Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s how we research.
Using a VPN in India is legal. No law criminalises downloading, installing or using one, and millions of people do daily for remote work, banking and streaming.
What changed is the position of the providers. In 2022 India required any VPN company with servers in the country to store user data — real names, IP addresses, usage patterns — for five years. Rather than comply, every major provider physically removed its Indian servers.
That decision shapes everything about using a VPN in India today, and this guide explains what it means in practice.
The Short Answer
VPNs are legal for users. The regulation applies to providers, not to you — with one district-level exception that reaches users directly.
The major providers left. ExpressVPN went first, followed by NordVPN, Surfshark, IPVanish, Private Internet Access, CyberGhost and Proton VPN.
They still offer Indian IP addresses — through servers physically located in Singapore, the UK or the Netherlands, outside Indian jurisdiction.
Free VPNs are a worse idea here than almost anywhere, and the reason is specific to this regulation.

What the 2022 Directive Actually Requires
CERT-In issued Direction No. 20(3)/2022 in April 2022, covering VPN providers, data centres, virtual private server hosts and cloud services. The text, the dates and who exactly it binds are set out in full on our legality page; what matters here is the effect.
It requires them to collect and retain subscriber information for a minimum of five years — including after someone cancels their service.
The conflict is structural. A provider cannot simultaneously operate a no-logs policy and store five years of identifying data. There was no middle ground available, which is why the response was to leave rather than to negotiate. Indonesia’s platform rules create a similar bind, with registration and 24-hour data-request deadlines.
Crucially, it targets providers. Using a VPN remains legal for individuals, and no provision criminalises ordinary use — though magistrates in several Jammu and Kashmir districts have prohibited it anyway, and police have detained people under those orders.
What Changed in April 2026
A second directive arrived this year, and it works differently.
MeitY instructed VPN providers to actively block access to banned gambling and prediction-market platforms — regardless of where their servers are physically located. Turkey is discussing a licensing regime that would go further still.
This is a shift in kind rather than degree. The 2022 rule said store data if you operate here. The 2026 advisory asks providers to enforce Indian content rules for Indian users wherever the infrastructure sits.
How providers respond to this is still unfolding. It’s worth watching if you’re choosing a service now, because it may affect what a provider does with your traffic rather than just what it stores.
How Virtual Indian Servers Work
You can still get an Indian IP address from every provider we rank. Here’s the mechanism.
A virtual server location assigns you an IP address registered to India while the physical machine sits elsewhere — Singapore, the United Kingdom or the Netherlands are the common choices.
To websites and services, you appear Indian. Regional content, banking portals and local services see an Indian address and behave accordingly.
To Indian regulators, the server isn’t in India, so CERT-In’s data-retention mandate doesn’t apply to it.
What this costs you: latency. A “Mumbai” server physically located in Singapore adds real distance to every request. If you’re in India connecting to an Indian virtual server, your traffic travels out of the country and back — our speed guide covers why distance is the second-largest factor in VPN speed.
What it gains you: the provider’s no-logs policy stays intact, backed by audits conducted outside Indian jurisdiction.

Why Free VPNs Are Worse Here Than Elsewhere
This deserves its own section, because the usual arguments against free VPNs apply plus one specific to India.
The usual problems: data caps that make streaming impractical, speeds at roughly a tenth of paid services, and address ranges flagged by streaming platforms within days. Our free VPN guide covers which three free tiers are genuinely safe.
The India-specific problem: the providers that left were the ones with reputations to protect and audited no-logs policies to maintain. Smaller and free services with servers still in India face the same five-year retention requirement — and complying with it is far cheaper than relocating infrastructure.
So the question to ask of any free VPN offering Indian servers is whether those servers are physical or virtual, and whether the provider has said anything public about CERT-In. Most haven’t.
⚠️ And the general rule still holds: a service with no paid product has to make money somehow. When the regulatory environment specifically rewards data retention, that calculation gets worse.
Which Provider to Choose
All five we rank offer virtual Indian locations with their no-logs policies intact. The differences are elsewhere.
NordVPN runs RAM-only servers, holds six independent no-logs audits, and posted the best speed result in independent benchmark testing — which matters when your Indian IP already comes with a latency penalty.
Surfshark allows unlimited devices, useful for households, and renews cheaper than most.
ExpressVPN was first to withdraw from India and has published the most audits of any provider we rank — 28 in total, three of them examining the no-logs claim specifically.
CyberGhost published its reasoning for leaving publicly, offers virtual Mumbai locations, and gives 45 days to change your mind — the longest window in the category.
⚠️ What to verify before buying: that the provider’s audits post-date its Indian withdrawal, and that its Indian locations are labelled virtual. Both are usually stated in the server list or the audit announcements.

What a VPN Doesn’t Change
Worth stating plainly, since the regulatory noise obscures it.
Illegal activity stays illegal. Fraud, cybercrime, unauthorised access, copyright infringement and prohibited content remain offences under the Information Technology Act and other statutes, with or without encryption. A VPN changes what a website sees, not what the law says.
Blocking orders still apply. Court-ordered and government-ordered blocks are enforced through ISPs, and circumventing them doesn’t remove the underlying legal position.
Records still exist elsewhere. Payment records, device data and platform accounts remain relevant regardless of how traffic reaches a service. Our guide on whether you need a VPN covers what the technology genuinely does and doesn’t do.
How We Research
This guide draws on CERT-In’s published directions, reporting from named sources including Outlook India, LegalClarity and Cloudwards, and public statements from the providers themselves about their withdrawal decisions — cross-checked and verified at publication. Where providers described their own reasoning, we attribute it as their statement rather than as established fact. Regulations in this area are actively changing; verify current requirements before relying on anything here. This is not legal advice. Our full approach lives on the About Us page.
India VPN FAQ
Yes, and employer-run VPNs sit outside the 2022 directive by its own terms. That exemption is why corporate remote-access setups continued unchanged while consumer providers withdrew their Indian hardware. Personal use is lawful too, with district-level orders in Jammu and Kashmir as the exception.
CERT-In Direction No. 20(3)/2022 requires any provider with servers in India to collect and retain user data — including real names and IP addresses — for at least five years, even after cancellation. That is incompatible with a no-logs policy, so ExpressVPN, NordVPN, Surfshark, IPVanish, Private Internet Access and CyberGhost all withdrew their physical infrastructure rather than comply.
Yes, through virtual server locations. The IP address is registered to India while the physical machine sits in Singapore, the United Kingdom or the Netherlands. Websites see an Indian address; Indian data-retention rules don’t apply because the hardware is outside the country.
Somewhat, because the physical distance is real even though the IP address says otherwise. If you’re in India connecting to a virtual Indian server in Singapore, your traffic leaves the country and returns. Distance is the second-largest factor in VPN speed after protocol choice.
Less so than elsewhere, and for a specific reason. The providers that withdrew were the ones with audited no-logs policies to protect. Services that kept servers in India face the same five-year retention requirement — and complying is considerably cheaper than relocating infrastructure. Ask whether a free provider’s Indian servers are physical or virtual before trusting them.
India’s Ministry of Electronics and Information Technology instructed VPN providers to actively block access to banned gambling and prediction-market platforms, regardless of where their servers are located. This differs from the 2022 rule: rather than requiring data storage from providers operating in India, it asks providers to enforce Indian content rules for Indian users. How providers respond is still developing.
The Short Version
Legal to use, complicated to provide. India’s 2022 directive required five years of user data retention from any VPN with servers in the country. Every major provider left rather than comply.
You can still get an Indian IP — from a virtual server in Singapore or Europe, outside Indian jurisdiction, with the no-logs policy intact.
The cost is latency, since your “Indian” server isn’t in India.
And free VPNs are the wrong answer here specifically, because the providers who stayed are the ones for whom compliance was cheaper than relocation.
