Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Is a VPN legal in India? Ordinary personal use is permitted; the CERT-In directions examined here regulate covered organizations rather than prohibit individuals from installing a VPN. The practical question is who operates the service and what information that operator must retain, not simply whether the app has a VPN label; checked on October 4, 2026, this guide expands the India section of our overview of VPN laws across countries.[1][2]
Key Takeaways:
- Individual citizens are excluded from these CERT-In directions; online conduct still has to be lawful.
- Consumer VPN providers and internal corporate VPNs have different roles under the subscriber-record requirement.
- Subscriber records and ICT system logs are separate obligations with different retention periods.
- An overseas server, a foreign IP, or a no-logs slogan does not establish a provider's regulatory position.
For day-to-day SIM registration, payments and hotel connections, use the India digital travel guide; those operational checks are separate from provider obligations discussed here.
Yes: these directions do not create a general ban on personal VPN use. CERT-In's FAQ expressly separates individual citizens from the organizations covered by the directions. That answers the narrow question about this regulatory instrument; it does not exempt fraud, unauthorized access, or other unlawful activity because a connection travels through an encrypted tunnel.[2]
A VPN is a network tool that forwards traffic through a service or a private network. An employer may use it to reach internal systems, while a consumer service offers an alternative route to the public internet. Similar software can therefore support different arrangements, and its legal classification cannot be inferred from a screenshot of a connected status.
For you as a traveler, the useful starting point is the account and network you actually plan to use. Accessing your own email on an authorized hotel connection is a different task from operating a service for customers. Before connecting, check the accommodation's network policy and the destination service's terms; permission to use the software does not confer access rights to an account or system.
The directions were issued on April 28, 2022 under section 70B(6) of the Information Technology Act. Their scope includes several categories of organization, with additional duties attached to particular services. The FAQ is official explanatory guidance, but explicitly says it does not replace or amend the law or rules.[1][2]
| Role | Subscriber-record requirement | Practical consequence |
|---|---|---|
| Individual citizen using a VPN | Not covered by these directions as an individual citizen | Do not treat organizational duties as a personal installation ban |
| Consumer VPN service provider | The specific requirement applies to the covered service | Check collection, retention, and disclosure information before subscribing |
| Enterprise or corporate internal VPN | Outside the VPN-provider definition for that specific requirement | The company may still have general cybersecurity obligations |
The corporate distinction is narrow. FAQ question 34 describes the relevant VPN service provider as an operator supplying internet-proxy-like services to general internet users. It excludes enterprise or corporate VPNs from that particular subscriber-registration direction, rather than exempting every company using a tunnel from the entire cybersecurity framework.[2]
An employee should therefore ask IT which connection is approved. A personal VPN subscription is not automatically an acceptable replacement for the employer's gateway, access controls, or incident procedures. If you run a business, the role table is a starting point for professional advice, not a compliance determination for your infrastructure.
India VPN logging rules involve two different datasets. Direction (v) requires covered services to retain specified subscriber information for five years after cancellation or withdrawal of registration, or longer where another law mandates it. Direction (iv) separately requires covered organizations to keep ICT system logs securely for a rolling 180 days.[1]
The prescribed fields are validated customer names; service-hire dates; assigned or used IPs; onboarding email, IP, and timestamp; purpose of hiring; validated address and contact numbers; and ownership details. These are identity and service records. Calling the whole list “every website visited for five years” adds a claim that this provision does not make.[1]
For a subscription decision, ask which entity holds each category and what happens when you close the account. A deletion button is not evidence that all legally required records disappear immediately. Equally, a retention duty does not by itself tell you every field an operator actually collects, how securely it stores it, or whether a particular request for disclosure is valid.
The original direction specifies a rolling 180-day log period and Indian jurisdiction. FAQ question 35 explains that logs may also be stored outside India provided the obligation to produce them to CERT-In within a reasonable time is met. Read both texts together instead of presenting the FAQ as a repeal of the direction or claiming all storage must occur exclusively in India.[1][2]
Log types depend on the systems and sector. Incident-response records and subscriber-registration information should be described separately in a privacy policy. For a corporate connection, ask the administrator about applicable logging rather than assuming the consumer-provider exception removes all records.
No. A server location and an operator's obligations are different facts. The FAQ discusses services outside India and provision to Indian users; a foreign address alone is insufficient to decide the whole question. Do not infer either complete exemption or complete compliance from a location picker.[2]
A virtual location can describe the apparent IP country without showing where the machine, company, support staff, or records are situated. You need the provider's actual explanation of those arrangements. If the privacy policy and product description conflict, ask for clarification before submitting additional personal information or paying.
The same distinction helps when comparing Saudi Arabia's conduct-based legal risks. India's provider-record discussion should not be exported as a universal VPN rule. Each jurisdiction needs its own sources, actors, and conditions.
A no-logs statement also needs a defined scope. Activity logs, account information, billing records, and incident records are not interchangeable categories. An app cannot promise away a binding legal duty; this guide does not certify any provider's compliance or establish anonymity.
On an Indian hotel or airport network, complete the legitimate Wi-Fi sign-in before expecting a tunnel to work. Verify the network name with staff, keep HTTPS enabled, and stop if a portal asks you to install an unexpected certificate or disclose unrelated account credentials. These are practical precautions for your connection, not a finding about any particular Indian venue.
For personal account access during a trip, AethoVPN offers an Android APK and a Windows installer. After joining an authorized network, choose from the app's currently available locations, connect, and check the observed exit IP before using your own accounts. This helps establish the network route; it does not resolve CERT-In retention duties, account eligibility, or permission to access a restricted service.
You can create an account with an email verification code; registration does not require setting a password. Evaluate the route on the network you will actually use, rather than assuming a successful connection elsewhere proves availability at your destination.
If a bank rejects the connection, use its approved support route instead of repeatedly switching countries to obtain a login. A changed exit IP can trigger security checks, and it does not change your residence or customer identity. The VPN fundamentals guide explains the network mechanism, while the hotel Wi-Fi safety checks cover the local connection layer.
Keep the purchase decision tied to evidence you can obtain. Ask the provider for its operating entity, the distinction between subscriber records and activity logs, retention after cancellation, and any limits on supported locations. Do not upload identity documents to an unofficial support message simply because somebody describes the request as a regulatory requirement.
For work access, get approval from the employer and retain its contact instructions. For personal access, make sure the account and activity are permitted and preserve an alternative connection for essential tasks. If a service cannot explain a material privacy question, pause that use rather than treating the existence of a VPN app as reassurance.
Availability is another separate check. A connection failure can come from a captive portal, device configuration, or the network path; it does not prove a new national law. Likewise, a connected indicator does not prove privacy, legal permission, or successful access to the destination account.
The UAE criminal-purpose IP provision and Turkey access-provider duties illustrate why installation, operators, and conduct need separate analysis rather than one worldwide rule.
Ordinary personal VPN use is not prohibited by the CERT-In directions examined here. Tourists still need lawful account access, permitted online conduct, and compliance with the network's terms.
The subscriber-record duty is imposed on covered providers, not individual citizens using a VPN. A provider may hold information about you, which is a separate privacy consideration.
The FAQ excludes enterprise or corporate VPNs from that specific VPN-provider definition. A company may still owe general logging, incident-response, and other duties applicable to its role.
The five-year provision lists subscriber and service information, not a universal list of every visited page. ICT logging is a separate obligation, so examine the operator's actual policies.
A foreign server alone does not establish the operator's legal position or data practices. Check the entity, service arrangement, and policy rather than relying only on the IP country.
Deletion need not remove records that a covered provider must retain after cancellation. Ask which information is deleted and which remains subject to a legal retention duty.
A working tunnel demonstrates a connection, not legal permission for the activity or account. Verify the applicable rules and seek qualified advice when the intended use is uncertain.
Disclaimer: VPN regulations vary by country and region and are subject to change. This article does not constitute legal advice. Please review and comply with your local laws before using a VPN.
Sources checked 4 October 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.