Computer security

India imposes pre-installation of a government app on all smartphones

It is called 'Sanchar Saathi' and it is the Modi government's new weapon against digital theft and fraud. But the non-installable pre-installation requirement opens a fierce clash over privacy, mass surveillance and control of personal devices in the world's most populous democracy

5' min read

Translated by AI
Versione italiana

5' min read

Translated by AI
Versione italiana

The Indian government has decided that the smartphone is no longer just a private object. In a confidential order dated 28 November,the Ministry of Communications has ordered all phone manufacturers to pre-install the public 'Sanchar Saathi' app on every new device sold in the country, with no possibility for users to uninstall it, and to push it also on models already in circulation through software updates. For the government, a necessary response to the explosion of digital fraud; for some observers, a new phase in the relationship between citizens, technology and power in the world's most populous state.

Ninety days to get the state app in your pocket

The directive, which was only made public after an investigation by Reuters and the dissemination of the full text by journalists and specialised sites, relies on the Telecom Cyber Security Rules 2024 - the Indian regulation that gives the government the legal basis to impose cybersecurity obligations on telecommunications operators - amended in October 2025. Manufacturers - from Apple to Samsung, from Xiaomi to Vivo and Oppo - are given 90 days to ensure that every new smartphone destined for the Indian market leaves the factory with 'Sanchar Saathi' pre-installed, clearly visible on first boot and with all its functions active. For phones already manufactured and in the sales pipeline, the executive 'urges' that the app be delivered via software update; manufacturers will also have to submit a compliance report within 120 days, with the threat of penalties under the Telecommunications Act 2023 and the Cyber Security Rules themselves.

Loading...

It is to all intents and purposes a compulsory Stat app, entering the deepest layer of the users' digital experience. The order was sent privately to selected companies, without going through a parliamentary debate or public consultation: a detail that fuels criticism about the transparency and proportionality of such an invasive measure.

What 'Sanchar Saathi' is and why the government likes it

'Sanchar Saathi', launched in early 2025 as a 'citizen-focused' initiative of the Department of Telecommunications, is designed to protect users from phone theft, bogus SIMs and call or message scams. On its institutional portal, the government describes it as a platform that allows users to block and track stolen devices, check how many SIMs are in their name, verify the authenticity of a phone through its IMEI code, and report international calls masquerading as Indian numbers.

In recent months, New Delhi has claimed important numbers: over 7 lakh (700,000) phones recovered in total, more than 50,000 in October 2025 alone, and a growth in returns such that, according to the government, 'more than one phone per minute' would be recovered across the country thanks to the platform.

At the same time, 'Sanchar Saathi' has become a central node of a broader anti-fraud ecosystem: through the 'Chakshu' module, users can report suspicious communications - from fake bank operators to 'KYC' scams, which use the Know Your Customer (KYC) identity checks that banks and financial services are required by law to do - and help detect illegal call centres and SIM cards used for crimes.

Indeed, India has experienced an explosion of digital fraud related to online payments and financial apps. According to data presented to Parliament and compiled by industry bodies, the losses from cyber-fraud in 2024 would have risen to about Rs 22,845 crore (over EUR 2 billion), an increase of more than 200% over the previous year and millions of complaints filed with national portals. In contrast, cybersecurity incidents more than doubled between 2022 and 2024, while thousands of SIMs and numbers linked to fraud were blocked nationwide.

'Sanchar Saathi' is thus presented as a key piece of secure 'Digital India', a way to close the loopholes that allow fraudsters to exploit stolen phones, cloned IMEIs and numbers in the names of unsuspecting people.

Where security ends and surveillance begins

The directive does not merely incentivise the use of a useful app, it makes it mandatory, non-deactivatable and potentially pervasive. The text of the order itself refers to the 'serious endangerment of telecommunications cybersecurity' due to duplicated or forged IMEIs, but then goes on to build an infrastructure that allows the state to introduce its own software on the device, with extensive permissions and upgradeable over time.

On MediaNama, one of India's leading digital policy analysis sites, it is pointed out that "Sanchar Saathi" requires access to call logs, SMS, phone management, camera and files to automate reporting and verification.

Loading...

This means that, at least in theory, the State secures a privileged channel inside the heart of the smartphone, capable of collecting and cross-referencing extremely sensitive data. The government insists that the app only serves to block stolen phones and report fraud, but the mistrust stems from the combination of three elements: compulsoriness, impossibility of removal, and vagueness about how the data will be processed.

The point raised by many experts is one of principle: if today the app presents itself as an anti-fraud tool, tomorrow what will prevent an amendment or a new administrative order from expanding its functions, e.g. by adding more intrusive tracking modules, cross-referencing data with other state databases or integrating it with digital behaviour recognition systems?

The Internet Freedom Foundation, one of India's leading digital rights NGOs, spoke of a "profound and worrying expansion of executive control over personal devices", judging the blanket obligation to be disproportionate to the stated goal of targeting IMEI-related fraud.

But criticism is not only coming from activists and techies. The Congress Party, the main opposition force, branded the measure as 'dystopian' and 'beyond the bounds of the Constitution', directly evoking the right to privacy recognised by the Supreme Court in 2017.

The clash with big tech and the Apple case

On an industrial level, the directive threatens to open a front with the big global brands. Apple, which traditionally only pre-installs its own apps and prohibits governments and third parties from adding non-removable software before sale, faces a dilemma: accept the Indian exception or initiate a regulatory tug-of-war that could affect its already limited, but symbolically important, 4.5% of the Indian smartphone market.

Even for Android manufacturers, the knot is not trivial. Pre-installing a mandatory state app means overhauling the initial configuration experience, adapting interfaces and firmware, managing forced updates on millions of devices already in the sales chain, and assuming potential liability, including reputational liability, in the event of app abuse or security holes.

But the greatest risk, on a global level, is that of precedent. If India, a mega-market with hundreds of millions of smartphones, succeeds in imposing a non-removable government app on the global giants, it will be more difficult for the latter to fend off similar demands elsewhere.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti