India's Cybersecurity Mandate Ignites Privacy vs. Security Battle

Generated by AI AgentCoin WorldReviewed byRodder Shi
Monday, Dec 1, 2025 11:45 am ET1min read
Aime RobotAime Summary

- India mandates pre-installation of state-owned Sanchar Saathi app on all new smartphones, effective 90 days after November 28 directive.

- Major brands including

face compliance challenges as the app cannot be uninstalled, raising privacy concerns and corporate resistance.

- While the app claims to block 3.7 million stolen devices and recover 700,000 lost phones, critics warn it centralizes user data access under government control.

- Apple's refusal to pre-install third-party apps risks regulatory clashes, highlighting tensions between cybersecurity mandates and corporate autonomy.

India has ordered smartphone manufacturers to pre-install its state-owned Sanchar Saathi cybersecurity app on all new devices, a move that has sparked concerns over privacy and regulatory overreach. The directive, issued by the telecom ministry on November 28 and

, gives companies 90 days to comply, with the app being non-removable by users. Devices already in the supply chain must receive the app via software updates. The mandate, which applies to major brands including , Samsung, Vivo, Oppo, and Xiaomi, .

The Sanchar Saathi app, launched in January, is designed to address telecom cybersecurity threats such as spoofed or duplicate IMEI numbers, which enable scams and network misuse

. Government data shows the app has recovered over 700,000 lost phones since its launch, including 50,000 in October alone, while and terminating 30 million fraudulent connections. However, the app's mandatory pre-installation has drawn criticism from privacy advocates and legal experts. Mishi Choudhary, a technology lawyer, noted that the policy "effectively removes user consent as a meaningful choice," echoing concerns raised over Russia's similar MAX app requirement .

Apple, which holds a 4.5% market share in India's 735 million smartphones, is likely to resist the mandate.

, the company's internal policies prohibit pre-installing third-party or government apps on devices before sale. This stance aligns with Apple's previous clashes with India's telecom regulator over an anti-spam app. , such as prompting users to install the app voluntarily rather than enforcing a system-level preload. The company's resistance could escalate tensions with India, especially as it simultaneously challenges the country's antitrust law, which could impose fines up to $38 billion .

The telecom ministry's directive was issued confidentially, raising transparency concerns. Cybersecurity expert Prashant Mali warned that non-public mandates risk eroding trust, enabling regulatory overreach, and undermining due process.

that the lack of consultation with manufacturers before the order's release has raised operational and privacy concerns.

While the government argues the app enhances national security and combats fraud, critics question its long-term implications. The app's centralized tracking system grants the state extensive access to user data, potentially setting a precedent for future state-controlled digital tools. As India's 1.2 billion telecom subscribers navigate this new regulatory landscape, the balance between cybersecurity and individual privacy remains a contentious issue .

Comments



Add a public comment...
No comments

No comments yet