Is Using a VPN Legal in India?

Is Using a VPN Legal in India?

Elena Ross
October 4, 2026· 10 min read

Is a VPN legal in India? Ordinary personal use is permitted; the CERT-In directions examined here regulate covered organizations rather than prohibit individuals from installing a VPN. The practical question is who operates the service and what information that operator must retain, not simply whether the app has a VPN label; checked on October 4, 2026, this guide expands the India section of our overview of VPN laws across countries.[1][2]

Key Takeaways:

  • Individual citizens are excluded from these CERT-In directions; online conduct still has to be lawful.
  • Consumer VPN providers and internal corporate VPNs have different roles under the subscriber-record requirement.
  • Subscriber records and ICT system logs are separate obligations with different retention periods.
  • An overseas server, a foreign IP, or a no-logs slogan does not establish a provider's regulatory position.

For day-to-day SIM registration, payments and hotel connections, use the India digital travel guide; those operational checks are separate from provider obligations discussed here.

Is a VPN legal in India for personal use?

Yes: these directions do not create a general ban on personal VPN use. CERT-In's FAQ expressly separates individual citizens from the organizations covered by the directions. That answers the narrow question about this regulatory instrument; it does not exempt fraud, unauthorized access, or other unlawful activity because a connection travels through an encrypted tunnel.[2]

A VPN is a network tool that forwards traffic through a service or a private network. An employer may use it to reach internal systems, while a consumer service offers an alternative route to the public internet. Similar software can therefore support different arrangements, and its legal classification cannot be inferred from a screenshot of a connected status.

For you as a traveler, the useful starting point is the account and network you actually plan to use. Accessing your own email on an authorized hotel connection is a different task from operating a service for customers. Before connecting, check the accommodation's network policy and the destination service's terms; permission to use the software does not confer access rights to an account or system.

Who has obligations under the CERT-In VPN requirements?

The directions were issued on April 28, 2022 under section 70B(6) of the Information Technology Act. Their scope includes several categories of organization, with additional duties attached to particular services. The FAQ is official explanatory guidance, but explicitly says it does not replace or amend the law or rules.[1][2]

RoleSubscriber-record requirementPractical consequence
Individual citizen using a VPNNot covered by these directions as an individual citizenDo not treat organizational duties as a personal installation ban
Consumer VPN service providerThe specific requirement applies to the covered serviceCheck collection, retention, and disclosure information before subscribing
Enterprise or corporate internal VPNOutside the VPN-provider definition for that specific requirementThe company may still have general cybersecurity obligations

The corporate distinction is narrow. FAQ question 34 describes the relevant VPN service provider as an operator supplying internet-proxy-like services to general internet users. It excludes enterprise or corporate VPNs from that particular subscriber-registration direction, rather than exempting every company using a tunnel from the entire cybersecurity framework.[2]

An employee should therefore ask IT which connection is approved. A personal VPN subscription is not automatically an acceptable replacement for the employer's gateway, access controls, or incident procedures. If you run a business, the role table is a starting point for professional advice, not a compliance determination for your infrastructure.

What must providers retain, and for how long?

India VPN logging rules involve two different datasets. Direction (v) requires covered services to retain specified subscriber information for five years after cancellation or withdrawal of registration, or longer where another law mandates it. Direction (iv) separately requires covered organizations to keep ICT system logs securely for a rolling 180 days.[1]

Subscriber information is not just a browsing history

The prescribed fields are validated customer names; service-hire dates; assigned or used IPs; onboarding email, IP, and timestamp; purpose of hiring; validated address and contact numbers; and ownership details. These are identity and service records. Calling the whole list “every website visited for five years” adds a claim that this provision does not make.[1]

For a subscription decision, ask which entity holds each category and what happens when you close the account. A deletion button is not evidence that all legally required records disappear immediately. Equally, a retention duty does not by itself tell you every field an operator actually collects, how securely it stores it, or whether a particular request for disclosure is valid.

System logs have a separate clock

The original direction specifies a rolling 180-day log period and Indian jurisdiction. FAQ question 35 explains that logs may also be stored outside India provided the obligation to produce them to CERT-In within a reasonable time is met. Read both texts together instead of presenting the FAQ as a repeal of the direction or claiming all storage must occur exclusively in India.[1][2]

Log types depend on the systems and sector. Incident-response records and subscriber-registration information should be described separately in a privacy policy. For a corporate connection, ask the administrator about applicable logging rather than assuming the consumer-provider exception removes all records.

Does an overseas server remove the privacy questions?

No. A server location and an operator's obligations are different facts. The FAQ discusses services outside India and provision to Indian users; a foreign address alone is insufficient to decide the whole question. Do not infer either complete exemption or complete compliance from a location picker.[2]

A virtual location can describe the apparent IP country without showing where the machine, company, support staff, or records are situated. You need the provider's actual explanation of those arrangements. If the privacy policy and product description conflict, ask for clarification before submitting additional personal information or paying.

The same distinction helps when comparing Saudi Arabia's conduct-based legal risks. India's provider-record discussion should not be exported as a universal VPN rule. Each jurisdiction needs its own sources, actors, and conditions.

A no-logs statement also needs a defined scope. Activity logs, account information, billing records, and incident records are not interchangeable categories. An app cannot promise away a binding legal duty; this guide does not certify any provider's compliance or establish anonymity.

How can travelers use an authorized public connection?

On an Indian hotel or airport network, complete the legitimate Wi-Fi sign-in before expecting a tunnel to work. Verify the network name with staff, keep HTTPS enabled, and stop if a portal asks you to install an unexpected certificate or disclose unrelated account credentials. These are practical precautions for your connection, not a finding about any particular Indian venue.

For personal account access during a trip, AethoVPN offers an Android APK and a Windows installer. After joining an authorized network, choose from the app's currently available locations, connect, and check the observed exit IP before using your own accounts. This helps establish the network route; it does not resolve CERT-In retention duties, account eligibility, or permission to access a restricted service.

You can create an account with an email verification code; registration does not require setting a password. Evaluate the route on the network you will actually use, rather than assuming a successful connection elsewhere proves availability at your destination.

If a bank rejects the connection, use its approved support route instead of repeatedly switching countries to obtain a login. A changed exit IP can trigger security checks, and it does not change your residence or customer identity. The VPN fundamentals guide explains the network mechanism, while the hotel Wi-Fi safety checks cover the local connection layer.

What should you check before subscribing or connecting?

Keep the purchase decision tied to evidence you can obtain. Ask the provider for its operating entity, the distinction between subscriber records and activity logs, retention after cancellation, and any limits on supported locations. Do not upload identity documents to an unofficial support message simply because somebody describes the request as a regulatory requirement.

For work access, get approval from the employer and retain its contact instructions. For personal access, make sure the account and activity are permitted and preserve an alternative connection for essential tasks. If a service cannot explain a material privacy question, pause that use rather than treating the existence of a VPN app as reassurance.

Availability is another separate check. A connection failure can come from a captive portal, device configuration, or the network path; it does not prove a new national law. Likewise, a connected indicator does not prove privacy, legal permission, or successful access to the destination account.

The UAE criminal-purpose IP provision and Turkey access-provider duties illustrate why installation, operators, and conduct need separate analysis rather than one worldwide rule.

Summary

  • Personal use and the obligations of a consumer VPN operator are distinct questions.
  • Separate five-year subscriber records from rolling 180-day ICT logs.
  • The corporate VPN exception is specific, not a blanket corporate exemption.
  • Verify the account, network permission, privacy explanation, and actual route before relying on a travel connection.

FAQ

Is a VPN legal in India for tourists?

Ordinary personal VPN use is not prohibited by the CERT-In directions examined here. Tourists still need lawful account access, permitted online conduct, and compliance with the network's terms.

Must individual users keep five years of VPN records?

The subscriber-record duty is imposed on covered providers, not individual citizens using a VPN. A provider may hold information about you, which is a separate privacy consideration.

Do corporate VPNs have the same subscriber-registration duty?

The FAQ excludes enterprise or corporate VPNs from that specific VPN-provider definition. A company may still owe general logging, incident-response, and other duties applicable to its role.

Do the directions require every browsing page to be stored for five years?

The five-year provision lists subscriber and service information, not a universal list of every visited page. ICT logging is a separate obligation, so examine the operator's actual policies.

Can I assume a foreign server is exempt?

A foreign server alone does not establish the operator's legal position or data practices. Check the entity, service arrangement, and policy rather than relying only on the IP country.

Does deleting my VPN account erase retained records immediately?

Deletion need not remove records that a covered provider must retain after cancellation. Ask which information is deleted and which remains subject to a legal retention duty.

Does a working VPN prove that my activity is lawful?

A working tunnel demonstrates a connection, not legal permission for the activity or account. Verify the applicable rules and seek qualified advice when the intended use is uncertain.

Disclaimer: VPN regulations vary by country and region and are subject to change. This article does not constitute legal advice. Please review and comply with your local laws before using a VPN.

Sources

  1. CERT-In — Directions under section 70B(6), 28 April 2022
  2. CERT-In — FAQs on Cyber Security Directions, May 2022

Sources checked 4 October 2026.

Related Articles

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Is Using a VPN Legal in India? | AethoVPN