Citizen complaint — NCII/morphed
Requires a triage step that can identify private, morphed, or non-consensual intimate content on intake and route it to this lane immediately, ahead of the general complaint queue.
Home/AI & Synthetic Media Law/IT Rules 2026 Compliance
Practice Area · India
The IT Amendment Rules, 2026 changed three things that matter operationally: what counts as synthetically generated information, how it must be labelled, and how fast a grievance has to be actioned once it is received. This page is written for the people who have to build that into a working system — not for content, but for process.
The obligations under the amended Rules attach to intermediaries as defined under the IT Act — social media intermediaries, hosting providers, and significant social media intermediaries with the additional obligations that status carries. In practice this also reaches AI tool and model providers whose output is published or shared through a covered platform, and creator or marketing agencies operating tools that generate synthetic content on a platform's behalf. Where the obligation sits in a supply chain with several parties is a question of fact, not a single rule.
The 2026 amendment defines “synthetically generated information” in Indian law for the first time. Content falling within that definition must be labelled clearly and prominently, and carry provenance metadata that allows it to be traced back to its origin. Two consequences follow for anyone building or operating a platform or tool: labelling has to be applied at the point of generation or publication, not bolted on afterwards, and the label has to survive ordinary re-sharing and re-encoding if it is to do the job the Rules intend.
A grievance mechanism has to route an incoming complaint to the correct clock before it can meet it. The three windows are not interchangeable.
Requires a triage step that can identify private, morphed, or non-consensual intimate content on intake and route it to this lane immediately, ahead of the general complaint queue.
Includes notices routed through the Sahyog mechanism from agencies such as I4C. This is an inbound government channel your compliance workflow has to be able to receive and prioritise — it is not something your platform initiates.
Still requires a defined SLA and audit trail; the longer window is not a reason to deprioritise a category-appropriate complaint.
General grievances outside these tiers still carry a twenty-four-hour acknowledgment requirement and a seven-day disposal period, shortened from fifteen days. A workflow built only around the fastest lane will miss this obligation.
Safe harbour under Section 79 of the IT Act is conditional, not automatic. On the current framework, the following materially increase exposure:
Where a tool trains on or generates content from personal data — a photograph, a voice sample, or other identifying material — the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are separately engaged. Substantive Data Fiduciary obligations, including notice, consent and breach reporting, commence 13 May 2027, with penalties reaching ₹250 crore. Compliance architecture built now for the IT Rules is generally cheaper to extend to DPDP than to retrofit later.
A working starting point for legal and product teams to build from — not a substitute for an audit of your specific systems.
With a functioning, monitored intake channel, not just a named individual on a policy page.
Able to route an incoming complaint to the correct tier — NCII/morphed, court or government notice, or general grievance — at intake, not after review.
Not as a post-publication add-on, and tested against ordinary re-sharing and re-encoding.
Two hours, three hours, thirty-six hours and the general twenty-four-hour/seven-day track, each with its own escalation path.
These are inbound and time-sensitive; the workflow needs a defined owner and priority handling.
Timestamped records of receipt, classification, and action taken, sufficient to demonstrate compliance if safe harbour is later challenged.
Wherever personal data feeds training or generation, so notice and consent architecture can be planned against the 13 May 2027 commencement rather than built afterwards.
A notice from a grievance officer's own users is a different matter from a notice issued by a government agency or a court order, and the two call for different responses. Where a platform has actually received a notice, a complaint, or an indication that safe harbour is being questioned, the position depends heavily on what the platform did before the notice arrived.
Safe harbour is a defence to be established, not an entitlement to assume
Section 79 protection is conditional on due diligence, and in a dispute the burden of showing that diligence was observed falls on the intermediary. This is where an audit trail — records of when a complaint was received, how it was classified, and what was done within the applicable window — stops being a compliance nicety and becomes the actual evidence a platform relies on.
Where a notice has been received under Section 79(3)(b), whether directly or routed through the Sahyog mechanism, the immediate questions are: what window applies to the notice as framed, whether the platform's classification of the underlying content was correct, and whether the response taken and its timing are documented. Where a platform disputes that it is the correct addressee for a notice — because it is not an intermediary in the relevant sense, or because the content falls outside what it hosts or transmits — that position needs to be established on the specific facts rather than asserted generally.
Where enforcement action follows a claimed loss of safe harbour, the platform's exposure is then assessed as if it were directly liable for the content in question, which is why the question of whether due diligence was actually observed becomes central rather than incidental. Where a regulator or a court is involved rather than an individual complainant, the procedural posture and the timeline both change, and early engagement generally produces a better outcome than a delayed one.
On representation
A platform facing a notice, a complaint, or a question over its safe harbour position is entitled to establish its own compliance record and to contest a finding that due diligence was not observed. Nothing on this page is a comment on the merits of any particular matter.
Law stated as at 11 August 2026
Sahyog is the inbound government and law-enforcement channel through which agencies such as I4C issue notices under Section 79(3)(b) of the IT Act. Intermediaries need the operational capacity to receive and act on these notices within the applicable window; it is not a channel your platform uses to report content outward.
Content that meets the Rules' definition of synthetically generated information must carry a clear, prominent label and traceable provenance metadata. Whether a specific output meets that definition depends on how it was produced and how it is presented, which is a fact-specific assessment.
Missing the applicable window once actual knowledge is established is a factor that can put Section 79 safe harbour at risk, in addition to any liability arising from the underlying content itself.
Section 319 addresses cheating by personation as an offence committed by an individual; it is not, by itself, a basis for intermediary liability. Platform exposure is generally assessed separately under the IT Act and the Rules, based on how the platform responded once it had knowledge.
The Data Protection Board was constituted on notification of the Rules. Consent manager registration opens in November 2026. Substantive Data Fiduciary obligations commence on 13 May 2027.
The response depends on the platform's own record: when the notice was received, how it was classified, and what was done and when. Where that record supports the platform's position, it is the primary evidence relied on. Where it does not, the exposure is assessed on the underlying content as though safe harbour did not apply.
Yes, where the position is genuinely arguable — for instance, that the service does not fall within intermediary classification for the relevant function, or that the content in question falls outside what the platform hosts or transmits. This needs to be established on the specific facts of the service rather than asserted as a general defence.
The platform is then assessed as though it were directly liable for the user content in question, in whatever proceeding has been brought. This is the material exposure behind the compliance obligations, and it is why the due diligence record matters as much before a dispute arises as during one.
Yes. A notice from a government agency, a court, or one routed through Sahyog carries a different procedural posture and generally a different timeline from an individual user complaint, and early engagement is generally more effective than a delayed response.
If a matter is time-sensitive — content already circulating, a takedown window running, or a statutory deadline approaching — say so in the first line.
Or write directly to info@bylaw.in
As per the rules of the Bar Council of India, an advocate is not permitted to advertise or solicit work. By continuing to use this website, you acknowledge that you are seeking information about Bylaw.in of your own accord, that no advocate-client relationship is created by your visit, and that the content here is for general information only and is not legal advice.
We also use privacy-first analytics (Google Consent Mode v2, per the DPDP Act 2023) to understand how this page is used. Continuing agrees to this — or continue without it below.