Image for Representation
NEW DELHI: The Indian government is actively developing a more robust legal framework to regulate virtual private network (VPN) providers, aiming to address persistent challenges in enforcing cybersecurity norms and content-blocking orders.
This initiative builds on earlier directives while introducing structural requirements to ensure better compliance from both domestic and international operators serving Indian users.
Recent discussions within the government highlight concerns that many VPN services enable users to bypass official blocks on websites, applications, and platforms.
This has prompted authorities to seek mechanisms that go beyond data retention, focusing on operational presence and direct accountability within India.
Key Elements of the Proposed Framework
Officials indicate that VPN providers could be required to establish a physical office or registered presence in India. Additionally, they may need to appoint dedicated compliance officers or authorized representatives to handle requests from law enforcement agencies and the Indian Computer Emergency Response Team (CERT-In).
These measures draw inspiration from the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which apply to major social media platforms.
Under that regime, significant intermediaries must designate a Chief Compliance Officer, a Nodal Contact Person for 24/7 coordination with authorities, and a Resident Grievance Officer.
A similar structure is being considered for VPN services to facilitate quicker responses during investigations.
Penalties for non-compliance are also under discussion, potentially including legal consequences for local representatives, such as fines or imprisonment, mirroring provisions for other digital intermediaries.
Revival of 2022 CERT-In Directions
The current push revisits the April 2022 CERT-In directives, which mandated VPN providers, along with cloud services, virtual private servers, and data centres, to collect and retain detailed subscriber records for a minimum of five years, even after service cancellation.
Required data includes names, physical addresses, contact numbers, email addresses, IP addresses, service usage periods, and purposes.
This data must be provided to authorities upon lawful requests tied to cyber incident investigations. The goal is to aid probes into ransomware, financial fraud, phishing, and other cybercrimes where anonymization tools are commonly used.
A senior government official told NDTV “There has been rampant abuse of VPN services. People use them to conceal their identity, bypass law enforcement, and access websites that have been blocked in India. The objective is not to monitor ordinary users but to ensure investigative agencies have the ability to trace those involved in cybercrime and other unlawful activities.”
The 2022 rules faced significant pushback from VPN providers and privacy advocates, who argued that mandatory logging conflicted with “no-logs” policies central to their privacy offerings.
Several prominent services, including ExpressVPN, Proton VPN, NordVPN, and Surfshark, responded by removing physical servers from India and routing Indian traffic through locations abroad.
The government had extended the original compliance deadline from June to September 2022 to allow adjustments.
However, officials now acknowledge that these measures have not fully curbed the ability of users to access blocked content via foreign servers.
India has intensified content blocking in recent years, issuing over 24,000 orders in 2025 compared to more than 12,000 in 2024, the Indian Express noted.
VPN usage has surged during specific events, such as the temporary blocking of Telegram ahead of the NEET-UG retest, where one provider reported a over 120% jump in Indian registrations.
Experts note that while these rules aim to bolster national cybersecurity and enforce lawful restrictions, they raise questions about privacy, internet freedom, and the operational feasibility for global VPN firms.
Privacy-focused providers may face difficult choices: comply and potentially alter their core offerings, or limit services to Indian users through non-compliant models that could invite enforcement actions.
The framework also reflects a wider pattern in India’s digital regulation, where platforms are increasingly expected to maintain local accountability mechanisms to align with national security and public order priorities.
For ordinary users, everyday VPN applications for secure browsing or accessing geo-restricted (non-blocked) content are unlikely to face direct disruption.
However, services that actively facilitate evasion of government blocks may encounter stricter technical or operational hurdles if providers are compelled to enforce geo-restrictions more rigorously.
As the government refines this legal approach, industry consultations are expected. The Ministry of Electronics and Information Technology (MeitY) has not yet issued official comments on the latest developments.
This evolving regulatory landscape underscores the ongoing tension between enhancing cyber resilience, enforcing digital sovereignty, and preserving user privacy in an increasingly connected world.
