HomeNewsBusinessCERT-In to issue clarifications on controversial April 28 directions

CERT-In to issue clarifications on controversial April 28 directions

The April 28 directions stated that “virtual private server (VPS) providers”, “VPN service providers” will be required to maintain logs including names of customers, their IP addresses etc for a period of 5 years.

May 13, 2022 / 21:36 IST
Story continues below Advertisement
According to information available with Moneycontrol, the term “VPN service providers” will just apply for entities that provide ‘internet proxy liek services’ through the use of VPN technologies to general Internet subscribers.
According to information available with Moneycontrol, the term “VPN service providers” will just apply for entities that provide ‘internet proxy liek services’ through the use of VPN technologies to general Internet subscribers.

The Indian Computer Emergency Response Team (CERT-In) is set to come out with a clarification on the April 28 directions, with it likely to state that the rules of maintaining customer logs may not apply to enterprise and corporate virtual private networks.

The April 28 directions stated that “virtual private server (VPS) providers”, “VPN service providers” will be required to maintain logs including names of customers, their IP addresses etc for a period of 5 years. Since then, this mandate has raised privacy concerns and it has also been criticised by major VPN companies such as NordVPN, Surfshark and others.

Story continues below Advertisement

According to information available with Moneycontrol, the term “VPN service providers” will just apply for entities that provide ‘internet proxy liek services’ through the use of VPN technologies to general Internet subscribers. These recommendations and clarifications have still not been finalised, and are expected to be released in the coming days.

The clarifications are also likely to mandate that service providers, data centres and body corporates who do not yet have a physical presence in India will be required to designate a point of contact for liaising with CERT-In. Apart from that, CERT-In is expected to clarify that non-compliance of the April 28 directions which has been issued under Sec 70B of the IT Act 2000 will attract penal provisions of the same Act.

Earlier, VPN provider Surfshark’s legal department head Gytis Malinauskas had told Moneycontrol that the company has a strict no-logs policy, which implies that it does not collect or share customer browsing data or any usage information. In a tweet, Proton VPN said that India’s new VPN regulations are “an assault on privacy, and that it will continue maintaining its no-log policy”.