Centre's SIM-binding rules: WhatsApp Web must log out every 6 hours
Centre's SIM-binding rules: WhatsApp Web must log out every 6 hours
India introduces SIM-binding for app-based messengers, forcing periodic logouts and QR re-linking to curb cyber threats.
The Centre has issued a new notification on SIM-binding for app-based communication services, effective immediately. The rules require that web-based sessions for apps like WhatsApp, Telegram, Signal, Arattai, Snapchat and others stay tied to the user’s active SIM. In simple terms: if the SIM is not physically present in the device, the service cannot run. The notification lists the affected apps and marks the importance of cybersecurity in the mobile ecosystem.
From 90 days after the instructions are issued, the web service instance of the mobile apps, if provided, must be logged out periodically (not later than 6 hours) and allow users to re-link the device using a QR code. It also mandates that these app-based services stay continuously linked to the SIM card associated with the user’s mobile number installed in the device, making it impossible to use the app without that active SIM. This two-pronged approach aims to close gaps where devices operate without a SIM, a vulnerability the DoT says has been exploited to carry out cyber frauds, including cross-border attempts.
The move marks the DoT’s first significant push to regulate messaging platforms at the policy level and follows prior telecom cyber security rules updated in 2024 and 2025. DoT officials say the issue arises when apps run on devices lacking the required SIM, a gap exploited by bad actors, including from outside India. The notification notes discussions with major service providers to align on practical implementation, signaling a coordinated effort across the telecom and tech sectors.
For users, the changes could mean a tighter balance between security and convenience. Those who rely on WhatsApp Web or other multi-device setups may need to ensure their device always has an active SIM and be prepared to re-link via QR codes when prompted. In the long run, proponents argue the policy will reduce cybercrime risks by ensuring that access to messaging platforms is continuously tied to the user’s verified SIM identity.
As the new rules roll out, telecom operators and app developers will be watching closely to implement the requirements smoothly while minimizing disruption for legitimate users.
Cover image source: WhatsApp ordered to enforce ‘SIM binding,’ log out web sessions every 6 hours 🔗