The Centre is reportedly working on a fresh legal framework to regulate virtual private network (VPN) providers, addressing concerns over content bypassing.
New Delhi, India Jul 3, 2026 ALN: The Centre is reportedly working on a fresh legal framework to regulate virtual private network (VPN) providers, a move that could significantly reshape the landscape of internet privacy and security in India. As the digital ecosystem evolves, so do the challenges associated with it, particularly concerning user privacy, cybersecurity, and the government's ability to enforce laws in the digital space. The proposed regulations aim to impose stricter oversight on VPN providers, requiring them to establish a physical presence in India, appoint compliance officers, and designate local personnel to liaise with the government.
This initiative is not merely a bureaucratic maneuver; it reflects a growing concern within the Indian government regarding the increasing use of VPNs to circumvent restrictions on applications, accounts, and online content that have been blocked within the country. VPNs, which mask usersâ IP addresses and encrypt internet traffic, enable anonymous browsing and access to geo-restricted content. However, the Centre has expressed apprehension that these tools are being exploited to bypass content-blocking orders, leading to a perceived erosion of regulatory authority.
According to reports, the new legal framework could introduce penal provisions for non-compliance, including potential jail terms for local employees of VPN companies. This level of enforcement indicates the seriousness with which the government views the matter. The obligations under this proposed framework are likely to mirror those imposed on large social media intermediaries under the Information Technology (IT) Rules of 2021, which have already faced criticism for their stringent requirements.
The urgency for a new legal framework stems from the government's belief that the existing directions issued by the Indian Computer Emergency Response Team (CERT-In) in 2022 have not achieved the desired level of compliance from global VPN providers. The 2022 guidelines mandated VPN providers to collect and retain user information, including names, email IDs, contact numbers, and IP addresses, for a minimum of five years to assist in cybersecurity investigations. However, many VPN providers have resisted these guidelines, arguing that they conflict with their commitment to user privacy and data protection. Instead of complying, several companies opted to withdraw their physical servers from India, routing Indian traffic through virtual servers located in countries with more lenient data retention laws, such as Singapore.
For instance, major VPN providers like Proton VPN, NordVPN, ExpressVPN, and Surfshark have publicly opposed the CERT-In directive, asserting that mandatory data retention practices are incompatible with their no-logs privacy policies. Proton VPN, for example, stated that it had "no intention of complying with this invasive mass surveillance law," highlighting the tension between government mandates and corporate privacy commitments. This standoff has raised critical questions about the balance between national security and individual privacy rights.
Critics of the 2022 CERT-In directions, including digital rights groups and legal experts, have voiced concerns that mandatory data retention without a comprehensive data protection framework could facilitate unwarranted surveillance, undermine user privacy, and expose vulnerable individualsâsuch as journalists, activists, and whistleblowersâto greater risks. They argue that such measures could create a chilling effect on free speech and dissent, as individuals may be deterred from expressing their opinions or engaging in activism for fear of monitoring and reprisal.
Despite these criticisms, the Indian government has maintained that the measures are essential for strengthening cybersecurity and enhancing the efficiency of cybercrime investigations. The governmentâs rationale is that by ensuring VPN providers maintain local points of contact, authorities can more effectively direct them to restrict access to content that has been blocked in India. Officials assert that the use of VPNs undermines the effectiveness of geo-blocking orders, allowing users to route internet traffic through servers located outside the country and thereby evade regulatory controls.
The renewed push for regulation comes at a time when India has significantly expanded its content-blocking regime. Reports indicate that the government issued more than 24,000 content-blocking orders in 2025, a sharp increase from over 12,000 in the previous year. This escalation in content blocking underscores the government's proactive stance in controlling the digital narrative and limiting access to information deemed inappropriate or harmful. The spike in VPN usage during the temporary blocking of Telegram in India last month further illustrates the reliance on such services to bypass government-imposed restrictions. Reports indicated that downloads of leading VPN apps surged by 49%, rising from about 139,000 to 208,000 after the restrictions on Telegram were announced, marking the largest increase since the beginning of 2025.
This situation raises important implications for the future of internet freedom in India. As the government seeks to impose stricter regulations on VPN providers, the potential for increased surveillance and decreased privacy for users becomes a pressing concern. The balance between national security and individual rights will be tested as the legal framework evolves. Moreover, the international implications of such regulations cannot be overlooked, as they may affect how foreign VPN providers operate in India and how they handle user data globally.
In conclusion, the Centre's plans to establish a new legal framework for VPN providers represent a significant shift in the regulatory landscape of digital privacy in India. As the government grapples with the complexities of cybersecurity, user privacy, and digital freedom, the outcomes of these proposed regulations will be closely monitored by stakeholders across the spectrum, from government officials to digital rights advocates. The ongoing dialogue surrounding these issues will be crucial in shaping the future of internet governance in India and beyond.
To learn more about the latest developments in Startup Policies & Regulations, stay updated with our exclusive reports and analyses on AiLensNews.