Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.
Every guide to this question closes with the same reassurance: India’s rules target VPN companies, not the people who use them. That sentence is accurate as a description of the national directive. It is also incomplete, and the missing part matters more than the part everyone repeats.
Since May 2025, district magistrates across Jammu and Kashmir have issued their own prohibitions on VPN use — and police have detained people for having the apps installed. No national law was amended to allow this. A colonial-era public-order provision was used instead.
So the honest answer has two halves. Nationally, using a VPN in India carries no penalty at all. Locally, in a handful of districts, it has carried one.
Is a VPN Legal in India?
Yes. No Indian statute criminalises downloading, installing or using a VPN for a lawful purpose. There is no licence, no registration and no fine for having the app. The 2022 CERT-In directive that changed the market imposes duties on providers, not subscribers. The exception is district-level orders in Jammu and Kashmir, which prohibit use directly.
What the Law Actually Says, and Whom It Binds
The document behind every headline is CERT-In direction No. 20(3)/2022, issued on 28 April 2022 under Section 70B(6) of the Information Technology Act and in force from 27 June that year.
It requires covered providers to keep subscriber records for five years, including names, the period of service, IP addresses allotted, the email address and timestamp used at sign-up, the stated reason for using the service, and verified contact details. Those records must survive five years past cancellation. Providers must also report cybersecurity incidents within six hours and retain certain system logs inside Indian jurisdiction.
Every one of those obligations lands on the company. None of them creates an offence for the person paying the subscription — unlike China, where the implementing rules name the individual directly. That distinction is real, and it is why the reassurance in most guides is worded the way it is.
Corporate networks were carved out explicitly. A VPN run by an employer for internal access falls outside the directive, which is why remote-work setups continued unchanged while consumer providers packed up. For an idea of what these rules do and do not conceal in the first place, what a VPN actually hides covers the mechanics.

The Part Most Guides Leave Out
On 2 May 2025, the District Magistrate of Doda in Jammu and Kashmir prohibited VPN use across the district for two months. The order came days after the Pahalgam attack and covered individuals, institutions, cyber cafés and internet service providers alike. Its legal basis was Section 163 of the Bharatiya Nagarik Suraksha Sanhita — the successor to the old Section 144, a general public-order power rather than anything written for the internet.
Two weeks later, district police confirmed that several people had been detained for using VPNs to get around local restrictions, and said questioning was continuing.
The orders then spread. In late December 2025, Doda police booked two men for running VPN apps in breach of the magistrate’s order, and comparable prohibitions were issued in Shopian, Kulgam, Pulwama, Rajouri and Kupwara. Reporting at the time described security personnel checking handsets for VPN software.
Lawyers were sharply critical. Supreme Court senior advocate Nitya Ramakrishnan described the provision as granting “blanket and unguided power” to the executive. Advocate-on-record Talha Abdul Rahman argued that the IT Act and its rules already cover this ground entirely, leaving no room for a public-order provision to prohibit VPNs at all.
⚠️ None of that changes the practical position for someone standing in Doda. A contested order is still an order until a court says otherwise. If you are in a district with one in force, the answer is to comply with it — not to look for a way around it. Our general legality guide sets out how this pattern repeats elsewhere, and Turkey’s law shows the opposite arrangement, where obligations fall on providers and stay there.
April 2026: The Demand Changed Shape
The 2022 directive asked providers for records. The newest instruction asks them for something else entirely.
On 25 April 2026, MeitY’s Cyber Laws Division issued an advisory telling VPN services and other intermediaries to stop enabling access to blocked betting and prediction-market platforms, naming Polymarket among them. It leaned on the Promotion and Regulation of Online Gaming Act, 2025, which prohibits real-money online gaming in every form. India had blocked more than 8,300 gambling and betting sites by late March 2026, and a formal blocking order against Polymarket followed on 21 May.
The consequence for a non-compliant provider is loss of safe harbour under Section 79 of the IT Act — the protection that stops an intermediary being treated as the publisher of what passes through it. That is a commercial threat aimed at companies, and again not a penalty aimed at subscribers.
⚠️ But notice what compliance would require. Logging is passive: a company records what already flows through its systems. Blocking is active: it means inspecting traffic and deciding what to let through. A provider that can do the second has built the capability it spent years promising it lacked. Whether any provider actually complies is the thing worth watching over the next year.
What the Law Does Not Do
Four things are worth stating plainly, because the volume of coverage around this topic tends to blur them.
There is no licence. Nothing requires you to register a VPN, declare one, or seek permission before installing it.
Possessing the app is not an offence anywhere in India outside the districts described above.
Employer VPNs are outside the directive by its own terms.
Illegal acts stay illegal, which is the one rule every jurisdiction shares — the UAE builds its entire framework on it. A VPN changes nothing about the underlying conduct — fraud, piracy and accessing platforms blocked under Section 69A carry the same consequences whether or not traffic was encrypted. Enforcement to date has concentrated on platforms, ISPs and providers rather than individuals, though the legal exposure exists.
| Country | What the rule aims at | Reaches the user? |
|---|---|---|
| Turkey | The tunnel — ISPs must block | No |
| The UAE | Conduct behind an address | No |
| India | The provider's records | Not nationally |
| China | Provider, tunnel and user | Yes |
| Brazil | Nothing, until a court acts | For 39 days |
| Indonesia | Paperwork — registration | No |
| The UK | The destination you visit | No, and ministers said so |
| The US | The platform, state by state | No, in all twenty-seven |
| Russia | The search, not the tool | Only if you went looking |
| Australia | The platform, and the tunnel itself | No — platforms must detect it |
| France | The VPN provider itself | No, the orders bind five companies |
| Italy | The provider, by regulator order | No, but one VPN left the market |
| Spain | The provider, by injunction without a hearing | No, and only two firms were named |
| Germany | The provider's logfile, for three months | No, and the courts twice removed it |
⚠️ This is general information about published rules, not legal advice. Orders at district level change on short notice and are not always easy to find. If your situation is specific, ask someone qualified in Indian law.

Why Your VPN No Longer Has Servers in India
The market answered the 2022 directive by leaving.
Physical servers came out of the country. ExpressVPN, Surfshark, NordVPN, Proton VPN, CyberGhost, Private Internet Access and others removed their Indian hardware rather than start keeping records. CyberGhost published its reasoning at the time, framing the choice as incompatible with its no-logs commitment.
What replaced them is a virtual location. You still see India in the app and still receive an Indian IP address, but the machine handing it to you sits in Singapore, London or the Netherlands. Surfshark said so directly when it announced the change, listing all three. Because the hardware is outside India, CERT-In’s retention rule does not reach it.
The cost is latency, and it is small. Traffic travels further, so expect a modest delay — enough to notice on a ping graph and not enough to notice on Hotstar. How much speed a VPN actually costs you puts that in context, and our streaming guide covers which services care about it.

⚠️ The corollary is the useful part. A provider still advertising physical servers inside India is either logging as required or ignoring a directive that applies to it. Neither is comfortable. Free services deserve more suspicion still, since they carry the same obligations with less scrutiny and a weaker reason to refuse.
If jurisdiction is the deciding factor for you, the providers worth reading about are the ones whose architecture limits what they could hand over at all: Proton VPN’s Swiss base and published audits, Mullvad’s account numbers with no email attached, and PIA’s record in actual US court proceedings.
How We Research
This page is built on the text and dating of CERT-In direction No. 20(3)/2022 and the MeitY Cyber Laws Division advisory of 25 April 2026, on contemporaneous Indian reporting of the district orders in Doda, Shopian, Kulgam, Pulwama, Rajouri and Kupwara, and on the providers’ own published statements about withdrawing hardware from India. Lawyers’ assessments are attributed to the individuals who gave them. We don’t run our own speed tests, and we don’t offer legal advice. Where a rule is contested in court or applied unevenly between districts, we say so rather than flattening it into a single answer. Our full approach lives on the About Us page.
India VPN Legality FAQ
Not under national law. No statute makes installing or using a VPN an offence, and no fine attaches to the software. District orders in Jammu and Kashmir are the exception: police there have detained people and registered cases for using VPNs in breach of magistrates’ prohibitions since May 2025.
It requires VPN providers, cloud services and data centres to keep subscriber records for five years — names, IP addresses, registration details, stated purpose and verified contacts — and to report cybersecurity incidents within six hours. Every obligation falls on the company. Corporate VPNs run by employers are excluded by the directive itself.
Most major providers removed their Indian hardware in 2022 rather than start logging. What you see labelled India today is usually a virtual location: an Indian IP address served from equipment in Singapore, London or the Netherlands. A service still advertising physical Indian servers is either complying with the retention rule or ignoring it.
In several districts, yes. Magistrates in Doda, Shopian, Kulgam, Pulwama, Rajouri and Kupwara have issued temporary prohibitions under Section 163 of the BNSS, a general public-order power. Lawyers have questioned whether that provision reaches VPNs at all, but the orders remain binding where they are in force.
No. Fraud, piracy and accessing platforms blocked under Section 69A carry the same consequences whether or not traffic passed through a VPN. Enforcement has concentrated on platforms, intermediaries and providers rather than individual subscribers, though the underlying legal exposure has not gone away.
The Verdict
Using a VPN in India is legal, and the sentence most guides stop at is the correct one for most of the country. No licence, no registration, no penalty attached to the software itself.
The caveat is geographic rather than legal. District magistrates in Jammu and Kashmir have prohibited VPN use under a general public-order power, and people have been detained under those orders. Lawyers dispute whether the power stretches that far. Until a court settles it, the orders bind anyone inside those districts.
For providers, the ground is still shifting. The 2022 directive asked for records and emptied the country of physical servers. The 2026 advisory asks for blocking, which is a harder thing to agree to and a more revealing thing to be capable of.
And the practical position for a reader is unchanged by any of it. Pick a provider whose hardware sits outside Indian jurisdiction, check whether your district has an order in force, and read our India guide for what actually works there day to day.
