Now NordVPN to remove servers from India over new CERT-In data norms

  • Infrastructure Exit: NordVPN is officially decommissioning its physical server presence in India to maintain its strict “no-logs” policy amidst tightening local data mandates.
  • Compliance Conflict: The move responds to CERT-In’s directive requiring VPNs to store user names, IP addresses, and contact details for five years—a protocol fundamentally at odds with privacy-first encryption.
  • 2026 Market Shift: This exit signals a broader transition toward “Virtual India” servers located in offshore jurisdictions, utilizing RAM-only hardware to bypass local surveillance while retaining regional access.

The digital border between individual privacy and state sovereignty has reached a decisive breaking point. In a move that reshapes the cybersecurity landscape of South Asia, NordVPN has announced the complete removal of its physical servers from India. This strategic retreat follows a period of intense regulatory friction, positioning the Panama-based giant alongside industry peers who refuse to compromise encryption integrity for government access.

The Privacy Stand: Why NordVPN is Unplugging

The catalyst for this exodus is the directive from the Indian Computer Emergency Response Team (CERT-In). Originally issued as a cybersecurity mandate, the regulation requires VPN providers, data centers, and cloud service intermediaries to maintain granular logs of their users. For a company built on the premise of total anonymity, these requirements represent an existential threat to their core product.

“As one of the industry leaders, we adhere to strict privacy policies, which means we don’t collect or store customer data,” a NordVPN spokesperson stated. “No-logging features are embedded in our server architecture and are at the core of our principles and standards. Consequently, we are no longer able to keep physical servers in India.”

This decision aligns with a global trend where privacy-centric firms are increasingly clashing with national security mandates. The situation mirrors broader concerns regarding government spyware usage and the expansion of digital surveillance footprints worldwide. By removing physical hardware, NordVPN ensures that no Indian legal jurisdiction can compel the seizure of user data that, by design, does not exist on their RAM-only servers.

The CERT-In Data Retention Checklist

Under the current mandates, service providers must log and store the following for a minimum of five years:

  • Validated customer names and contact numbers
  • Assigned IP addresses and usage patterns
  • Ownership patterns and email addresses
  • Purpose of service utilization

The Legal Paradox: CERT-In vs. DPDP Act 2023

As we navigate the 2026 regulatory environment, a significant legal tension has emerged between the 2022 CERT-In directives and the Digital Personal Data Protection (DPDP) Act of 2023. While CERT-In demands five-year data hoarding, the DPDP Act emphasizes “data minimization” and the “right to erasure.” This contradiction leaves VPN providers in a precarious position, forced to choose between conflicting Indian laws.

The impact of such policy shifts extends beyond privacy, influencing the broader digital economy. Much like the India UPI Fee Update transformed the payments landscape, the tightening of VPN norms is forcing a total rethink of how international tech entities operate within the subcontinent. NordVPN’s exit follows similar moves by ExpressVPN and Surfshark, creating a vacuum in local high-speed infrastructure that is being filled by virtual alternatives.

The Rise of “Virtual” India Servers

To mitigate the impact on users who require an Indian IP address for banking or localized content, NordVPN and its competitors are pivoting to virtual server locations. These servers are physically located in privacy-friendly jurisdictions—such as Singapore or the Netherlands—but are programmed to provide Indian IP addresses. This allow users to bypass the official CERT-In logging requirements while maintaining the functional benefits of a local connection.

Feature Physical Servers (Pre-Exit) Virtual Servers (2026 Standard)
Jurisdiction Indian Law International/Offshore Law
Data Logging Mandatory 5 Years Zero Logs (RAM-only)
Latency Ultra-Low Moderate to Low

“The new Indian VPN regulations are an assault on privacy and threaten to put citizens under a microscope of surveillance. We remain committed to our no-logs policy.”
— Proton VPN Statement on Regional Policy Evolution

Looking Ahead: Post-Quantum Security

As we move deeper into 2026, the conversation is shifting from simple data logging to advanced interception. The next frontier for VPNs operating in high-regulation zones is the implementation of Post-Quantum Cryptography (PQC). With state actors increasingly investing in AI-driven decryption, the removal of physical servers is merely the first step in a long-term strategy to stay ahead of sophisticated surveillance capabilities.

For the average user in India, the day-to-day experience may not change significantly thanks to virtual routing. However, the precedent set by NordVPN underscores a vital reality of the modern era: in the struggle between legislative overreach and digital anonymity, the most powerful tool a tech company possesses is the ability to walk away.

More From Category

More Stories Today