On July 3, 2026, MediaNama reported that India is preparing a new law to regulate VPN providers, because officials believe the 2022 CERT-In rules never achieved what they set out to do. Nothing is official yet, no draft, no notification, but the direction is worth understanding, especially if you rely on a VPN in India.

Why the 2022 rules failed

Back in 2022, India’s Computer Emergency Response Team (CERT-In) issued a directive ordering VPN providers with servers in India to log user data (names, email IDs, IP addresses, usage patterns) and keep it for at least five years, even after a customer cancels. For a no-logs VPN, that is a contradiction in terms. You cannot promise to keep no logs and simultaneously store five years of user records.

So the major providers did the obvious thing: they left. ExpressVPN, NordVPN, Surfshark and Private Internet Access pulled their physical servers out of India entirely. They now serve Indian users through “virtual India servers,” physical machines sitting in Singapore, the UK or the Netherlands that hand you an Indian IP address while keeping the data outside Indian jurisdiction.

That workaround is exactly why officials now consider the 2022 directive a failure. It pushed the servers offshore without giving the government the data leverage it wanted. Users kept their Indian IPs, providers kept their no-logs promises, and the rule missed.

What the new proposal reportedly wants

According to the July 2026 report, the framework being considered would try to close that gap by targeting the companies rather than just the servers. The reported measures include requiring VPN providers to open an office in India, appoint compliance officers as points of contact for government requests, and designate officials to handle government grievances.

The logic is clear. If a provider has a legal presence and named officers inside the country, the government has someone to compel, regardless of where the servers physically sit. It is a shift from “regulate the hardware” to “regulate the company.”

Important caveat: no official draft law, notification or public government announcement has been released. This is a report about a proposed framework, not a passed law. It could change substantially or stall.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Yes. Despite the headlines, the government has not banned VPNs, and using one in India remains legal. The proposals are about how providers operate, not about criminalizing the tool. This matters, because “India VPN ban” gets searched a lot and the premise is wrong. Our best VPN for India guide covers the providers that still serve the country well.

The real question for a privacy-minded user is not legality. It is jurisdiction: whose laws can reach your provider, and whether your provider is structured to have nothing useful to hand over.

What it means for your choice

If a provider is forced to open an Indian office and appoint compliance officers, it faces a decision: comply with local data demands, or refuse and risk that presence. The providers that already left in 2022 chose to keep no Indian footprint precisely so they could keep saying no. A provider based in a privacy-friendly jurisdiction, running a genuine no-logs policy, with no legal presence to compel, is the strongest position for a user who wants to stay out of reach.

Proton VPN, based in Switzerland and open source, scores 4.24/5 in our comparison and has no incentive to build data-collecting infrastructure in India. NordVPN, headquartered in Panama at 4.63/5, was one of the providers that removed its Indian servers in 2022 rather than log users. Both offer Indian IPs through virtual servers hosted abroad. Our jurisdiction guide explains why the country a VPN answers to matters as much as its encryption.

The bigger picture

India’s move fits a global pattern of governments trying to pull VPN providers into their legal reach, from the EU’s data-retention debates to age-verification laws across the West. The providers that survive these pushes with their privacy intact are the ones built to collect nothing and hold no assets in the jurisdictions doing the compelling.

For now, nothing has changed for Indian users on a practical level. VPNs are legal, the major no-logs providers still work through virtual servers, and no new law exists. Watch for an actual draft. Until then, the smart position is a provider that is audited, no-logs, and based somewhere with no mandatory retention.

Our verdict

India's reported new VPN law targets companies, not servers, aiming to force local offices and compliance officers so the government has someone to compel. It is a proposal, not a passed law, and VPNs remain fully legal in India. The takeaway for users is unchanged: pick an audited no-logs provider based outside India with no local presence to lean on. Proton VPN and NordVPN both fit, and both already serve Indian IPs from servers held abroad.