Information Technology Act, 2000, Exemption from Liability of an Intermediary (section 79 as substituted in 2009)
Information Technology Act, 2000 (No. 21 of 2000), s. 79
In force since .
An intermediary liability rule binding public and private bodies.
As of .
What it requires
- Limit your role to that of an intermediary to keep the section 79(1) exemption from liability for third party information, data or communication links you make available or host: either limit your function to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored or hosted, or do not initiate the transmission, do not select its receiver, and do not select or modify the information in it.
- Observe due diligence while discharging your duties under the Act, including the due diligence listed in rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, because an intermediary that fails to observe those Rules loses the section 79(1) exemption under rule 7.
- Publish the name and contact details of a Grievance Officer on your website or mobile application, together with the mechanism by which a user or victim may make a complaint, as rule 3(2)(a) of the Rules requires.
- Remove or disable access to information used to commit an unlawful act of the kinds listed in rule 3(1)(d) within three hours of a court order or of a reasoned written intimation from an authorised officer of the appropriate Government or its agency, or risk losing the exemption.
- Remove or disable access to the material expeditiously, without vitiating the evidence, once you have actual knowledge, or are notified by the appropriate Government or its agency, that information, data or a communication link on a computer resource you control is being used to commit the unlawful act, or lose the exemption.
- Do not conspire, abet, aid or induce, whether by threats or promise or otherwise, the commission of the unlawful act, or lose the exemption.
What this law does
Section 79(1) provides that, notwithstanding anything contained in any law for the time being in force but subject to sub-sections (2) and (3), an intermediary is not liable for any third party information, data or communication link made available or hosted by it.
An intermediary, with respect to any particular electronic records, is any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record, and the definition in section 2(1)(w) names telecom service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes.
Section 79(2) applies the exemption if the function of the intermediary is limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored or hosted, or if the intermediary does not initiate the transmission, does not select the receiver of the transmission, and does not select or modify the information contained in the transmission.
Section 79(2) also requires that the intermediary observe due diligence while discharging its duties under the Act and observe such other guidelines as the Central Government may prescribe. Section 79(3) removes the exemption if the intermediary has conspired or abetted or aided or induced, whether by threats or promise or otherwise, the commission of the unlawful act.
Section 79(3) also removes the exemption if, upon receiving actual knowledge, or on being notified by the appropriate Government or its agency, that information, data or a communication link residing in or connected to a computer resource it controls is being used to commit the unlawful act, the intermediary fails to expeditiously remove or disable access to that material on that resource without vitiating the evidence in any manner.
Section 81 gives the Act overriding effect over inconsistent law, and provides that nothing in the Act restricts any person from exercising any right conferred under the Copyright Act, 1957 or the Patents Act, 1970. The Digital Personal Data Protection Act, 2023 adds itself to that proviso by its section 44(2).
Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 lists the due diligence that an intermediary must observe while discharging its duties. Rule 7 of those Rules provides that where an intermediary fails to observe them, section 79(1) does not apply to it and it is liable for punishment under any law in force.
Rule 3(1)(d) of those Rules requires an intermediary to remove or disable access to information used to commit an unlawful act of the kinds it lists within three hours of receiving actual knowledge.
That actual knowledge arises only from an order of a court of competent jurisdiction or from a reasoned written intimation issued by an authorised officer of the appropriate Government or its agency who is not below the rank of Joint Secretary or an officer equivalent in rank, or a Director or an officer equivalent in rank where no officer of that rank is appointed.
Where the police administration issues the intimation, each authorised officer must be not below the rank of Deputy Inspector General of Police. An amendment notified on replaced the thirty-six hour period in that clause with three hours. Rule 3(1)(d) was substituted with effect from .
When LexLint raises it
When your app profile says your app operates a social platform or reuses other publishers' content.