India Orders VPN Companies to Collect and Hand Over User Data

  • Thread starter Thread starter minuteman
  • Start date Start date
  • Replies Replies 182
  • Views Views 17,408
On Reddit a user asked Nord who said they will discontinue their Indian nodes/server to begin with. I reached out to NORD VPN

I think this is just the beginning and will eventually lead to a VPN ban given that back in Oct '21 a parliamentary comnittee comprising of worthies from different parties had suggested a ban. As I said before, Govt of India rule of the thumb is "If you can't control, it ban it". What's next? Restrict internet access? The Great Firewall of India?
 
Last edited:
oh well, dictators are all over the world including the West. I guess you have heard of what the 5 Eye, 9 Eye and 14 Eye countries, the so called torch bearers of freedom, free speech etc, etc, do to surveil their own citizens and of course foreign subjects or Governments. :) Take a look 5-Eyes, 9-Eyes, and 14-Eyes agreement explained Most major VPNs are owned directly or indirectly by companies based in these countries. Even if the registered office of the VPN is innocuously located in some tropical paradise island in the Caribbean.
 
You are free to buy a rack space in Switzerland and set up your own server with secure boot, own encryption protocols, and even keep the server caged physically under lock and key. Can the same be said for China or in future India?
Dictators exist. That’s true. But rights and freedoms also exist with legal mechanisms to prevent such dictators from overriding it. That’s where other countries lack. Of course such a private rack space doesn’t give you immunity. If the authorities want to search it, they can under court orders and warrants, and you will be legally obliged to cooperate. But it won’t happen behind your back. That’s the difference.
 
Frankly even if were to set up a PVS in Switzerland, at a substantially higher cost than what I pay for my plain ol' VPNs of course, I would have to follow their rules i.e T&C of service. And most service providers do not take kindly to abuse of their systems that include incidents covered in the MEITY/CERT-In notice. I know for sure if anybody were to indulge in those activities, the VPS/VPN and other service providers would themselves willingly throw a customer under the bus and disclose the information to law enforcement and other authorities provided the Indian Govt. jumps through the hoops and gets a court order from the legal system of that country. for e.g. let me quote from a Swiss provider here:

Do we disclose any information to outside legal parties?
We will not disclose any information that we collect or that is entrusted to us to any attorneys, law firms, courts, or law enforcement agencies unless otherwise presented with an official court order executed by a judge or magistrate within the Swiss Confederation.

This sounds quite similar to what is done at Swiss banks

Net, net, we as users are not 100% anonymous. If the crime is serious it can probably be traced given enough time, effort and determination. The immediate impact of this notice will be all VPNs asking for KYC info from Indian customers. To give you an example, back in Feb, Surfshark asked for my PAN for a renewal of my subs! I was like WTF!! When I contacted their Support via chat they said it is mandatory for customers from India. I chose to continue my biz with PIA and renewed that instead. But it's beginning to make sense now. It's only a matter of time before other VPNs ask for this information.
 
Here's what ProtonVPN, based in Switzerland and whose services I have subbed to says:

Using VPN servers in high-risk countries

Quoting from that page:

Leave countries rather than compromise our values

We expect that in some high-risk countries, law enforcement or intelligence agencies may exert pressure on our infrastructure providers to monitor network traffic upstream of our servers. In the US, for example, ISP monitoring and NSA data collection is the default on almost all Internet connections. Since our Secure Core architecture reduces the amount of information that these agencies can collect through this type of surveillance, they may try to force ProtonVPN to log the online activity on our servers. If this situation arises, we will shut down our server and withdraw from the country in question, instead of compromising our values or our strict no-logs policy.

So I expect them and other VPNs to stop operating nodes/servers in India at some point in the future if the Govt presses the issue.
 
Just be prepared, in the future you'd be required to perform KYC just to open a social media account, India is not very far from being the next China.
 
i mean government is basically asking VPN services to become we-add-lag-to-your-network-while-keeping-a-record-of-everything service. so what's the option?
 
Back