India Tightens Smartphone Security Rules, Demands Source Code Access
The Indian government is moving forward with a comprehensive set of cybersecurity regulations aimed at protecting smartphone users from online fraud and data theft. However, this proposed framework has sparked significant concern among the world’s largest technology companies, including Apple, Samsung, and Xiaomi. The new standards, if implemented, would fundamentally alter how smartphones operate in the country.
What the New Security Framework Demands
Under the proposed Telecom Security Assurance Requirements (ITSAR), the government has outlined 83 security benchmarks that all smartphones sold in India must meet. The goal is to create devices resistant to cyberattacks, data breaches, and surveillance. The framework rests on four key pillars:
Mandatory Source Code Review
Manufacturers would be required to submit the source code of their devices to government authorities for security analysis. This provision has become the most contentious point of the entire proposal.
Pre-Approval for Software Updates
Companies must notify and receive clearance from regulators before rolling out any major software updates or security patches. This includes all modifications that could affect device security.
Automatic Malware Scanning
Every smartphone would need built-in, automated malware scanning capabilities that run regularly without user intervention. This feature is designed to catch threats before they cause harm.
Extended Log Retention
System logs must be stored locally on devices for a minimum of twelve months. This would allow forensic analysis in case of security incidents or investigations.
Why Tech Giants Are Pushing Back
Smartphone manufacturers and the Manufacturers’ Association for Information Technology (MAIT) have raised strong objections to these proposals. Their concerns fall into several categories:
Intellectual Property Risks: The most significant worry revolves around trade secrets. Source code represents the core intellectual property of any technology company. Sharing it with government agencies, even for security audits, creates risks of leaks or misuse that could expose proprietary technology to competitors.
Performance and Battery Impact: Industry experts argue that continuous background malware scanning would drain battery life significantly and slow down device processing speeds. They point out that even the most advanced smartphones struggle with battery optimization under constant security monitoring.
Global Precedent Concerns: Companies note that even strict regulatory markets like the European Union, the United States, and Australia do not impose such requirements. They question why India, despite being a major market, should demand conditions that exceed global norms.
Cracking Down on Bloatware and Background Access
A major focus of the new regulations is controlling pre-installed applications, commonly known as bloatware. These apps often collect user data without explicit consent and cannot be removed easily. Under the proposed rules, manufacturers must allow users to uninstall all pre-loaded applications.
Additionally, the government wants strict controls on background access. Apps should not be able to activate cameras or microphones without clear user permission. The administration believes these changes are essential to eliminate hidden surveillance and unauthorized data collection at the hardware and software level.
India’s Strategic Importance in the Smartphone Market
India currently ranks as the world’s second-largest smartphone market, with approximately 750 million active users. Xiaomi leads with a 19 percent market share, followed by Samsung at 15 percent, and Apple at 5 percent. For these companies, India represents a critical revenue engine and a key growth market.
If the government remains firm on implementing all 83 security standards, it could trigger a prolonged legal and regulatory battle between global tech corporations and Indian authorities. Technology analysts warn that without a balanced approach, companies might delay launching new models in India or pass on the increased compliance costs to consumers through higher prices.
The Government’s Position
IT Secretary S. Krishnan has stated that the government’s intention is not to disrupt business operations but to safeguard the data of Indian citizens. Officials have left the door open for dialogue and have assured the industry that legitimate concerns will be considered before finalizing the regulations.
Technology experts view this move as part of India’s broader push for digital sovereignty. The nation wants its citizens’ data to remain secure within its borders and ensure no security vulnerabilities exist at the device level. However, maintaining the delicate balance between robust security and technological innovation remains a significant challenge.
The coming months will be crucial as both sides negotiate the terms. The outcome could set a precedent for how other nations approach smartphone security regulation in an increasingly connected world.
