Intermediary liability in india: the safe harbour principle under section 79 of the information technology act, 2000 and the due diligence mandate of rule 3 of the information technology (intermediary
- Aug 24
- 9 min read

I. Introduction
The exponential growth of the internet has transformed the manner in which information is created, shared, and consumed. At the heart of this digital ecosystem lie "intermediaries" entities such as internet service providers, search engines, social media platforms, and online marketplaces that do not themselves generate content but merely facilitate its transmission, storage, or communication between third parties. Given the sheer volume of user-generated content that passes through these platforms every second, it would be commercially and practically unworkable to hold intermediaries liable for every piece of unlawful content posted by a third party. It is this practical reality that gave birth to the doctrine of "safe harbour" a legal shield that insulates intermediaries from liability for third-party content, provided they satisfy certain statutory conditions.
II. Who is an "Intermediary"? Section 2(1) (W) of the Information Technology Act, 2000
Section 2(1)(w) of the IT Act defines an "intermediary", with respect to any particular electronic record, as any person who, on behalf of another person, receives, stores, or transmits that record, or provides any service with respect to that record. This definition is deliberately wide in its sweep, so as to bring within its fold every entity that plays a role however incidental in the flow of digital information.
The statutory illustration to Section 2(1)(w) clarifies that the term includes telecom service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online auction sites, online marketplaces, and cyber cafes. The common thread running through all these categories is that the intermediary acts on behalf of another person it does not originate the content in question but merely facilitates its transmission, storage, or communication. It is this position of a neutral conduit, rather than that of an active publisher, that forms the conceptual foundation for the grant of safe harbour protection under Section 79.
III. Section 79 of the Information Technology Act, 2000: the Safe Harbour Principle
Section 79 of the IT Act, 2000 is the central provision governing intermediary liability in India. It embodies a conditional immunity the intermediary is not automatically exempt from liability; rather, the exemption is available only so long as the intermediary satisfies certain statutory conditions.
1. The Basic Rule
Section 79(1) provides that an intermediary shall not be liable for any third-party information, data, or communication link made available or hosted by it. This provision recognises that platforms are, in the ordinary course, facilitators of communication rather than publishers of content, and that it would be inequitable to impose publisher-like liability on an entity that merely provides the technological infrastructure through which third parties communicate.
2. Conditions for Availing Protection - The "Passive Conduit" Test
The immunity under Section 79 is not unconditional. Section 79(2) requires the intermediary to demonstrate that:
It does not initiate the transmission of the impugned content;
It does not select the receiver of the transmission; and
It does not select or modify the information contained in the transmission.
These three conditions collectively establish what may be termed the "passive conduit" test the intermediary must confine its role to that of a neutral technological facilitator, without exercising editorial control over, or influencing, the content that passes through its platform.
3. The Due Diligence Requirement
Section 79(2)(c) further mandates that the intermediary must observe due diligence while discharging its duties, and must also comply with such other guidelines as the Central Government may prescribe. This obligation is given concrete shape by Rule 3 of the IT Rules, 2021, discussed in the following section. Broadly, due diligence entails publishing terms of service and privacy policies, informing users not to host or share unlawful content, and acting responsibly once an issue is brought to the intermediary's notice. Failure to observe due diligence disentitles the intermediary from claiming the safe harbour, regardless of whether the other conditions under Section 79(2) are satisfied.
4. Actual Knowledge and the Take-Down Obligation
Section 79(3)(b) carves out an exception to the exemption: an intermediary loses safe harbour protection where, upon receiving actual knowledge, or upon being notified by the appropriate Government or its agency, that its computer resource is being used to commit an unlawful act, it fails to expeditiously remove or disable access to that material. The interpretation of the phrase "actual knowledge" has been the subject of extensive judicial scrutiny, most notably in Shreya Singhal v. Union of India, where the Supreme Court read down this provision to prevent private parties from compelling intermediaries to act as adjudicators of what constitutes unlawful content.
5. Active Participation and Loss of Neutrality
Where an intermediary goes beyond the role of a passive facilitator and actively participates in the creation, selection, modification, or promotion of unlawful content, it forfeits its character as a neutral intermediary and, consequently, the protection of Section 79. Courts have increasingly scrutinized the actual conduct and business model of a platform rather than its self-description as an "intermediary" to determine whether such active participation exists.
IV. Rule 3 of the information technology (intermediary guidelines and digital media ethics code) rules, 2021: the due diligence framework.
Rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 operationalizes the due diligence requirement contemplated under Section 79(2)(c) of the IT Act. It sets out the specific obligations that an intermediary must fulfil in order to retain safe harbor protection. Broadly, these obligations include:
Publishing clear rules, regulations, privacy policy, and user agreements informing users of the categories of content such as content that is defamatory, obscene, infringing, or violative of any law that they are prohibited from hosting, uploading, or sharing;
Making reasonable efforts, including through automated tools, to proactively identify and remove certain categories of unlawful content, particularly content depicting child sexual abuse or content that is identical to material previously removed;
Establishing a grievance redressal mechanism, including the appointment of a Grievance Officer, to receive and resolve complaints within prescribed timelines;
Removing or disabling access to unlawful content within thirty-six hours of receiving actual knowledge through a court order or a notification from an appropriate government agency, and within twenty-four hours in respect of certain categories of sensitive content upon a complaint by an affected individual;
Preserving such removed information and associated records for a specified period for investigative purposes; and
For significant social media intermediaries, additional obligations such as appointing a Chief Compliance Officer, a Nodal Contact Person, and a Resident Grievance Officer, and enabling the identification of the first originator of certain unlawful information where required under a judicial order.
The relationship between Rule 3 and Section 79 is symbiotic: strict compliance with the due diligence obligations under Rule 3 is what enables an intermediary to continue availing itself of the safe harbour protection under Section 79. Conversely, non-compliance with Rule 3 exposes the intermediary to the risk of losing this statutory immunity altogether, thereby rendering it liable as if it were the publisher of the third-party content itself.
V. Duties and responsibilities of intermediaries QUA third-party content: guiding principles
Reading Section 79 and Rule 3 together, along with the judicial pronouncements discussed below, certain guiding principles emerge regarding the responsibility of intermediaries when third-party content is posted on their platforms:
Principle of Neutrality: An intermediary must not initiate, select the receiver of, or modify the content that it transmits or hosts; it must function as a neutral conduit.
Principle of Due Diligence: An intermediary must proactively frame and publicise rules against unlawful content and take reasonable preventive measures, rather than adopting a purely reactive stance.
Principle of Actual Knowledge and Expeditious Removal: The obligation to take down content is triggered only upon actual knowledge in the form of a court order or a government notification, and such content must be removed expeditiously and within the timelines prescribed under Rule 3.
Principle of Non-Adjudication: An intermediary is not expected, and is not entitled, to act as a private adjudicator of the lawfulness of content based on unverified private complaints.
Principle of Accountability upon Active Participation: Where an intermediary's conduct -- such as exercising control over pricing, quality checks, warranties, or promotional activities demonstrates active participation in the underlying transaction or content, it loses the shield of neutrality and may be held liable as though it were the author or publisher of the content.
Principle of Proportionate Grievance Redressal: An intermediary must maintain an accessible and effective grievance redressal mechanism, ensuring that legitimate complaints of affected persons are addressed within defined timelines.
VI. Judicial interpretation: landmark case laws
The statutory framework outlined above has been substantially shaped -- and in certain respects, constrained -- by judicial interpretation. The following decisions are illustrative of how Indian courts have understood the duties and responsibilities of intermediaries in relation to third-party content.
1. Avnish Bajaj v. State (NCT of Delhi)
This was among the earliest cases to test the boundaries of intermediary liability in India, arising prior to the 2008 amendment that introduced the present safe-harbour regime under Section 79. An obscene video clip was listed for sale by a third-party user on Bazee.com (an online marketplace, now eBay India), leading to the arrest of its CEO, Mr Avnish Bajaj, under provisions of the Indian Penal Code and the IT Act. While the Delhi High Court ultimately discharged Mr Bajaj personally from the obscenity charges on procedural grounds relating to corporate criminal liability, it held that the website, having failed to act with due diligence and having removed the listing only after the matter came to its notice could not entirely escape scrutiny. The case exposed the inadequacy of the safe harbour regime as it then stood and directly precipitated the 2008 amendment to Section 79, which introduced the structured conditions for exemption that exist today, along with the associated intermediary guidelines.
2. Shreya Singhal v. Union of India
This is the most significant judicial pronouncement on intermediary liability in India. While the Supreme Court is best known for striking down Section 66A of the IT Act as unconstitutional in this case, it also examined and read down Section 79(3)(b) along with Rule 3(4) of the erstwhile Intermediary Guidelines, 2011. The Court held that the requirement of "actual knowledge" for an intermediary to take down content must be understood to mean either an intimation received through a court order, or notification by the appropriate Government or its agency and not merely a private complaint by an aggrieved individual. The Court reasoned that requiring intermediaries to independently adjudicate the legality of vast quantities of user content, based on private complaints alone, would compel them to act as untrained judges of speech, resulting in excessive and arbitrary censorship to avoid liability. This interpretation struck a careful balance between the constitutional guarantee of free speech under Article 19(1)(a) and the legitimate need to regulate unlawful online content, and it remains the governing standard for determining when the take-down obligation under Section 79(3)(b) is triggered.
3. MySpace Inc. v. Super Cassettes Industries Ltd.
In this case, Super Cassettes Industries Ltd. (T-Series) sued MySpace, a social networking platform, alleging that it had permitted the unauthorised hosting of copyrighted cinematograph films, sound recordings, and musical works uploaded by its users. The Delhi High Court examined the interplay between Section 79 and Section 81 of the IT Act on the one hand, and Section 51(a)(ii) of the Copyright Act, 1957 on the other, and held that these provisions must be read harmoniously, such that the safe harbour defence remains available to intermediaries even in copyright infringement actions. Importantly, the Court clarified that liability could be imposed on an intermediary only where it possessed actual knowledge of specific infringing content -- general awareness that infringement was occurring on the platform at large was held to be insufficient. The Court accordingly modified the blanket interim injunction that had earlier been granted, replacing it with a workable regime requiring the copyright owner to furnish specific details and locations of infringing content, upon receipt of which the intermediary was required to remove or disable access within a defined period. This decision is significant for affirming that the due diligence obligation of an intermediary is content-specific and notice-based, rather than a general duty of pre-emptive surveillance.
4. Christian Louboutin SAS v. Nakul Bajaj & Ors.
This decision of the Delhi High Court is the leading authority on the "active participation" limb of intermediary liability. The plaintiff, a luxury footwear brand, alleged that the defendant's e-commerce website, Darveys.com, was engaged in the unauthorized sale of products bearing the plaintiff's trademarks. The website in question performed a wide range of functions beyond passive hosting including identifying sellers, guaranteeing the authenticity of products, undertaking quality checks, arranging for packaging and shipping, and promoting the sale of branded goods through its own marketing efforts. The Court enumerated an extensive, non-exhaustive list of factors relevant to determining whether an e-commerce platform functions as a passive intermediary or an active participant, and held that the greater the number of such value-added functions performed by a platform, the more likely it is to be treated as an active participant rather than a neutral intermediary. Since active participation of this nature amounts to "conspiring, abetting, aiding, or inducing" unlawful conduct within the meaning of Section 79(3)(a), the Court held that such conduct would disqualify the platform from claiming safe harbour protection altogether. This judgment significantly raised the compliance threshold for e-commerce intermediaries operating in India, particularly in the context of intellectual property infringement by third-party sellers.
VII. Conclusion
The Indian legal framework governing intermediary liability reflects a deliberate policy choice to balance two competing interests: enabling the growth of digital platforms as facilitators of free expression and commerce, while ensuring that such platforms do not become havens for unlawful content. Section 79 of the IT Act grants intermediaries a conditional safe harbour, contingent upon their functioning as neutral conduits and observing due diligence, while Rule 3 of the IT Rules, 2021 translates this abstract due diligence obligation into concrete, enforceable compliance requirements.
Judicial decisions from Avnish Bajaj through Shreya Singhal, MySpace, and Christian Louboutin have progressively refined this framework, narrowing the circumstances in which take-down obligations arise while simultaneously raising the bar for platforms that exercise substantive control over third-party content or transactions. The cumulative effect of this statutory and judicial architecture is a nuanced, fact-sensitive standard: an intermediary that remains a genuinely passive facilitator, observes due diligence, and acts promptly upon receiving actual knowledge of unlawful content will continue to enjoy safe harbour protection; one that steps beyond this role whether through editorial control, active promotion, or complicity in unlawful conduct forfeits that protection and assumes the liability of a publisher. As digital platforms continue to evolve, this balance between immunity and accountability is likely to remain one of the most dynamic and closely watched areas of Indian technology law.



