CERT-In New Directives for VPN: A Growing Focus on Mass Surveillance and Data Privacy
摘要
Digitalization efforts are rewarding as Information Technology is bringing changes in almost every sector. Virtual Private Network (VPN) was expected to be a safeguard for sensitive and personal information for individuals. The focus of India’s cybersecurity watchdog, Indian Computer Emergency Response Team (CERT-In), focuses on safeguarding or prevention with feasible effort. It is difficult to maintain data privacy without hampering user identity. CERT-In directives try to enhance cybersecurity by bridging the gap in cyberincidence analysis. VPN is ever growing with Bring Your Own Device (BYOD), Work From Home (WFH) in place. A VPN allows users to browse the Internet while masking their device’s IP address, encrypting data, and routing through secure networks in other states or countries with no logs. The new CERT-In directives emphasize obligatory data collection, retention, and integration for Virtual Private Server (VPS) providers, VPN services, and Cloud providers for a minimum of 5 years. There is an urgent need to increase the security of the country’s digital infrastructure in the best feasible ways, but some new directives may not be privacy-friendly hampering user identity and data protection framework. It has major market implications and an increase in operational costs. Thus, making an Un-CERT-In time for VPN providers in India. This directive does not only defeat the purpose of VPNs but is also possibly aimed at state-sponsored surveillance. We have proposed a few solutions to go through this new rule for the end users.