Disclaimer

By clicking, "I Accept" below, you accept and acknowledge the following:

The purpose of this website is to provide general information and insights about TLH, Advocates & Solicitors, and not to advertise or solicit work in any manner whatsoever.

Please note that as per the Bar Council of India Rules, advocates in India are prohibited from advertising or soliciting work in any form or manner. You acknowledge that you are visiting this website at your discretion and that there has been no solicitation, invitation, or inducement of any sort whatsoever from TLH, Advocates & Solicitors or any of its professionals in relation to this website.

The content available on this website does not constitute legal or other professional advice and should not be substituted for advice relevant to particular circumstances.

The access and use of this website does not establish any fiduciary or other relationship between you and TLH, Advocates & Solicitors or any of its advocates.

Please read the ‘Terms of Use’ and our ‘Privacy Policy’ before accessing this website.

Blog default background
Blog
Information Technology

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: Adequate Regulation of Intermediaries?

Authors:
Saumitra
January 4, 2022
•
5 min read
Share this post
Copied!

Introduction: What is an Intermediary

The term ‘Intermediary’ has been defined in clause (w) of sub-section 1 of section 2 of the Information Technology Act, 2000 (“ IT Act”) as “any person who on behalf of another person receives, stores or transmits an electronic record or provides any service with respect to that record and includes telecom service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes”.

This is a very broad definition. This not only covers social media companies (e.g., Facebook, Twitter) but also a wide range of players in the internet ecosystem including search engines (Google Inc., Yahoo Inc.), online payment sites (Paypal, Phonepe), online-market place (Amazon, Flipkart), telecom service providers (Jio, Vi), and cyber-cafes. The definition applies to any company where the user has an identity in the intermediary in form of a unique account/number (though some intermediaries may not require prior registration for access), who accesses, uses, and interacts with other users (who may or may not be of the same kind) and the intermediary enables these interactions. Cyber-cafes would be an exception to this notional definition.

Regulation of Intermediary in India

Intermediaries did not have protection of safe harbour until 2008. That is, there was nothing in the IT Act which protected intermediaries from content posted by its users. This became clear in Avinash v State[1], where the managing director of an e-commerce company was charged with criminal provisions of the Indian Penal Code, 1860 for the content posted by third parties on the e-commerce company. The Delhi High Court observed that there was a requirement for widening the scope of protection given to intermediaries. Consequently, the IT Act was amended in 2008 to include a safe harbour regime under Section 79 of the IT Act, along with an amendment in the definition of intermediaries.

Intermediary Guidelines, 2011 and the Shreya Singhal Judgement

In 2011, the Government of India notified the Information Technology (Intermediaries Guidelines) Rules, 2011 (“Intermediary Guidelines, 2011”) which brought certain obligations for the intermediaries, which included, inter alia, publication of privacy policy and user agreement on its website/App, prohibition of posting of harmful content, developing systematic and organizational measures for data security, etc.

In the landmark judgment of Shreya Singhal v Union of India[2], the Supreme Court also discussed the intermediary liability, “Section 79 is valid subject to Section 79(3)(b) being read down to mean that an intermediary upon receiving actual knowledge from a court order or on being notified by the appropriate government or its agency that unlawful acts relatable to Article 19(2) are going to be committed then fails to expeditiously remove or disable access to such material…. Similarly, the Information Technology "Intermediary Guidelines" Rules, 2011 are valid subject to Rule 3 sub-rule (4) being read down in the same manner as indicated in the judgment.”

Intermediaries Guidelines 2021

The Intermediaries Guidelines 2011 were superseded by Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Guidelines”). The new guidelines inter alia have brought a classification of intermediaries. They classified them into social media intermediary and significant social media intermediary, based on the number of users served by the intermediary. Significant social media intermediary, which has a higher threshold of registered users (50,00,000 (fifty lakh) as per a recent notification[3]), has certain additional obligations. Unlike the Intermediary Guidelines, 2011, these guidelines also regulate OTT channels and providers of news and current affairs on the internet under a different chapter.

According to the Rule 3, intermediaries are required to observe due diligence, such as prominently publishing on its website or application or both, the rules and regulations, privacy policy, etc. They have to inform the users beforehand about the prohibited content. Further, upon receiving actual knowledge in the form of an order by a court of competent jurisdiction or on being notified by the appropriate Government or its agency, the intermediary shall not host, store or publish any such prohibited information. In case, any such information is hosted, stored or published, the intermediary shall disable access to that information within 36 hours from the time of being notified. It shall also preserve such information and associated records for 180 days for investigation purposes, or for longer period as may be required by Government agencies or by the court. Intermediaries are also required to furnish information concerning verification of identity, or prevention, detection, investigation, or prosecution, of offences under any law or for cyber security incidents to the Indian Computer Emergency Response Team within 72 hours of the receipt of a lawful order. The intermediary shall also publish the name of the Grievance Officer and his/her contact details as well as mechanism for complaint. Grievance Officer shall acknowledge the complaint within 24 hours and resolve it within 15 days from the date of its receipt. Intermediaries are also required to remove or disable access to any content which exposes the private area of any person, or shows nudity or sexual act or conduct including artificially morphed images within twenty four hours from the receipt of a complaint.

A ‘significant social media intermediary’ has to observe certain additional due diligence[4] such as appointing an Indian resident as Chief Compliance Officer, a nodal contact person for 24x7 coordination with law enforcement agencies and officers, and a Resident Grievance Officer and publisha monthly compliance report.

Conclusion

It is only logical that intermediaries cannot be made responsible for what third parties post on their platforms but to absolve them entirely from third-party liability would not be advisable in this hyperconnected world where companies like Facebook and Twitter are universes in themselves. Cambridge Analytica scandal showed the potential of these platforms. Facebook, which remains the first and often the only source of information for many people could influence the world in manners no one can, and could affect public order, markets, and entire democracies, on a very large scale. The point is to strike a balance between the two opposite ends of the spectrum. The bottom line is provide freedom to intermediaries to operate smoothly but have enough checks and compliances to prevent them from becoming uninhibited, archaic tech nations. Intermediary Guidelines so far as the social media intermediaries are concerned (which cannot be said about the regulation of digital media and OTT platforms), have arguably struck the balance between the security of the State and privacy of the citizens.

The views and opinions expressed in this article belong solely to the author and do not reflect the position of TLH, Advocates & Solicitors.

[1] 2008 (105) DRJ 721

[2] (2013) 12 S.C.C. 73

[3] Ministry Of Electronics and Information Technology, [F. No. 16(4)/2020-CLES], (Notified on 25.02.21)

[4] Rule 4, Information Technology (Intermediaries Guidelines) Rules, 2011

No items found.
intermediary guidelines, regulations

Footnotes

Share this post
Copied!

Latest posts

Dispute Resolution
October 8, 2026
Arbitration Case Comment: Venue is Seat in the absence of contrary indicia ��� Implied Overruling of The Verdict in the Hardy Exploration case
A recent decision of the Supreme Court of India has far reaching ramifications for arbitration law in the country. While the decision in the BGS Soma[1] case has seemingly set out the ���correct law�۝ concerning the venue and seat dichotomy which has been the subject matter of a high volume of contested litigation over the years, its clarity and efficacy may come undone due to issues touching on the law of precedent.
Read more
Arrow Right
Information Technology
October 8, 2026
Privacy Shield Set Aside by CJEU ��� A Guidance for India
The European Union (���EU�۝) is a major source of revenue for the information technology and business process outsourcing industry in India. However, there are several challenges that India faces with respect to transfer of personal data from EU to India. Presently, the data protection regime in India does not provide the same level of protection as the data protection regime in the EU, in particular because the Personal Data Protection Bill, 2019 has not been enacted yet.
Read more
Arrow Right
Corporate Law
October 8, 2026
The Fate of Online Gaming in India: Game of Chance versus Game of Skill
With the advent of technology, there have been a lot of developments and inventions which have blurred the concepts of physical presence and boundaries that were prevalent a couple of decades ago. Today, even traditional games like rummy, flush, poker, ludo, cricket, etc. are played online, some of which include real money as stakes. ��
Read more
Arrow Right
Corporate Law
October 8, 2026
Whether Call / Put Options in FDI Transactions are considered as Assured Returns?
In the context of increased liberalisation of various foreign exchange laws in India, the country has seen a surge in the investment from abroad. Whereas, in case of divestments by foreign investors, the Indian foreign exchange laws have not been as liberalised as the foreign investors would have preferred, especially with regards to an assured exit price.
Read more
Arrow Right
October 8, 2026
Captive Generating Plants in the States of Telangana and Andhra Pradesh
A captive generating plant is a power plant set up by any person to generate electricity primarily for his own use and includes a power plant set up by any co-operative society or association of persons for generating electricity primarily for use of members of such co-operative society or association (���CGP�۝).
Read more
Arrow Right
Employment Law
October 8, 2026
Non-Compete Clauses in Employment Contracts
A very fine line divides the issues that fall within the sphere of: (a) the principle of the freedom to contract, and (b) restraint of trade. A non-compete clause by its very nature falls on the periphery.
Read more
Arrow Right
View All Blogs
Arrow Right