Will VPN Providers and the Indian Government Clash Over New Rules on User Data Collection?

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

The Ministry of Electronics and Information Technology, which administers CERT-in, has mandated all VPN providers and cryptocurrency exchanges save user records for five years. Some of the most well-known VPN providers, such as NordVPN and ExpressVPN, claim to collect only the most basic information about their customers and to provide ways for them to stay relatively anonymous by accepting Bitcoin payments. 
VPNs reroute users’ internet connections through a separate network; this can be done for a variety of reasons, such as connecting to a workplace network that is not available from the general internet or accessing prohibited websites by using servers in other nations. 
Another characteristic of VPNs several VPN companies like Nord promote as a selling factor is privacy. They frequently claim to keep no logs; Nord’s no-logs policy has been examined by PriceWaterhouseCoopers regularly. However, the IT Ministry’s ruling would force the corporation to deviate from such a guideline for servers in India.
What sort of data does the government expect firms to preserve? 
  • Names of subscribers/customers who have hired the services have been verified.
  • Hire period, including dates.
  • IP addresses assigned to/used by members.
  • At the moment of registration/onboarding, the email address, IP address, and time stamp were utilized. 
  • Why are

    […]
    Content was cut in order to protect the source.Please visit the source for the rest of the article.

    Read the original article: