India has made a proposal to smartphone makers that would require them to share their source code with the government, and with that, the government also requires these companies to make several new software changes as a part of safeguards and security protocols that need to be adhered to. This definitely is not going smoothly with the smartphone-making giants who are in opposition of the said measures behind the scenes; Apple and Samsung are amongst those giants.
The smartphone makers and tech giants have countered the proposition, saying that the 83 security standards, which also include the requirement to alert the government to major software updates, lack any global precedent and risk revealing proprietary details. This is according to four people familiar with the discussion and Reuters' review of confidential government and industry documents.
Why India Wants To Move In This Direction
The move forms part of Prime Minister Narendra Modi’s strategy to enhance user data security, addressing the rising incidents of online fraud and data breaches in India, which has nearly 750 million smartphones in use.
IT Secretary S. Krishnan told Reuters that "any legitimate concerns of the industry will be addressed with an open mind," adding it was "premature to read more into it." The ministry has denied any further comments on the matter, as discussions and consultations with tech companies are still ongoing with regard to the proposal.
Tug Of War Between The Govt And Tech Giants
Apple, Samsung, Google, Xiaomi and MAIT, the industry body representing these firms in India, declined to comment on the matter.
Technology companies have clashed with Indian regulatory demands earlier as well. In a recent instance, the government rolled back a directive that would have required smartphones to carry a state-backed cyber safety app, following concerns around surveillance. That said, similar resistance did not work last year, when authorities went ahead with strict security testing rules for cameras, citing fears linked to Chinese spying.
According to Counterpoint Research, Xiaomi and Samsung together control over a third of India’s smartphone market, with shares of 19% and 15%, respectively, while Apple’s presence stands at 5%. Both Xiaomi and Samsung rely on Google’s Android platform for their devices.
A key point of contention in the new Telecom Security Assurance Requirements is the demand for access to source code, the core software instructions that power smartphones. The documents show this code could be reviewed and, if required, tested at government-designated laboratories in India.
The proposed rules also push manufacturers to rework their software so users can remove pre-installed apps. In addition, companies would need to restrict apps from accessing cameras and microphones in the background to "avoid malicious usage".
"Industry raised concerns that globally security requirements have not been mandated by any country," an IT ministry document says, detailing the meetings that officials have held with tech giants like Apple, Samsung, Google and Xiaomi.
Now the latest security standards that were drafted in 2023 have become the centre stage of discussion as the government is considering their legal imposition. The IT ministry and tech executives have planned a meeting due on Tuesday, according to sources familiar with Reuters.
What Happens If the Proposal Is Implemented?
Source code is held sacred by smartphone makers, and a similar request was denied by Apple between 2014 and 2016 when China requested its source code. Not just that, but even the U.S. has tried to get its hands on it but has failed in its attempt.
India’s proposed rules on “vulnerability analysis” and “source code review” would force smartphone manufacturers to carry out a “complete security assessment”, after which Indian testing laboratories could verify those claims by reviewing and analysing source code.
“This is not possible ... due to secrecy and privacy,” MAIT said in a confidential document prepared in response to the government’s proposal and reviewed by Reuters. “Major countries in the EU, North America, Australia and Africa do not mandate these requirements.”
According to a source with direct knowledge of the matter, MAIT asked the ministry last week to withdraw the proposal.
Under the draft rules, smartphones would be required to run automatic and periodic malware scans. Manufacturers would also need to notify the National Centre for Communication Security about significant software updates and security patches before rolling them out to users, with the agency retaining the right to test those updates.
ALSO READ: Health-Tech Revolution 2026: Blood Sugar Tests Without Needles And Instant Food Allergy Detection
MAIT argued in its document that frequent malware scanning would lead to noticeable battery drain, while seeking prior government clearance for software updates is “impractical” because such fixes often need to be deployed quickly.
The proposals further call for phones to store system logs — digital records of device activity — for a minimum of 12 months on the device itself.
“There is not enough room on the device to store 1-year log events,” MAIT said in the document.
(Includes Agency Inputs)
