27 March 2023
The Minister of State of Electronics & Information Technology presented a glimpse into the Digital India Act, 2023 (‘DIA’) on March 9 (‘Presentation’), as part of ongoing consultations[1]. The DIA is set to replace the Information Technology Act, 2000 (‘IT Act’) on account of the transformed internet landscape today, with significant internet penetration, multiple intermediaries operating across the internet and complex forms of user harms. As part of said presentation, many clarifications regarding the nature, scope and extent of DIA were given by the Minister.
Apart from highlighting the need for ‘global standard’ cyber laws to secure an open, safe and trusted internet, it was also emphasized that such law acts as a catalyst for innovation and growth of the technology and digital ecosystem, for managing complexities of intermediaries, for protecting citizen rights and addressing risks associated with emerging technologies. Considerable importance was also accorded to the importance of a framework that would be future-proof and future-ready.
It was proposed that the comprehensive digital framework would comprise of four pillars: an overarching Digital India Act, which would govern information technology law, a telecommunications law framework, a draft of which was released for public consultations recently i.e., the Draft Indian Telecommunications Bill, 2022[2] (‘Telecom Bill’); and the proposed personal data protection law, being the Digital Personal Data Protection Bill, 2022[3] (‘DPDP Bill’) which deals with personal data, all of which laws are currently in the draft stage. A separate framework regarding regulation of non-personal data, being the National Data Governance Framework Policy[4] (‘Data Governance Policy’), was also proposed recently.
The Presentation emphasized on the importance of an open internet which presents choice to consumers, promotes competition among digital players, furthers online diversity, facilitates fair market access for start-ups and new entities, and extends ease of doing business and compliance. Some of the key aspects proposed under the open internet objective include:
The proposed legislation also includes several aspects concerning protection of online safety and trust of internet users. As part of its objectives, the Bill aims to:
It was also proposed to introduce an accountability framework which includes adjudicatory and appellate mechanisms for digital operators, digital contraventions or offences, algorithmic transparency, and periodic risk assessments applicable to certain players.
At the outset, it was recognized that the nature of intermediaries and role played by them have transformed significantly and are functionally different. Intermediaries may be conduits (or technical providers of internet access or transmission services) or hosts (which provide content or platform services) or of any other nature[8]. They may also be classified based on nature and extent of involvement in content transmission, type of work undertaken by them, platform content vis-à-vis user generated content, role in peer-to-peer sharing of information etc. This is in stark contrast to the one-size-fits-all approach adopted under the IT Act[9].
It is recognized that different types of intermediaries exist in the digital space today, which is only expected to increase in the future. These may include e-Commerce platforms, search engines, social media platforms, digital media entities, gaming platforms, and pure-play intermediaries such as Telecom Service Providers, Internet Service Providers. There is a need to treat each of them distinctly in terms of the role played by them and introduce a nuanced regulatory approach and separate rules for each class thereof.
Significant questions were also raised as to the suitability of safe harbour for all intermediaries, given that the IT Act approaches this issue with extending safe harbour to all intermediaries[10]. In contrast, the DIA may witness novelty in approaching intermediary regulation. It was reported[11] that the Minister spoke on the multiple types of participants in the internet ecosystem and the different types of guardrails and regulatory requirements that would have to be developed for each of them.
While some broad obligations around due diligence, content restrictions, and grievance redressal are likely to remain, the new approach may invite certain new requirements linked with definitive penalties for non-compliance, unlike the IT Act in which liability only accrues for third-party content[12].
This may include a proposal to limit safe harbour to certain types of ‘pure-play’ intermediaries such as Telecom Service Providers, Internet Service Providers and hosting or cloud providers. However, it is unclear if intermediaries which have a role in content moderation or selectively propagating (sponsored or other) content would be able to take advantage of the safe harbour provisions. This may also have a wide-ranging effect on many intermediaries such as online content platforms, social media, search engines, e-commerce portals and other intermediaries facilitating uploading of sponsored content. Distinction may have to be drawn between platform-generated, user-generated content and further inquiry may have to be made into the (decisional) role that intermediaries may exercise with regard to the latter.
The DIA has big shoes to fill, as it sets to replace a vital, comprehensive and overarching information technology legislation. The first draft of the DIA is expected to release after the conclusion of stakeholder consultations on the issue[13]. In any case, it would be interesting to track incremental developments on the Digital India Act and analyze its impact across various industries.
[The authors are Senior Associate and Partner, respectively, in Data Protection and TMT practice at Lakshmikumaran & Sridharan Attorneys, New Delhi]