What Exactly Are the New Rules?
The rules, issued by the Indian Computer Emergency Response Team (CERT-In) under the IT Act of 2000, introduce several demanding obligations for tech companies. Two key mandates have caused the most controversy. First, a wide range of entities—including
data centres, cloud service providers, and Virtual Private Network (VPN) providers—must report cybersecurity incidents to the government within six hours of detection. Second, these service providers are required to collect and store extensive user data for five years. This data includes names, contact details, IP addresses, and usage patterns, which must be handed over to government agencies upon request. These rules apply to any entity offering services to Indian users, even if their infrastructure is based outside the country.
The Government's Case: A Safer Digital India
The government's rationale is centered on national security and law enforcement. Officials argue that the rapid increase in cybercrime, data breaches, and online fraud necessitates a more robust response mechanism. In recent years, India has seen major data breaches affecting millions of users, from Air India to Domino's India. The six-hour reporting window is designed to give CERT-In near real-time visibility into emerging threats, allowing for faster coordination and mitigation. Similarly, the data retention mandate is positioned as a critical tool for law enforcement agencies to investigate and prosecute criminals who use digital tools to hide their tracks. The government contends that these measures are essential to protect the country's critical infrastructure and its billion-dollar digital economy.
The Pushback: A 'Grave Threat' to Privacy
Privacy advocates, civil society groups, and many tech companies have condemned the rules as a dangerous overreach. Critics argue that forcing companies to log user activity fundamentally undermines the very concept of privacy. The Internet Freedom Foundation has warned that it leads to both government and private firms having far more data than necessary, creating a massive trove of sensitive information vulnerable to misuse or further breaches. There are significant concerns that these rules could be used to enable mass surveillance, chilling free speech and targeting journalists, activists, and political opponents. International bodies, including UN Special Rapporteurs, have noted that such requirements do not conform with international human rights norms.
The VPN Conundrum
VPN providers are at the epicentre of this debate. Their core service proposition is user anonymity and data privacy, often through strict 'no-logs' policies. The CERT-In directives make this business model nearly impossible to sustain in India. Forcing VPNs to log user data for five years directly contradicts their promise of privacy. In response, several major international VPN providers, including NordVPN, Surfshark, and ExpressVPN, announced they would remove their physical servers from India to avoid complying with the law. While they continue to offer services to Indian users via servers located in other countries, it highlights the operational clash between the regulations and the technology's fundamental purpose.
What This Means for You
For the average Indian internet user, the implications are significant, though not always visible. Using a VPN service that complies with the new rules means your online activities are no longer truly private and can be linked back to you. The extensive data collection by a wider range of service providers increases your digital footprint, potentially exposing more of your personal information in the event of a data breach. While the aim is to make the internet safer from crime, the trade-off is a tangible reduction in personal anonymity online. The debate also intersects with broader legislation like the Digital Personal Data Protection Act (DPDP), which grants individuals rights over their data but also contains exemptions for government agencies on the grounds of national security, creating a complex and contested legal landscape for privacy in India.













