In a recent LinkedIn post, Chirag Goswami highlights a significant development in India’s approach to cybersecurity, which he argues may be encroaching on user privacy. Goswami details the government’s mandate for smartphone manufacturers to pre-install a cybersecurity app, Sanchar Saathi, designed to combat cyber fraud.
Mandatory App and Broad Permissions
Goswami points out the extensive permissions granted to the Sanchar Saathi app, noting the potential for deep surveillance. He states:
The Sanchar Saathi app can:
• Make and manage calls
• Access your messages
• Read your files and photos
• Use your camera
• View call/message logs
A critical aspect highlighted by Goswami is the non-negotiable nature of the app’s installation. He explains that manufacturers have a strict 90-day deadline to comply, with no option for users to opt-out or disable the core functions of the application. This lack of user control is a central concern in his analysis.
Potential Global Precedent and Surveillance Concerns
The implications of this policy extend far beyond India’s borders, according to Goswami. He emphasizes the sheer scale of the Indian smartphone market, with over 1.2 billion users, suggesting that any policy adopted here could set a global precedent. Goswami warns:
If this sticks:
• Surveillance-first cybersecurity becomes normal
• Apple faces a major compliance showdown
• Other countries may copy this model
Goswami draws parallels to similar initiatives in other countries, such as China’s MAX messenger and Russia’s mandatory communication apps, framing India’s move as part of a broader trend towards what he terms “surveillance-first cybersecurity.” He argues that while the stated goal is to prevent fraud and block stolen phones, the method employed raises serious questions about user consent and privacy.
“Security Without Consent Is Surveillance”
Goswami articulates a core principle of digital rights in his analysis, stating:
Security without consent is surveillance.
He further elaborates on this point, suggesting that the mandatory, non-removable nature of the app, coupled with its comprehensive access to device data, moves in the wrong direction for true cybersecurity. In Goswami’s view, genuine cybersecurity should foster trust rather than erode it through intrusive pre-installation practices.
The post concludes by pointing out a discrepancy between public statements and official orders regarding the app’s voluntary nature. Goswami notes that while the minister stated the app is “voluntary,” the written order suggests otherwise, leaving the true status uncertain.
📝 About This Content
This article is based on insights shared by Chirag Goswami on LinkedIn.
📅 Originally posted on December 6, 2025 | View original post on LinkedIn →