India Is Weighing New Rules That Could Force VPN Providers to Open Up to Investigators

India's government is reportedly working on a plan that would tighten the screws on VPN providers operating in the country — this time by requiring them to appoint dedicated compliance officers who'd work directly with law enforcement and CERT-In, the country's cyber emergency response team.

The idea, according to officials cited in Indian media, is to give investigators a faster, clearer channel into VPN companies when they're chasing cybercrime cases — ransomware, financial fraud, phishing, that sort of thing. Right now, tracking down who's behind an attack gets complicated fast when VPNs are involved, and the government wants a designated point of contact at each provider who can respond quickly to lawful requests.

The proposed structure borrows heavily from India's 2021 intermediary rules for social media platforms, which require a chief compliance officer, a round-the-clock contact person, and a grievance officer. Officials say applying something similar to VPN companies would close what they see as an accountability gap — especially for providers serving Indian users while operating entirely from abroad.

This builds on rules CERT-In already put in place back in 2022, which require VPN providers, cloud services, and data centers to hold onto subscriber details — names, addresses, IP addresses, how long someone used the service — for at least five years. Those rules triggered pushback at the time; several major VPN companies, ExpressVPN among them, responded by pulling their physical servers out of India entirely and switching to virtual servers based elsewhere, specifically to avoid falling under the data retention requirement.

Officials are framing this new push as being about cybercrime investigations, not blanket surveillance of ordinary users. Whether that distinction holds up in practice is exactly the kind of thing privacy advocates and VPN providers pushed back on last time — and given the history here, it's a safe bet they'll do it again. Nothing is finalized yet. This is still at the proposal stage, and there's no confirmed timeline for when — or if — it becomes an actual rule.