Is Meta Still Just an Intermediary? Why India Is Rethinking Safe Harbour
By Vikrant Rana, Lucy Rana, and Huda Jafri
Introduction
In mid-September 2026, government sources said Meta Platforms’ Indian operations, Facebook, Instagram and Threads, should no longer be viewed merely as an “internet intermediary” but should also be treated as a “service provider,” arguing that the company’s monetised algorithms actively decide what content gets amplified, distributed and shown to whom.[1][2] That is a government position, not a new statutory classification, and this article returns to that distinction below. The statement came amid a wider controversy: the National Commission for Protection of Child Rights (NCPCR) has twice summoned Meta India’s leadership over allegations that paid Instagram advertisements gave users access to child sexual abuse material (CSAM), and the Ministry of Electronics and Information Technology (MeitY) had earlier directed Instagram to disable such advertisements.[3][4][5]
The framing matters because it touches the single most important protection available to online platforms in India: the “safe harbour” exemption under Section 79 of the Information Technology Act, 2000 (the “IT Act”), which shields intermediaries from liability for content posted by third parties. If that exemption is genuinely at risk in Meta’s case, the consequences reach well beyond Meta, to every platform in India whose business model depends on ranking, recommending or monetising user content.
This article looks at what the government’s position actually means in law, separates that position from what the statute and the 2021 Rules say, reviews the judicial precedents that will shape any such dispute, and sets out what businesses running platforms in India should take from this moment.
The NCPCR’s inquiry began after reports, including a BBC investigation, alleged that Instagram had carried paid advertisements that gave users access to CSAM.[6] The Commission took cognisance and issued its first notice to Meta around 3 July 2026, seeking an explanation; Meta responded about a week later, and MeitY separately directed Instagram to disable the advertisements in question. The NCPCR then summoned Meta India’s Managing Director for a hearing, and after that appearance proved unsatisfactory, issued a fresh summons in September 2026 as its formal inquiry continues.[7]
Union Minister for Electronics and Information Technology Ashwini Vaishnaw said Meta had “admitted it made mistakes” and had committed to reporting CSAM to law enforcement, and that the company had begun routing such reports to the Indian Cyber Crime Coordination Centre (I4C).[8] It is against this backdrop, not as a standalone policy announcement, that government sources put forward the “service provider” argument: that a platform charging advertisers to have algorithms decide who sees what content has moved well beyond passive hosting and must carry responsibility to match, including for advertisements that gave access to unlawful material.
To test that claim, it helps to start with what Section 79 actually says, because Indian law does not, at present, recognise “service provider” as a separate liability category standing outside, or above, “intermediary.”
Section 2(1)(w) of the IT Act defines an “intermediary,” in relation to any electronic record, as any person who, on behalf of another, “receives, stores or transmits” that record, or provides any service with respect to it: a definition wide enough to cover social media platforms, telecom operators, search engines, cyber cafés and payment gateways alike.
Section 79(1) exempts intermediaries from liability for third-party information hosted or transmitted through their systems, but the exemption is conditional, not automatic. Section 79(2) sets out when it applies: the intermediary’s function must be limited to providing access to a communication system, or it must not (a) initiate the transmission, (b) select the receiver of the transmission, or (c) select or modify the information contained in the transmission, and it must observe “due diligence” in discharging its duties. Section 79(3) then removes the exemption where the intermediary has conspired in, abetted, aided or induced the unlawful act, or where, on receiving “actual knowledge,” or notification by the government or its agency, that material is being used to commit an unlawful act, it fails to remove or disable access to that material expeditiously.
Rule 7 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 adds an important layer: where an intermediary fails to observe the due diligence obligations set out in the Rules, Section 79(1) simply does not apply to it. Rule 3(1)(b) requires intermediaries to make reasonable efforts to keep users from hosting, displaying or sharing content that is, among other things, obscene, paedophilic, or “harmful to child,” and material depicting CSAM specifically is separately and heavily penalised under Section 67B of the IT Act, which criminalises publishing or transmitting material that depicts children in sexually explicit acts. Platforms that cross the registered-user threshold for “significant social media intermediaries” (SSMIs), currently five million registered users in India, carry further obligations, including grievance redressal timelines, a resident Chief Compliance Officer, and traceability of the first originator of certain messages.[9]
Two further obligations placed on SSMIs speak directly to the facts of the Meta controversy. Rule 4(3) requires an SSMI that provides a service for direct financial benefit in a way that increases the visibility or prominence of content, or that targets the receiver, to clearly identify that content as advertised, marketed, sponsored, owned or exclusively controlled. Rule 4(4) requires an SSMI to endeavour to deploy technology-based measures, including automated tools, to proactively identify material depicting rape or child sexual abuse, subject to safeguards of proportionality, privacy, free expression and human oversight. Both provisions expressly contemplate paid, targeted amplification as part of operating a significant social media intermediary, and they regulate it through disclosure and proactive-detection duties rather than by treating it as automatically incompatible with intermediary status. That matters for what follows: it means the government’s argument has to work within a framework that already expects platforms to target and promote content for money, not against one that treats any such targeting as disqualifying in itself.
In short, the statute already distinguishes platforms on the Section 79(2) conditions themselves: whether a platform’s function is limited to providing access, whether it initiates transmission, selects the receiver, or selects or modifies the information, and whether it observes due diligence, including on CSAM. The government’s argument is better understood not as inventing a new category, but as saying that Meta’s paid, algorithmically targeted amplification falls outside those conditions. That is a serious argument, but it runs up against rules that already contemplate paid targeting inside the intermediary framework, so it does not follow automatically. A narrower and perhaps more direct route lies in Meta’s alleged failure to keep CSAM-linked advertisements off the platform, which, if established, could amount to a breach of Rule 3(1)(b) due diligence and trigger Rule 7, whatever the eventual answer on receiver selection.
It is worth being precise about what the “reclassification” reports do not establish. Section 79 sets out the conditions on which the exemption from liability is available; it is for a court, or in some contexts a quasi-judicial authority, to decide in a given case whether those conditions are met. It is not a licence or status that a ministry grants or withdraws by administrative declaration. A government official is reported to have acknowledged as much, saying that the “final decision on whether the company is liable will rest with the judiciary.”[10] Nothing in the IT Act or the 2021 Rules currently creates a separate, defined legal category called “service provider” that replaces “intermediary” for Meta or for any other platform. At this stage, the phrase reflects a policy position and a signal of the government’s likely litigating stance, not an enacted reclassification.
That distinction matters for businesses. What changes immediately is not Meta’s legal status under a statute, but the seriousness with which the government appears ready to contest safe harbour claims over algorithmically curated, monetised content, and, as discussed below, the direction of rule-making still to come.
Shreya Singhal v. Union of India (2015)
Decided by the Supreme Court on 24 March 2015, this remains the foundational precedent on Section 79.[11] The Court read down Section 79(3)(b) and the corresponding Rule 3(4) of the 2011 Intermediaries Guidelines, holding that “actual knowledge” for the purpose of withdrawing safe harbour must mean knowledge that comes from a court order, or from a notification by the appropriate government or its agency, that certain material must be taken down, not mere awareness, complaint, or private notice. The 2021 Rules now build this holding into their own text: Rule 3(1)(d) frames actual knowledge in terms of a court order or a government notification, echoing the Supreme Court’s reading of Section 79(3)(b). That does not mean a platform can simply wait for such an order before acting on every front. The CSAM-specific duties in Rule 3(1)(b) and Rule 4(4), discussed above, operate independently of any notification and call for proactive effort. Shreya Singhal remains good law on what counts as actual knowledge for Section 79(3)(b) purposes, and nothing in the September 2026 developments purports to disturb it.
Decided by the Delhi High Court (Pratibha M. Singh, J.) on 2 November 2018 in CS(COMM) 344/2018, this case addressed a related question: could an e-commerce platform that did far more than host content, verifying authenticity, warehousing inventory, and using a trademark in its meta-tags, still claim intermediary immunity for trademark infringement?[12] The Court held that it could not. Platforms actively involved in transactions, rather than simply connecting buyer and seller, forfeit the “passive” character that Section 79 protects, the Court reasoned, drawing on comparative case law including L’Oréal v. eBay (EU) and Tiffany v. eBay (US). No reported Indian decision located for this article has held that ordinary recommender-system ranking, on its own, removes Section 79 protection. In our assessment, Louboutin is the closest available Indian authority for the government’s “active participation” argument against Meta, though its facts concerned an e-commerce platform’s conduct in individual transactions, not a social media platform’s automated ranking of content. Courts will still have to decide whether, and how far, its reasoning extends to recommender systems and ad targeting.
Decided on 24 September 2025 in Writ Petition No. 7405 of 2025, Justice M. Nagaprasanna of the Karnataka High Court upheld the constitutional validity of the Union government’s “Sahyog” portal for issuing content-blocking directions to intermediaries, and held that Section 79(3)(b), read with Rule 3(1)(d) of the 2021 Rules, lets the government notify intermediaries of unlawful content without relying only on the Section 69A blocking mechanism.[13] The Court rejected the platform’s argument that mandatory compliance with such notices was unconstitutional, finding “constitutional harmony” between the provisions rather than conflict. X Corp has since filed an intra-court appeal before the Karnataka High Court’s Division Bench; the appeal was pending as of the most recent public reporting reviewed for this article, and its current status should be checked before publication.[14] The single-judge ruling supports the government’s use of Sahyog as a notification mechanism under Section 79(3)(b), read with Rule 3(1)(d), even without any “service provider” reclassification, though that support remains subject to X Corp’s pending appeal.
A useful illustration, though not a Section 79 precedent, comes from a dispute under a different statute altogether. In an order reported around 19 August 2026, the Central Consumer Protection Authority (CCPA) imposed a penalty of Rs 5 lakh on Flipkart for facilitating the listing, advertising and sale of toys that did not meet mandatory Bureau of Indian Standards (BIS) requirements. Secondary reporting states that the order treated the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020 as imposing platform-level obligations independent of Flipkart’s intermediary status; this article has not reviewed the CCPA’s order itself, so that characterisation should be checked against the primary order before publication.[15] Flipkart challenged the penalty before the Karnataka High Court, arguing among other things that Section 2(47) of the Consumer Protection Act requires a positive misrepresentation, which it denies making, and that the BIS framework rather than the CCPA was the appropriate forum. At a hearing on 3 September 2026, the Court directed Flipkart to file an affidavit on its compliance measures and to display grievance officer details more prominently, while Flipkart recorded its undertaking to pay the penalty under protest pending disposal of its writ petition, which remains listed for further hearing.[16] The episode illustrates a regulator declining to accept a “we are just an intermediary” argument, but it arises under consumer protection law rather than Section 79 of the IT Act, and the underlying penalty itself is under challenge, so it should be read as an analogy rather than as authority on IT Act safe harbour.
Strip away the “service provider” label, and the government’s argument reduces to a claim under Section 79(2)(b): that a recommender system which ranks, amplifies or suppresses content, and an advertising system that lets buyers target audiences “based on age, location, gender and other factors,” amounts to “selecting the receiver of the transmission” and/or “selecting or modifying the information contained in the transmission.”[17] That gives the government a plausible argument, because Section 79(2)(b) expressly refers to selecting the receiver. But the existence of targeting does not, by itself, establish that safe harbour is lost. As the discussion of Rule 4(3) above shows, the 2021 Rules already contemplate an SSMI providing services for direct financial benefit that target the receiver, and they regulate that conduct through disclosure obligations rather than through automatic disqualification from Section 79. Ranking and recommendation are also near-universal features of the modern internet, and if every act of algorithmic ordering defeated the passivity condition, the practical scope of Section 79 could shrink sharply, a concern legal commentators have already raised.[18] Courts will likely have to draw a line between ordinary ranking, which the Rules already assume happens inside the intermediary framework, and monetised, granular targeting that facilitates unlawful content specifically, such as advertisements alleged to have put CSAM in front of particular audiences.
A second, narrower argument does not need that broader question answered at all. If Meta’s own systems allowed CSAM-linked advertisements to run despite the Rule 3(1)(b) duty to make reasonable efforts against such content, Rule 7 independently takes away Section 79(1) immunity for that conduct, regardless of whether the platform is called an “intermediary” or a “service provider.” Given how serious Section 67B offences are, this due diligence route may turn out to be the more direct legal avenue in the present controversy, even as “service provider” language dominates public commentary.
The Global Context: Comparable Regulatory Trends
India’s debate has echoes elsewhere, though the legal architecture differs. The European Union’s Digital Services Act (Regulation (EU) 2022/2065) creates a distinct, heavier-obligation category for “Very Large Online Platforms” (VLOPs), designated once a platform reaches an EU-wide average of 45 million monthly active recipients, which must run systemic risk assessments (Article 34) and adopt mitigation measures (Article 35), including for risks to minors, and must disclose the main parameters of their recommender systems under Article 27. Unlike India’s position, this is an explicit, codified tiered-liability structure, not an interpretation stretched out of an existing conduit-immunity provision.
In the United States, the Supreme Court in Gonzalez v. Google LLC, 598 U.S. 617 (2023), was asked whether Section 230 of the Communications Decency Act protects YouTube’s recommendation algorithm; the Court ultimately decided the case on other grounds, leaving the Supreme Court’s treatment of Section 230’s application to recommender systems unresolved.[19] India, in other words, is working through a live question that has not been settled internationally either: whether algorithmic curation is functionally different from passive hosting for liability purposes.
Practical Implications for Platforms and Businesses
For social media companies, e-commerce marketplaces, and any platform that monetises algorithmic ranking or targeting in India, a few practical points follow.
First, safe harbour is not a shield that, once claimed, stays put. It has to be actively maintained through demonstrable, documented due diligence under the 2021 Rules, particularly around Rule 3(1)(b) and Rule 4(4) on CSAM, and through prompt action on Section 79(3)(b) notifications, including through mechanisms such as the Sahyog portal that the Karnataka High Court has upheld, subject to X Corp’s pending appeal.
Second, features involving verification, branding assurances, active promotion or granular targeting may attract closer scrutiny where they show a platform doing more than passively hosting third-party material. Louboutin remains the clearest domestic authority for that active-participation principle, even though it arose from e-commerce rather than social media; the Flipkart proceedings are a cross-statute illustration of the same regulatory instinct rather than a Section 79 precedent.
Third, platforms should watch the Draft Information Technology (Second Amendment) Rules, 2026, which propose a new Rule 3(4) making compliance with ministry-issued advisories and codes of practice part of Section 79 due diligence. The consultation on this draft closed in May 2026; as of the most recent sources reviewed for this article, the broader rules had not been notified in final form, though separate notification of Rule 3(4) alone was reportedly being considered, so the current status should be verified before relying on it.[20]
Fourth, sector-specific reporting obligations are tightening in practice even without new legislation, as Meta’s own move to route CSAM reports through the I4C shows.
Emerging and Unresolved Questions
A few real questions remain open. It is unsettled whether a court, faced with an actual dispute, would accept that monetised algorithmic amplification alone defeats the Section 79(2) conditions, particularly given that Rule 4(3) already contemplates such targeting inside the intermediary framework, or would instead limit any loss of immunity to specific instances of due diligence failure. It is also unclear whether the government means to pursue a legislative amendment that defines a distinct liability tier, something like the EU’s VLOP model, or will keep working within the existing Section 79 framework read more expansively, including through the Draft Information Technology (Second Amendment) Rules, 2026, whose final status should be verified before publication. X Corp’s pending appeal against the Sahyog ruling and Flipkart’s pending challenge before the Karnataka High Court may each offer earlier judicial guidance, on government notification powers and on platform-level branding and verification respectively, than any ruling that touches Meta directly. And the NCPCR’s inquiry itself, carried out under the Commissions for Protection of Child Rights Act, 2005, which gives the Commission the powers of a civil court under Section 14 for its inquiries, is still ongoing; any findings or referrals it makes may shape the specific facts on which a Section 79 dispute, if it is litigated, would ultimately turn.
Conclusion
The governing framework remains Section 79, the 2021 Rules, and the existing case law interpreting particular aspects of intermediary liability: Shreya Singhal on actual knowledge, Louboutin on active participation, and X Corp on government notification powers. Those authorities establish that safe harbour is conditional, but they do not, on their own, add up to a settled test for when recommender algorithms or paid audience targeting turn a social media platform from a protected intermediary into an independently liable participant. Calling Meta a “service provider” rather than a “mere intermediary” is best read as a strong policy signal and a statement of litigating intent, not as an enacted change to India’s intermediary liability framework. What has changed is the government’s evident willingness to test the existing Section 79 framework against a platform whose business runs on paid promotion, audience targeting and algorithmic amplification, backed by parallel regulatory pressure through the NCPCR inquiry and by rule-making still in progress. For platforms operating in India, the practical lesson comes before any judicial ruling: whether the Section 79(2) conditions are met, and whether due diligence under the 2021 Rules is observed on an ongoing basis, is what determines whether the exemption is available, not any label attached to the platform, and how far that test stretches over algorithmic curation remains an open question.
[1] Business Standard, “Meta platforms must be treated as service provider, not intermediary,” 16-17 September 2026. Available at: business-standard.com
[2] Medianama, “Can Meta Lose Safe Harbour Over Its Algorithms?,” September 2026. Available at: medianama.com
[3] Deccan Herald, “NCPCR summons Meta India chief over alleged child sexual abuse material ads,” September 2026. Available at: deccanherald.com
[4] Deccan Herald, “NCPCR summons Meta India head again for inquiry into alleged ads promoting child sexual abuse material,” September 2026. Available at: deccanherald.com
[5] Business Today, “Meta may no longer qualify as ‘intermediary’, government weighs greater responsibility for content,” 16 September 2026. Available at: businesstoday.in
[6] Outlook India, “Why India Is Questioning Meta’s ‘Intermediary’ Status Over Facebook, Instagram,” September 2026 (reporting the BBC investigation into paid advertisements). Available at: outlookindia.com
[7] See note 4 above.
[8] Statement of Ashwini Vaishnaw, Minister of Electronics and Information Technology, reported September 2026, on Meta’s admission of lapses and the routing of CSAM reports to the Indian Cyber Crime Coordination Centre (I4C).
[9] Rule 2(1)(w) and Rule 4, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (significant social media intermediary threshold and added due diligence, including traceability of the first originator).
[10] See note 1 above.
[11] Shreya Singhal v. Union of India, Writ Petition (Criminal) No. 167 of 2012, Supreme Court of India, decided 24 March 2015; AIR 2015 SC 1523; (2015) 5 SCC 1.
[12] Christian Louboutin SAS v. Nakul Bajaj & Ors., CS(COMM) 344/2018, Delhi High Court, decided 2 November 2018 (Pratibha M. Singh, J.).
[13] X Corp v. Union of India, Writ Petition No. 7405 of 2025, Karnataka High Court, decided 24 September 2025 (M. Nagaprasanna, J.), upholding the validity of the “Sahyog” portal and Section 79(3)(b) read with Rule 3(1)(d) of the 2021 Rules.
[14] X Corp filed an intra-court appeal before the Division Bench of the Karnataka High Court in mid-November 2025; Bar and Bench
[15] Central Consumer Protection Authority, order against Flipkart reported around 19 August 2026: Bar and Bench
[16] Flipkart’s challenge to the CCPA penalty before the Karnataka High Court, LiveLaw
[17] See note 1 above.
[18] See note 2 above.
[19] Gonzalez v. Google LLC, 598 U.S. 617 (2023). Available at: Knight First Amendment Institute
[20] Draft Information Technology (Second Amendment) Rules, 2026, MeitY,
Article | IP Laws