India to force VPN companies to hand over user data


Using your favorite VPN in India may soon be impossible thanks to new regulations that will require VPN providers to collect and store a wide range of data on their customers for a period of five years.
As reported by ENTRACKR, the Computer Emergency Response Team (CERT-in) which is under the control of the country’s Ministry of Electronics and Information Technology has issued a new set of directions in an effort to “coordinate response activities as well as emergency measures with respect to cyber security incidents.
VPN providers aren’t the only companies that will be required to store customer data though as the directions also apply to data centers, cryptocurrency exchanges and Virtual Private Server (VPS) providers as well.
Beginning in June of this year, companies in these industries will be required to register customer names, customer ownership patterns, customer contact information and the reason they have purchased their services in the first place.
Improving cyber incident response at a cost
CERT-in’s new order appears to be aimed at ensuring the government agency can respond to all manner of cyber incidents within six hours of their discovery. While the order itself may be well-intentioned, the range of data CERT-in is asking organizations to store and provide upon request is quite unusual.
CERT-in requires organizations to report data breaches, fake mobile apps, attacks on server infrastructure and even unauthorized access to a user’s social media accounts. Additionally, businesses that fail to provide the necessary information are governed by Section 70B(7) of the IT Act which could lead to up to one year in prison.
Another snag in the Indian government’s plan is that most VPNs have a ‘no-logs policy’ or at the very least, only keep user data temporarily. As a result of CERT-in’s new directions, many VPN providers and other IT companies could potentially stop doing business in India as they can no longer legally operate in the country.
The new directions will go into effect at the end of June unless the window for compliance is extended which very well could be the case. Until then though, consumers and businesses in the country should pick up one of the best India VPNs while they still can.
Via ENTRACKR
Audio player loading… Using your favorite VPN in India may soon be impossible thanks to new regulations that will require VPN providers to collect and store a wide range of data on their customers for a period of five years. As reported by ENTRACKR, the Computer Emergency Response Team (CERT-in)…
Recent Posts
- Elon Musk says Grok 2 is going open source as he rolls out Grok 3 for Premium+ X subscribers only
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin will suffer a humane death
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010