Google Is Forcing Every Android Developer to Hand Over Their Government ID. Even If They Never Used Google.
Key Takeaways:
- Starting September 2026, Google will require every Android developer to submit government ID, a legal name, physical address, phone number, and a $25 fee, even developers who never use the Google Play Store
- Any app from an unregistered developer will be blocked from installation on certified Android devices, which cover over 95% of all Android-compatible phones outside China
- Brave, the Electronic Frontier Foundation, the Tor Project, F-Droid, and more than 40 other organizations have signed an open letter demanding Google withdraw the policy
- The requirement applies to developers distributing through alternative stores like F-Droid, Samsung Galaxy Store, direct downloads, and enterprise distribution channels
- India's DPDP Act 2023 raises immediate questions about how Google will handle this centralized database of developer identities, and what Indian developers' rights are when that data is processed or shared
You wrote an app. You put it on F-Droid, or posted a direct APK download, or distributed it through your company's internal server. You never touched Google Play. You never agreed to Google's developer terms. You never had any relationship with Google at all.
Starting September 2026, Google will block your app from running on Android phones anyway.
Not because your app is malicious. Not because it violates any law. Because you did not submit your government-issued ID, your legal name, your home address, your phone number, and a $25 fee to a Google registration database.
That is not a hypothetical. It is Google's announced policy for the Android ecosystem, and it has sparked the largest coordinated developer pushback in years. Brave, the Electronic Frontier Foundation, the Tor Project, Article 19, the Free Software Foundation, F-Droid, Fastmail, Vivaldi, and more than 40 other organizations have signed an open letter demanding Google withdraw the requirement entirely.
The letter was copied directly to competition regulators worldwide. That is the signal that the coalition has concluded Google will not move without external pressure.
What Google Is Actually Requiring
The policy entered early preview in November 2025 and opened to all developers in March 2026. Enforcement becomes mandatory in September 2026, beginning with Brazil, Indonesia, Singapore, and Thailand. More regions follow after that.
To remain able to distribute apps to Android devices, every developer must complete the following: pay a one-time $25 fee, create a Google payment profile, provide a legal name, physical address, and email, submit government-issued identification, prove ownership of app signing keys, agree to Google's terms and conditions, and pre-declare current and future app identifiers.
That last item deserves attention. Pre-declaring future app identifiers means a developer must register apps with Google before those apps exist. The dependency runs in one direction: you seek Google's approval before you build. Not after.
The requirement applies regardless of how apps are distributed. Developers using the Samsung Galaxy Store, the Amazon Appstore, F-Droid, a personal website, a direct file transfer, or an enterprise internal distribution system are all covered. The only carved-out exceptions are custom Android builds like GrapheneOS, LineageOS, and /e/OS, which run AOSP without Google's certification. Those cover a small fraction of devices. Certified Android devices constitute over 95% of all Android-compatible devices outside of China. That is the market the policy controls.
The Database Problem Nobody Is Talking About
Google's developer verification policy creates a centralized database, controlled by a single corporation, containing the real-world identity of every person who writes software for Android.
Think about who that database contains.
Developers who build privacy-first browsers. Encrypted messaging tools. VPN applications. Tor-based anonymization software. Journaling apps used by activists in hostile political environments. Security research tools. Applications built for journalists. Anonymous whistleblowing platforms. Every developer of any of these tools, regardless of whether they have ever interacted with Google's Play Store, must hand their government ID to Google or lose the ability to distribute.
These developers are unlikely to trust Google and might stop developing for Android, leaving vulnerable users much worse off.
The coalition's open letter framed it plainly: mandatory registration imposes barriers on developers with limited resources, researchers, and academics, raises concerns about privacy and surveillance, extends Google's opaque, unaccountable app review process to a broader set of developers, and raises antitrust and regulatory concerns.
Google's own framing is that this is identity confirmation rather than content review, comparable to an ID check at the airport. But an airport ID check does not create a permanent, searchable database of every traveler's identity linked to every trip they have ever taken, controlled by a single private company with a commercial interest in surveillance infrastructure.
This Is Part of a Pattern
Google has repeatedly proposed mechanisms that expand its control over the platforms it operates. The Android developer registry is not an isolated policy decision. It sits in a sequence.
Manifest V2 deprecation reduced what browser extensions can do, weakening tracker blockers and privacy tools. Google's AMP Project inserted Google between users and websites they wanted to visit. Privacy Sandbox attempted to use Google's browser dominance to force participation in advertising infrastructure. Each of these followed the same structural pattern: Google uses its platform position to insert itself into activities where users and developers had not asked for Google's involvement, framing the change as beneficial.
AMP was eventually walked back under pressure. Privacy Sandbox was walked back under pressure. The Android developer registry is the current version of that same pattern.
Google built its mobile dominance partly on the argument that Android was different: more open, less controlled, a genuine alternative to Apple's walled garden. This policy narrows that difference considerably.
The Android Developer Verification program is a grievous breach of trust with the free and open-source community that helped propel Android to the dominant position it holds today in the mobile computing world.
The Antitrust Dimension
The open letter was addressed to Alphabet and Google CEO Sundar Pichai, co-founders Larry Page and Sergey Brin, and Vijaya Kaza, General Manager for App and Ecosystem Trust. It was copied to competition regulators worldwide.
That choice is deliberate. The shift from months of private outreach to a coordinated public letter, copied directly to regulators, indicates the coalition has concluded Google will not move voluntarily. For organizations like F-Droid and the EFF, a public record before competition authorities creates pressure that private correspondence does not: regulators reviewing future antitrust proceedings will have documented evidence of how the policy was contested before enforcement began.
Google currently faces antitrust scrutiny on multiple fronts in the US and EU. The EU Digital Markets Act creates explicit obligations around platform openness. A policy that extends Google's gatekeeping authority from its own Play Store to every alternative distribution channel on Android is precisely the kind of conduct DMA proceedings are designed to address.
Signatories argue this move centralizes control, mirroring Apple's iOS ecosystem and threatening Android's open nature, innovation, and user freedom. They contend that Google is extending its gatekeeping authority beyond its own marketplace into channels where it has no legitimate operational role.
F-Droid board member Marc Prud'hommeaux has made contact with Brazilian regulators, US antitrust officials across four states, and EU policy bodies. No formal investigation has opened as of early March 2026. The regulatory attention, however, is real and documented.
What This Means for Indian Android Developers
India has one of the largest Android developer communities in the world. The country is the third-largest app market by download volume, and a substantial share of Android development for global markets happens in Indian studios, agencies, and individual developer accounts.
The September 2026 enforcement timeline does not initially list India in its first-phase countries. Brazil, Indonesia, Singapore, and Thailand are the launch markets for hard enforcement. India will follow. The question is not whether Indian developers will be required to submit government ID to Google. It is when.
For Indian developers who distribute apps outside Google Play, through enterprise MDM systems, direct APK downloads, or alternative stores, the requirement creates several immediate concerns.
Under the DPDP Act 2023: Google's developer registry will constitute a database of personal data about Indian individuals, including government ID documents. When Google processes this data, it acts as a Data Fiduciary or Data Processor under the DPDP Act, depending on how the relationship is structured. Indian developers who submit their Aadhaar or passport data to Google's registry have a right to know how that data is stored, how long it is retained, whether it is shared with third parties, and what happens to it if their developer account is terminated.
None of those answers are currently clear from Google's published policy. That absence is itself a compliance concern.
For enterprise app distribution: Indian companies that build internal tools, distributed to employees via enterprise channels rather than the Play Store, will need to register those tools and their developers with Google. An enterprise that previously kept its internal software distribution entirely within its own infrastructure now has a dependency on Google's registry that it did not consent to and cannot opt out of.
For security and privacy tool developers: Indian developers building VPNs, encrypted communication tools, or privacy-protective applications face the same risk identified in the open letter: they must hand their real identity to a corporation whose business model is built on surveillance infrastructure. For developers working with journalists, activists, or other sensitive user communities, that is not a formality. It is a threat model.
What the Three Core Demands Are
The open letter at keepandroidopen.org asks Google to do three specific things.
First, rescind the mandatory registration requirement for developers distributing outside Google Play entirely. The argument is that Google's authority extends to its own platform and not to alternative distribution channels that operate independently of Google's infrastructure.
Second, engage transparently with developers and civil society on security improvements that respect the platform's historical openness. The letter does not dismiss security concerns. It rejects the premise that a centralized government ID database controlled by Google is the correct solution, given that Android already includes multiple existing security mechanisms that do not require identity registration.
Third, commit to platform neutrality. Google should not use its certification authority over Android hardware to extend gatekeeping power into distribution channels it does not own or operate.
Frequently Asked Questions
Q: Does this affect Indian developers right now?
A: The verification console is open globally as of March 2026. Indian developers can and are expected to register now, though hard enforcement where unregistered apps are blocked from installation begins in September 2026 in the first-phase countries. India has not been listed in the first-phase rollout, but the policy applies globally and enforcement will reach India. The registration process is available and running today.
Q: What happens to apps from unregistered developers after September 2026?
A: Starting in September 2026, Android will require all apps to be registered by verified developers in order to be installed on certified Android devices. Apps from developers who have not completed registration will be blocked from installation on those devices. Google has referenced a potential "advanced flow" that might allow experienced users to install unverified software, but has refused to confirm what that will look like before enforcement begins, leaving developers with no confirmed alternative path.
Q: Does the policy affect apps already installed on Android devices?
A: The current policy language addresses installation rather than operation of already-installed apps. However, the practical implication for future updates, re-installation after device resets, and new user acquisition is significant for any developer who has not registered.
Q: What protections do Indian developers have under the DPDP Act when submitting data to Google's registry?
A: The DPDP Act 2023 gives Data Principals, which includes Indian developers submitting personal data, the right to access information about how their data is processed, the right to correction, the right to erasure, and the right to grieve. Google, as the entity collecting and processing that data, must comply with the Act's obligations when handling data of Indian individuals. Whether Google's current privacy terms and practices for the developer registry satisfy DPDP Act requirements is a question without a clear published answer. Indian developers submitting government ID to Google's registry should document what they submitted and when, and retain copies of any acknowledgment.
Q: Is there any legal avenue in India to challenge this requirement?
A: Indian developers facing harm from this policy have potential avenues under competition law through the Competition Commission of India, under consumer protection law if they have paid fees based on representations that are later changed, and through DPDP Act grievance mechanisms once the Data Protection Board is constituted. The CCI has previously investigated Google's conduct in Android-related markets and issued significant findings. A coordinated complaint from Indian developer organizations about this policy would be consistent with the kind of antitrust engagement that has already begun in other jurisdictions.
Q: Can Indian enterprises avoid this by using AOSP-based devices?
A: Custom Android builds like GrapheneOS, LineageOS, and /e/OS are carved out of the policy because they do not use Google's certification. Enterprises willing to deploy and manage AOSP-based device fleets without Google certification can avoid the registration requirement. For most enterprises, the operational cost of moving to non-certified Android is prohibitive. For privacy-sensitive organizations or those with specific data sovereignty requirements, it may be worth evaluating.
Indian Android developers and enterprises with questions about data rights under the DPDP Act 2023, competitive conduct by platform operators, or digital privacy obligations have advisory options. The LLM Advocates team advises clients across India on cyber law, AI governance, and data protection compliance. Contact us at contact@llmadvocates.com or call +91-8572022292.