India internet shutdowns and censorship

Doda's Two-Month VPN Ban Uses a Colonial-Era Nuisance Law to Do What India's Blocking Rules Cannot

Doda's DM banned VPNs district-wide under BNSS Section 163, bypassing IT Act blocking procedure and the Supreme Court's proportionality test from Anuradha Bhasin.

Doda's VPN Ban in Context People of Internet Research · India 2 months Duration of Doda VPN ban District-wide, covering individual… 2nd globally India's 2025 shutdown rank 65 shutdowns in 2025, the most of … 5 years VPN data retention required CERT-In's 2022 rule already forced… peopleofinternet.com
Doda's VPN Ban in Context People of Internet Research · India 2 months Duration of Doda VPN ban 2nd globally India's 2025 shutdown rank 5 years VPN data retention requir… peopleofinternet.com

Key Takeaways

On September 5, 2026, the District Magistrate of Doda, Jammu & Kashmir, Krishan Lal, ordered a two-month, district-wide ban on VPN use, invoking Section 163 of the Bharatiya Nagarik Suraksha Sanhita (BNSS) — the successor to Section 144 of the old Code of Criminal Procedure. The order covers individuals, institutions, cyber cafes, businesses and ISPs, carving out exceptions only for government-authorised use, and warns that violators face legal action (kimskashmir.com). The stated justification: VPNs were allegedly being used to "circumvent lawful cyber restrictions" and spread "inflammatory material" that could threaten public order.

The case for it

Doda sits in a district with a live counter-terrorism footprint, and district magistrates facing an imminent, specific threat — a planned assembly, a communal flashpoint, a verified plot — do need some fast, discretionary tool that doesn't wait on a multi-agency committee. Encrypted tunnels genuinely do let banned content back in after a targeted block, and a magistrate weighing a narrow window before an anniversary or protest date has a real operational problem to solve. If the order were tightly scoped, short, and paired with public evidence of the specific threat, the criticism here would be much weaker.

Why the vehicle matters

But Section 163 was written for physical unlawful assemblies, not encrypted traffic. It lets a magistrate act unilaterally and often ex parte, without the layered review that India's own digital-blocking law requires. Section 69A of the IT Act, 2000 — the actual blocking regime — routes website and app takedowns through a review committee and requires reasoned, generally published orders. Section 163 has neither: a single official's signature is sufficient, and the order takes effect immediately. The Internet Freedom Foundation has flagged this precise pattern before, noting that district-level blocking orders under Section 163 (and its predecessor Section 144) have circumvented the Section 69A regime without the factual specificity that emergency powers are supposed to require.

The Supreme Court already drew the relevant line. In Anuradha Bhasin v. Union of India (January 10, 2020), decided after the 2019 Kashmir communications blackout, the Court held that any restriction on internet access must clear a four-part proportionality test — a legitimate aim, a rational connection to that aim, no less-restrictive alternative available, and a benefit that outweighs the harm — and ruled that indefinite suspensions are impermissible, that orders must be reviewed periodically as the underlying threat evolves, and that they must be published so citizens can challenge them (indiankanoon.org). A blanket, fixed-term ban on an entire technology, for an entire district, covering every business and ISP, sits uneasily with a test that specifically asks whether a narrower measure would have worked.

Doda is also not a one-off. Medianama reported that VPN services were suspended for two months in J&K's Rajouri and Poonch districts in December 2025 — the same instrument, the same duration, a different district months earlier. A tool meant for a single urgent nuisance is becoming a standing quarterly practice in the Union Territory.

The market context

This ban lands on an industry India has already reshaped once. CERT-In's April 28, 2022 directive under Section 70B of the IT Act required VPN providers to register and retain customer names, IP addresses, and usage records for five years (cert-in.org.in). SFLC.in's contemporaneous analysis noted that the rule broke VPN providers' traditional no-log model and pushed major players including NordVPN and ExpressVPN to pull their physical servers out of India rather than comply (sflc.in). Doda's order goes further still — it doesn't regulate VPN providers, it prohibits use of the technology outright, for everyone in the district, including the small businesses and cyber cafes that rely on it for basic network security.

Namrata Maheshwari, senior policy counsel at Access Now, called the order "unnecessary and disproportionate," adding that "VPNs are not illegal" and that restrictions on the right to information "ought to be legal, necessary, and proportionate — a standard this ban does not meet," noting that less intrusive options were available (TechRadar via Yahoo News). That criticism lands against a stark backdrop: Access Now's #KeepItOn coalition recorded 65 internet shutdowns in India in 2025 — second only to Myanmar globally, and the highest count among the world's democracies (Access Now).

What proportionate would look like

A magistrate genuinely worried about VPNs enabling access to specific banned content already has a remedy: Section 69A blocking orders, with review-committee oversight, aimed at the actual sites or apps in question. Prohibiting the technology itself, for an entire district's population and businesses, for a flat two months, is the least targeted version of that fix available — and it is precisely the kind of order the Supreme Court told India's magistrates, six years ago, to stop issuing.

Sources & Citations

  1. Kashmir Independent Media Service — original order report
  2. Anuradha Bhasin v. Union of India (Supreme Court, 2020)
  3. CERT-In Directions under Section 70B, IT Act (28 April 2022)
  4. SFLC.in analysis of CERT-In VPN directive
  5. Access Now — Internet Shutdowns in 2025 report
  6. TechRadar expert reaction (via Yahoo News)