§Legal Chronicle
Research · Privacy & Technology

Encryption Backdoors and the Right to Privacy: A Comparative Look

Governments keep asking messaging platforms for a way to break encryption when investigating serious crime. Every technical proposal for doing that so far breaks it for everyone, not just the target.

Aditi Rao9 January 20268 min read3 sources
Methodology
Comparative review of encryption-access proposals and litigation in India, the United States and the United Kingdom, read against the proportionality standard for privacy restrictions set out in Puttaswamy.
Research · Privacy & Technology

End-to-end encryption ensures a message can be read only by its sender and recipient — not by the platform carrying it, and not by anyone who intercepts it in transit. Law enforcement agencies in several countries, including India, have periodically asked platforms to provide a mechanism to access message content when investigating serious crimes such as terrorism or child exploitation. The technical and legal debate over whether that's possible without undermining encryption for everyone has been running for years, with the same conclusion reached repeatedly.

Abstract

This piece reviews how the encryption-access debate has played out in India, the US and the UK, and argues that the technical consensus among security researchers — that any deliberate access mechanism becomes a vulnerability exploitable by anyone who finds it, not just the intended authority — should be treated as load-bearing in any Indian proportionality analysis under Puttaswamy, not as a detail for engineers to solve separately from the legal question.

The Indian traceability requirement

India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, require large messaging platforms to enable identification of the 'first originator' of a message when required by a court order or a competent authority, for offences above a specified severity threshold. Platforms including WhatsApp have challenged this requirement, arguing that implementing it would require breaking end-to-end encryption itself, since determining the true originator of a specific message requires either weakening encryption or attaching identifying information to every message sent — for every user, not just those under investigation.

What comparative litigation has shown

  • In the US, the FBI's 2016 attempt to compel Apple to build software bypassing an iPhone's encryption was dropped after the FBI found an alternative technical route — leaving the core legal question of compelled backdoor creation formally unresolved, but illustrating how contested even a single-device request became.
  • The UK's Investigatory Powers Act allows government-issued technical capability notices that could require providers to maintain the ability to decrypt communications; providers including Apple have restricted certain UK features rather than comply, citing exactly the same 'no selective backdoor' technical objection.
  • Security researchers across jurisdictions have converged on the same finding in open letters and technical analyses: a mechanism built for lawful access is, mathematically, a vulnerability available to anyone who discovers it, not a capability that stays confined to authorised requesters.
The choice being presented is rarely 'privacy versus security'. It is usually 'security for everyone versus a theoretical, selective access that the technical record suggests doesn't stay selective for long'.

Applying Puttaswamy's proportionality test

Puttaswamy requires a restriction on privacy to be necessary and proportionate to a legitimate state aim, not merely rationally connected to it. If the technical record shows that a traceability or backdoor mechanism cannot be confined to its intended targets without materially weakening security for the entire user base, that is a proportionality problem, not just an engineering inconvenience — the restriction's actual burden falls on far more people than the legitimate aim (investigating specific serious offences) requires. Any Indian court asked to weigh this squarely will need to treat the technical evidence as central to the constitutional analysis, not separate from it.

References

  1. [1]K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 — Supreme Court of India — proportionality standard for privacy restrictions.
  2. [2]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — Rule 4(2) — traceability requirement.
  3. [3]WhatsApp LLC v. Union of India (Delhi HC, pending) — Challenge to the traceability requirement.
Written by
AR
Aditi Rao

Aditi studies law with a focus on how courts are adapting constitutional doctrine to digital-age questions. She founded Legal Chronicle to give student legal writing a more rigorous, research-first home.