Is a VPN Legal in India? The Data Retention Rules Users Should Know
Using a VPN in India is not illegal. But a 2022 government directive changed what some providers are required to record about you — and most major VPNs responded by leaving the country rather than comply.
Quick answer
Yes, using a VPN in India is legal for individuals — there is no law banning VPN use for privacy, security, or accessing content. What changed is a 2022 CERT-In directive requiring VPN providers serving Indian customers to retain specific subscriber records (names, IP addresses, registration details) for five years, even after account cancellation. Because that requirement conflicts with strict no-logs policies, several major VPN companies withdrew physical servers from India and now serve "India" as a virtual location hosted elsewhere. A VPN also does not make an otherwise illegal activity legal.
Is a VPN legal in India?
Yes. There is no law in India that makes it illegal for an ordinary person to install and use a VPN. India does not maintain a nationwide VPN ban comparable to the restrictions found in a small number of other countries, and using a VPN to encrypt your traffic, access geo-restricted content, or protect your connection on public Wi-Fi is not, by itself, a criminal act. Millions of people across the country use VPNs routinely — for remote work, for streaming, for general privacy — without any legal issue arising from the fact that they used one.
What has changed the conversation around VPNs in India is not a ban on using them. It is a 2022 data retention directive aimed at the companies that operate VPN services, and the ripple effects that directive has had on which providers are willing to keep physical infrastructure in the country at all. That distinction — legality of use by an individual, versus a regulatory record-keeping requirement placed on providers — is the thing most short answers to "is a VPN legal in India" skip past, and it is the thing worth actually understanding before you pick a provider or worry about your own legal exposure.
This guide walks through what the underlying rule actually says, why it pushed several well-known VPN companies to change how they operate in India, what it does and doesn't mean for you personally, and how to evaluate a provider if data retention specifically is what you're trying to avoid.
It's worth saying up front why this particular question gets asked so often. India has one of the largest internet-user populations in the world, and VPN adoption there has grown for a mix of ordinary reasons — remote and hybrid work setups that require secure access to company networks, general interest in privacy tools, and access to streaming or content platforms that vary their catalogs by region. Against that backdrop, a 2022 government directive aimed at VPN providers was always going to generate headlines, some of them more alarmist than the underlying rule actually warrants. The goal of this guide is to separate what the directive actually says from how it got summarized in a lot of shorter coverage at the time, so you can make an informed decision about your own VPN use rather than relying on a secondhand characterization of a rule that's more specific, and more limited in scope, than "VPNs in India now spy on you" would suggest.
What is the CERT-In directive, and what does it actually require?
In April 2022, India's Computer Emergency Response Team (CERT-In) — the agency under the Ministry of Electronics and Information Technology responsible for national cybersecurity incident response and coordination — issued a set of directions under Section 70B of the Information Technology Act, 2000. Section 70B is the provision that empowers CERT-In to issue directions for carrying out its functions, including collecting, analyzing, and disseminating information on cybersecurity incidents, and it also creates a penalty for non-compliance: failure to follow CERT-In's directions under this section can result in imprisonment of up to one year, a fine, or both, under the Act.
The April 2022 directions covered a fairly broad set of entities — data centers, virtual private server (VPS) providers, cloud service providers, and, notably, VPN service providers offering services to Indian users — and imposed new record-keeping obligations on all of them. The specific requirement most relevant to VPN users is this: VPN providers were directed to register and retain, for a minimum of five years, a defined set of customer records. Per the text of the directive, that includes:
- Validated names of subscribers or customers hiring the service
- Period of hire, including specific dates
- IP addresses allotted to and being used by members
- Email addresses and the IP address used at the time of registration or sign-up
- The purpose for which the service is being used
- The customer's validated address and contact number
- The ownership pattern of the subscribers or customers hiring the service
Two details of the directive tend to get lost in shorter summaries but matter a lot in practice. First, the five-year retention window applies even after a customer cancels or withdraws their subscription — the obligation to keep the records doesn't end when the customer relationship does. Second, the directive separately requires covered entities to report specified categories of cybersecurity incidents to CERT-In within six hours of noticing them, which is an unusually short window by international standards and was itself a point of significant industry pushback when the rules were announced.
The directions were originally announced with a 60-day compliance window, which industry groups argued was too short given the scale of infrastructure and process changes involved; CERT-In granted a short extension, and the rules formally took effect in the second half of 2022.
Why is this different from a typical "no-logs" VPN policy?
The premise of a "no-logs" VPN — a phrase you will see on nearly every provider's marketing page — is that the company does not retain identifying records connecting a specific user to specific online activity or connection metadata over time. A strict no-logs provider's position is typically that even if compelled by a court order or law enforcement request, there is nothing meaningful to hand over, because nothing was recorded in the first place. The whole point is that a demand for data hits a wall, not a database.
CERT-In's directive runs in the opposite direction. It does not ask providers to hand over data only when compelled by an individual investigation — it asks them to proactively collect and retain a defined set of subscriber records as an ongoing operational requirement, regardless of whether any specific user is ever investigated or suspected of anything. For a VPN provider whose entire value proposition rests on minimal data retention, that is close to structurally incompatible with the directive as written. It is not a request for occasional cooperation with law enforcement on a case-by-case basis; it is a standing obligation to keep records on every customer, all the time.
This is why the directive became a much bigger story for VPN users specifically than most single-country regulatory actions usually are. It did not target VPN use the way a website-blocking order or an app ban would — it targeted the operating model that many privacy-focused VPN companies had built their entire brand around. A provider could, in theory, comply with the letter of the directive while still not logging browsing activity or DNS queries, since the directive's list of required records is about subscriber identity and account metadata rather than browsing history. But retaining validated name, address, and IP-at-signup data tied to an individual account for five years is still a meaningfully different privacy posture than "we don't know who you are."
Why did some VPN providers pull their servers out of India?
Several well-known VPN companies publicly announced, around the time the directive took effect in 2022, that they were removing their physical servers from India rather than complying with the retention requirements. The reasoning providers gave was broadly consistent across companies: retaining the kind of subscriber and account-identity records the directive describes would conflict with the no-logs commitments they had made to customers worldwide, and they were not willing to weaken that global commitment — or maintain two different privacy standards for different markets — for one country's regulatory requirement.
The practical workaround several of these providers adopted is the use of virtual server locations. Rather than operating a physical server inside India, a VPN app can show an India-based server location in its list of countries while the underlying hardware is physically located in another jurisdiction — Singapore is a common choice given its geographic proximity to India and its role as a regional data-center hub — configured so the server presents an Indian IP address to the outside world. This lets a provider continue offering "India" as a connection option in its app, which matters for users who specifically need an Indian IP address (for banking apps, regional content, or work reasons), without the server itself — and the company's legal obligations tied to it — being subject to Indian law in the way a server physically hosted in-country would be.
It's worth being clear about what a virtual server location does and doesn't change for a user. Functionally, from inside the app, connecting to a virtual India server usually looks identical to connecting to a physical one — you get an Indian IP address and can typically access India-specific content or services that check for that. What differs is where your traffic is physically routed and processed, and, in some configurations, a very small amount of added latency compared to a true in-country server, though this varies by provider and route. Whether a given provider uses a physical or virtual India location — and whether that distinction matters to you — is a detail worth checking directly on the provider's own server-location or transparency page rather than assuming, since providers periodically update this information as infrastructure and policy shift.
Not every provider responded the same way
It's worth noting that the industry response to the CERT-In directive was not uniform. Some providers withdrew physical servers entirely and switched to virtual locations, as described above. Others reportedly continued operating in some capacity while reviewing their compliance posture, and the picture for any specific company can change over time as legal interpretation, enforcement activity, and provider business decisions evolve. This is not a static, one-time event you can read about once and consider permanently settled — if a specific provider's India server status matters to your decision, checking that provider's current, dated statement on the subject is more reliable than relying on any single article, including this one, as a permanent record.
Does the CERT-In directive apply to a VPN provider based outside India?
This is genuinely unsettled ground, and it's worth being precise about what is known versus what is debated rather than stating a confident legal conclusion. CERT-In's directions describe the obligation as applying to VPN providers "offering services in India," which raises a real jurisdictional question for a company headquartered elsewhere, with no legal entity, employees, or physical infrastructure in the country, that simply happens to have Indian customers signing up through its public website.
In practice, many international VPN providers appear to have concluded that direct enforcement against a foreign entity with no local presence is difficult for Indian authorities to carry out, and have continued serving Indian customers without changing their global logging practices — while separately choosing to remove physical servers from Indian soil as a more concrete, verifiable way of sidestepping the underlying question of whether the directive binds them. That combination — no physical India infrastructure, no change to the company-wide logging policy — is the position most major privacy-focused VPN providers appear to have settled into.
None of this is a substitute for a real legal opinion if your specific situation has meaningful legal stakes attached to it. It's a description of the general, publicly observable landscape — how providers have responded and what they say publicly — not personalized legal advice, and cross-border regulatory questions like this one are exactly the kind of area where the practical answer can differ from the theoretical one, and where things can shift with little notice.
Who can actually access the data VPN providers are required to retain?
A point that gets lost in a lot of the coverage of this directive is the difference between a provider being required to retain records and the government having ongoing, automatic access to those records. The CERT-In directive, on its own terms, is a record-keeping obligation: it requires covered entities to hold onto a defined set of subscriber data so that it exists and is available if a lawful request for it is later made, not a real-time data feed piping every subscriber's records to a government agency continuously. In that sense it functions similarly to how many countries require telecom operators or internet service providers to retain certain subscriber and connection records for a set period, precisely so that a legitimate investigative request has something to work from.
Separately, Section 69 of the IT Act and its associated procedural rules govern when and how Indian government agencies can actually compel access to retained data or intercept communications — that access is meant to run through defined procedures and designated authorities rather than being unrestricted. Whether those procedural safeguards are adequate has been a subject of genuine public debate and legal challenge in India, and this guide isn't taking a position on that debate — the point here is narrower: the CERT-In directive itself is about what a provider must be able to produce if lawfully asked, not a standing surveillance pipeline that operates independently of any request. For a VPN user, the practical concern is less "is the government watching me in real time" and more "does my provider now hold identity-linked records about me that didn't exist before, which could be produced later if a legal process requires it." That is a meaningfully smaller — but still real — change in privacy posture than a live monitoring system would represent.
What are the penalties if a VPN provider doesn't comply with the directive?
Section 70B of the IT Act, which is the legal basis for CERT-In's directions, attaches a specific penalty for non-compliance with a direction issued under it: imprisonment for a term that may extend to one year, a fine that may extend to a specified amount, or both, for the entity or individual who fails to comply. This is the general enforcement mechanism behind CERT-In's directions as a category, not a penalty invented specifically for VPN providers — the same section covers the other entities named in the broader 2022 directions, including data centers and cloud service providers.
In practice, for a VPN provider with no legal entity, staff, or assets in India, the realistic enforcement lever available to Indian authorities is narrower than for a company physically operating in the country — there is no straightforward mechanism to imprison an executive who has never set foot in India or seize assets that don't exist there. This asymmetry is part of why several providers concluded that removing physical India infrastructure while continuing to serve Indian customers from abroad was a workable position: it reduces the surface area within India's direct jurisdiction while still leaving the service available to users. Whether that position is durable long-term as regulatory approaches evolve is not something this guide can predict with confidence — it describes the situation as it has played out so far, not a permanent guarantee about how enforcement might change.
Is using a VPN suspicious or does it attract legal scrutiny in India?
Using a VPN in India is a common, mainstream activity — for remote work access to a corporate network, for securing a connection on public Wi-Fi, for accessing region-specific content libraries, and simply as a general privacy tool — and it is not, by itself, evidence of wrongdoing or a trigger for legal scrutiny. A large and growing share of internet users in India use a VPN for entirely ordinary, lawful reasons, and the software itself carries no special legal stigma.
What remains true in India, as in virtually every country, is that using a VPN does not make an otherwise illegal act legal. A VPN encrypting your traffic and masking your IP address has no bearing on the legality of what you do once connected. If an activity would be illegal under Indian law without a VPN — accessing content that is specifically banned, engaging in fraud, or violating another specific statute — routing it through a VPN does not change that underlying legal status. The regulatory conversation around CERT-In's directive is about what VPN providers must record about their subscribers as a matter of company-level compliance, not about creating new restrictions on what an individual is legally permitted to do online.
How does the CERT-In directive fit into India's broader data and surveillance rules?
The 2022 VPN-specific directive did not appear in isolation — it sits alongside a wider set of Indian laws and rules governing data, intermediaries, and government access to information, and understanding where it fits helps explain why it drew so much attention from privacy-focused companies specifically.
Section 69 of the IT Act already gives designated government agencies the power to intercept, monitor, or decrypt information on computer resources under specified circumstances related to national security, public order, and similar grounds, subject to procedural safeguards set out in accompanying rules. This power predates the 2022 CERT-In directive and applies broadly, not just to VPN providers.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 impose their own set of obligations on "intermediaries" more broadly — a category that can include a range of online service providers — around content takedowns, grievance officers, and in some cases traceability of message originators for certain large messaging platforms. Whether and how these rules interact with VPN providers specifically has been a subject of ongoing legal debate rather than a settled, universally agreed answer.
The Digital Personal Data Protection Act, 2023 is India's first comprehensive, dedicated data protection statute, establishing rules around how personal data of Indian residents may be collected, processed, and stored, along with obligations on entities designated as "significant data fiduciaries." Its rules and enforcement mechanics have continued to be worked out through subsequent rulemaking, and its relationship to sector-specific rules like the CERT-In VPN directive is still developing rather than fully codified in one unified place.
The practical point for a VPN user is this: the CERT-In directive is one piece of a larger, evolving regulatory picture around data in India, not a standalone, isolated rule. If you're trying to understand your overall privacy exposure as an internet user in India, a VPN's logging policy is one variable among several — it doesn't operate in a vacuum separate from these other frameworks.
Are VPNs used for streaming or torrenting a special legal risk in India?
VPN use for accessing geo-restricted streaming content is common worldwide, including in India, and by itself is generally treated as a contract or terms-of-service matter between a user and a streaming platform, not a criminal law issue. If you use a VPN to access a foreign version of a streaming catalog that's technically restricted to another country, the more likely consequence is the streaming service's own detection systems blocking the connection or, in some cases, the account being flagged — a private company enforcement action, not a legal proceeding.
Copyright infringement is a different matter and is treated more seriously under Indian law regardless of whether a VPN is involved. India has an established practice of courts issuing website-blocking orders — sometimes called "John Doe" or "Ashok Kumar" orders in Indian legal practice — against sites found to be facilitating copyright infringement, particularly around film and sports broadcast piracy, and internet service providers are directed to block access to the named domains. A VPN is one of the tools people commonly use to route around ISP-level blocking of a specific site, similar to how VPNs are used for that purpose in many other countries with comparable blocking regimes. Using a VPN to reach a blocked site does not change the underlying legal status of downloading or distributing copyrighted material without authorization — that remains a separate legal question governed by India's copyright law, independent of whatever tool was used to access the content.
What should businesses and remote workers in India know about VPN compliance?
Individuals using a personal VPN and organizations operating VPN infrastructure for business purposes face somewhat different considerations. A company that operates its own VPN servers or gateway — for example, to let employees connect securely to internal systems — may fall within the scope of entities CERT-In's broader 2022 directions describe, depending on the specifics of what the company operates and how it's classified, which is a determination worth making with actual legal counsel rather than guesswork, since the directive's language covering data centers, virtual private server providers, and cloud service providers alongside consumer VPN services creates real classification questions for some business setups.
For most remote workers, the practical situation is simpler: connecting to a company-provided VPN to access work systems is a routine, expected part of many jobs and carries no special legal risk tied to the CERT-In directive, which is aimed at the providers operating the infrastructure rather than individual employees using a VPN their employer has set up. Separately, some regulated industries in India — notably parts of the financial sector, under Reserve Bank of India data-localization guidance for payment systems data — have their own, distinct data-residency requirements that are unrelated to consumer VPN services but occasionally get conflated with them in casual discussion. If your organization handles regulated data categories, that's a separate compliance question from anything covered in this guide and worth addressing with a specialist directly.
How should the CERT-In directive change how you choose a VPN if you're in India?
If the CERT-In directive matters to you — because privacy and minimal data retention are a primary reason you want a VPN in the first place — there are several practical things worth checking on any provider you're considering, rather than assuming a "no-logs" badge on a homepage settles the question on its own.
Check the provider's current India server setup
Look at whether the provider still operates physical servers inside India, or has moved to virtual India-location servers hosted elsewhere. Providers that have made this shift usually explain it directly, often with a specific date, on a server-network or transparency page — that specificity is itself a reasonably good sign, since a vague claim with no detail is harder to verify than a dated, explained one.
Read the actual privacy policy, not the marketing summary
A provider's homepage will almost always say some version of "we don't log your activity." What matters more is what the full privacy policy says about compliance with India-specific regulations specifically, since a general no-logs claim and an India-specific regulatory compliance stance are two different statements, and a thorough provider will typically address both somewhere in its own documentation rather than leaving the India question implicit.
Look for independent no-logs audits
An independent audit of a provider's systems or source code doesn't retroactively cover new jurisdictional pressure that emerges after the audit's date, and it isn't a permanent guarantee — but a provider that has already submitted its infrastructure to outside verification has demonstrated a general willingness to be checked, which is a reasonable proxy for how seriously it treats its privacy claims more broadly. Note the audit's date and scope rather than treating "audited" as a permanent, unqualified badge.
Consider the provider's overall jurisdiction
A company's home country affects what legal obligations it operates under globally, separate from any single directive covering one market it happens to serve. This is why jurisdiction gets discussed as its own factor in VPN evaluations generally — it shapes the baseline legal environment the company answers to, independent of country-specific rules like CERT-In's.
Decide whether you actually need an India server location
If your reason for wanting a VPN has nothing to do with needing an Indian IP address specifically — for example, you mainly want to secure your connection on public Wi-Fi or access content available elsewhere — the India server question may be largely moot for your use case, and you can weigh a provider on its general privacy posture without needing to dig into its India-specific server arrangement at all.
None of this requires picking a provider based on a single feature checklist. It means treating "no logs" as a claim to verify against a provider's actual, current documentation rather than a fixed fact that's permanently true the moment you read it on a homepage — which, frankly, is good practice for evaluating any VPN provider's privacy claims, in any country, not just one specific to India.
How does India's approach compare to VPN rules elsewhere?
It can help to place India's situation on a general spectrum, without overstating the comparison. At one end, a small number of countries maintain outright or near-outright restrictions on VPN use for ordinary consumers, or require VPN services to be specifically licensed or government-approved before they can legally operate — commonly discussed examples include China's regulatory environment around unauthorized VPN services and the United Arab Emirates' restrictions tied specifically to VoIP-adjacent uses of VPNs. Countries in this category treat unauthorized VPN use itself, not just what's done with it, as a regulatory concern.
At the other end, many countries have no VPN-specific regulation at all — VPN use is legal by default and simply isn't addressed as its own category of law, with general laws about fraud, harassment, or copyright applying the same way whether a VPN was used or not.
India's situation sits closer to the second category but with a notable regulatory intervention layered on top: individual VPN use remains unrestricted and unlicensed, but the CERT-In directive imposes a specific, ongoing data-retention obligation on the provider side that doesn't exist in most VPN-friendly jurisdictions. That combination — legal for users, meaningfully more demanding for providers — is somewhat distinctive, and it's part of why India's rule gets discussed as its own specific case in VPN industry commentary rather than being grouped in with either a "banned" or a "no rules at all" bucket.
Other countries have taken yet another approach: rather than a licensing regime or a data-retention directive, some have pursued technical blocking of VPN protocols or specific VPN providers' infrastructure at the network level, which is a different mechanism again from either of the two approaches described above. The point of laying these out isn't to rank countries by how VPN-friendly they are — it's to make clear that "is a VPN legal here" and "how does this country regulate VPN providers" are two separate questions with two separate answers, and conflating them is where a lot of confusion about India's situation specifically comes from. India answers the first question with an unambiguous yes and the second with a specific, provider-facing rule that doesn't exist in most VPN-friendly countries — which is exactly the nuance this guide is trying to make clear rather than collapsing into a single headline answer.
Do free VPN apps in India carry any different risk under this rule?
The CERT-In directive doesn't distinguish between free and paid VPN services in its wording — the record-keeping obligation, where it applies, applies to a VPN service provider regardless of its pricing model. That said, the general privacy trade-offs that come with free VPN apps anywhere in the world are worth keeping in mind separately from the India-specific rule. A free VPN app has to fund its operations somehow, and business models built around aggregating and monetizing user data are more common among free consumer VPN apps than among established paid providers with a public no-logs commitment and a brand reputation to protect. That's a general caution about free VPN apps as a category, not something specific to the CERT-In directive — but it compounds the same underlying concern: if data retention and who can see your information is the reason you're thinking about India's VPN rules in the first place, a free app's own data practices are worth scrutinizing at least as closely as any single country's regulatory requirement.
What if I already have a VPN subscription — do I need to do anything?
If you're already using a VPN in India and it's working the way you expect — you can connect, your traffic is encrypted, and you're not experiencing unexplained blocks or disconnections — there's no action forced on you by the CERT-In directive itself, since the compliance obligation sits with the provider, not the subscriber. If data retention specifically is a concern for you, the two things worth doing are: checking your specific provider's current, dated statement on India server infrastructure and its India-specific privacy policy language (most providers that made changes publicized them, so this is usually a quick search on the provider's own site or support pages), and deciding whether that provider's current posture still matches what you originally signed up expecting. There's no requirement to switch providers, and no legal risk to you personally either way — it's purely a question of whether the specific privacy trade-offs of your current provider still line up with your own priorities.
Practical takeaway
Using a VPN in India is legal, and the existence of the CERT-In directive does not change that for ordinary users — there is no law against installing or using VPN software for privacy, security, or content access in India, and there's no indication that individual VPN users face legal scrutiny simply for using one. What the directive changed is the operating reality for VPN companies: a rule requiring five years of subscriber record retention pushed several privacy-focused providers to withdraw physical servers from India and, in some cases, serve Indian customers through virtual server locations hosted elsewhere instead. Whether that shift matters to you personally depends on how much weight you put on data retention specifically, and whether you need a genuine India-based IP address for a particular use case.
If you're in India and privacy is a priority, the useful move is checking a specific provider's current server setup and privacy policy for how it addresses India compliance directly — not assuming the question is settled by a general "no-logs" claim alone, and not assuming that any single article, including this one, is a permanent, unchanging record of a regulatory situation that continues to evolve.
Frequently asked questions
Is it illegal to use a VPN in India?
No. There is no Indian law banning VPN use for ordinary purposes such as privacy, security on public networks, or accessing region-specific content. Using a VPN does not, by itself, break any Indian law, and it is not evidence of wrongdoing on its own.
What is the CERT-In VPN rule from 2022?
In April 2022, India's Computer Emergency Response Team (CERT-In) issued a directive under Section 70B of the Information Technology Act requiring VPN providers serving Indian customers to register and retain specified subscriber records — including validated names, IP addresses, registration email, and contact details — for a minimum of five years, even after a customer cancels their subscription. It took effect in mid-2022 after a short extension to the original compliance deadline.
Why did some VPN companies remove their servers from India?
Several VPN providers said the CERT-In directive's record-keeping requirements conflicted with their global no-logs policies, and chose to withdraw physical servers from India rather than comply. Some replaced them with virtual servers — hardware physically located in another country, such as Singapore, configured to present an Indian IP address — so users can still select an India connection location inside the app.
Does using a VPN make illegal activity legal in India?
No. A VPN encrypts your connection and masks your IP address, but it has no effect on the legality of what you do while connected. If an activity is illegal under Indian law without a VPN — such as copyright infringement or accessing specifically banned content — it remains illegal with one.
Does the CERT-In directive apply to VPN providers based outside India?
This is legally unsettled. The directive is worded to cover providers "offering services in India," but enforcement against a company with no physical presence or legal entity in the country is widely considered difficult in practice. Many international providers have kept their global no-logs policies unchanged while removing physical India-based servers as a separate precaution. This is general information, not legal advice for a specific situation.
How can I tell if a VPN's India server is physical or virtual?
Check the provider's own server-network or transparency page, which typically discloses which locations are physical versus virtual and often gives a date for when a change was made. This detail can change over time as providers adjust infrastructure, so it is worth verifying directly with the provider's current documentation rather than relying on an older source.