictions took effect.
In its notice to GitHub, I4C alleged that BitChat creates a ‘substantial risk of misuse’ by anti-national elements, terrorist groups, organised criminal networks and cybercriminals, and invoked Sections 43, 84B and 84C of the IT Act, along with Section 61 read with Sections 196 and 197 of the Bharatiya Nyaya Sanhita, 2023.
II. The Legal Instrument: Section 79(3)(b) and Rule 3(1)(d)
Notice No. 11072601011432 invokes Section 79(3)(b) of the IT Act read with Rule 3(1)(d) of the IT Rules, 2021 directing GitHub, as an intermediary, to disable access to the identified repositories while preserving evidence. Section 79 provides intermediaries a safe harbour from third-party content liability; Section 79(3)(b) withdraws that immunity where the intermediary fails to act on actual knowledge or a government notification of unlawful material. The critical legal question is whether Section 79(3)(b) confers an independent blocking power on the government, or merely sets the condition for loss of intermediary immunity.
The Internet Freedom Foundation (IFF), citing Shreya Singhal v. Union of India (2015) 5 SCC 1, maintained that Section 79 is not an independent blocking power and the proper route being Section 69A of the IT Act, which mandates a designated officer, advisory committee review, a reasoned order, and an opportunity for the intermediary to be heard.
III. Constitutional Infirmities: Grounds of Challenge
A. Procedural Bypass of Section 69A
The Information Technology (Procedure and Safeguards for Blocking) Rules, 2009 prescribe a structured process under Section 69A which involves designated officer review, inter-ministerial committee consideration, intermediary response, and a reasoned order. None of these safeguards were engaged. Using Section 79(3)(b) as a blocking tool, with a three-hour midnight deadline, raises serious questions about compliance with the procedural architecture that the legislature has prescribed for content restriction under the IT Act.
B. Proportionality Failure Under Anuradha Bhasin
A three-hour deadline issued close to midnight fails the proportionality standard in Anuradha Bhasin v. Union of India (2020) 3 SCC 637, which requires orders restricting communication to satisfy necessity and proportionality and remain subject to judicial review. An order issued at 11:16 pm during an active protest situation may have the practical effect of precluding both legal challenge and meaningful review.
C. Targeting Architecture, Not Unlawful Content
Unlike previous takedown orders involving websites, social media posts, or mobile applications, this notice specifically targets open-source code repositories. Rather than blocking access to a deployed service, the government instructed an intermediary to remove the software’s publicly accessible source code. The order has the purported effect of targetting the technology’s architecture and its capacity to function without internet rather than any unlawful use of that technology. This conflation of capability with criminality purports to represent a constitutionally significant overreach that, if left unchallenged, could provide a template for suppressing any privacy-enhancing or resilience-oriented software.
D. Want of Jurisdictional Competence- MHA Issuing Notices Under a Statute Administered by MeitY
Notice No. 11072601011432 was issued by I4C, an agency under MHA, not Ministry of Electronics and Information Technology (MeitY), the nodal Ministry that administers the IT Act, 2000. The formal blocking power under Section 69A is vested exclusively in the Central Government acting through MeitY, with a designated officer, advisory committee, reasoned order, and an opportunity for the intermediary to be heard. None of this was engaged. By invoking Section 79(3)(b), MHA assumed a content governance function that Parliament vested in a different Ministry, through a different mechanism, with materially different procedural safeguards.
The constitutional validity of I4C’s authority to issue such notices is under active judicial scrutiny before the Karnataka High Court in X Corp. v. Union of India where the core question is whether Section 79(3)(b) confers any blocking power at all, and whether Rule 3(1)(d) of the IT Rules 2021 is ultra vires the parent Act.
IV. The Technical limitation of the Order
Deleting a code repository removes one copy. BitChat can be forked, recompiled, and shared by any developer worldwide and the international attention the order attracted likely produced the opposite effect: wider distribution and heightened awareness. What the takedown effectively prevents is public scrutiny of the underlying code an outcome that sits uneasily with the transparency principles that underpin open governance in a constitutional democracy.
As of the date of this writing, BitChat remained available on Google and Apple app stores, and GitHub repositories remained accessible to users outside India. No law in India as of July 2026 specifically criminalises its use.
V. The Legal Road Ahead
Whether any Indian court takes up a challenge to the notice will determine whether this three-hour order establishes a precedent for content restriction through this route, or is subject to judicial correction. A writ petition under Articles 19(1)(a) and 19(1)(g) that guarantees freedom of speech and expression, and the right to practise any profession or trade would find substantial support in the existing jurisprudential framework.
CONCLUSION
The BitChat takedown order is significant not for what it achieved but for what it attempted and how it was attempted. It deploys an intermediary liability provision as a surrogate blocking power, without engaging the procedural architecture that the legislature has prescribed for content restriction under the IT Act. India’s courts, if approached must now decide whether the constitutional protections affirmed in Shreya Singhal and Anuradha Bhasin extend to open-source code and decentralised communication architecture or are susceptible to administrative override through alternative procedural routes.
For technologists, developers, and businesses operating in India’s digital ecosystem, the BitChat order is a reminder that legal compliance in the technology sector is not merely about what the law prohibits, it is equally about understanding how legal instruments designed for one purpose are being deployed for another, and being prepared to engage those developments with speed, clarity, and constitutional rigour.