

A senior SpaceX executive said on Wednesday that Starlink is "ready to serve in India, once India is ready." The company has its licence and its space regulator approval, but it is still waiting for security clearance and other regulatory approvals. To see why security is the sticking point, one needs to go back to Mumbai in 2008.
The 26/11 attackers carried a satellite phone (UAE-based Thuraya) and used it to talk to their handlers in Pakistan. India's regulation of satellite phones was set up for national security after that. The worry was that a satellite phone does not use any Indian mobile network, so agencies cannot easily intercept or track it.
That is why one needs a DoT licence for a sat phone today, with only specific types of Inmarsat terminals permitted. In practice, DoT permits are restricted to Inmarsat phones. BSNL has provided satellite service to the government, security and rescue agencies. Foreigners have been stopped at airports for carrying Thuraya and similar phones. At sea, a 2012 shipping circular reportedly bans Thuraya, Iridium and similar phones in Indian waters.
Similar security concerns, different technology
Starlink, developed by SpaceX, is a satellite internet service providing broadband via low Earth orbit satellites. It plans to launch 42,000 satellites globally to form a mega-constellation providing global coverage. Although operational in over 60 countries, including Bangladesh and Bhutan, it lacks full regulatory approval in India, where foreign satellite services face restrictions.
Technology wise, Inmarsat and Thuraya use a few big satellites parked about 36,000 km up. They mainly carry calls and light data. Starlink uses thousands of small satellites flying low, at about 550 km, equipped with phased-array and parabolic antennas. That gives fast broadband with low latency.
India has authorised Starlink's first-generation network of 4,408 satellites, out of roughly 11,000 in orbit worldwide. The user needs only a small dish, which can connect a phone or laptop through Wi-Fi. The dish talks to a satellite overhead, the satellite sends the signal down to a ground station called a gateway, and the gateway connects to the internet. That is why India insists the gateway must be on Indian soil. It is the one place where agencies can watch and intercept traffic. In case of Starlink, the company has set up 20 gateway sites comprising hundreds of antennas.
Even so, the security concerns are almost the same as for sat phones. In both cases the user sits outside the normal phone and internet system. If the signal goes from dish to satellite to a gateway abroad, Indian agencies have no local network to tap. The device can be carried anywhere and used without a local SIM or normal KYC checks. It works where there is no mobile coverage, such as border hills, forests and the open sea. It can also beat internet shutdowns.
Manipur seizure and security conditions
The Myanmar border shows the same fear playing out. In December 2024, the Indian Army recovered weapons and a dish and receiver with a Starlink logo on it from a militant hideout in Manipur's Imphal East district. The device was labeled "RPF/PLA". Military officers said a militant group was using the device and that it was likely smuggled across the porous border with Myanmar, where rebel groups' use of Starlink has been documented. The discovery raised concerns about circumvention of geographic restrictions by non-state actors.
Earlier that month, police sent Starlink a legal demand for purchase details of a device found on smugglers caught at sea with $4.2 billion worth of methamphetamine. Police suspect the smugglers used it to navigate. SpaceX founder Elon Musk replied on X that Starlink beams were "turned off over India" and "never on in the first place."
This is why the government has written so many security conditions in 2025. The DoT added new security rules to the Unified Licence for satellite internet firms. Each gateway site needs separate security clearance, and lawful interception and monitoring must work there before launch. The core network, data centres and DNS must be in India, all user traffic must pass through Indian gateways, and Indian data cannot be copied or decrypted abroad. Terminals cannot link to each other through satellites and bypass Indian infrastructure. Companies must block banned websites, share metadata with the Telecom Security Operation Centre, and deny or suspend service to users or areas when security agencies order it.
Every terminal must be registered and authenticated, and foreign devices must be verified first. Operators must give authorities the live location of terminals on request. Geo-fencing must stop signals spilling across borders, and security agencies get special monitoring access within 50 km of land borders and up to 200 nautical miles off the coast. Companies must also make at least 20% of their ground equipment in India within five years of launch, and are encouraged to support NavIC in terminals by 2029.
Reportedly, Starlink has agreed to these security norms. As the executive reinforced on Wednesday at the India Mobile Congress, "We've built our Starlink operations specifically for India in recognition of Indian security requirements and other regulations, establishing controls at every layer for India and keeping India user data within India."
Where approvals stand
On approvals, Starlink has cleared two big steps. It got its GMPCS licence from the DoT in June 2025. IN-SPACe then gave final approval on July 8, 2025, valid until July 7, 2030. It still needs spectrum from the DoT, final security clearance for its gateway sites, and FDI approval.
The other two companies are in a similar position, and they started earlier. Bharti-backed Eutelsat OneWeb holds a DoT licence and got its IN-SPACe approval in November 2023, and Jio Satellite Communications, the Jio-SES venture, got its IN-SPACe approval in June 2024. Both received trial spectrum in 2024 and were later given six-month extensions while they await final security clearances. Like Starlink, they still need final spectrum assignment and security clearance.