Mandatory govt app on phones a concern

India has entered a troubling new phase of digital governance. In an order issued quietly and without public consultation, the Department of Telecommunications has directed smartphone manufacturers to preload every new device with Sanchar Saathi, a State-run security app that users cannot remove. The directive, dated November 28, gives companies 90 days to comply and instructs that the app be pushed to phones already in the supply chain through software updates. The public was told nothing. The order was never placed in the public domain.
On Monday, after widespread criticism, Union Communications Minister Jyotiraditya Scindia said users would be able to delete the app if they wished. But this clarification does not change the core reality: the mandate still forces the installation of a government app onto every new phone sold in India. A removable app is not the same as a voluntary one. If deletion truly settled the issue, the government would not need to compel installation in the first place. Scindia’s comment softens the optics, not the directive.
India has never before required compulsory pre-installation of a government digital tool on every smartphone. Even during the pandemic, Aarogya Setu could be deleted. This mandate goes much further. It embeds the state directly into the operating system layer, creating a precedent future administrations could expand with little resistance.
That alone should have triggered public debate. Instead, the government has offered no explanation for why existing mechanisms like IMEI blocking — the long-standing system through which telecom operators disable lost or stolen phones using a device’s unique identifier — are suddenly deemed insufficient. Nothing in the DoT order shows why this function requires an undeletable or even mandatory app.
What worries experts most is the structural risk. Once an app cannot be refused, its permissions can grow through updates users cannot decline. Access that might begin with device information could later expand to messages, storage, call logs or location history. Mission creep in technology rarely arrives all at once; it expands quietly through incremental updates. Digital rights commentator Nikhil Pahwa has warned that forced installation normalises a template for broader digital monitoring. If one compulsory app becomes acceptable, the next step could be a mandatory digital ID layer, DigiYatra integration, restrictions on VPN use or tools that log browsing patterns. Some technologists note that system-level apps can, in theory, read unencrypted messages, scan local files or monitor keystrokes. If tied to network services, that capability could extend to laptops or tablets using the phone’s hotspot.
The manner in which the mandate was introduced intensifies these concerns. Reuters reported that the directive was circulated privately to select manufacturers and not released publicly. Policy decisions with surveillance implications should never be implemented through undisclosed instructions to private companies. The comparison to past controversies is therefore unavoidable. Pahwa — one of India’s most credible voices on digital rights — has pointed out that the secrecy and depth of access demanded here echo patterns that once enabled state-grade spyware like Pegasus, even though the technologies differ. The parallel is not about identical function; it is about the method: opacity, access and irreversibility.
India’s Digital Personal Data Protection Act compounds the anxiety. The law grants sweeping exemptions to the government on grounds of national security and public order. When those exemptions intersect with a compulsory app that can be pushed into phones without consent, the checks that protect citizens begin to weaken. Users do not know what data Sanchar Saathi collects, how long it is retained, who may access it or whether future updates might alter its behaviour. They cannot refuse the installation. They cannot opt out of the system that inserts it.
This goes beyond privacy. It changes the balance of power between citizens and the State. A smartphone today contains financial records, health information, authentication keys, photographs, location history, work material and private conversations. Granting the state a permanent place inside that device recasts the very meaning of digital autonomy.
There are practical implications too. Global manufacturers such as Apple have resisted government backdoor demands even in high-profile FBI investigations. If India requires OS-level modifications unique to its market, companies may be forced to weaken platform security or fragment their global systems. Neither outcome benefits users.
None of this diminishes the need to curb telecom fraud. But security achieved through secrecy is not security. A transparent process with public consultation, independent audits and clearly defined limits would have strengthened trust. Silence has done the opposite. Citizens deserve straight answers: What exactly will Sanchar Saathi collect? Who controls that data? What oversight exists? Can its powers expand without warning? And why must it be installed at all if its deletion is supposedly harmless?
A mandatory app — deletable or not — marks a shift in how the state sees its role inside citizens’ digital lives. In the name of safety, India must not surrender the digital freedoms that make citizenship meaningful.

Share This Article