'No safe harbour if law violated; message has gone home': Government sources on talks with Meta
Government talks with Meta reiterated that intermediary "safe harbour" protection is not guaranteed if platforms fail to comply with legal obligations
Discussions centred on content moderation practices and handling of child sexual abuse material (CSAM)
The government sought greater local/cultural sensitivity in Meta's content moderation decisions for the Indian context
Deepfakes and synthetically generated content were flagged as requiring clear, prominent labelling for users
WhatsApp usernames are being examined as part of a broader review across messaging platforms
Safe Harbour under Section 79 of the IT Act, 2000
Section 79 of the Information Technology Act, 2000 grants intermediaries (social media platforms, ISPs, etc.) conditional immunity from liability for third-party content hosted on their platforms, provided they observe due diligence and do not initiate, select, or modify the content transmitted. This is the legal basis of the term "safe harbour" repeatedly invoked in the government's talks with Meta.
Key Details
- Section 79(2) sets out the conditions for immunity: the intermediary must not have initiated the transmission, must not select the receiver, and must not modify the content
- Section 79(3)(b) is the key "exception to the exception" — safe harbour is lost if the intermediary fails to expeditiously remove or disable access to unlawful content upon receiving "actual knowledge," typically via a court order or a notification from an appropriate government agency
- The Supreme Court, in Shreya Singhal v. Union of India (2015), read down the actual-knowledge requirement, holding it is triggered only by a court order or a government notification — not by mere private complaints — while striking down Section 66A of the IT Act as unconstitutional
- IT Rules, 2021 (framed under Section 79 read with Section 87) impose additional due diligence obligations on intermediaries, especially "significant social media intermediaries"
The government's statement that "no safe harbour" exists if law is violated is a direct invocation of Section 79(3)(b) — signalling that continued non-compliance (e.g., on CSAM or unlabelled deepfakes) could expose Meta's platforms to full liability for user content, losing the conditional immunity that underlies platforms' business model.
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — Due Diligence Obligations
The IT Rules, 2021 lay down due diligence requirements intermediaries must observe to retain Section 79 protection, including grievance redressal mechanisms, content takedown timelines, and (for significant social media intermediaries) additional obligations such as identifying the first originator of certain messages and appointing India-based compliance officers.
Key Details
- Applies a three-tier structure of due diligence: general intermediaries, social media intermediaries, and "significant social media intermediaries" (above a user threshold notified by the government)
- Requires a Grievance Officer, Nodal Contact Person, and Chief Compliance Officer based in India for significant social media intermediaries
- Rule 3(1)(d) requires removal of unlawful content upon receiving a court/government order, generally within 36 hours
- 2026 amendments to the IT Rules tightened requirements around AI-generated/synthetic content — mandating prominent labelling and permanent provenance metadata for synthetically generated information, with a short (reported as roughly 3-hour) takedown window for unlabelled AI content flagged by authorities
The specific complaint about deepfakes lacking labels is a direct reference to the 2026 IT Rules amendment on synthetic content labelling and provenance metadata — non-compliance here is what the government is signalling could cost Meta its safe harbour.
Intermediary Liability — International and Comparative Angle
India's safe harbour model (conditional immunity subject to due diligence) is broadly comparable to Section 230 of the US Communications Decency Act (near-blanket immunity) and the EU's Digital Services Act (graduated obligations based on platform size, with the largest platforms classified as "Very Large Online Platforms" facing the strictest duties).
Key Details
- US Section 230 (1996) offers broader immunity with fewer proactive obligations compared to India's regime
- EU Digital Services Act (2022) introduces a risk-based, tiered obligation structure similar in spirit to India's "significant social media intermediary" classification
- India's approach increasingly resembles the EU's tiered model, especially after the 2026 IT Rules amendments targeting AI-generated content
Positions India's regulatory posture toward large platforms like Meta within a global trend of moving away from blanket immunity toward conditional, compliance-linked protection.
- Legal basis of "safe harbour": Section 79, IT Act, 2000
- Key exception (loss of immunity): Section 79(3)(b) — failure to act on actual knowledge of unlawful content
- Landmark case narrowing "actual knowledge": Shreya Singhal v. Union of India (2015), which also struck down Section 66A
- Governing subordinate legislation: IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, amended 2026 for AI-generated/deepfake content labelling
- 2026 amendment reported takedown window for unlabelled synthetic/AI content: approximately 3 hours