1. Introduction
The internet is changing fast because of digital intermediaries, instant sharing and fake media such as AI-generated videos. This has completely changed how we communicate online. The internet remains an important space for democratic participation and freedom of expression, but it also facilitates harmful activities such as non-consensual private images, financial scams and deliberately false information.
To address these developments, India's regulatory framework for the internet has evolved from a model primarily concerned with intermediary protection towards one that places greater compliance responsibilities on digital platforms. This change is mainly governed by two legal frameworks: the Information Technology Rules1 and the Digital Personal Data Protection Act 2023.2
These laws address the removal of content and the handling of personal information in different ways, within the framework of constitutional rights. The Information Technology Rules focus on public order, national security, regulation of online speech and intermediary accountability. The Digital Personal Data Protection Act, on the other hand, is based on the constitutional recognition of privacy and the right to control personal information.3 It therefore provides mechanisms through which individuals can seek deletion of personal data and places obligations on entities processing such information.
2. Safe Harbour, Fast Takedowns, and Free Speech
Online intermediaries such as media platforms, search engines and web hosts depend on the statutory immunity provided by section 79 of the Information Technology Act 2000.
This "safe harbour" principle means that an intermediary is generally protected from liability for third-party content where it acts as an intermediary and complies with the applicable due-diligence requirements.
In the past, this protection was at risk because private parties could seek removal of content without sufficient legal safeguards. This could potentially lead to private censorship.
In Shreya Singhal v Union of India (2015),4 the Supreme Court struck down section 66A of the Information Technology Act 2000 on the ground that it was unconstitutional. The Court also considered the operation of section 79(3)(b) and the intermediary framework.
The judgment established an important principle concerning "actual knowledge": an intermediary's safe-harbour protection could be affected where it received knowledge through a court order or an appropriate government notification under section 69A.
The Court's approach was intended to prevent private intermediaries from becoming the primary decision-makers on the legality of speech and thereby reduce the risk of restricting speech protected by article 19(1)(a) of the Constitution.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 and subsequent amendments introduced faster mechanisms for dealing with harmful online content.
2.1 Rule 3(1)(d) – The 36-Hour General Takedown Mandate
When a platform receives knowledge through a court order or government notification, it must remove or disable access to the relevant content as quickly as possible and, under the applicable framework, within 36 hours.
2.2 Rule 3(2)(b) – The 24-Hour Express Removal for Morphed Imagery
This provision creates an expedited mechanism for specified forms of harmful content.
Victims can report content involving non-consensual nudity, sexual acts or impersonation, including certain forms of AI-generated or manipulated imagery. The platform must take steps to disable access within 24 hours of receiving the complaint.
2.3 Rule 3(1)(j) – 72-Hour Law Enforcement Assistance
Platforms are required to provide assistance to government agencies within 72 hours of receiving a request. This may include information and support required for investigations.
2.4 Rule 3(2)(a) – Grievance Redressal Acceleration
Platforms must acknowledge a complaint within 24 hours and resolve it within the prescribed period, including the stated 15-day period for grievance resolution. Individuals may appeal decisions to the government-approved Grievance Appellate Committees (GACs).
3. Judicial Challenges to Faster Content Removal
The push for faster removal of online content has also faced constitutional and judicial challenges.
In Kunal Kamra & Ors v Union of India (2024),5 the Bombay High Court considered a challenge concerning amendments to Rule 3(1)(b)(v).
The challenged amendment enabled a government-approved Fact Check Unit (FCU) to identify content concerning the Government as "fake, false or misleading" and potentially require its removal.
The Court held that allowing the Government to determine the truth of statements concerning itself raised serious concerns under article 19(1)(a) and the constitutional limitations contained in article 19(2).
The decision highlights an important principle: mechanisms designed to enable fast content removal must still operate within constitutional limits and cannot give the Government unrestricted power to determine what information is permissible online.
4. User Rights, Privacy, and Data Erasure Under the DPDP Act 2023
The Digital Personal Data Protection Act 2023 (DPDP Act) adopts a rights-oriented framework concerning personal data. This approach is closely connected with the constitutional right to privacy recognised under article 21.
The DPDP Act uses the terms Data Fiduciary for entities that determine the purpose and means of processing personal data and Data Principal for the individual to whom the personal data relates.
The Act operates within a framework that reflects the principle of proportionality. The proportionality approach requires State action affecting fundamental rights to have a legal basis, pursue a legitimate objective and maintain an appropriate relationship between the means used and the objective pursued.
The Supreme Court's decision in Justice K S Puttaswamy (Retd) v Union of India (2017)6 is an important constitutional foundation for the right to privacy.
4.1 Right to Erasure
Section 12(3) of the DPDP Act 2023 provides for the right of a Data Principal to request erasure of personal data, subject to the circumstances and requirements contained in the Act.
Where a Data Fiduciary receives such a request, the relevant personal data is to be erased where required by the statutory framework, subject to circumstances in which retention is legally required or otherwise permitted.
4.2 Withdrawal of Consent
Section 6(4) of the DPDP Act 2023 provides for withdrawal of consent.
Where consent is withdrawn, the Data Fiduciary must cease processing based on that consent and take the steps concerning erasure required by the Act, subject to applicable legal requirements.
4.3 Erasure After Fulfilment of Purpose
Section 8(9) of the DPDP Act 2023 provides obligations concerning erasure when the purpose for which personal data was collected has been fulfilled, subject to the statutory conditions and exceptions.
4.4 DPDP Act and the GDPR's Right to Be Forgotten
The DPDP Act 2023 differs from the European Union's General Data Protection Regulation (GDPR) in its treatment of erasure and the so-called "right to be forgotten".
The DPDP Act does not establish an identical framework under which individuals can generally require search engines to remove information from search results.
Instead, its framework primarily regulates the obligations of Data Fiduciaries concerning personal data and requests for erasure.
4.5 Exceptions to Erasure
The right to erasure is not absolute.
Section 17 of the DPDP Act 2023 provides exemptions in specified circumstances. These include situations where processing or retention may be necessary for purposes such as preventing or investigating offences, legal proceedings or security-related purposes.
The Act therefore establishes a framework that identifies circumstances in which personal data must be erased as well as circumstances in which retention may continue.
5. Comparison Between Old and New Law
| Legal Parameter | IT Rules, 2011 (Old Regime) | IT Rules, 2021 & Amendments (Current Regime) | DPDP Act, 2023 (New Framework) |
|---|---|---|---|
| Primary Scope | Passive intermediary immunity under section 79. | Active due diligence, compliance oversight and grievance escalation. | Protection of personal digital data and enforcement of data privacy rights. |
| Takedown / Erasure Timelines | Broad requirement to act within 36 hours, often interpreted as merely initiating a response. | Strict operational deadlines: 36 hours for court/government orders and 24 hours for specified non-consensual sexual or morphed media. | No fixed hourly clock; requires erasure within the applicable statutory framework after consent withdrawal or fulfilment of the processing purpose. |
| Legal Trigger | Court orders or formal government notifications following the Shreya Singhal framework. | Court orders, government directives and direct user complaints for specified non-consensual intimate content. | Data Principal request under section 12 or applicable expiration of the processing purpose under section 8(9). |
| Grievance Framework | Grievance Officer had up to 30 days to resolve issues. | Acknowledge within 24 hours; resolve within 15 days; decisions may be appealed to the Grievance Appellate Committee (GAC). | Internal grievance redressal by the Data Fiduciary, with statutory mechanisms involving the Data Protection Board of India (DPBI). |
| Proactive Content Duties | None; strictly passive carriage. | Significant Social Media Intermediaries must deploy automated tools to detect specified categories of harmful content, including child sexual abuse material and rape-related content. | Continuous obligations to deploy appropriate technical and organisational safeguards. |
| Penalties for Default | Loss of section 79 safe-harbour immunity. | Loss of safe-harbour immunity, potentially exposing the platform to direct civil and criminal liability. | Statutory financial penalties, including substantial penalties for specified data-security failures. |
6. Conclusion
India's modern digital regulatory framework reflects an attempt to balance speedy action with fundamental rights.
6.1 The IT Rules Framework
The IT Rules framework focuses strongly on speed and compliance. Short deadlines, including 24-hour and 36-hour periods, are intended to enable rapid removal of harmful material such as non-consensual or manipulated imagery.
However, these tight deadlines also place considerable pressure on platforms. This can create a risk of over-censorship, where platforms remove content that may be legally permissible simply to minimise regulatory risk and preserve safe-harbour protection under section 79.
6.2 The DPDP Act 2023
The DPDP Act 2023 adopts a more rights-oriented approach by giving individuals greater control over their personal information.
Individuals can, subject to the statutory framework, request erasure of personal data and withdraw consent for its processing.
6.3 Balancing Speed and Liberty
As courts continue to interpret these frameworks, the regulation of digital platforms in India must remain consistent with constitutional principles.
These include the safeguards concerning intermediary takedowns recognised in Shreya Singhal, the privacy principles associated with Puttaswamy and the constitutional limits on governmental control over online information highlighted by Kunal Kamra.
The challenge is therefore not simply to remove harmful content quickly.
The deeper challenge is to ensure that speedy content regulation does not come at the cost of freedom of speech, privacy, due process and fair treatment.
References
Legislation
- Constitution of India.
- Information Technology Act 2000 (Act No 21 of 2000).
- Information Technology (Intermediaries Guidelines) Rules 2011.
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (as amended).
- Digital Personal Data Protection Act 2023.
- Regulation (EU) 2016/679 (General Data Protection Regulation), art 17.
Cases
- Shreya Singhal v Union of India (2015).
- Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
- Kunal Kamra & Ors v Union of India (2024).
- X Corp v Union of India (2023).
Blogs and Articles
- 'Balancing Urgency and Liberty: Constitutional Scrutiny of India's Emerging Blueprint for Regulating AI-Generated Content'.
- 'Intermediary Liability, Personality Rights, and Safe Harbour in the Era of Deepfakes'.
- 'Bombay High Court Strikes Down IT Rules Fact Check Unit: An Analysis of the Kunal Kamra Verdict'.
- 'The 24-Hour Express Takedown Mandate: Chilling Effects and Platform Censorship'.
Academic Reference
- Yogesh V Nayyar, The Digital Personal Data Protection Act, 2023: Law, Practice & Commentary, Cyber & Data Protection Law Series (Whitesmann / EBC Publishing).
Footnotes
Footnotes
-
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, GSR 139(E) (25 February 2021) (India). ↩
-
Digital Personal Data Protection Act 2023, No 22 of 2023 (India). ↩
-
Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1. ↩
-
Shreya Singhal v Union of India (2015). ↩
-
Kunal Kamra & Ors v Union of India (2024). ↩
-
Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1. ↩