Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

India mandates pre-installed cyber safety app on new phones

India’s telecom ministry has directed smartphone makers to pre-install a government cyber safety app, Sanchar Saathi, on all new devices within 90 days of a November 28 order.

The Sanchar Saathi app, developed by India’s telecom ministry, helps users report suspicious calls, verify device IMEI numbers, and block stolen phones via a central registry.

The order also requires manufacturers to push the app to phones already in the supply chain through software updates, and users will not be able to disable it.

The government says the app is needed to address telecom cybersecurity risks, including scams and misuse involving duplicated or spoofed IMEI numbers.

🔗 Source: Reuters

🧠 Food for thought

Implications, context, and why it matters.

Enforcement remains vague for original equipment manufacturers (OEMs)

  • Tampering with calling line identification (CLI, the caller ID information) can bring fines up to Rs 50 lakh or jail up to three years, or both 1. The sources do not mention a matching law or penalty for the Sanchar Saathi pre-install rule.
  • The reported order cites no specific legal power or penalties. Phone makers remain unsure about who is liable, whether OEM, distributor, or retailer, and what event triggers non-compliance.
  • The 90 day window is tight. OEMs must fit firmware work, carrier reviews, and regional variants into release cycles. The order asks makers to push the app to units already in the supply chain through updates. Treatment of devices sold at retail stays unclear.
  • Apple uses a walled garden that limits pre-installed third party apps before sale. The rule requires a non-removable app, which raises questions about an exemption or another path to comply.

Enterprise mobility management (EMM) and regulatory technology (regtech) vendors can build Central Equipment Identity Register (CEIR) toolkits

  • India’s Department of Telecommunications (DoT) runs CEIR for International Mobile Equipment Identity (IMEI) blocking, verification 12. It also runs the ICDR portal, a government system for telecom device import certificates 3. The sources give no public detail on over the air (OTA) app rollout or compliance audit trails.
  • EMM firms plus systems integrators (IT providers that combine software and hardware into working solutions) can ship ready tools. These tools handle over the air install, create compliance logs, and connect to CEIR IMEI checks 2 for reports.
  • For OEMs, distributors, and refurbishers (companies that restore used devices for resale), a kit that checks IMEI status before sale would help. It would install Sanchar Saathi before activation and record audit trails under the 90 day rule.
  • Regtech vendors can sell Software as a Service (SaaS) dashboards that roll up compliance metrics across supply chains. Early rollouts would help before enforcement penalties are clarified.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.