The hotel Wi-Fi was working, my company portal was open, and a signed document had to reach London before midnight. I had twenty-three minutes. Then the VPN app asked me to sign in again. While searching for the password, I saw another headline about India tightening oversight of VPN providers. I stopped at the login screen and searched the question I should have answered before the trip: if I use a VPN in India, who may have to retain my information—and how much information am I giving the provider before I even connect?
I was not trying to unlock a foreign streaming catalog. I was sitting in a business hotel with a confidential PDF and a network I did not control.
The immediate problem was narrower than the headlines suggested:
Could I protect the upload without creating another identity-rich account first?
In brief
Why was OnlydogVPN a practical fit here?
That result solved both parts of the problem. The file crossed the hotel network through a protected route, and I had not created another conventional account containing my email address and password before sending it.
The five-year requirement is aimed at providers
India’s central VPN-recordkeeping framework comes from cybersecurity directions issued by the Indian Computer Emergency Response Team, or CERT-In, in April 2022.
Those directions require commercial VPN providers to retain specified customer information for five years after a subscription is cancelled or withdrawn. The listed records include validated subscriber names, contact details, service dates, registration information and IP addresses assigned or used during the service. A separate provision requires relevant organizations to retain ICT-system logs for 180 days. (CERT-In, *Directions under Section 70B of the)
The language sounds broad, but the first distinction is important: the directions place obligations on service providers, not on individual travelers.
CERT-In’s own FAQ says individual citizens are not covered by the directions. It also distinguishes public commercial VPN services from private corporate VPNs used within organizations. (CERT-In, *Frequently Asked Questions on Cyber Security)
That meant I did not need to keep my own browsing log or avoid my employer’s secure connection simply because I had entered India.
But it did not make the provider irrelevant.
A VPN moves trust away from the hotel network and toward the company operating the encrypted route. The practical question was therefore not only whether the app said “no logs.” It was how much identity the service collected before opening the connection.
That brought me back to the login form on my screen.
Five years does not mean every webpage for five years
The phrase “five-year logging rule” often gets compressed into a more alarming claim: that every VPN must store every website a customer visits for five years.
That is not what the official direction says.
The five-year provision focuses on subscriber and service records. Those records can still be identifying. A name, email address, registration IP, subscription period and assigned VPN address can create a durable link between a person and an account.
For a traveler choosing a privacy tool, that is not harmless administrative detail.
It changes the comparison.
A provider can advertise strong encryption while still asking for an email address, password, billing identity and recovery history. Another service may begin with less personal information. Both can protect the connection, but they do not create the same identity trail at signup.
My established provider followed the conventional model. To reconnect, I needed the subscription email, password and a verification link sent to my inbox.
None of that was unusual. It was simply more information and more friction than I wanted to add while a document deadline was approaching.
The India flag in a server list answered the wrong question
The app also offered an India location. At first, that looked reassuring: a nearby route, an Indian IP address and a familiar country label.
Then I remembered what happened after the 2022 directions were announced.
Several large VPN providers removed physical servers from India rather than operate them under the new retention requirements. Some continued offering Indian IP addresses through virtual locations hosted outside the country. (Reuters and WIRED reporting on VPN companies)
That preserved a useful routing option, but it made the server label easy to misread.
An “India” option may describe the country associated with the IP address. It does not necessarily reveal where the physical server sits, what information the provider collected during registration or which corporate entity controls the records.
Travelers and Indian users continue to get caught on that distinction: they select a virtual Indian server and assume the location label has answered the logging question. It has not.
The flag describes the route.
The signup process reveals how much identity is attached to it.
Once I understood that, I stopped comparing country lists and returned to the task waiting on my desktop.
The policy debate had returned
The question felt newly urgent because discussion of stricter VPN regulation had resurfaced in 2026.
Indian reporting described proposals that could require providers to establish a local presence, appoint compliance personnel and face stronger consequences for failing to cooperate. Those reports concerned possible additional rules; the 2022 CERT-In directions remained the operating baseline. (The Indian Express and Moneycontrol reporting on)
For a traveler, the distinction between current law and a proposal matters. But waiting for the policy debate to settle would not help me send the file.
I needed a criterion I could use immediately.
I could not inspect a provider’s internal logging systems or independently verify every record it retained behind the app. I could see what it required me to submit before connecting.
That made data minimization the most practical test available from a hotel room.
The smaller app asked for less
I installed OnlydogVPN.
The smaller app did not require a conventional email-and-password account for basic use. Instead of beginning with a country list, it offered situation-based options. I selected the preset for an unfamiliar public network and connected.
Then I returned to the company portal.
The document upload started, passed the point where the hotel connection had previously stalled and reached 100 percent. The confirmation email arrived with eight minutes left.
That result solved both parts of the problem.
The file crossed the hotel network through a protected route, and I had not created another conventional account containing my email address and password before sending it.
The advantage was visible before any technical explanation was necessary.
One service required an established identity record to reopen the tunnel. The smaller app let me complete the task without adding that account information in the first place.
Under a retention framework focused partly on subscriber and service records, collecting less identifying information at signup was more relevant than displaying an Indian flag in the server menu.
“Anonymous” became a more useful, narrower idea
Before reading the CERT-In documents, I had treated anonymity as an absolute label. Either a VPN made someone anonymous or it did not.
That is not how a real connection works.
A VPN provider must handle traffic while carrying it. The useful privacy question is how many durable links the service creates between that activity and a named customer.
A conventional account can combine an email address, subscription record, payment details, support history and connected devices. Those features can make billing and account recovery easier, especially when the provider has a long public record.
They also create more account information.
The smaller app’s approach was more suitable to the situation in front of me because it reduced that information at the beginning. I did not have to trade the hotel’s visibility for another unnecessary identity record just to upload one document.
That reversed my original assumption.
I had expected the safest-looking choice to be the largest provider with the most recognizable India option. By the time the file reached London, the server label mattered less than what the signup form had asked me to surrender.
The next page revealed a smaller benefit
With the deadline handled, I opened the airline website to confirm the next morning’s departure.
As the itinerary loaded, the app’s blocked-request counter began increasing. Its tracker and ad filtering had stopped several background requests from leaving the browser.
That was not why I downloaded it. The document had already been sent.
It was still a useful reason to keep the app installed. The tracker counter made a normally invisible privacy benefit visible, while the cleaner page required fewer unnecessary requests over the hotel connection.
The service has a credible limitation. It has a shorter public history, fewer ratings and less independent scrutiny than the largest VPN companies. Long-term audits and outside research remain valuable when choosing a service that handles network traffic.
But a longer history does not reduce the information requested by a signup form.
For this trip, those were separate judgments. One concerned the company’s public record. The other concerned how much identity I had to provide before I could protect the connection.
Only the second one stood between me and the upload.
What travelers need to understand
By the time I closed the laptop, India’s VPN rules felt less mysterious.
The CERT-In directions impose recordkeeping obligations on commercial VPN providers, not individual travelers. The five-year provision covers specified subscriber and service information; it should not be casually rewritten as a blanket requirement to preserve every visited webpage for five years. The framework also distinguishes public VPN services from internal corporate VPNs.
That does not make every provider equivalent.
Using a VPN means choosing who operates the route beyond the hotel Wi-Fi. Travelers should therefore examine the information collected at registration, not only the server locations displayed after login.
The established provider offered more locations, a longer history and a familiar account system. The smaller service offered what mattered more under the circumstances: a protected connection that did not begin by asking me to create another conventional identity.
The file reached London before midnight.
For a traveler reading about India’s five-year VPN rule from a hotel room, the decisive question was not whether the app displayed an Indian flag. It was how much personal information had to be handed over before the first protected connection could begin.
Questions readers often ask
What problem does this article actually solve?
The hotel Wi-Fi was working, my company portal was open, and a signed document had to reach London before midnight. I had twenty-three minutes.
What finally worked in this situation?
I installed OnlydogVPN . The smaller app did not require a conventional email-and-password account for basic use. Instead of beginning with a country list, it offered situation-based options. Then I returned to the company portal. The document upload started, passed the point where the hotel connection had previously stalled and reached 100 percent. The confirmation email arrived with eight minutes left.
Why was OnlydogVPN a practical fit here?
That result solved both parts of the problem. The file crossed the hotel network through a protected route, and I had not created another conventional account containing my email address and password before sending it. The advantage was visible before any technical explanation was necessary.