Government Postpones Compliance Deadline for VPN Providers to Store, Share User Data to September 25

VPN service providers have been told to collect and store user information for five years or longer.

Advertisement
By Sourabh Kulesh | Updated: 28 June 2022 12:43 IST
Highlights
  • The first directive was issued on April 28
  • Time for generating capacity building for implementation sought
  • Non-compliance with the order may invite "punitive action"

The cybersecurity directives were to come into effect on June 28

Photo Credit: Unsplash/ Petter Lagson

The Indian Computer Emergency Response Team (CERT-In) appointed by the Ministry of Electronics and Information Technology has extended the implementation date of its April 28 order in which it asked virtual private network (VPN) providers to register and preserve user information for at least five years. Additionally, the compliance deadline for all government and private agencies to mandatorily report cybersecurity breach incidents to it within six hours of noticing them has also been pushed forward. The order, which was to come into force on June 28, will now become effective on September 25, 2022.

In a new directive issued on Monday, CERT-In said that it has taken into consideration the extension of timelines sought by VPN service providers as well as Micro, Small and Medium Enterprises (MSMEs) for enforcement of Cyber Security Directions of April 28, 2022 issued under sub-section (6) of section 70B of the Information Technology Act, 2000.

Data centres, Virtual Private Server (VPS) providers, Cloud Service providers, and Virtual Private Network Service (VPN Service) providers sought more time for validation of subscribers/customers. MSMEs sought more time for generating capacity building required for implementation of the cybersecurity directions. As mentioned, the compliance date for both these cybersecurity directives has been postponed to September 25, 2022.

Advertisement

In the directive issued in April, VPN service providers — alongside data centres, virtual private server (VPS) providers, and cloud service providers — were ordered to register and maintain accurate information of their services for five years or longer “as mandated by the law after any cancellation or the registration as the case may be”.

Advertisement

The user information mentioned includes “the valid names of subscribers, period of subscribing to the service, IPs allotted to and being used, email address and IP address as well as accurate time recorded during the registration, purpose of subscribing, validated address and contact numbers, and ownership pattern of the subscribers signing into the service.”

Furthermore, it was also directed that the service providers will have to present the information as called for by CERT-In — failing of which (or non-compliance with the order) may invite "punitive action" under sub-section (7) of the section 70B of the IT Act, 2000 and other laws as applicable.

Advertisement

CERT-In had also asked all government and private agencies, including Internet service providers, social media platforms, and data centres, to mandatorily report cybersecurity breach incidents to it within six hours of noticing them.


Is Poco F4 5G a new best-of contender under Rs. 30,000? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Sony WF-1000XM6 Price, Launch Timeline and Key Features Leaked
  2. Samsung Galaxy F70e 5G India Will Launch in India on This Date
  3. Samsung Galaxy S26, Galaxy S26+ Renders Leak Ahead of Launch
  4. Vivo Y21 5G, Vivo Y11d Visit Malaysia's SIRIM Website, Might Launch Soon
  5. Realme Buds Air 8 Review: Big on Features, but There's A Catch
  6. Sony Has Patented a PlayStation Controller Design Without Any Buttons
  7. Samsung Galaxy S26 Hits Geekbench With This Chipset, Specifications
  1. Scientists Discover Cosmic Clock in Zircon Crystals That Tracks Earth’s Landscape History
  2. NASA Confirms Axiom Mission 5 Private Astronaut Launch to ISS in Early 2027
  3. Mountain Climbing Indie Game Cairn Sells 200,000 Copies on PC, PS5 in 3 Days
  4. Sony WF-1000XM6 Price, Launch Timeline and Key Specifications Leaked
  5. Vivo Y21 5G and Vivo Y11d Listed on Malaysia's SIRIM Database, Might Launch Soon
  6. UK Watchdog Wants Google to Let Publishers Opt Out of AI Overviews
  7. Budget 2026: Government Proposes Penalties for Inaccurate Reporting of Crypto Assets
  8. Om Shanti Shanti Shantihi OTT Release Reportedly Revealed Online: What You Need to Know
  9. Cristina Kathirvelan Now Available for Streaming on Tentkotta and Aha Tamil
  10. Samsung Galaxy S26 Series Will Reportedly Support Google's Pixel-Exclusive Scam Detection Feature
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.