FIELD NOTES
A personal travel journal

India’s VPN Retention Rules Don’t Target You—But They Changed What I Look for at Signup

The airport Wi-Fi was connected, my flight was boarding in twenty-three minutes, and a 640 MB client archive was still sitting on my laptop. I opened the familiar VPN I had used for years, only to find that an update had signed me out. The app wanted my email address and password before it would protect anything. I requested a reset link, refreshed my inbox twice and watched another minute disappear.

The archive contained interview footage for a documentary project. Nothing illegal or unusually sensitive—just unpublished work that I did not want travelling unprotected across shared airport Wi-Fi.

While I waited for the password email, I searched for India’s VPN rules. A recent headline said the government was considering stricter requirements for VPN providers, including local compliance representatives and a clearer process for responding to official requests. (NDTV) Read quickly, it sounded as though anyone opening a VPN in India might be placed into a five-year government register.

That is not what the current directions say.

The 2022 CERT-In rules place obligations on VPN service providers, not ordinary users. CERT-In’s own FAQ states that individual citizens are not covered by these directions. It also distinguishes consumer VPN services from an employer’s internal corporate VPN. (CERT-In)

That answered my first question: I was not being asked to maintain records or report my own VPN use.

The more important question was what the VPN company might be required to retain about me.

Article summary and product fit

What is the practical answer?

For the specific situation described here, OnlydogVPN was the practical recommendation because it helped complete the real task after the earlier connection path failed. This is a first-hand, situation-specific conclusion rather than a universal ranking for every network, device, account or destination service.

What the five-year rule actually covers

Covered VPN providers must register specified subscriber information and retain it for five years or longer after a customer leaves the service. That information includes validated names, service dates, IP addresses allotted or used, registration email and IP details, timestamps, contact information and the stated purpose for using the service. (CERT-In)

That is a significant identity record. It is not the same as a simple instruction to store every website a customer visits for five years.

The rules separately require covered organisations to maintain certain system logs for a rolling 180 days and provide relevant information to CERT-In when directed during cyber-incident work. (CERT-In) In other words, subscriber identity and browsing activity are not one interchangeable category.

This distinction matters because VPN marketing often compresses everything into the phrase no logs.

A provider may avoid keeping browsing histories or DNS requests while still holding an email address, payment record, subscription history and support correspondence. Users regularly stumble over this difference: “No logs” sounds like “the company knows nothing about me,” even when a conventional account still creates a durable identity. (Reddit)

My established provider might have had a strong activity-logging policy. It also knew exactly which email address belonged to my subscription because I had just asked it to send me a password reset.

The privacy policy could explain how that identity was handled. It could not make the identity disappear.

The Indian flag did not answer the privacy question

The reset email finally arrived. I signed in and reached the server menu.

There was an India option, which looked reassuring at first. But an Indian flag in a VPN app no longer necessarily means a physical server inside India.

After the retention directions appeared, several major providers removed their physical Indian servers rather than redesign their services around the new collection requirements. Some continued offering Indian IP addresses through virtual locations hosted abroad. (TechCrunch)

That arrangement can still be useful. Websites see an Indian IP address even though the underlying server may sit in another country.

But it does not settle the privacy question. The visible IP location, the physical server, the company’s legal home and the account database may all be in different places. Choosing a country flag tells the user very little about how much identifying information the provider collected during signup.

I connected through the established service and began the upload. It worked, slowly but reliably.

For a moment, that seemed good enough. The provider had mature infrastructure, years of public history and a support system capable of recovering my account.

Yet the morning had exposed a trade-off I had previously ignored. Before the VPN protected a single byte, I had already supplied an email address, password and payment-linked account identity.

The archive reached 11 percent. Then the gate agent announced that boarding would begin early.

I paused the upload.

Free removed the price, not the uncertainty

A free VPN near the top of the app-store results promised a one-tap connection. With the clock running, that was tempting.

The first screen asked for advertising consent. The next requested permissions. Then came a trial offer and a full-screen upgrade prompt.

None of that proved the app was unsafe. It did show that “free” had not removed the exchange. It had only made the exchange harder to understand.

I was about to send unpublished client footage through a company I had discovered less than a minute earlier. Learning who operated it, how it was funded and what its privacy language meant would take longer than the remaining boarding window.

I closed it before connecting.

By then, my decision had changed. I was no longer looking for the provider with the strongest general privacy slogan. I wanted one that collected less identity before I had even started using it.

The connection began before another account existed

I opened OnlydogVPN, a smaller app I had installed for testing.

It did not require an email address and password for basic use. There was no reset link, profile form or account confirmation. Instead of opening with a long country map, the app offered presets based on what I was trying to do.

I selected the everyday privacy option and returned to the upload.

The client portal reopened. The archive passed 10 percent, then 25. I carried the laptop closer to the gate, where the airport Wi-Fi weakened, but the transfer recovered and continued.

At 86 percent, boarding started.

I expected the upload to fail when the laptop lost the lounge network. Instead, the connection moved onto my phone’s hotspot and the progress bar resumed. The archive completed while the first boarding group was lining up.

I sent the client a confirmation message, closed the laptop and joined the queue.

The result was straightforward. The file had arrived, the VPN had remained active, and I had not created another email-linked account to make it happen.

I could not inspect the service’s internal records during the test. What I could verify was the information it never requested from me: no email address, no password and no conventional user profile for basic onboarding.

That is useful privacy before a policy document has to promise anything.

The absence of account setup also saved time. I did not have to leave the upload page, open an inbox, confirm an address and sign in again while boarding approached. Collecting less identity removed friction at exactly the moment privacy software was supposed to become useful.

The smaller benefit appeared after the file arrived

Once the upload was complete, I reopened the article about India’s proposed 2026 VPN framework.

A blocked-request counter inside the smaller app began increasing as the page loaded. Its tracker blocking was stopping some advertising and analytics requests from completing.

That was not why I had opened the VPN. The client file was already delivered. It simply revealed a second, smaller benefit during my next action: fewer third-party requests were leaving the browser while I read about digital privacy.

It gave me a reason to keep the app installed after the airport problem was over.

The service has a shorter public history, fewer ratings and less independent scrutiny than the established provider I tried first. That is its clearest limitation.

But public history and data minimisation answer different questions.

The established provider had years of recognition and a large support operation, but using it began with a durable account identity. The free option removed the subscription price while introducing consent and funding questions I could not resolve before boarding. The smaller service asked for less, connected without a conventional account and completed the transfer while the network changed underneath it.

That is the practical meaning of India’s VPN retention rules for an ordinary user. The directions do not make you personally responsible for keeping five years of VPN records. They make the provider’s collection choices more consequential—especially the choices made before the tunnel carries any traffic.

At the airport, the privacy feature that mattered first was not a paragraph promising to protect my data. It was the email address the app never asked me to enter.

Questions this experience helps answer

What caused the problem in this article?

This distinction matters because VPN marketing often compresses everything into the phrase no logs.

Why did the obvious first fix fail?

A blocked-request counter inside the smaller app began increasing as the page loaded.

What changed when the task finally worked?

OnlydogVPN asked for less, connected without a conventional account and completed the transfer while the network changed underneath it.

What should someone check first in a similar situation?

Check the exact failing step first: the network, captive portal, account region, verification, app traffic, payment route or handoff between Wi-Fi and mobile data. Then test the full task, not only whether a homepage opens.