Hindustan Times (Gurugram)

Centre asks VPN services to log, hand over customer data

- HT Correspond­ent letters@hindustant­imes.com

NEW DELHI: Soon, companies offering virtual private network (VPN) or cloud services in India may be required to collect, as well as maintain, extensive and “accurate” data of their consumers for five years under Union ministry of electronic­s and informatio­n technology’s (MeitY) cybersecur­ity policy.

The new directives from India’s Computer Emergency Response Team (CERT-in), the government’s nodal agency for detecting and responding to cyber incidents, may have farreachin­g ramificati­ons on how VPN services are offered and used in the country. “The failure to furnish the informatio­n or non-compliance with the... directions, may invite punitive action,” the order dated April 28 said. The policy, details of which were first reported by HT last week, will come into effect within 60 days of the order.

It states that all cloud service providers and VPN providers will be required to maintain extensive customer informatio­n, including validated names, address, contact number, email address and IPs, for at least five years. The rules will also apply to data centres, virtual private server (VPS) providers. The companies will have to maintain all customer informatio­n for five years or longer (as mandated by law), even after “any cancellati­on or withdrawal of the registrati­on” by a customer.

“With respect to transactio­n records, accurate informatio­n shall be maintained... along with ...informatio­n relating to the identifica­tion of the relevant parties including IP addresses along with timestamps and time zones, transactio­n ID, the public keys (or equivalent identifier­s), addresses or accounts involved (or equivalent identifier­s), the nature and date of the transactio­n, and the amount transferre­d,” it adds. Also under the policy, the government has asked service providers, intermedia­ries, data centres, body corporates and government organisati­ons to mandatoril­y report breaches or leaks within six hours of them being flagged.

Union minister for MeitY Ashwini Vaishnaw last week allayed privacy concerns surroundin­g the storing of data by the provider, stating that there was “nothing to worry about”.

The government was yet to respond to a specific query by HT on the issue.

Newspapers in English

Newspapers from India