INDIA
Since April 2015, as amended in March 2018
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Foreign Trade Policy (2015-2010)
As per the Foreign Trade Policy, 2015-2020, India has distinguished between goods that are new and those that are second-hand, remanufactured, refurbished or reconditioned. The country allows the import of second-hand capital goods by end-users without an import license, provided the goods have a residual life of five years. In addition, users are required to present the certificate of an Indian chartered engineer attesting that such spare parts have at least 80% residual life of the original spare part, while second-hand domestic capital goods are not subject to this requirement. Problems reported by industry representatives include excessive details required in the license application, quantity limitations set at specific part numbers, and long delays between application and license issuance. According to a 2018 amendment (DGFT Notification No. 58/2015-2020), second-hand goods imported for repair, refurbishment, reconditioning or re-engineering purposes can be exported back under the customs notification provided that the waste generated during the repair or refurbishment of the imported items is treated in accordance with national environmental laws/regulations/rules/regulations/standards.
Coverage Refurbished computer spare parts
Sources
- https://web.archive.org/web/20211227075438/https://cpcb.nic.in/uploads/hwmd/June_Amendemnet_HOWM.pdf
- https://web.archive.org/web/20190212220509/https://www.eximguru.com/notifications/amendment-in-para-2-31-82672.aspx
- https://web.archive.org/web/20241216171302/https://www.teamleaseregtech.com/updates/article/3343/dgft-amends-import-policy-on-second-hand-goods-imported-for-the-purpose-of-repair-re-furbishing-re-cond...
- Show more...
INDIA
Since July 2020
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Notification No. 22/2015-2020
On 30 July 2020, the Indian Directorate General of Foreign Trade, through Notification No. 22/2015-2020, amended the import policy of colour television sets from "Free" to "Restricted". According to the notification, a license shall be required for imports of these TV sets, including smart TVs.
Coverage Smart TVs
Sources
- https://web.archive.org/web/20230118030837/https://content.dgft.gov.in/Website/dgftprod/b1b48bd4-bcda-4a71-b96c-5ea3c3306760/Notification%2022%20English.pdf
- https://web.archive.org/web/20241128003707/https://www.globaltradealert.org/intervention/80549/import-licensing-requirement/india-imports-of-television-sets-restricted
INDIA
Since October 2012, last amended in July 2021
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order, 2021
According to the Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order of 2021, and subsequent notifications, 76 ICT products must undergo registration and labelling prior to being launched in the market. In addition, no person shall manufacture or store for sale, import, sell, or distribute goods that do not conform to the Indian standard specified in the order and do not bear the Standard Mark with a unique registration number obtained from the Bureau of Indian Standards (BIS). BIS grants a license to the manufacturers to use or apply Standard Mark with a unique R-number through registration based on self-declaration of conformity for goods and articles as per Indian Standards. Examples of products subject to the scheme include set-top boxes, amplifiers, laptops/notebooks/tablets, scanners, printers, and mobile phones. It is reported that India has been tightening quality clearances for electronic products from China, which has ended up holding up products such as mobile phones from Chinese companies. While applications to the BIS are typically processed within 15 days, they now take more than two months.
Coverage ICT goods
Sources
- https://web.archive.org/web/20231031054948/https://www.crsbis.in/BIS/products-bis.do
- https://web.archive.org/web/20210126080530/https://gadgets.ndtv.com/mobiles/news/iphone-12-apple-xiaomi-smartphones-india-import-bis-delays-report-2330064
- https://web.archive.org/web/20230320115447/https://www.crsbis.in/BIS/about-crs.do
- https://web.archive.org/web/20220201093858/https://www.crsbis.in/BIS/app_srv/tdc/gl/docs/New_Gazette_Notification_2014_11_13.pdf
- https://web.archive.org/web/20220519064038/https://www.crsbis.in/BIS/app_srv/tdc/gl/docs/Gazette_notification_phase_3_CRO_1.pdf
- Show more...
INDIA
Since May 2019
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Notification No. 5 (2015-2020), 2019
According to Notification No. 5 (2015-2020), the import of goods (new as well as second-hand, whether or not refurbished, repaired, or reconditioned) notified under the Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order of 2021 is prohibited unless they are registered with the Bureau of Indian Standards and comply with its labelling requirements, or on a specific exemption letter from the Ministry of Electronics and Information Technology (MEITY) for a particular consignment.
Coverage Electronic and IT Goods including second-hand computers and mobile phones
INDIA
Since April 2013, last amended in October 2020
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Local content requirements (LCRs) on ICT goods for the commercial market
Consolidated Foreign Direct Investment (FDI) Policy Circular of 2020
According to the Consolidated Foreign Direct Investment (FDI) Policy Circular 2020, for any single-brand retail, including e-commerce entities with physical stores in India, foreign investment exceeding 51% is only allowed when 30% of the value of goods purchased is done from India. This requirement was established by the Consolidated Foreign Direct Investment (FDI) Policy Circular 2013. It is reported that India has modified the requirements in recent years, including by allowing firms to offset the local sourcing requirement by sourcing products from India for global supply chains. In addition, despite these modifications, it is reported that the local content requirements remain prohibitive for certain retailers with highly specialised supply chains.
Coverage E-commerce sector
Sources
- https://web.archive.org/web/20230131002741/https://dpiit.gov.in/sites/default/files/FDI-PolicyCircular-2020-29October2020_0.pdf
- https://web.archive.org/web/20241125212008/https://www.mofpi.gov.in/sites/default/files/1-FDI_Policy.pdf
- https://web.archive.org/web/20230919071254/https://ustr.gov/sites/default/files/2022%20National%20Trade%20Estimate%20Report%20on%20Foreign%20Trade%20Barriers.pdf
- Show more...
INDIA
Since August 1992
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Export restrictions on ICT goods or online services
Foreign Trade (Development and Regulation) Act 1992
According to the Foreign Trade (Development and Regulation) Act, the export of dual-use items and technologies is either prohibited or permitted under a license. The list of dual-use items also includes electronics, computers, and information technology, including information security.
Coverage Several items including electronics, computers, and information technology (including information security)
Sources
- https://web.archive.org/web/20220620100719/https://content.dgft.gov.in/Website/Foreign_Trade_(Development_&_Regulation)_Act,_1992.pdf
- https://web.archive.org/web/20211130010542/https://content.dgft.gov.in/Website/append3_0.pdf
- https://web.archive.org/web/20191024001249/http://dgftcom.nic.in/exim/2000/scomet/2017/guidelines2017.pdf
- Show more...
INDIA
Since September 2017
Since October 2012, last amended in July 2021
Since October 2012, last amended in July 2021
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
Telegraph (Amendment) Rules, 2017
Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order, 2021
Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order, 2021
In September 2017, India’s Ministry of Communications introduced the Telegraph (Amendment) Rules, requiring testing and certification for all telegraph equipment. This formed the basis for the implementation of the Mandatory Testing and Certification of Telecom Equipment (MTCTE) procedures in 2019, which mandate local security testing for telecom products. In September 2021, the MTCTE programme was expanded to include 175 products, prompting concerns from stakeholders about the burden of in-country testing requirements.
Additionally, the 2021 Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order requires manufacturers and importers to register and certify their products with laboratories accredited by the Bureau of Indian Standards, even if those products are already certified internationally. Expanded to cover 63 product categories, this order has drawn criticism due to limited government testing capacity, a complex registration process, and high compliance costs—including factory- and component-level testing.
In response, the Department of Telecommunications (DoT) has released the draft Telecommunications (Standards, Conformity Assessment and Certification) Rules, 2025. These Draft Rules, notified under Section 19 of the Telecommunications Act, 2023 (which repealed the Telegraph Act of 1885), aim to revise and streamline the framework for standardisation and certification of telecom equipment in India. Once finalised, the Draft Rules will supersede and replace the earlier Telegraph (Amendment) Rules.
Additionally, the 2021 Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order requires manufacturers and importers to register and certify their products with laboratories accredited by the Bureau of Indian Standards, even if those products are already certified internationally. Expanded to cover 63 product categories, this order has drawn criticism due to limited government testing capacity, a complex registration process, and high compliance costs—including factory- and component-level testing.
In response, the Department of Telecommunications (DoT) has released the draft Telecommunications (Standards, Conformity Assessment and Certification) Rules, 2025. These Draft Rules, notified under Section 19 of the Telecommunications Act, 2023 (which repealed the Telegraph Act of 1885), aim to revise and streamline the framework for standardisation and certification of telecom equipment in India. Once finalised, the Draft Rules will supersede and replace the earlier Telegraph (Amendment) Rules.
Coverage Telecom equipment
Sources
- https://web.archive.org/web/20240302203505/https://usof.gov.in/en/act-rules
- https://web.archive.org/web/20231130233756/https://www.mtcte.tec.gov.in/phaseWiseproductsList
- https://web.archive.org/web/20241010042606/https://www.tuv.com/content-media-files/master-content/rs/Attachments/2498_Amendment%20to%20CRO-2021.pdf
- https://www.lexology.com/library/detail.aspx?g=176cd1b9-b92c-4186-973d-21595779e724&utm
- https://web.archive.org/web/20230921075157/https://www.meity.gov.in/esdm/standards
- https://web.archive.org/web/20240330123614/https://ustr.gov/sites/default/files/2024%20NTE%20Report_1.pdf
- Show more...
INDIA
Since May 2011
Since September 2017
Since September 2017
Pillar Technical standards applied to ICT goods and online services |
Indicator Product screening and additional testing requirements
Amendment to the Unified Access Service License Agreement for Security-Related Concerns for the Expansion of Telecom Services in Various Zones of the Country No. 10-15/2011
Telegraph (Amendment) Rules, 2017
Telegraph (Amendment) Rules, 2017
The rules on security clearance for telecom equipment have required that telecom service providers (TSPs) use network elements that have been tested as per contemporary Indian or international security standards. Since April 2013, no certification of network equipment has been undertaken by authorised and certified agencies/labs in India.
Only resident-trained Indian nationals can be employed as executives responsible for certain security checks. There is also a possibility of extensive inspections of hardware, software, design, development and manufacturing facilities, as well as supply chains that might jeopardise intellectual property rights. High fines are imposed in case of non-compliance.
Additionally, since September 2017, India's Telegraph (Amendment) Rules require onerous in-country security testing on all telecom network equipment and products. Previously, such products could be tested and certified in laboratories globally or at manufacturers' in-house laboratories (self-certification). Mandatory testing and certification by Indian laboratories trigger additional costs and unnecessary delays for companies, especially given that the availability of suitable laboratories in India remains unclear. Furthermore, there are concerns about India's compulsory security certification scheme (CRS).
The Department of Telecommunications (DoT) has released the draft Telecommunications (Standards, Conformity Assessment and Certification) Rules, 2025 (Draft Rules), revising and streamlining the framework for the standardisation and certification of the telecom equipment in India. The Telegraph (Amendment) Rules, 2017, continue to be operative under the transitional provisions of the Telecommunications Act, 2023, until they are formally repealed or replaced by new regulations.
Only resident-trained Indian nationals can be employed as executives responsible for certain security checks. There is also a possibility of extensive inspections of hardware, software, design, development and manufacturing facilities, as well as supply chains that might jeopardise intellectual property rights. High fines are imposed in case of non-compliance.
Additionally, since September 2017, India's Telegraph (Amendment) Rules require onerous in-country security testing on all telecom network equipment and products. Previously, such products could be tested and certified in laboratories globally or at manufacturers' in-house laboratories (self-certification). Mandatory testing and certification by Indian laboratories trigger additional costs and unnecessary delays for companies, especially given that the availability of suitable laboratories in India remains unclear. Furthermore, there are concerns about India's compulsory security certification scheme (CRS).
The Department of Telecommunications (DoT) has released the draft Telecommunications (Standards, Conformity Assessment and Certification) Rules, 2025 (Draft Rules), revising and streamlining the framework for the standardisation and certification of the telecom equipment in India. The Telegraph (Amendment) Rules, 2017, continue to be operative under the transitional provisions of the Telecommunications Act, 2023, until they are formally repealed or replaced by new regulations.
Coverage Telecom equipment
Sources
- https://web.archive.org/web/20170505113747/http://www.tiaonline.org//sites/default/files/pages/1377%20Report%202013%20-%20TIA%20Submission%20-%20Final.pdf
- https://web.archive.org/web/20211026012142/https://www.ft.com/content/6e5f923a-53b8-11df-aba0-00144feab49a
- https://web.archive.org/web/20230320181616/http://www.tec.gov.in/mandatory-testing-and-certification-of-telecom-equipments-mtcte/
- https://www.lexology.com/library/detail.aspx?g=176cd1b9-b92c-4186-973d-21595779e724&utm
- Show more...
INDIA
Since February 2021
Pillar Intermediary liability |
Indicator Monitoring requirement
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
According to Art. 4.2 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules of 2021, a significant social media intermediary (defined as a social media intermediary having a number of registered users in India above five million) providing messaging services must enable identification of the first originator of the information on its computer resource as may be required by a judicial order or an order passed by a competent authority. In complying with an order for the identification of the first originator, a significant social media intermediary will not be required to disclose the contents of the electronic message related to the first originator or other users. No order must be passed in cases where there are less intrusive means of identifying the originator of the information.
Coverage Social media
Sources
- https://web.archive.org/web/20231005153411/https://www.meity.gov.in/writereaddata/files/Information%20Technology%20(Intermediary%20Guidelines%20and%20Digital%20Media%20Ethics%20Code)%20Rules%2C%202021...
- https://web.archive.org/web/20230929034953/https://sflc.in/analysis-information-technology-intermediary-guidelines-and-digital-media-ethics-code-rules-2021/
INDIA
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
India has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal
INDIA
Since June 2000, entry into force in October 2000, last amended in August 2023
Since October 2009
Since October 2009
Pillar Content access |
Indicator Blocking or filtering of commercial web content
Information Technology Act, 2000
Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009
Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009
Section 69A of the Information Technology Act empowers the Central Government, or any officer expressly authorised by it for this purpose, to issue directions for the blocking of public access to information where it is satisfied that such action is necessary or expedient. Such directions may be issued in the interests of the sovereignty and integrity of India, the defence of India, the security of the State, friendly relations with foreign States, public order, or for the prevention of incitement to the commission of any cognisable offence relating to these grounds. Where these conditions are met, the Government may, for reasons recorded in writing, order any government agency or intermediary to block, or to cause the blocking of, public access to any information that is generated, transmitted, received, stored, or hosted in any computer resource.
Pursuant to Section 69A of the Information Technology Act, read together with the relevant provisions of the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules:
- TikTok, WeChat, and 57 other applications of Chinese origin were banned in India with effect from 29 June 2020, with the blocking orders remaining in force as of 2025.
- 14 messaging applications were blocked in early May 2023, with the restrictions remaining in place as of 2025. Subsequent court proceedings clarified that these blocking orders were, in fact, geographically limited to Jammu and Kashmir. The Delhi High Court upheld the ban on Briar primarily on the basis that its application was confined to the Union Territory of Jammu and Kashmir.
Pursuant to Section 69A of the Information Technology Act, read together with the relevant provisions of the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules:
- TikTok, WeChat, and 57 other applications of Chinese origin were banned in India with effect from 29 June 2020, with the blocking orders remaining in force as of 2025.
- 14 messaging applications were blocked in early May 2023, with the restrictions remaining in place as of 2025. Subsequent court proceedings clarified that these blocking orders were, in fact, geographically limited to Jammu and Kashmir. The Delhi High Court upheld the ban on Briar primarily on the basis that its application was confined to the Union Territory of Jammu and Kashmir.
Coverage Applications
Sources
- https://www.accessnow.org/keepiton-data-dashboard/
- https://web.archive.org/web/20260429213418/https://wipolex-res.wipo.int/edocs/lexdocs/laws/en/in/in212en_1.pdf?last-modified=1753881770&Expires=1777498716&Signature=fFiHiyJLKBqjGX1EIGJUnFZ8JY6TU3UfdJS...
- https://web.archive.org/web/20260429215338/https://www.meity.gov.in/static/uploads/2024/10/91f628cb778f94e76df356bc3fd3ac60.pdf
- https://web.archive.org/web/20260429214124/https://www.pib.gov.in/PressReleasePage.aspx?PRID=1635206®=3&lang=2
- https://web.archive.org/web/20260429215028/https://sflc.in/sflc-in-assists-in-challenge-to-blocking-of-foss-apps-element-and-briar-before-kerala-high-court/
- Show more...
INDIA
Since August 2023, entry into force in May 2027
Pillar Domestic data policies |
Indicator Framework for data protection
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act establishes a comprehensive regime for safeguarding digital personal data in India, extending its reach extraterritorially where processing relates to the provision of goods or services to individuals in India. It imposes statutory duties on data fiduciaries, confers defined rights upon data principals, and generally permits the outward transfer of personal data. The Act introduces the novel institution of independent consent managers, entrusted with administering individuals’ consent and operating separately from data fiduciaries and data processors. It further provides for significant penalties for non‑compliance, including a maximum fine of INR 2.5 billion (approx. USD 31 million), and designates the Data Protection Board of India as the regulatory authority. The Act is implemented in phases, with certain provisions commencing on 13 November 2025, further provisions taking effect one year thereafter, with the remaining substantive provisions entering into force in May 2027.
Coverage Horizontal
Sources
- https://web.archive.org/web/20251216131748/https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- https://web.archive.org/web/20251216133658/https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
- https://www.dataguidance.com/jurisdictions/india
- Show more...
INDIA
Reported in 2025
Pillar Content access |
Indicator Blocking or filtering of commercial web content
Reported instances of commercial web content blocking
It is reported that several instances of the blocking of commercial web content occurred in India in 2025, as detailed below:
- 23 social media and messaging platforms were blocked in Jamui District, Bihar, from 23:30 on 16 February 2025 until 23:30 on 18 February 2025.
- 23 social media and messaging platforms were blocked in Katihar District, Bihar, from 20:00 on 6 July 2025 until 20:00 on 7 July 2025.
- 23 social media and messaging platforms were blocked in the Hathwa sub‑division of Gopalganj District, Bihar, from 12:00 on 30 September 2025 until 12:00 on 2 October 2025.
- At least four platforms were shut down for several days in October 2025 across three areas of Cuttack city, Cuttack District, Odisha, namely the Cuttack Municipal Corporation (CMC) area, the Cuttack Development Authority (CDA) area, and the 42 Mauza region.
- At least four platforms were shut down for several days in December 2025 in Malkangiri District, Odisha.
- 23 social media and messaging platforms were blocked in Jamui District, Bihar, from 23:30 on 16 February 2025 until 23:30 on 18 February 2025.
- 23 social media and messaging platforms were blocked in Katihar District, Bihar, from 20:00 on 6 July 2025 until 20:00 on 7 July 2025.
- 23 social media and messaging platforms were blocked in the Hathwa sub‑division of Gopalganj District, Bihar, from 12:00 on 30 September 2025 until 12:00 on 2 October 2025.
- At least four platforms were shut down for several days in October 2025 across three areas of Cuttack city, Cuttack District, Odisha, namely the Cuttack Municipal Corporation (CMC) area, the Cuttack Development Authority (CDA) area, and the 42 Mauza region.
- At least four platforms were shut down for several days in December 2025 in Malkangiri District, Odisha.
Coverage Social media and platforms
INDIA
Since April 2022
Pillar Domestic data policies |
Indicator Minimum period for data retention
Indian Computer Emergency Response Team Direction No. 20(3)/2022-CERT-In
Section 5 of Direction No. 20(3)/2022-CERT-In mandates data centres, virtual private server providers, cloud service providers, and virtual private network service providers to mandatorily collect and retain certain subscriber-related information accurately for a minimum period of five years after the subscriber is no longer availing the underlying services. These data sets include subscriber names, period of hire including dates, IPs allocated and used, e-mail address along with IP and time stamp used at time of registration, purpose of availing the services, verified address and contact numbers, and ownership pattern of subscribers. Virtual asset service providers, virtual asset exchange providers and custodian wallet providers must also maintain KYC information and records of financial transactions for a period of 5 years. Specific to transaction records, Direction No. 20(3)/2022-CERT-In states that information must be maintained accurately in such a way that individual transactions can be reconstructed along with the relevant constituents such as IP addresses, time zones, transaction ID, public keys or equivalent identifiers, addresses or accounts involved, nature and date of transaction, amount transferred, etc.
Coverage Data centres and virtual private server, cloud service, virtual private network service, virtual asset service, virtual asset exchange and custodian wallet providers
Sources
- https://web.archive.org/web/20240818125254/https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- https://web.archive.org/web/20240227013228/https://www.mondaq.com/india/social-media/1233722/new-cert-in-directions-overview-and-implications
- https://web.archive.org/web/20231204133353/https://internetfreedom.in/cert-in-guidelines-on-cybersecurity-an-explainer/
- https://web.archive.org/web/20241211173426/https://www.lexology.com/library/detail.aspx?g=899f3b94-c31f-4983-868f-5ee5abbf78c8
- Show more...
INDIA
Since November 1998, last amended in January 2022
Pillar Domestic data policies |
Indicator Minimum period for data retention
Licence Agreement for Provision of Internet Services
According to the License Agreement for Provision of Internet Services, the Internet Service Provider licensee shall maintain all commercial records, call detail records, exchange detail records, and IP detail records with regard to the communications exchanged on the network. Such records shall be archived for at least two years for scrutiny by the Licensor for security reasons and may be destroyed thereafter unless directed otherwise by the Licensor.
Coverage Internet Service Providers
Sources
- https://web.archive.org/web/20220127122544/https://dot.gov.in/sites/default/files/Amendment%20in%20Internet%20Service%20Provider%20.pdf?download=1
- https://web.archive.org/web/20231003081823/http://cis-india.org/internet-governance/blog/data-retention-in-india#fn8
- https://web.archive.org/web/20130611231210/http://www.dot.gov.in/data-services/internet-services
- https://web.archive.org/web/20220927210431/https://www.saras.gov.in/main/License%20Agreement/ISP.pdf
- https://www.dataguidance.com/notes/india-data-protection-overview
- Show more...
