The Information Technology Act of 2000 stands as India’s primary legislation governing digital commerce and cybercrimes. While the Act was groundbreaking when enacted, making India one of the earliest countries with dedicated cyber legislation, its provisions regarding Internet Service Provider liability have faced persistent criticism. These criticisms center on fundamental issues of clarity, practical implementation, and fairness in how different types of service providers are treated under the law.
Table of Contents
- The core challenge of unclear classifications
- The vague concept of due diligence
- The burden of proof problem
- The knowledge standard dilemma
- Inadequate protection for passive conduits
- The challenge of balancing responsibilities
- Proposed reforms and their limitations
- International perspectives on reform
- The practical impact on innovation
The core challenge of unclear classifications
One of the most significant criticisms of the IT Act is its failure to adequately distinguish between the varied roles ISPs play in the digital ecosystem. The Act’s broad definition of intermediaries under Section 2(w) includes telecom service providers, web-hosting services, search engines, online marketplaces, and cyber cafes under a single umbrella. This one-size-fits-all approach treats fundamentally different entities as though they perform identical functions.
A simple internet access provider that merely transmits data packets operates very differently from a social media platform that hosts user-generated content, or an e-commerce marketplace that facilitates transactions. Yet the IT Act applies the same liability framework to all these entities. Critics argue this creates confusion around how the law applies to different types of intermediaries and potentially imposes unreasonable burdens on passive conduits while inadequately addressing active platforms.
The vague concept of due diligence
Section 79 of the IT Act exempts intermediaries from liability for third-party content if they meet certain conditions, including observing due diligence while discharging their duties. However, critics point out that the term due diligence is nowhere defined in the IT Act, creating significant uncertainty for service providers trying to comply with the law.
The absence of a clear definition raises difficult questions. If due diligence requires monitoring each aspect of the internet, it could lead to privacy violations and have disastrous effects. Service providers are left wondering whether they must proactively scan all content, respond only to complaints, or implement specific technical measures. This vagueness makes it nearly impossible for ISPs to know with certainty whether they have fulfilled their legal obligations.
Critics note that Section 79 has long been criticized for its poor drafting, including uncertainty about whether the due diligence requirement stands separate from the Intermediary Guidelines prescribed by the government. While the Information Technology Rules of 2011 and their 2021 replacement attempt to clarify these obligations, questions remain about whether these rules exhaust the meaning of due diligence or whether intermediaries face additional, undefined responsibilities.
The burden of proof problem
The IT Act requires ISPs to prove they had no knowledge of illegal activity and took sufficient steps to prevent violations in order to claim exemption from liability. Critics argue this creates an unfair burden of proof on service providers. When millions of pieces of content are uploaded daily, expecting an ISP to demonstrate lack of knowledge and preventive action for every potential violation seems practically impossible.
This issue becomes particularly acute in copyright cases. The Indian position on service provider liability for copyright infringement is not explicitly covered by the Copyright Act, leaving ISPs to navigate uncertainty. If someone claims copyright over material on a network, is the ISP liable for failing to remove it quickly enough? Does the plea of lacking knowledge remain available if the ISP received a complaint? These questions lack clear answers in current legislation.
The knowledge standard dilemma
The Supreme Court’s landmark judgment in Shreya Singhal v. Union of India clarified that actual knowledge means either a court order or notification by a government agency, not just any user complaint. However, implementing this standard creates practical challenges. ISPs must distinguish between legitimate government notices, court orders, and the countless complaints they receive daily from users claiming various forms of illegality.
Inadequate protection for passive conduits
The Copyright Act’s Section 51 can potentially impose liability on ISPs who permit places to be used for infringing communication, unless they were unaware and had no reasonable grounds for believing infringement would occur. Critics argue this provision, predating the internet era, fails to recognize that modern ISPs often function as mere passive conduits with no practical ability to monitor or control all content passing through their systems.
This becomes especially problematic for basic infrastructure providers. A company providing internet connectivity cannot reasonably inspect every data packet for potential copyright violations without fundamentally undermining the functioning of the internet itself. Yet the law’s framework potentially exposes even these passive actors to liability.
The challenge of balancing responsibilities
The IT Act attempts to balance protecting rights holders and the public against allowing digital innovation to flourish. Critics argue the current provisions tilt too far toward making ISPs responsible for policing content, rather than recognizing their primary function of building and maintaining internet infrastructure.
The American approach under the Digital Millennium Copyright Act provides clearer safe harbor provisions with specific categories of protected activities: transitory communications, system caching, storage at user direction, and information location tools. Each category has defined requirements. U.S. courts have not granted general immunity but impose liability based on degree of control and knowledge of infringing activity. Critics suggest India needs similarly nuanced provisions that recognize different types of intermediary functions.
Proposed reforms and their limitations
Various expert committees have proposed amendments to Section 79 and related provisions. These proposals typically aim to clarify ISP classifications, define due diligence more precisely, and establish clearer procedures for takedown notices and counter-notices. However, critics worry that rushed reforms might create new problems.
For instance, proposals requiring intermediaries to enable traceability of message originators raise serious privacy and freedom of expression concerns. Requirements for proactive content filtering could force platforms to implement expensive automated systems that inevitably produce both false positives and false negatives, either over-censoring legitimate speech or failing to catch genuinely harmful content.
International perspectives on reform
Other jurisdictions have grappled with similar challenges. The European Union’s Digital Services Act attempts to create a graduated system of obligations based on platform size and risk. Some critics suggest India could benefit from examining these international models, though any reforms must account for India’s unique legal and social context.
The practical impact on innovation
Beyond legal technicalities, the criticism of current ISP liability provisions extends to their real-world impact. Unclear liability standards can deter investment in digital platforms and services. Startups and smaller players may lack resources to navigate complex compliance requirements or defend against liability claims, while larger companies can absorb these costs more easily.
This creates barriers to entry and may stifle innovation. If potential ISPs face undefined responsibilities and unpredictable liability exposure, they may choose not to enter the Indian market or may limit their services to reduce risk. The result could be fewer choices for Indian consumers and reduced competition in digital services.
What do you think? Should Indian law adopt a more differentiated approach to ISP liability based on the type of service provided? Can clear standards be developed that protect rights while avoiding excessive burdens on digital platforms?
References
- https://www.legalservicesindia.com/articles/isp_in_us.htm
- https://www.lawyered.in/legal-disrupt/articles/internet-service-providers-and-its-liabilities-under-indian-law/
- https://lawandotherthings.com/intermediary-liability-and-safe-harbour-on-due-diligence-and-automated-filtering/
- https://ksandk.com/corporate/safe-harbor-intermediary-liability-indian-law/
- https://egyankosh.ac.in/bitstream/123456789/7674/1/Unit-13.pdf
- https://www.nishithdesai.com/SectionCategory/33/Technology-Law-Analysis/12/60/TechnologyLawAnalysis/15155/1.html
Leave a Reply