India Mandates Pre-Installed Cyber Safety App on All New Smartphones, Raising Privacy Concerns

India Orders Mandatory Cybersecurity App on New Mobile Devices

India has directed all smartphone manufacturers to pre-install a government-run cybersecurity application on new devices, a move that has ignited debate over privacy rights and state surveillance in one of the world’s largest mobile markets.

The order, passed last week and made public on Monday, requires companies to ensure all new smartphones come equipped with the Sanchar Saathi app within 90 days. According to the directive, the app’s “functionalities cannot be disabled or restricted.”

Government Cites Cybersecurity and Device Verification as Key Reasons

The Department of Telecommunications states the measure is necessary to help citizens verify the authenticity of their handsets and report suspected misuse of telecom resources. Officials argue that mobile devices with duplicate or spoofed IMEI numbers pose “serious endangerment” to telecom cyber security.

“India has big second-hand mobile device market. Cases have also been observed where stolen or blacklisted devices are being re-sold,” the department said, adding that this makes the purchaser an “abetter in crime and causes financial loss to them.”

Privacy Experts Raise Surveillance Concerns Over App Permissions

The mandate has drawn sharp criticism from cybersecurity experts and digital rights advocates who argue it violates citizens’ privacy rights. The decision affects more than 1.2 billion mobile users in India’s massive smartphone market.

According to the app’s privacy policy, Sanchar Saathi can:

  • Make and manage phone calls
  • Send messages
  • Access call and message logs
  • Access photos and files
  • Access the phone’s camera

“In plain terms, this converts every smartphone sold in India into a vessel for state mandated software that the user cannot meaningfully refuse, control, or remove,” advocacy group Internet Freedom Foundation said in a statement.

Minister Clarifies App Can Be Deleted Despite Mandatory Installation

Responding to mounting criticism, India’s Minister of Communications Jyotiradtiya Scindia has clarified that users will have the option to delete the app if they choose not to use it.

“This is a completely voluntary and democratic system – users may choose to activate the app and avail its benefits, or if they do not wish to, they can easily delete it from their phone at any time,” he wrote on X.

However, the minister did not explain how users could remove the app if its functions cannot be disabled or restricted, as stated in the original order.

What Is Sanchar Saathi and How Does It Work?

Launched in January, the Sanchar Saathi app offers several features designed to combat mobile device fraud:

  • Check a device’s IMEI (International Mobile Equipment Identity)
  • Report lost or stolen phones
  • Flag suspected fraud communications

An IMEI is a unique 15-digit code that identifies and authenticates a mobile device on cellular networks, essentially serving as the phone’s serial number.

According to a Reuters report citing official figures, the app has helped recover more than 700,000 lost phones, including 50,000 in October alone.

Implementation Requirements and Compliance Deadline

Under the new regulations, the pre-installed app must be “readily visible and accessible” to users during device setup. Smartphone manufacturers must also “make an endeavour” to provide the app through software updates for devices that have left factories but remain unsold.

All companies have been asked to submit compliance reports on the order within 120 days.

Technology Experts Question Data Access and Collection Scope

Technology analyst Prasanto K Roy emphasized concerns about the extent of access the app may ultimately be granted on devices.

“We can’t see exactly what it’s doing, but we can see that it’s asking for a great deal of permissions – potential access to just about everything from flashlight to camera. This is itself worrying,” he told the BBC.

On Google’s Play Store, the app states it doesn’t collect or share any user data. The BBC has reached out to the department of telecommunications with questions about the app and privacy concerns related to it.

Compliance Challenges for Global Smartphone Makers

Roy noted that compliance will be difficult, as the order contradicts the policies of most handset manufacturers, including Apple.

“Most companies prohibit installation of any government or third-party app before the sale of a smartphone,” he says, “barring in China and Russia.”

India’s smartphone market is dominated by Android devices, while Apple’s iOS powered an estimated 4.5% of the 735 million smartphones in the country by mid-2025, according to Counterpoint Research.

Apple has not commented publicly, but Reuters reports the company does not intend to comply and “will convey its concerns to Delhi”.

India Joins Russia in Mandating Pre-Installed State Apps

India is not the only country to have tightened rules on device verification. In August, Russia ordered all phones and tablets sold in the country to come pre-installed with the state-backed MAX messenger app, sparking similar privacy and surveillance concerns.


Key Takeaways:

  • India mandates Sanchar Saathi cybersecurity app on all new smartphones within 90 days
  • App has broad permissions including access to calls, messages, camera, and files
  • Minister says users can delete the app, contradicting “cannot be disabled” clause
  • Privacy advocates warn of surveillance risks and mandatory state software concerns
  • Major manufacturers like Apple reportedly unwilling to comply with the directive

Leave a Comment