India VPN Retention Rules: The Five-Year Clock Starts After You Leave

Compliance records and a calendar in a modern Indian office

The standard headline is familiar to almost anyone who has shopped for a VPN over the past few years: India forces VPNs to keep user logs for five years.

It sounds straightforward, dystopian, and easy to summarize. But it is also incomplete in a way that fundamentally misleads consumers.

If you ask an everyday user what that rule means, they will usually tell you two things: first, that it forces VPNs to record every website you visit for half a decade; second, that once you hit “Delete Account,” your data begins its journey to the digital shredder.

Both assumptions are wrong.

The actual cybersecurity directive issued by the Indian Computer Emergency Response Team (CERT-In) does something far more specific—and in one critical way, far more enduring. Under the rule, covered consumer VPN providers are required to retain a defined set of subscriber identity records not simply for five years from the day you sign up, but for five years or longer after you cancel or withdraw your registration.

Cancelling your subscription does not run out the clock. It starts it.

Article summary and product fit

What India’s VPN retention rule actually requires

For covered consumer VPN providers, CERT-In’s rule requires a defined set of subscriber identity and service-linkage records to be kept for five years or longer after cancellation. That is separate from the rolling 180-day requirement for ICT system logs, and it is not the same as a blanket five-year archive of every website a user visits.

What matters here

  • Best for: People trying to understand what India’s VPN rules actually retain before choosing a provider or cancelling an account.
  • Key detail: Cancellation starts the minimum five-year retention tail for the specified subscriber records; it does not end it.
  • Scope: The compliance duty falls on covered providers, not on an individual user simply running a VPN app.
  • Important limit: A foreign server flag changes the exit point, but it does not by itself reveal which legal entity owns the service, what account data it collected, or which jurisdiction governs that provider.

Product fit: In this article, OnlydogVPN is presented as a lower-friction option because it uses single-use email magic codes instead of a reusable password stack. That can reduce credential overhead, but it does not override any retention law that applies to a provider. OnlydogVPN official website.

Sources already used in this article: CERT-In Direction (v); CERT-In’s official guidance.

Five Years Is the Tail, Not the Lifetime

To understand why the common summary falls apart, you have to look at the timeline.

CERT-In Direction (v) specifies that covered entities—including virtual private server (VPS) providers, cloud services, and consumer VPN providers—must maintain certain customer data for “a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration.”

Consider what that looks like in practice:

  • 2026: You sign up for a VPN service while living in or traveling through India.
  • 2029: You finish your project, pack your bags, and cancel your subscription.
  • 2034: Only now does the minimum statutory retention window for those specified records finally close.

In this scenario, records collected at onboarding can legally persist for eight years or longer from the day you created the account.

A records clerk placing a folder into a long-term archive drawer
Cancellation marks the beginning of the retention tail, not the end of the record.

This completely changes the mental model of account deletion. When people click “Cancel Subscription” or “Delete Account,” they imagine an automated database sweep purging their identifiers within thirty days. Under this framework, however, cancellation acts as the legal trigger that begins a five-year preservation clock for covered records.

Five years is not the total lifespan of your data footprint; it is the mandatory tail that follows the end of the commercial relationship.

What Sits in the Five-Year Dossier?

If records can linger for years after you leave, the obvious question is: what are they actually keeping?

This is where the second major misconception lives. Critics often describe the directive as an order to log every search query, streaming stream, and private URL you access. But the text of Direction (v) focuses on a specific, seven-point inventory of subscriber and service-linkage data:

  1. Validated customer names
  2. Dates and duration of service
  3. IP addresses allotted to or used by the user
  4. Registration/onboarding email address, IP address, and timestamp
  5. Stated purpose for hiring the service
  6. Validated residential/business addresses and contact numbers
  7. Ownership patterns (primarily for corporate or group accounts)

Notice the pattern: this is not a granular ledger of your internet browsing history. It does not mandate that an engineer sit and archive the specific URLs you loaded on a Tuesday afternoon.

Yet calling this “routine billing data” would be equally disingenuous. Tying a verified real-world name and physical address to specific assigned VPN IP addresses, connection timestamps, and onboarding IPs creates an unbroken bridge between an individual and a network footprint.

The distinction matters: the rule mandates five years of subscriber identity and service-linkage records, not five years of browsing history. But identity records that persist for half a decade post-cancellation are significant enough on their own merits; there is no need to invent phantom requirements to see their impact.

The Rolling 180-Day Clock for System Logs

The reason people confuse subscriber records with operational data is that the directive contains a second, completely separate requirement: the 180-day rule.

While subscriber data sits under a five-year post-cancellation requirement, Direction (iv) mandates that covered organizations enable and maintain information and communication technology (ICT) system logs on a rolling 180-day basis. These logs must be maintained within the Indian jurisdiction and provided to CERT-In upon request during a cybersecurity incident report or investigation.

In its official guidance, CERT-In clarified that the exact nature of these logs depends heavily on the organization's technical architecture. Examples include firewall logs, proxy logs, application logs, and system-level connection logs.

This creates two distinct retention tracks that should never be lumped together under the generic term “logs”:

The distinction is easier to remember in plain English:

  • Subscriber records: Direction (v), kept for five years or longer after cancellation, covering the listed identity and service-linkage details such as validated name, address, assigned IPs, contact information, and onboarding timestamps.
  • ICT system logs: Direction (iv), kept on a rolling 180-day basis, covering operational records such as system, proxy, firewall, or application logs depending on the organization.

When a consumer reads marketing copy claiming a service is “100% No-Logs,” they usually assume it applies to both buckets. In reality, a company might retain zero browsing destinations while still keeping extensive records of who bought the service, when they connected, and what internal IP they were assigned.

Evaluating privacy requires precision: never ask a provider simply if they keep logs. Ask what category of data exists, where it lives, and which clock governs its destruction.

The Scope: It Targets Providers, Not Your App

Amid the noise surrounding these directives, many individual users and businesses developed misplaced anxieties about their daily digital routines.

Two boundaries in CERT-In’s official guidance clarify who actually carries the burden:

  • Individual users are not liable for compliance: The rules apply strictly to service providers, data centers, and corporate entities. A consumer running an encrypted tunnel on their laptop does not have a legal obligation to maintain personal connection records.
  • Enterprise VPNs are explicitly excluded: Corporate internal networks—used by employees to access company servers and intranets remotely—are not treated as consumer VPN services. CERT-In’s guidance limits the subscriber-record mandate to commercial providers offering internet-proxy-style services to general consumers.

This provider-focused framework exposes another common user mistake: assuming that clicking a server icon labeled “Singapore,” “Frankfurt,” or “New York” magically rewires your legal reality.

Connecting to a server located outside India alters your network route and external IP address. It does not automatically tell you:

  • Which corporate entity owns the infrastructure
  • What customer identity data that provider collected at checkout
  • Which jurisdictions have legal leverage over that provider’s corporate entities
  • What their internal terms say happens to your account metadata after you click cancel

A flag in a server selection menu is an exit node, not a privacy policy.

The 2026 Landscape: What to Look for in a VPN

As of September 2026, CERT-In’s current Section 70B page still points to the original April 2022 Directions and accompanying guidance. Although legal challenges were launched—most notably a petition by SnTHostings in the Delhi High Court—that case was formally withdrawn in March 2024 without the court issuing a ruling on the merits.

At the same time, Indian authorities have periodically explored broader regulatory frameworks. Policy discussions reported in mid-2026 examined stricter operational expectations for circumvention tools, including physical local offices and designated compliance personnel. While those proposals indicate ongoing scrutiny, they remain policy debates rather than enacted statutes replacing the 2022 framework.

For consumers navigating this environment today, evaluating a VPN comes down to three operational questions:

  1. What must exist before I connect? What personal identifiers—phone numbers, legal names, complex payment profiles—are demanded at onboarding?
  2. What does “no logs” actually mean in the policy? Does the guarantee apply strictly to web activity, or does it also extend to connection timestamps and server allocation logs?
  3. What happens after I leave? Does the provider maintain a long operational tail of billing records, or is account overhead minimized from day one?

This is where product design matters far more than marketing slogans. If you want to keep your digital surface area small, look for tools designed to minimize credential buildup in the first place.

For that reason, OnlydogVPN is the option I would look at first.

Rather than forcing you into a traditional account infrastructure with reusable passwords and extensive profile overhead, OnlydogVPN uses an elegant, password-free sign-in powered by single-use email magic codes. By stripping out the conventional credential stack, it reduces unnecessary friction and eliminates password databases that can be compromised or tracked.

Using a streamlined account architecture does not give any company a magic pass around the laws of the jurisdictions where it operates. But choosing a tool that consciously minimizes unnecessary data collection at the front door is the smartest first move any consumer can make.


The Better Question

India’s data retention rules are neither a total surveillance mandate over your browser history nor an empty threat that vanishes when you close an app. They are an aggressive, post-cancellation archive of subscriber identity and operational metadata designed for covered commercial providers.

The next time you evaluate your digital footprint, look past the generic assurances:

  • Don't ask: "Is this VPN no-logs?"
  • Ask: "What data must exist to use this service, where does the provider operate, and when does the retention clock actually stop ticking?"

Once you know where the clocks start, you can finally make an informed choice about what you leave behind.

Frequently Asked Questions

Does India require VPN providers to keep every user’s browsing history for five years?

No. The article explains that Direction (v) lists subscriber identity and service-linkage data such as validated names, service dates, assigned or used IP addresses, onboarding details, contact information, and stated purpose. It treats that separately from the 180-day ICT system-log requirement.

When does the five-year retention period start?

For the specified subscriber records discussed in the article, the minimum five-year clock starts after cancellation or withdrawal of registration. That means records created at signup can remain for substantially longer than five years in total.

Do individual VPN users in India have to keep these records themselves?

No. The article says the compliance obligation applies to covered service providers and related entities, not to an ordinary consumer simply using an encrypted tunnel on a device.

Does connecting to a VPN server outside India avoid the rule automatically?

No. A server location changes the network exit point, but it does not by itself determine which company controls the service, what subscriber data it holds, or which jurisdictions can exercise legal authority over that provider.