Indian authorities are drafting new regulations to mandate data retention for VPN providers, aiming to curb cybercrime and enforce content blocks despite significant opposition from privacy advocates and companies.
Key Points
- India’s government is pursuing new rules to track VPN users, citing concerns over cybercrime and the circumvention of over 24,000 government-issued content-blocking orders.
- An estimated 400 million people in India use VPNs, representing roughly half of the country's total internet-connected population.
- Previous 2022 mandates requiring VPN providers to store customer data failed after major companies removed physical servers from India to maintain no-logs privacy policies.
- Proposed measures include requirements for appointing compliance officers and potential prison terms for non-compliance, mirroring stricter internet controls seen in China and Russia.
- India reported a 13% increase in data breaches in 2025, with the average cost per incident rising to $2.31 million according to IBM.