Why In News?

The Parliamentary Standing Committee on Communications and Information Technology warned Facebook that persistent non-compliance could invite reconsideration of its Section 79 safe harbour protection.

What is the Safe Harbour Principle?

Safe Harbour is a conditional legal immunity that protects intermediaries from liability for third-party content, provided they comply with statutory due diligence requirements.

Conditional Immunity

  • Platforms only get safe harbour if they:

    1. Act purely as passive transmitters of user data.

    2. Do not select the content, modify the data, or choose the content's recipients.

    3. Fully perform the due diligence requirements ordered by the government.

    4. Quickly delete unlawful content when given a government or court notice.

What is an Intermediary?

An intermediary is any platform that receives, stores, or transmits electronic records on behalf of someone else. The IT Rules divide them into several main classes:

  • Social Media Platforms (e.g., Facebook, Instagram, X): Host public user posts. Under the IT Rules, social networks with over 50 lakh (5 million) users in India are Significant Social Media Intermediaries (SSMIs), bearing the highest compliance rules.

  • Messaging Services (e.g., WhatsApp, Signal): Enable encrypted private communications. They face heavy legal pressure to trace viral messages, sparking privacy debates.

  • Search Engines (e.g., Google, Bing): Crawl and fetch general web search results. 

  • E-Commerce Platforms (e.g., Amazon, Flipkart): Host third-party products and listings .  

Safe Harbour under Indian Law

Information Technology Act, 2000 (Section 79)

  • Section 79(1): Exempts intermediaries from civil and criminal liability for third-party uploads.

  • Section 79(2): Limits immunity to instances where the platform is a pure conduit and does not modify data.

  • Section 79(3)(b): Disables safe harbour if the platform fails to quickly remove unlawful content after receiving actual knowledge via court order or government direction.

Information Technology Rules, 2021, 2025, and 2026

  • IT Rules, 2021: Laid down baseline due diligence, requiring Significant Social Media Intermediaries (SSMIs) to:

    • Appoint India-resident officers: Chief Compliance Officer, Nodal Officer, and Grievance Officer.

    • Track and identify the "first originator" of messages for law enforcement.

    • Publish monthly compliance reports on complaints.

  • IT Amendment Rules, 2025: Added checks on government takedowns to ensure fairness:

    • Required Joint Secretary or DIG-level police authorization for takedown orders.

    • Mandated precise legal reasons and exact URL addresses in notices.

    • Set up monthly Secretary-level reviews of federal takedowns to protect free expression.

  • IT Amendment Rules, 2026: Created India's first structured AI and deepfake rules, effective Feb 20, 2026:

    • Synthetically Generated Information Defined: Formally defined AI-created or altered audio-visual content that mimics real events or people, while exempting minor good-faith edits (translation, translation, accessibility).

    • Mandatory AI Watermarking: Mandated visible labels on synthetic media and disclaimers on synthetic audio, with embedded metadata and unique identifiers that platforms cannot allow users to strip.

    • Proactive Filtering Obligation: Replaced "endeavour to deploy" with a mandatory legal duty to "deploy appropriate technical measures" to filter out non-consensual deepfakes, CSAM, fraud, and illegal AI content.

    • User Declarations: Obligated SSMIs to make users declare synthetic content and verify declarations via tech tools before uploading.

    • Highly Tightened Takedown Windows: 

    • Alignment with Bharatiya Nyaya Sanhita (BNS), 2023: Replaced all outdated Indian Penal Code (IPC) references with the BNS, 2023.

Regulatory Action / Takedown Request Type
Pre-2026 Rules Timeline
New Timeline Under 2026 Rules
General Content Removal
36 Hours
3 Hours
Grievance Acknowledgement
15 Days
7 Days
Urgent Complaint Disposal
72 Hours
36 Hours
Sensitive Complaints (e.g., Deepfakes, CSAM, Non-Consensual Nudity)
24 Hours
2 Hours
 

When Can Safe Harbour Protection Be Lost?

Failure to Exercise Due Diligence

  • Breach of statutory due diligence under Section 79(2), IT Act, 2000 and the IT Rules, 2021 (amended 2026) results in loss of safe harbour. 

  • This includes failure to appoint Grievance, Compliance and Nodal Officers, issue periodic user advisories, or deploy technical measures for AI-generated content. 

Non-Compliance with Legal Directions

  • Intermediaries lose immunity if they fail to remove unlawful content within 3 hours of a court order or a reasoned government direction; 2-hour compliance applies to notified categories such as CSAM and specified synthetic-content harms.  

Active Participation in Unlawful Acts

  • Under Section 79(3)(a), immunity ceases where an intermediary conspires, abets or induces unlawful activity. Active editorial intervention or unlawful amplification may attract publisher-like liability. 

Challenges in Intermediary Regulation

Unreliable deepfake detection: AI detection tools perform poorly on compressed, low-resolution or edited media, increasing false positives and wrongful takedowns of legitimate content such as blurred faces or voice-masked investigative journalism. 

Short takedown timelines: Mandatory removal within hours prompts a "remove first, verify later" response, causing over-censorship and a chilling effect on free speech, particularly during crucial election periods.

Privacy and traceability concerns: Provenance standards like C2PA (Coalition for Content Provenance and Authenticity) enhance authenticity but can compromise the safety of journalists, whistleblowers, and activists if privacy safeguards are lacking.

Federal coordination deficit: Since 'Public Order' and 'Police' fall under the State List (Entries 1 & 2, List II, Seventh Schedule) and intermediary regulation is under the Union's Information Technology framework, overlapping Central and State directives cause regulatory uncertainty.

Platform accountability imbalance: A uniform compliance burden discourages innovation among smaller intermediaries while systemic risks originate primarily from dominant platforms. 

Strengthening Platform Governance

Risk-proportionate regulation: Implement a graded compliance framework like the EU Digital Services Act: systemic platforms face stricter transparency, risk, and audit mandates, while smaller intermediaries receive proportionate requirements.

Independent digital regulator: Establish a statutory Digital Services Council of judicial, technical, and civil society experts to independently review urgent content-blocking orders, ensuring due process and institutional accountability.

Indian AI authentication ecosystem: Develop Bureau of Indian Standards (BIS)-led watermarking and provenance standards and invest in multilingual deepfake detection models optimized for Indian languages and elections.

Due process safeguards: Codify transparent notice, reasoned orders and appellate remedies before content removal, ensuring compliance with the constitutional test of proportionality under Article 19(2) and procedural fairness under Article 21.

Regulatory harmonisation: Clarify the interaction between the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and intermediary liability provisions to avoid overlapping penalties and legal uncertainty.

Conclusion

Safe harbour serves as a vital constitutional safeguard, balancing Article 19(1)(a) free speech with state intervention against online harms via a risk-tiered framework that shields citizens and digital innovation. 

Source: thehindu

PRACTICE QUESTION

Q. "The conceptual line separating a neutral online intermediary from an active publisher has blurred in the modern digital economy." Discuss . (10 Marks, 150 Words)