Contents
Introduction
India’s 900-million-plus internet ecosystem is entering an era of active platform governance: the IT Rules, DPDP framework and recent Big Tech scrutiny increasingly make accountability a condition for digital-market access.

Why platform compliance is increasingly difficult
- Safe Harbour Immunity Abuse: Section 79 of the IT Act protects intermediaries, but algorithmic curation and targeted advertising blur the line between passive conduit and active platform. Example: Meta algorithms.
- Encryption vs. Traceability Friction: Platforms utilizing End-to-End-Encryption (E2EE), resist requirements to trace the “first originator”, citing systemic cybersecurity vulnerabilities and breaches of individual privacy rights. Example: Signal.
- Jurisdictional & Structural Extraterritoriality: Global firms, foreign servers and multinational corporate structures complicate enforcement of Indian orders. Example: Telegram.
- Dark Patterns & Algorithmic Harms: Platforms can amplify deepfakes, scams and polarising content without transparent accountability mechanisms. Example: AI deepfakes.
- Rapid technological change: Regulation often follows innovations such as AI agents, synthetic media and new platform architectures. Example: AI governance.
Comparative Regulatory Matrix
| Regulatory Dimension | Intermediary Rules (2021/2023) & DPDP Act, 2023 | Global Benchmarks (EU DSA / DMA) |
| Grievance Redressal | Mandates Chief Compliance Officers and Grievance Appellate Committees (GACs). | Mandates independent, out-of-court dispute settlement bodies. |
| Data & Design Protection | Penalizes “Dark Patterns”; mandates consent managers under DPDP Act. | Prohibits targeted ads to minors and manipulative UX design. |
| Penal Consequences | Loss of Section 79 Safe Harbour protection and financial penalties. | Systemic fines up to 6% of global annual turnover. |
Recent Interventions Reveal The Changing Regulatory Approach
- Scrutiny of Meta, Google, Telegram and Signal illustrates a transition from regulating content alone towards examining platform architecture and design.
- Telegram’s restrictions concerning examination-paper circulation demonstrate preventive platform intervention. Example: NEET controversy.
- Concerns over WhatsApp usernames illustrate regulation of potentially harmful design features, not merely posts. Example: Identity spoofing.
- Meta’s controversies over moderation and AI-generated misinformation highlight the need for demonstrable compliance rather than post-facto apologies. Example: Deepfake videos.
- Thus, India is gradually moving from “intermediary responsibility” to “systemic platform responsibility.”
International lessons
| Model | Key approach | Lesson for India |
| EU DSA/DMA | Risk-based systemic regulation | Regulate dominant platforms proportionately |
| EU GDPR | Strong privacy framework | Strengthen user control |
| US | Courts + competition enforcement | Preserve innovation and speech |
| India | Hybrid, sectoral approach | Combine sovereignty with proportionality |
Way Forward
- Enacting the Digital India Act (DIA): Replace outdated IT Act, 2000 with a modern framework that categorizes intermediaries by risk and function rather than applying blanket rules. Example: Risk-based classification.
- Algorithmic Transparency & Co-Regulation: Establish statutory auditing frameworks for algorithmic recommendations and dark patterns while involving tech platforms in formulating technical standards. Example: Accountability-by- Design.
- Harmonizing Security with Fundamental Rights: Implement privacy-preserving compliance tools, metadata analysis and hash-matching, to combat illegal content without compromising E2EE or fundamental rights under Article 21. Example: Whole-of-stakeholder-Approach.
- Regulatory Coordination: Create interoperability among MeitY, CCI, CERT-In and sectoral regulators. Example: Joint oversight.
- AI-content Provenance: Encourage watermarking and content credentials for synthetic media. Example: Deepfake detection.
- International Cooperation: Strengthen MLATs and cross-border data-access mechanisms. Example: Cybercrime cooperation.
- Regulatory Sandboxing: Allow startups to innovate under proportionate compliance regimes. Example: AI sandbox.
Conclusion
Digital sovereignty cannot mean state overreach, nor can platform autonomy mean lawlessness. By building transparent, rule-based accountability frameworks, India can protect user safety and national security while maintaining an open, innovative digital economy.

