The initiative, part of Prime Minister Narendra Modi’s efforts to strengthen user data security amid rising online fraud and breaches, covers 83 security standards, including mandatory alerts to the government for major software updates. Sources familiar with the discussions, along with a Reuters review of confidential government and industry documents, indicate that companies such as Apple, Samsung, Google, and Xiaomi have raised concerns over the unprecedented demands and the potential exposure of proprietary technology.
Under the proposed Indian Telecom Security Assurance Requirements, smartphone makers would face mandatory “vulnerability analysis” and source code reviews, with testing potentially conducted in designated Indian labs. Other requirements include the ability to uninstall pre-installed apps, restrictions on apps using cameras or microphones in the background, automatic malware scanning, and storing a full year of device logs. Industry representatives argue that these rules are globally unprecedented, technically impractical, and could compromise user privacy and device performance.
IT Secretary S. Krishnan told Reuters that any legitimate industry concerns would be addressed openly, describing it as “premature to read more into it.” A ministry spokesperson declined further comment due to ongoing consultations. The proposals, drafted in 2023, are now under consideration for legal enforcement, with government and tech company representatives scheduled for further discussions.
Analysts say the proposals reflect India’s balancing act between national cybersecurity and the practical constraints of the smartphone market, which includes nearly 750 million devices. Companies like Xiaomi and Samsung, whose phones run Google’s Android system, hold significant market shares at 19% and 15%, respectively, while Apple controls about 5%, according to Counterpoint Research.
Reuters notes that past Indian regulations, including mandatory pre-installed cyber safety apps, have prompted similar pushback from global technology firms, highlighting ongoing tensions between national security objectives and industry norms.

