Apple, Samsung Push Back on India's Mandatory Sanchar Saathi App Mandate

The app will have access to call logs, message metadata, contact information.
Experts warn that without clear data governance policies, the fraud-prevention mandate could become a surveillance tool.
Mark

So the Indian government just ordered every phone maker to put this fraud-reporting app on every phone they sell there. That seems like a big move.

Mimi

It is. Mobile fraud is a real problem in India—scammers spoofing numbers, phishing texts, stealing money. The app lets people report fraudulent calls and messages directly to telecom authorities. It's a crowdsourced early warning system.

Luke

But why are Apple and Samsung pushing back if the goal is just fraud prevention?

Mimi

Because mandatory pre-installation on their devices is a control issue. These companies design their platforms carefully. Being forced to include a government app changes that equation. There's also the compliance burden—updating manufacturing, coordinating across device models, pushing updates to existing phones.

Mark

That makes sense from a business perspective. But is the security benefit real?

Mimi

Yes. Anupam Shrivastava, who ran BSNL, called it a strong and necessary move. The fraud problem is genuine. But he also said the government needs to clarify exactly what data the app collects and how it's used.

Luke

That's the real issue, isn't it? We don't actually know yet what data access policies will govern the app. That's not in the order.

Mimi

Exactly. The app will have access to call logs, message metadata, contact information. Without transparent policies on collection, retention, and sharing, manufacturers worry about liability. Users should worry about surveillance.

Mark

So this could go either way—the government holds firm, or they negotiate something different.

Luke

The ninety-day deadline is tight. Apple says it may not comply in the current form. Samsung is reviewing. We don't know yet if the government will soften the requirements or if manufacturers will simply have to absorb it.

Mimi

The outcome will probably shape how other democracies think about mandating government apps on consumer devices.

  • India's 90-day deadline is already ticking, and two of the world's most powerful technology companies are signaling they will not simply fall in line.
  • Apple has indicated the mandate in its current form may be unworkable, while Samsung is moving cautiously through internal review — leaving the government's order in a state of open defiance.
  • The friction runs deeper than logistics: mandatory pre-installation of a state application on consumer devices cuts against the platform control that Apple and Samsung have spent years building as a competitive advantage.
  • Security experts and former telecom officials acknowledge the genuine threat of mobile fraud in India, but warn that the app's access to call logs, message metadata, and contact data demands transparent governance before any rollout.
  • Without clear policies on data retention, access, and law enforcement sharing, the line between fraud-fighting tool and surveillance infrastructure remains dangerously blurred.
  • Negotiations now underway could either soften the mandate's scope, force a reckoning over data governance, or set a precedent that other governments will watch closely.

In the closing days of November, India's Department of Telecom issued a directive requiring all new and existing smartphones to carry a government fraud-reporting application — a move that places the world's largest phone makers in direct tension with one of their fastest-growing markets. Apple and Samsung, guardians of tightly controlled digital ecosystems, are preparing to negotiate rather than comply, raising questions that extend well beyond one app: who governs the devices in our pockets, and at what cost to privacy does public safety come? The outcome of these talks may quietly redraw the boundaries between state authority, corporate sovereignty, and the rights of ordinary users.

On November 28, India's Department of Telecom ordered every smartphone sold or imported into the country to come pre-installed with Sanchar Saathi — a government application built to let users report fraudulent calls and messages directly to telecom authorities. Devices already in circulation must receive the app through software updates. The directive carries no exceptions, and a ninety-day clock is running.

Apple and Samsung are not prepared to accept the order quietly. Sources indicate Apple will seek negotiations, arguing that compliance in the mandate's current form may not be feasible given how tightly the company controls its platform. Samsung is conducting its own review before engaging officials. Neither company has spoken publicly, but the resistance is real — mandatory government applications sit uncomfortably alongside the platform governance philosophies both companies have built their reputations on.

The compliance challenge is also practical. Manufacturers must ensure the app works across dozens of device models, operating system versions, and regional configurations, while simultaneously managing supply chains and pushing updates to hundreds of millions of existing handsets.

The security case behind the mandate, however, is not easily dismissed. Mobile fraud has become a serious and widespread problem in India, with scammers exploiting spoofed numbers, phishing messages, and social engineering to drain accounts and steal personal data at scale. Anupam Shrivastava, former BSNL chairman and a board member at handset maker Lava International, described the directive as a necessary response to a genuine national crisis — acknowledging the burden on manufacturers while defending the underlying goal.

But Shrivastava also raised the concern that shadows the entire debate: data privacy. Sanchar Saathi requires access to call logs, message metadata, and contact information to function as intended. The government has not yet published policies explaining what data the app collects, how long it is stored, or who may access it. Industry voices are pressing for that clarity before implementation moves forward, warning that without transparent data governance, a fraud-fighting tool risks becoming something harder to distinguish from a surveillance instrument.

The negotiations ahead will decide whether the mandate holds, softens, or finds a middle path. What is already clear is that the outcome will carry consequences well beyond India — a signal to governments and manufacturers worldwide about where the boundaries of state authority over personal devices are being drawn.

On November 28, India's Department of Telecom issued an order that will reshape how millions of Indians receive their smartphones. Every handset manufactured domestically or imported into the country after ninety days must come with Sanchar Saathi pre-installed—a government fraud-reporting application designed to combat mobile phone scams and strengthen the nation's telecom security infrastructure. For existing devices already in users' hands, the app must arrive through software updates. The directive applies to all manufacturers and importers without exception.

Apple and Samsung, two of the world's largest phone makers, are now preparing to push back. Sources close to Apple indicate the company will seek negotiations with the government, arguing that compliance in the mandate's current form may not be feasible. Samsung is similarly reviewing the order and preparing its own discussions with officials before moving toward implementation. Neither company has publicly stated their objections, but the friction is real: mandatory pre-installation of government applications on consumer devices raises questions about control, user choice, and the technical architecture of operating systems that these companies have spent years perfecting.

The compliance burden is substantial. Handset makers must ensure the app functions across dozens of device models, operating system versions, and regional configurations. They must coordinate with their supply chains, update manufacturing processes, and manage the logistics of pushing updates to hundreds of millions of existing phones. For a company like Apple, which tightly controls what appears on its devices and how users interact with them, the directive represents an unusual constraint on its own platform governance.

But the security argument behind the mandate is not trivial. Mobile phone fraud has become endemic in India. Scammers use spoofed caller IDs, phishing texts, and social engineering to steal money and personal data from millions of users annually. The Sanchar Saathi app allows people to report fraudulent calls and messages directly to telecom authorities, creating a crowdsourced early warning system. Anupam Shrivastava, former chairman of state-owned BSNL and an independent director at handset maker Lava International, called the mandate a necessary and forceful response to a genuine national problem. He acknowledged the compliance burden manufacturers face but emphasized that the security benefit justifies the inconvenience.

Yet Shrivastava also named the elephant in the room: data privacy. The Sanchar Saathi app will have access to call logs, message metadata, and user contact information—the raw material needed to identify fraud patterns. The government has not yet published detailed policies governing what data the app collects, how long it retains information, who can access it, and under what circumstances it might be shared with law enforcement or other agencies. Industry voices are demanding clarity on these points before implementation proceeds. Without transparent data governance, the app risks becoming a surveillance tool as much as a security tool, and manufacturers worry about the liability they might face if user data is mishandled.

The coming negotiations will determine whether the mandate stands as written or whether a compromise emerges. Apple's signal that it may not comply in the current form suggests the company is willing to challenge the order rather than simply absorb it. Samsung's review process indicates a more cautious approach, but the outcome is uncertain. The Department of Telecom has set a ninety-day clock, which means decisions must come quickly. What remains to be seen is whether the government will hold firm on the mandate, whether it will soften the requirements to ease manufacturer concerns, or whether a middle path emerges that preserves the security goal while addressing legitimate questions about data access and user privacy.

The mandate to pre-install the Sanchar Saathi app is a strong and right move to combat mobile handset fraud and enhance national telecom cybersecurity, even when it imposes a significant compliance burden on handset manufacturers.
— Anupam Shrivastava, former BSNL chairman and independent director at Lava International
It is extremely critical that DOT should clarify the app's exact data access and usage policies to mitigate users' concerns about their digital and personal privacy.
— Anupam Shrivastava
Contattaci Domande frequenti