BREAKING
Revolutionary climate technology breakthrough announced • Championship finals draw record 150M+ viewers • Global markets surge following policy changes • New discovery in quantum computing promises faster processors
Technology

India’s Proposed Smartphone Security Rules Raise Concerns Among Global Tech Firms

What happened: India has proposed strict new smartphone security rules, covering source code disclosure, app permissions, malware scanning, and more. Why it matters now: Tech...

Jan 12
3 min read
India’s Proposed Smartphone Security Rules Raise Concerns Among Global Tech Firms
  • What happened: India has proposed strict new smartphone security rules, covering source code disclosure, app permissions, malware scanning, and more.

  • Why it matters now: Tech companies including Apple, Samsung, Google, and Xiaomi warn that the requirements could conflict with global privacy policies and affect device performance.

  • What changes for people: Potential delays in updates, battery-draining security scans, and stricter control over app functionality could impact user experience.

  • Who is affected: Smartphone makers, app developers, and millions of Indian users relying on Android and iOS devices.


India is pushing for a comprehensive set of smartphone security rules that could reshape how devices operate across the country. The proposals, shared with industry groups, include strict requirements for source code disclosure, app permission alerts, malware scanning, and mandatory log retention.

While the government aims to enhance cybersecurity and user safety, global tech giants have flagged several requirements as impractical or unprecedented, citing risks to performance, privacy, and rapid deployment of security updates.


Key Rules Under Consideration

  • Source Code Disclosure: Manufacturers would submit proprietary OS code to government labs for vulnerability testing. Apple, Samsung, Google, and Xiaomi argue this conflicts with corporate confidentiality.

  • Background Permissions Restrictions: Apps cannot access camera, microphone, or location when inactive. Continuous alerts are required, a rule industry experts call without global precedent.

  • Periodic Permission Reviews: Devices must push notifications asking users to review app permissions, though companies say only critical permissions should trigger alerts.

  • One-Year Log Retention: Phones must store audit logs for 12 months, covering app installs and login attempts. Industry notes many phones lack storage for long-term logging.

  • On-Device Malware Scanning: Phones must periodically scan for malware. Experts warn this could drain battery and slow devices.

  • Mandatory App Removal Option: All pre-installed apps, except essentials, must be deletable. Manufacturers argue some apps are critical system components.

  • Pre-Notification of Major Updates: Companies must inform government agencies before rolling out major OS updates or patches, which could delay critical security fixes.

  • Tamper Detection: Devices must detect rooting or jailbreaking and display warnings, though reliable detection remains technically challenging.

  • Anti-Rollback Protection: Older software versions must be permanently blocked to prevent downgrades, a rule with no global standard.


Industry Pushback

According to industry representatives and documents reviewed by sources, these rules could disrupt global supply chains, slow updates, and affect the overall user experience. Tech firms have requested dialogue with government agencies to make requirements more feasible while maintaining security goals.

The proposals highlight India’s broader push for digital sovereignty, local oversight of hardware and software, and stronger protection against cyber threats.