India VPN servers and the 2022 CERT-In directive
CERT-In's April 2022 direction requires VPN providers serving Indian users to retain subscriber records, including allocated addresses, for five years. Several international providers responded by removing their physical servers from India altogether and offering virtual Indian locations hosted in a neighbouring country instead.
4 min read
India is the clearest recent example of retention law reshaping where VPN infrastructure physically sits, and it is worth understanding because the pattern is likely to recur elsewhere.
What the direction requires
In April 2022, CERT-In — India's national computer emergency response team — issued directions under section 70B(6) of the Information Technology Act. Among other obligations, VPN providers, data centres and cloud service providers serving Indian users must register and retain subscriber information for five years, including names, addresses, contact details, the period of hire and the addresses allocated to or used by the subscriber.
Five years is a long retention period by any international standard, and the categories are precisely the ones a no-logs policy would ordinarily exclude.
What providers did
Several large international providers publicly removed their physical servers from India rather than comply, and began offering "virtual" Indian locations: addresses registered in India, announced from hardware in a neighbouring jurisdiction, most often Singapore.
That is a legitimate engineering response and it has consequences worth knowing:
- The jurisdiction governing the server is not India. Whatever the address suggests.
- The latency is that of the real location, so an Indian virtual location hosted in Singapore costs the round trip to Singapore.
- Services performing a geolocation lookup still see India, because the address is registered there. Services performing their own network analysis may not.
How to tell which you have
Latency answers it. A round trip from Mumbai to a genuinely Indian server should be well under 30 milliseconds. A round trip of 60 to 90 milliseconds is consistent with Singapore.
That check is the only reliable one available to a user, and it is worth running on any Indian location before assuming anything about the jurisdiction your traffic is subject to.
The broader legal picture
India's Digital Personal Data Protection Act 2023 establishes a general data protection framework, with obligations on data fiduciaries and rights for data principals. It coexists with the CERT-In directions rather than displacing them.
Filtering exists and is applied through directions to internet service providers, and its scope has varied over time and by state.
What this means practically
If you are in India and want the lowest latency, an Indian location matters and its physical reality matters more. Check the latency.
If you are outside India and want an Indian origin for a service that checks geolocation, a virtual location generally works and the jurisdiction question is moot for that purpose.
If jurisdiction is your concern, an Indian location — real or virtual — is one to understand carefully rather than pick by default.
Where VPNmine stands
VPNmine lists India in its region set. The honest thing to say about any provider's Indian presence is that the physical location and the legal obligations that follow from it are the questions worth asking, and that the latency check above is how a user verifies the answer independently.
The privacy policy states what is recorded generally, and the India page covers the country's network environment.
Why the direction was contentious
Two objections were made repeatedly at the time. The first was the retention period: five years is far longer than comparable regimes, and it applies to categories of data that a privacy-focused service exists specifically not to hold.
The second was scope. The directions cover VPN providers, data centres, cloud providers and virtual private server providers, which is a broad definition capturing services with very different relationships to their users. Corporate VPNs operated by an enterprise for its own staff were carved out, but the consumer category was squarely included.
The regulator's stated rationale was incident response: attributing cyber incidents requires knowing who was behind an address at a given time, and that attribution fails when an intermediary keeps no records.
That is a coherent position, and it is genuinely in tension with what a no-logs VPN is. Both things can be true.
What it means for Indian users specifically
If you are in India, the practical situation is that domestic providers comply and several international ones have no hardware in the country. Neither of those is hidden — compliant providers say so, and providers using virtual locations generally document it, though not always prominently.
The useful habit is the latency check described above, run once, on any Indian location you rely on. It takes ten seconds and it answers a question that no amount of reading marketing pages will.
The wider pattern
India is not unique in direction, only in the length of the retention period. Several jurisdictions have moved toward obligations on intermediaries in recent years, and the industry response — withdrawing hardware and offering virtual locations — is now a standard playbook.
Expect to see it again, and expect the latency check to remain the way to tell.