Certain mandates to make VPN service providers retain logs may not work as planned. VPN service providers have a global footprint and their India presence is mainly focused on providing users in other countries to navigate the internet as a user from India. This is used predominantly by overseas Indians to browse OTT platforms in India.

A cybercriminal planning an attack in India would not necessarily need a VPN server in India. The attacker can use an overseas server or use any other compromised machines in India that are widely available to such criminals.

Forcing VPN service providers to retain logs may result in them packing up their India servers but they will continue to offer VPN services through their overseas servers and the issue largely remain unaddressed.

On the contrary, even if they start logging from their India servers, attackers can still use the overseas servers of VPN service providers which will remain outside the purview of Indian authorities.

Originally Published 24 May 2022

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.