Country brief · Updated August 13, 2026
Using a VPN in India
VPN use is legal, but a 2022 directive requires VPN providers operating in India to retain customer records for five years — several providers removed their Indian servers rather than comply.
Legal, with restrictions on use
What actually matters here
A provider incorporated outside India with an audited no-logs position, so the retention directive does not reach it.
Most country pages on the web recycle the same global ranking with a place name attached. This one filters on the capability that the situation in India actually calls for, which is why 6 of our 11 providers qualify rather than all of them.
Highest-scoring provider that meets it: Proton VPN, 90.0/100.
Visit Proton VPNWe earn a commission if you subscribe through this link. It does not change Proton VPN’s score.
The legal position
CERT-In directions issued in 2022 require VPN, cloud and data-centre operators to retain subscriber names, addresses, contact details, and IP allocation records for five years. The requirement applies to providers with infrastructure in India, not to users. Using a VPN remains lawful.
This is a summary of publicly reported regulation, not legal advice. Rules in this area change without much notice and enforcement varies. If the consequences of getting it wrong are serious for you, check the current position locally.
What the network does
Blocking is applied to specific sites and applications under IT legislation, and regional connectivity shutdowns have been used during unrest. VPN protocols themselves are generally reachable.
Retention and logging
This is the decisive factor. Providers that kept physical Indian servers had to accept a five-year logging obligation. Several instead withdrew and now serve Indian addresses from virtual locations abroad, which keeps the no-logs position intact but places the server outside the country.
Providers that meet the requirement
| # | Provider | Based in | Protocols | Score |
|---|---|---|---|---|
| 1 | Proton VPN | Switzerland | WireGuard, OpenVPN, IKEv2, Stealth | 90.0 |
| 2 | NordVPN | Panama | NordLynx (WireGuard), OpenVPN, IKEv2 | 84.0 |
| 3 | IVPN Unpaid | Gibraltar | WireGuard, OpenVPN | 82.5 |
| 4 | ExpressVPN Unpaid | British Virgin Islands | Lightway, OpenVPN, IKEv2 | 74.0 |
| 5 | CyberGhost Unpaid | Romania | WireGuard, OpenVPN, IKEv2 | 70.0 |
| 6 | PureVPN | British Virgin Islands | WireGuard, OpenVPN, IKEv2 | 69.0 |
Sources
Questions
- Is using a VPN legal in India?
- Legal, with restrictions on use. CERT-In directions issued in 2022 require VPN, cloud and data-centre operators to retain subscriber names, addresses, contact details, and IP allocation records for five years. The requirement applies to providers with infrastructure in India, not to users. Using a VPN remains lawful.
- Which VPN works best in India?
- Proton VPN on the requirement that matters here: a provider incorporated outside india with an audited no-logs position, so the retention directive does not reach it. 6 of 11 providers in our dataset meet it.
- Does the network block VPN traffic in India?
- Blocking is applied to specific sites and applications under IT legislation, and regional connectivity shutdowns have been used during unrest. VPN protocols themselves are generally reachable.
- Are there logging or retention rules that affect me in India?
- This is the decisive factor. Providers that kept physical Indian servers had to accept a five-year logging obligation. Several instead withdrew and now serve Indian addresses from virtual locations abroad, which keeps the no-logs position intact but places the server outside the country.