Lexology

The Intermediary Rules, 2021- A Half Yearly Review

20 September 2021 · By Atmaja Tripathy

The Intermediary Rules, 2021- A Half Yearly Review

Introduction:

The Ministry of Electronics and Information Technology of India (MEITY) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (Rules) on February 25, 2021, which supersede the Information Technology (Intermediaries Guidelines) Rules, 2011 (2011 Rules). The Rules, enforceable from the date of notification, lay down guidelines under two parts: (a) due diligence and grievance redressal mechanism for intermediaries and (b) Code of ethics, procedure and safeguards in relation to digital media. With the enforcement of the Rules, the intermediary and digital landscape in India has seen a demonstrable change to bring the systems in terms with the revamped regulations.

This write up encapsulates in brief, the enforcement of the Rules, the success and misses, so far, with emphasis on the regulation of significant social media intermediaries.

Due Diligence by Intermediaries:

The Rules classify intermediaries into three kinds: (a) Social Media Intermediaries which primarily enable online interaction between users, allowing them to create, upload, share, disseminate, modify or access information using intermediary’s services; (b) Significant social media intermediaries which comprise of social media intermediaries having at least 5 million registered users in India; and (c) The other category comprising of every other intermediary such as search engine, internet service providers, digital platforms and such other entities which are included in the traditional sense of the term intermediary.

Intermediaries of all kinds are required to prominently publish their privacy policy and terms of use on their platforms, either website or mobile application. They must periodically and at least once a year inform users that the right to access and use the intermediary’s computer resource can be revoked where information uploaded, created, shared or transmitted is not as per the Rules or otherwise breaches intermediary’s terms and policies. The Rules require every intermediary to inform users that the computer resource cannot be used to host, display, upload, modify, publish, transmit, store, update or share certain kinds of information, such as information that infringes third-party intellectual property rights, is unlawful, defamatory, obscene, harmful to children, etc. The new inclusion to the list is fake information/ news, which was earlier absent in the 2011 Rules.

The Rules have codified the law laid down in Shreya Singhal v Union of India, obligating intermediaries not to host, store or publish any unlawful information in relation to specific categories set out under Rule 3(1)(d), upon receipt of actual knowledge, either by way of court order or on being notified by the government authorities. The Rules provide for a statutory retention period for information removed or in case where access is disabled, where such information should be stored by the intermediary for a period of at least 180 days for investigation purposes. Further, a retention period is also provided for storing information collected from users for registering on a computer resource, for a period of 180 days after cancellation or withdrawal of such registration. In addition to the obligations set out above, the Rules require intermediaries to, inter alia, take all reasonable measures to secure the computer resource and information by adopting the reasonable security practices and procedures prescribed in the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011. Intermediaries are also required to report cyber security incidents and share related information with the Indian Computer Emergency Response Team in accordance with the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013.

Compliance Requirements for SSMIs- An Executive Overreach?

In addition to the aforesaid due diligence, which is mandatory for all intermediaries, significant social media intermediaries (SSMIs) were required to comply with additional due diligence requirements under Rule 4 of the Rules, within three months of the Rules coming into force.

As a part of the due diligence mandate, SSMIs must appoint a Chief Compliance Officer, a Nodal Contact Officer and a Resident Grievance Officer, all residents of India. The Chief Compliance Officer (CCO) should be a key managerial personnel such as whole-time director, MD, CEO or other senior employee, who will be responsible for compliance with the Information Technology Act, 2000 (Act) and the Rules. The CCO shall also be liable in proceedings for non-compliance while discharging its duties, provided that no liability can be imposed without affording a hearing opportunity. Unlike other statutes which provide for a relief to the senior representative or the persons in charge of a company, exempting them from any liability in case an offence is committed without the knowledge of such person, the Rules do not provide for such customary statutory protection. In fact, while Section 85 of the Act provides for such an exemption in case of offences committed by the Company, Rule 4(a) which makes the CCO liable is devoid of such a protection and therefore, is contradictory to the Act. Imposing liability on senior managerial personnel who is appointed as the CCO is an unreasonable requirement, making a prospective candidate or senior representative averse to being appointed as the CCO of an SSMI. Considering the risk associated with the role of CCO, SSMIs will not only find it difficult to appoint and retain such CCOs, but also have to additionally remunerate such CCOs to undertake the additional onerous responsibility.

The Rules mandate SSMIs to appoint a separate Nodal Contact Person (NCP) for 24*7 coordination with law enforcement agencies to ensure compliance with orders made in accordance with law. While there is a requirement to appoint a distinct NCP, the Rules have left SSMIs with little autonomy in managing and appointing resources. The Rules fail to justify why the function and role of a CCO cannot be merged with that of the NCP, at the instance of the SSMI. Creation of a separate position for NCP coordinate with law enforcement agency is nothing but an added expenditure which the SSMIs have to incur in order to be compliant with the Rules.

Lastly, the Resident Grievance Officer of the SSMI (RGO) would be responsible for enforcing the grievance redressal mechanism of intermediary as per Rule 3(2) of the Rules. The Rules provide for a rigorous and strict grievance redressal mechanism. The RGO shall acknowledge complaints from a “user” or a “victim” within 24 hours and dispose it off within 15 days. The timelines provided to an SSMI to acknowledge and redress the complaints appears to be unreasonable, given the large outreach and access of users to the SSMI platforms and the large number of complaints/ grievances which the RGO of an SSMI would resultantly receive.

On receipt of a complaint which relates to any content that prima facie exposes private area of an individual or relates to nudity, sexual depiction, impersonation in electronic form, including morphed images, the intermediary must take all reasonable and practicable steps to remove or disable access to such content within 24 hours of receipt of such a complaint. It is interesting to note that in the specific circumstances set out under Rule 3(2)(b) above, a specific take down order for removal of content is not necessary and the intermediary’s actual knowledge will be presumed in such cases. The obligation on the part of SSMI to remove content within 24 hours on the basis of ‘prima facie’ opinion on the complaint without any supervision is disconcerting. Threshold for content removal under Rule 3(2)(b) is low and lacks reasonable justification, specifically when the content could be pursuant to valid consent. Rule 3(2)(b) may force SSMIs to remove content merely on the basis of a ‘user’s complaint’ even though the subject matter of such content could be a consenting individual or a work of art. Illustratively, on the basis of a user’s complaint received either in relation to nude portrait painting of a consenting adult which is later published on an intermediary platform or a partially nude video of a consenting adult shot as part of a film/ series, an SSMI will be mandated to remove the content, irrespective of valid and continuing consent of the adult whose private parts are exposed. Therefore, the prima facie opinion to be arrived at has to be on the basis of human intervention and not merely based on calculated results derived by AI tools as the latter may most likely provide responses which not necessarily require removal of the content. Further, the grievance redressal mechanism specific to SSMIs also require the latter to provide: (a) a unique ticket number to each complainant for tracking the complaint; (b) reasons for action taken pursuant to a complaint; and (c) publish a monthly compliance report providing details of complaints received, action taken, and number of specific communication links or information removed or disabled by intermediary pursuant to its proactive monitoring by automated tools.

The most onerous obligation under Part I is imposed on the SSMIs which provide messaging services, such as WhatsApp, Telegram etc. These SSMIs are required to enable the identification of the first originator of information on its computer resource pursuant to a judicial order or an order of an Authority under Section 69 of the Information Technology (Procedure and Safeguards for interception, monitoring and decryption of information) Rules, 2009 (Interception Rules 2009). However, such order can only be passed for prevention, detection, investigation, prosecution or punishment of certain offences involving 5 years sentence or its incitement for instance, offence relating to sovereignty and integrity, state security, friendly relations with other nations, public order, rape, etc., if no other “less intrusive” measures for identifying originator is available. The disclosure is limited to originator’s identity, but not the content of electronic message. Where the originator is located outside India, then first originator located within India will be disclosed. While a request for disclosure can be made only for limited purposes as per the first proviso to Rule 4(2), in consonance with the Interception Rules 2009, compliance with the aforesaid rule by the messaging platforms/ SSMIs require a complete technological transformation. For SSMIs with large user base, the requirement to allow for identification of first originator information would require a systemic overhaul where such decryption and identification facility is available for each message. Such a requirement is unreasonably arduous, particularly in cases involving repeated forward of a particular message.

Keeping the practical difficulty aside, a more pertinent issue concerns the proportionality, legitimacy, and reasonableness in favour of inclusion of such a Rule. Illustratively, an order for disclosure of first originator information from WhatsApp would result in derogation of right to privacy of the user which is protected by WhatsApp’s end to end encryption facility. Further, WhatsApp is used by members from critical service sectors such as government officials, law enforcement authorities, doctors, etc. and the communication exchanged therein could reveal sensitive personal information. In addition to this, inclusion of a traceability feature even violates freedom of speech and results in a chilling effect on lawful speech. Naturally, right after the end of the 3-month period, WhatsApp challenged the vires of Rule 4(2) as being violative of Articles 14, 19(1)(a), 19(1)(g) and 21 of the Constitution of India, ultravires the Act and illegal. WhatsApp has also sought reliefs in terms of zero criminal liability for non-compliance with Rule 4(2) as being unconstitutional and ultravires the Act. The petition is presently being considered by the Delhi High Court.

Another contentious requirement for SSMIs is the deployment of technology-based measures, including automated tools etc., to proactively identify information that depict any act or simulation in any form depicting rape, child sexual abuse or conduct, whether explicit or implicit, or any information which is exactly identical in content to information that has previously been removed or access to which has been disabled. Further, the SSMI shall also notify the user attempting to access such information that the information has been identified and removed pursuant to Rule 3(1). SSMIs also need to additionally ensure that the measures undertaken are proportional to the interests of free speech and privacy of users. While the provisos to Rule 4(4) require SSMIs to deploy human oversight mechanism to periodically review the automated tools to judge the accuracy and fairness of such tools, the legislators are completely oblivious to the inaccuracies and inventor induced bias which inevitably plague AI systems. Therefore, deployment of AI tools for filtering content may result in erroneous results with the tools flagging and filtering content which otherwise is in conformity with free speech norms. Another critical aspect of this sub-rule is that it requires the SSMI to actively deploy filtering tools and use technology to identify content, quite contrary to the meaning and functionality of an intermediary which merely acts as a conduit without having any active knowledge of the content so published.

Rules’ Enforcement - A tale of Success or Misses?

The additional due diligence requirements for SSMIs have been in force since May 25, 2021. The MEITY, vide letter dated May 26, 2021, sought details of compliance with the Rules from the SSMIs.

Initially, upon completion of the three-month period, major SSMIs such as Google, Facebook, Instagram, LinkedIn, Telegram and WhatsApp submitted their compliance reports with the government. While WhatsApp has complied with all provisions of the IT Rules, on May 26, 2021, it filed a writ petition before the Delhi High Court challenging the unconstitutionality and ultra-vires nature of the traceability and disclosure requirements under Rule 4(2).

A perusal of Rule 7 makes it clear that non-compliance with the 3-month timeline by SSMIs would strip the intermediaries of the safe harbour protection under Section 79(1) of the Act. In the absence of such a protection, SSMIs will be liable for criminal consequence prescribed under the Act, read with the Indian Penal Code, 1860, for the content hosted by third party users. Given the rigorous compliance requirements and the short timeline of 3 months to comply with the additional due diligence conditions for SSMIs, the practical difficulty to comply took over certain intermediaries. Most notably, Twitter remained non-compliant with the additional requirements under Rule 4 on the pretext of absence of corporate presence in India till July 2021. Though initially non-compliant with the Rules even after conclusion of the three-month period, given the drastic consequence of parting with the safe harbour immunity, the largest microblogging platform was last in line to comply with the excessive Rules. Pursuant to directions of the Delhi High Court in Amit Acharya v. Union of India & Ors.,Twitter had no alternative but to appoint an Indian resident as its CCO, NCP and GRO in compliance with the Rules in August 2021.

Several SSMIs submitted their first monthly compliance reports in compliance with Rule 4(1)(d) of the Rules, early June. A perusal of the compliance reports, though success story for the regulators, may be a matter of concern for citizens. Facebook actioned against more than 30 million content pieces during May 15 to June 15, YouTube and Google removed 59,350, 71,132 and 83,613 content pieces pursuant to complaints received in April, May and June 2021, respectively. Additionally, in May and June, Google removed 6,34,357 and 5,26,866 pieces by using automated deletion. The volume of removal of content speaks for itself. Removal of content pursuant to the Rules nevertheless create a room for suspension of legitimate speech, over-regulation by intermediaries, out of caution on the erring side, thereby resulting in a chilling effect.

The above are only certain glaring aspects of the Rules concerning intermediaries and SSMIs. On the aspect of the regulation of digital platforms pursuant to the Code of Ethics, several other concerns arise which are not being discussed in the present article. Most recently, in August, a division bench of the Bombay High Court stayed the mandatory observance of the Code of Ethics by content publishers and the three tier redressal mechanism under Rules 9(1) and 9(3) of the Rules on a prima facie finding that the provisions infringe free speech under Article 19(1)(a), are manifestly unreasonable and also go against substantive provisions of the Act. Following suit from the Bombay High Court decision, this month, the Madras High Court also issued an interim stay against Rule 9(1) and 9(3). A total of 18 writ petitions are currently pending across High Courts of Kerala, Karnataka, Madras, Delhi and Calcutta wherein the validity of the Rules are under challenge. While the Bombay, Madras and Kerala High Courts have granted partial interim reliefs to the Petitioners in the matters, other courts are seized of the matter and have issued notices to the Union of India. It is with time that the courts will deliver their final opinion on the validity of the Rules. Until then, the intermediaries and SSMIs have no relief and must comply in order to avail the safe harbour protection.

Back to all insights
Follow on LinkedIn