- Law4Startups
- Posts
- ⚖️ India's crackdown on Open-Source
⚖️ India's crackdown on Open-Source
India Targets Open-Source Code to Suppress Offline Protests
The Indian government, via the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs, issued an urgent takedown notice to GitHub demanding the removal of three open-source repositories for Bitchat within three hours. Bitchat, a peer-to-peer messaging application backed by Twitter co-founder Jack Dorsey, operates over local Bluetooth mesh networks, enabling encrypted communications without internet access, central servers, or phone number verification. The regulatory action coincided with widespread "cockroach" movement student protests in New Delhi over alleged national examination paper leaks, during which local authorities implemented mobile internet shutdowns. As protesters adopted offline tools like Bitchat and Briar, the government targeted the app's underlying source code under Section 79(3)(b) of the IT Act, alleging that its anonymous, decentralized architecture impedes lawful surveillance, investigation, and interception.
Expanding Regulatory Liabilities from Content to Code Architecture
This enforcement action highlights a expanding legal challenge for software developers: regulators targeting open-source codebase distribution based on inherent technological capabilities rather than specific illegal content. India's demand relies on safe-harbor intermediary provisions to force platforms like GitHub to restrict repository access under threat of lost legal protections. Digital rights advocates point out that banning source code repositories does not disable already-installed instances of peer-to-peer software, but it restricts public auditing, security verification, and open development. For technology ventures, this marks a shift where building censorship-resistant, decentralized, or zero-trust architectures can trigger direct regulatory liability, as governments treat the mathematical and architectural design of a tool as inherently unlawful if it bypasses traditional state interception frameworks.
Auditing Regulatory Risks in Decentralized Software Design
Early-stage founders developing open-source, peer-to-peer, or end-to-end encrypted software must actively anticipate and manage structural legal exposure across international jurisdictions. Building applications that operate outside centralized infrastructure creates heightened regulatory friction, particularly in markets with stringent surveillance mandates. Some ideas to limit risk include diversifying the way that your code is distributed, having contingency plans if any distribution channel is shut down and conducting a legal review of your architectural implementation.
In addition to our newsletter we offer 60+ free legal templates for companies in the UK, Canada and the US. These include employment contracts, investment agreements and more