India orders smartphone makers to preload state-owned cyber safety app

In a significant move to combat rising cybercrime, India’s telecommunications ministry has issued a directive requiring all smartphone manufacturers to pre-install the government’s Sanchar Saathi application on new devices. The order, dated November 28 and privately communicated to major technology companies, mandates that the cybersecurity app cannot be disabled or removed by users.

The directive affects industry giants including Apple, Samsung, Vivo, Oppo, and Xiaomi, giving them a 90-day compliance window for new devices. For existing phones already in distribution channels, manufacturers must deploy the application through software updates. This development places India alongside other nations like Russia in implementing state-backed digital security measures.

Sanchar Saathi, launched in January, has demonstrated substantial impact in India’s telecommunications landscape. Government statistics reveal the app has facilitated the recovery of over 700,000 lost mobile devices, including 50,000 in October alone. The platform operates through a central registry system that enables tracking and blocking of stolen smartphones across all networks while identifying fraudulent mobile connections.

The ministry emphasized that the measure addresses serious cybersecurity threats posed by duplicate or spoofed International Mobile Equipment Identity (IMEI) numbers, which enable various scams and network misuse. India’s massive telecom market, serving more than 1.2 billion subscribers, makes such security measures particularly significant.

Industry analysts note potential challenges, especially from Apple, which maintains strict policies against pre-installing third-party or government applications on its devices. Counterpoint Research indicates iOS powers approximately 4.5% of India’s 735 million smartphones, with Android dominating the remainder. Historical precedent suggests Apple may seek negotiated alternatives rather than full compliance with the pre-installation requirement.

Privacy advocates have expressed concerns about the mandatory nature of the implementation. Technology lawyer Mishi Choudhary noted that ‘the government effectively removes user consent as a meaningful choice,’ echoing criticisms previously directed at similar measures in Russia regarding their state-backed MAX messenger app.

As of the latest reports, affected companies and the telecommunications ministry have not issued public statements regarding the directive. The development represents a notable intersection of government security initiatives, digital privacy considerations, and corporate policy in one of the world’s largest mobile markets.