Moneycontrol PRO
HomeNewsBusinessCERT-In sends notices to VPN companies on compliance with cybersecurity directions

CERT-In sends notices to VPN companies on compliance with cybersecurity directions

Last year's CERT-In directions mandated service providers including those offering virtual private networks (VPN) to maintain customer logs for a period of 5 years

May 16, 2023 / 09:48 IST
The Indian Computer Emergency Response Team is the nodal agency under Ministry of Electronics and Information Technology to deal with cyber security threats like hacking and phishing.

In the latest conflagration between the Indian government and VPN service providers, the Indian Computer Emergency Response team sent notices to such companies inquiring about compliance to the cybersecurity guidelines the government released in April 2022.

The nodal body for cybersecurity under the Ministry of Electronics and Information Technology sent these notices to VPN service providers in February.

"The response received from entities are under examination, hence, at this stage there is no issue regarding blocking on blocking or initiation of any other proceeding as a result of non-compliance," response to an RTI filed with the Department of Electronics and Information Technology by Internet Freedom Foundation (IFF) showed.

In another RTI, the department clarified the notices it had sent were restricted to VPN service providers and not any other service providers, body corporate, or government organisations.

Howevevr, CERT-In responses to the RTIs did not include any specifics to IFF's queries on the total number of compliance notices that were issued; the list of entities to whom such notices were served; or the timeframe for compliance and the consequences of non-compliance.

Last year's CERT-In directions mandated service providers including those offering virtual private networks (VPN) to maintain logs including IP addresses used to register for the VPN, IP addresses used to connect to VPN servers in India, and list of IP addresses issued for each customer for a period of five years.

This requirement earned the ire of VPN companies, who, while vowing non-compliance removed their servers from India in protest.  Such companies include Switzerland-based Proton, Netherlands-based Surfshark, Express VPN, and Panama-based NordVPN.

Moneycontrol has reached  out to these companies on whether they have received notices from CERT-In regarding compliance with the cybersecurity directions, and the article will be updated when a response is received.

The CERT-In directions are also facing a legal challenge, with Delhi High Court on September 28, 2022 issuing a notice to the Union government in response to a petition that argued that the directions was unconstitutional and it violated privacy of citizens.

Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
first published: May 16, 2023 09:41 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347
CloseOutskill Genai