India’s new cyber rules risk driving away tech companies
A tech industry body has flagged that the rules could create create an “environment of fear”


Indian cyber security rules which will start being operational later this month have been criticised by a technology industry body.
The Internet and Mobile Association of India (IAMAI), which represents organisations including Google and Facebook, warned that the new rules will create an environment of fear rather than trust. It called for a one-year delay before the rules take effect, in a letter sent to India’s IT ministry seen by Reuters.
The new rules were set by the Indian Computer Emergency Response Team (CERT) in April and require tech companies to report data breaches within six hours of noticing the incident and maintain IT and communications logs for six months.
IAMAI proposed extending the six-hour window, highlighting that the global standard for reporting cyber security incidents is usually 72 hours.
CERT has also asked cloud service providers, like AWS, and virtual private network companies to retain the names of their customers and IP addresses for at least five years, even if they stop using the company’s services.
IAMAI said that the cost of complying with these directives could be massive, and the proposed penalties for violating them include prison, which would lead to entities ceasing operations in India for fear of running afoul.
RELATED RESOURCE
How governments can build resilience in a new normal
The cloud enables the flexibility public organisations need to overcome disruption
The government has said that the new rules are needed as cyber security incidents were reported regularly but the information needed to investigate them was not always readily available from service providers.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The new rules led to ExpressVPN removing its servers from India last Thursday. Users in the country will still be able to connect to VPN servers, but its virtual India servers will be physically located in Singapore and the UK.
The company said CERT’s new data law is incompatible with the purpose of VPNs, which are designed to keep users’ online activity private. “ExpressVPN refuses to participate in the Indian government’s attempts to limit internet freedom,” the company said in a press release.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Latitude Financial's data policies questioned after more than 14 million records stolen
News Some of the data is from at least 2005 and includes customers’ name, address, and date of birth
By Zach Marzouk
-
Latitude hack now under state investigation as customers struggle to protect their accounts
News The cyber attack has affected around 330,000 customers, although the company has said this is likely to increase
By Zach Marzouk
-
IDCARE: Meet the cyber security charity shaping Australia and New Zealand's data breach response
Case Studies IDCARE is recruiting a reserve army to turbocharge the fightback against cyber crime not just in the region, but in the interests of victims all over the world
By Zach Marzouk
-
Australia commits to establishing second national cyber security agency
News The country is still aiming to be the most cyber-secure country in the world by 2030
By Zach Marzouk
-
Medibank bleeds $26 million in cyber costs following hack
News The company believes this figure could rise to $45 million for the 2023 financial year
By Zach Marzouk
-
TikTok's two new European data centres to address data protection concerns
News The company is under pressure to prove its user data isn’t being accessed by the Chinese state
By Zach Marzouk
-
Cyber attack on Australia’s TPG Telecom affects 15,000 customers
News It is the third cyber attack on a major Australian telco since October
By Zach Marzouk
-
Telstra blames IT blunder for leak of 130,000 customer records
News Australia’s biggest telco said that the error was due to a mismanagement of databases and not a cyber attack
By Zach Marzouk