stricter rules for VPN providers

 Govt looks at stricter rules for VPN providers: Office in India, appoint compliance officials






What’s the ongoing story: 


The Centre is working on an expansive legal framework to curtail virtual private network (VPN) providers that could require them to establish a local India presence and appoint key personnel to serve as a liaison with the government


Key Takeaways:

•(Cert-In)  orders 

 This comes after a controversial directive in 2022 by the Indian Computer Emergency Response Team (Cert-In) 

which required VPN service providers to store a vast amount of 

  • customer data, 
  • including their names, 
  • email IDs, 
  • contact numbers 
  • and IP addresses.


• no satisfactory results -

 However, a new legal framework is now being seen as necessary due to an implicit acknowledgement that the 2022 directives may not have been able to yield satisfactory results. 


The primary concern that the government has is that VPNs are being increasingly used by people to get around the 

  • blocking of apps 
  • and online content.


• The new framework could require VPN operators 

to 

  • establish offices in India 
  • hire compliance officers who can address grievances raised by the government.


Penal consequences

including 

jail terms for local employees, are also being considered in case of non-compliance, it is understood. 


Much of these requirements and penalties are also present for large social media companies under India’s Information Technology (IT) Rules, 2021.


Do You Know:

• VPN services 


allow users to 

  • mask their IP addresses
  • browse the Internet via servers located elsewhere, 
  • making it appear like the traffic is coming from a different jurisdiction, while hiding the original location. 


India’s censorship orders 

typically require companies to geo-block content within the country’s jurisdiction, so, by using a VPN server located in the US, for instance, people can visit content that has been blocked here. 


They are also a way to anonymously browse the web, and are largely seen as a privacy-enhancing service.


India has stepped up its content blocking ecosystem 

in recent years, with 

  • over 24,000 orders issued in 2025, 
  •  over 12,000 orders it had issued in 2024, The Indian Express had earlier reported.


• Another official said the need for having local points of contact for VPN companies is being felt so that the government can direct these services to 

not allow access to content that is being blocked, as such services “otherwise defeat the purpose”.


• For instance, when the Centre temporarily blocked Telegram 

ahead of the NEET-UG retest last month, 

David Peterson, general manager at Proton VPN, a major VPN provider, said that daily registrations for the service from India jumped by more than 120%. 

Peterson’s post on X and his account were both blocked in India after he shared this information.


The 2022 Cert-In directive 

required VPN service providers along with data centres and cloud service providers, to store information such as 

  • names, 
  • email IDs, 
  • contact numbers and IP addresses (among other things) of their customers for a period of five years. 


In response, VPN operators like 

Proton VPN, NordVPN, ExpressVPN and Surfshark, had removed their servers physically located in India and had started routing traffic coming from India via Singapore.


IE 

Comments

Popular posts from this blog

Karnataka govt. unveils digital grievance portal for gig workers