+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Safe harbour: the obligations you may not know you have

Security By Mits Engineering Team 2 min read
Safe harbour: the obligations you may not know you have

The Information Technology Act defines an intermediary very broadly: any person who receives, stores, transmits or provides a service in respect of an electronic record on behalf of another person. That covers web hosts, internet service providers, search engines, e-commerce platforms and social media, and it catches a great many products whose founders have never thought of themselves as intermediaries — anything with user-generated content, reviews, listings, comments or file sharing.

Section 79 of the Act provides safe harbour: the intermediary is not liable for third-party content it merely hosts. That protection is conditional on the due diligence requirements in Rule 3 of the IT Rules 2021, and failing any of them strips it. That is the point worth internalising — this is not a compliance checklist with a fine attached, it is the mechanism by which your company is not directly liable for what a user posted.

The Rule 3 obligations are concrete. Publish terms of use and a privacy policy, in English or a language listed in the Constitution, clearly prohibiting defamatory, obscene, invasive and otherwise unlawful content. Appoint a Grievance Officer and publish their contact details. Maintain a takedown process responsive to court orders and government notifications. And retain records for at least a hundred and eighty days for law enforcement purposes.

The timelines are the part that needs building into a product rather than a policy. A grievance must be acknowledged within twenty-four hours and resolved within fifteen days. Complaints concerning content depicting minors or sexual abuse must be handled within seventy-two hours. Unlawful content must be removed within thirty-six hours of a court order or government notification, and child sexual abuse material as expeditiously as possible and within twenty-four hours in any case. A support inbox checked on working days cannot meet those.

Larger platforms carry more. A Significant Social Media Intermediary — more than fifty lakh registered users in India — must additionally publish monthly compliance reports detailing complaints received and action taken, appoint a Chief Compliance Officer and a full-time nodal contact for law enforcement, and enable identification of the originator of information on government request. There is also a requirement to publish a physical contact address in India, which applies more widely than the officer requirements do.

For a product team the practical work is a short list: a grievance intake that timestamps and tracks, a workflow with the statutory clocks visible and escalating, a takedown mechanism that can act quickly and records who authorised it, and retention configured to the hundred and eighty day floor rather than to whatever your logging vendor defaulted to. Most Indian platforms have the policy page and none of the machinery, which is the wrong half to have.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security