India Backs Down on Mandatory Pre-Installed Government "Snooping App"

Indian Government Revokes Controversial Order for Pre-installing 'Sanchar Saathi' App on Smartphones

INFORMATIONAL
December 2, 2025
4m read
Policy and ComplianceRegulatoryMobile Security

Related Entities

Organizations

India's Ministry of CommunicationsApple Samsung Google

Products & Tech

Sanchar Saathi

Full Report

Executive Summary

India's Ministry of Communications has reversed a contentious directive issued on November 28, 2025, that would have mandated all smartphone manufacturers, including Apple and Samsung, to pre-install the government's Sanchar Saathi app on all new devices sold in the country. The order also required that the app be non-deletable by the user. This move triggered a significant backlash from the technology industry and privacy advocates, who warned it could become a tool for state-sponsored surveillance. The government's quick withdrawal of the mandate represents a significant development in the discourse on digital rights and government oversight in India.


Regulatory Details

The original order, issued privately to smartphone manufacturers, gave companies a 90-day window to comply. The key and most controversial provisions were:

  1. Mandatory Pre-installation: All new smartphones sold in India had to come with the Sanchar Saathi app pre-installed.
  2. Retroactive Push: The app was also to be pushed to existing phones via software updates.
  3. Non-Deletable: Users would be unable to disable or uninstall the application from their devices.

The government officially positioned the app as a public safety tool to help citizens track lost or stolen phones and report fraudulent calls.

Affected Organizations

The directive would have impacted every smartphone manufacturer and operating system provider operating in India, one of the world's largest mobile markets. Key players included:

  • Apple
  • Samsung
  • Google (as the developer of Android)
  • All other Android device manufacturers (e.g., Xiaomi, OnePlus)

Backlash and Reversal

The mandate was met with immediate and fierce opposition. Privacy advocates and opposition politicians labeled it a "snooping app," expressing fears it could be used for mass surveillance, similar to how the Pegasus spyware was deployed against specific targets. They argued that a non-deletable government app with deep system access would fundamentally undermine user privacy and security.

Major technology companies, including Apple and Google, reportedly resisted the order, citing that it violated their internal security and privacy policies, which are designed to protect users from undeletable third-party applications with extensive permissions. The pressure from both civil society and industry led to a swift reversal. After initially defending the app as beneficial, the Ministry of Communications formally confirmed on December 3, 2025, that pre-installation would no longer be mandatory.

Impact Assessment

Had the order been enforced, it would have set a dangerous precedent for government control over personal devices. A non-deletable app with system-level permissions could potentially:

  • Access sensitive user data, including contacts, messages, location, and call logs.
  • Be exploited by threat actors if the app itself contained vulnerabilities.
  • Erode user trust in both the government and device manufacturers.

The withdrawal of the order is seen as a victory for digital privacy rights in India. It highlights the power of collective resistance from industry and civil society in checking potential government overreach. However, the incident also signals the Indian government's intent to increase its control over the digital ecosystem, suggesting that similar policy battles may occur in the future.

Timeline of Events

1
November 28, 2025
India's Ministry of Communications privately issues the directive to smartphone manufacturers.
2
December 2, 2025
The Minister of Communications publicly defends the app as non-compulsory.
3
December 2, 2025
This article was published
4
December 3, 2025
The ministry issues a formal statement confirming the mandatory pre-installation order has been revoked.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Tags

IndiaprivacysurveillancegovernmentAppleGoogleSanchar Saathi

📢 Share This Article

Help others stay informed about cybersecurity threats

Continue Reading