| Resolution | Adopted | What it says |
|---|---|---|
| 20/8, The promotion, protection and enjoyment of human rights on the Internet | 5 July 2012, without a vote | Affirms that the same rights that people have offline must also be protected online, in particular freedom of expression |
| 32/13, same title | 1 July 2016, without a vote | Condemns unequivocally measures to intentionally prevent or disrupt access to or dissemination of information online in violation of international human rights law |
| Family | Constitutional home in India | Where it shows up in development work |
|---|---|---|
| Access and connectivity | No standalone right to internet access; Anuradha Bhasin (2020) protects speech and trade through the internet under Article 19(1)(a) and (g) | Internet shutdowns, the gender gap in phone ownership, offline fallbacks for welfare |
| Expression and information | Article 19(1)(a), limited only by Article 19(2) | Blocking orders, takedowns of NGO content, the fact check unit, deepfakes in elections |
| Privacy and data | Article 21, as read in Puttaswamy (2017) | Beneficiary databases, biometric authentication, surveillance, facial recognition |
| Equality and due process | Articles 14 and 21 | Algorithms that cut people from welfare lists without notice or a hearing |
| Ground in Article 19(2) | A digital case it has been used for |
|---|---|
| Sovereignty and integrity of India; security of the State | Blocking of apps and accounts under IT Act s69A |
| Friendly relations with foreign States | Blocking of content about another country |
| Public order | Internet suspension during protests, the ground examined in Anuradha Bhasin |
| Decency or morality | Obscenity offences in IT Act ss67 and 67A |
| Contempt of court; defamation | Takedown of posts about judges or private persons |
| Incitement to an offence | Blocking of posts calling for violence |
| Provision | Holding in Shreya Singhal (2015) | What it means now |
|---|---|---|
| IT Act s66A | Struck down in its entirety | No prosecution can rest on it; it is dead law |
| IT Act s69A and the Blocking Rules 2009 | Constitutionally valid | The Centre may block content for reasons in writing, through a committee procedure |
| IT Act s79 (intermediary safe harbour) | Valid, with s79(3)(b) read down | A platform must act on actual knowledge from a court order or a government notification tied to Article 19(2) |
| IT (Intermediaries Guidelines) Rules 2011 | Valid, subject to the same reading down | Replaced in 2021 by the IT Rules, Section 04 |
| Country | Law | What changed | Status as of October 2026 |
|---|---|---|---|
| Bangladesh | Cyber Security Ordinance 2025 | Repealed the Cyber Security Act 2023; recognises internet access as a civic right | Gazetted 21 May 2025 by the interim government; check its standing after the 2026 Parliament |
| Pakistan | Prevention of Electronic Crimes (Amendment) Act 2025 | New s26A: false information likely to cause fear, panic or unrest, up to three years and Rs 2 million fine | In force from 29 January 2025 |
| Sri Lanka | Online Safety Act No. 09 of 2024 | Created an Online Safety Commission over prohibited statements | In force since February 2024; amendments under consultation in 2025 |
| Nepal | Social media registration requirement | At least 26 social media platforms blocked in 2025 | Triggered mass protests met with lethal force (Access Now 2026) |
| Stated reason | South Asian example | Proportionality question |
|---|---|---|
| Protests and political unrest | Bangladesh, July 2024 quota-reform protests | Was the blackout limited in area and time, and published? |
| Active conflict | Myanmar, most of its 95 shutdowns in 2025 | Did it cut off information people needed to stay safe? |
| Exam cheating | India: five exam shutdowns during government job exams in 2024, matching its 2018 record | Could invigilation or jammers in exam halls do the job instead? |
| Religious events and security | Pakistan: mobile suspensions during Muharram | Was a targeted measure available? |
| Platform regulation | Nepal: 26 platforms blocked in 2025 over registration rules | Was blocking the least restrictive way to enforce registration? |
| Function | What fails during a shutdown | Fallback to plan in advance |
|---|---|---|
| Ration and pension authentication | Online biometric match at the shop or the bank point | Offline or manual authentication with a register, as allowed by the scheme |
| Cash transfers and wages | Payment confirmation and withdrawals at agents | Cash advance policy and an agreed grace period with the department |
| Monitoring and data collection | Sync from field apps; dashboards go stale | Apps that store offline; paper forms with later entry |
| Helplines and grievance portals | Chat and web channels | Voice and SMS numbers, which often survive a data shutdown |
| Remote learning and telemedicine | Video sessions and uploads | Downloaded content; radio; phone consultations |
| Feature | Telecommunications (Temporary Suspension of Services) Rules 2024 |
|---|---|
| Who may order | The Union Home Secretary or a State Home Secretary; in unavoidable cases a Joint Secretary to the Central Government or above, authorised by them, and confirmed within 24 hours |
| How long | At most 15 days per order |
| Where | The order must state the geographic area |
| Review | A review committee meets within five days and may set the order aside |
| Publication | The order must be published and state its reasons, which tracks Anuradha Bhasin |
| Section | What it allows | Who acts | Penalty for non-compliance |
|---|---|---|---|
| s69 | Interception, monitoring or decryption of information in a computer resource | Central or State Government | Up to seven years for a person who fails to assist |
| s69A | Blocking public access to information | Central Government, for reasons recorded in writing | Up to seven years and fine for an intermediary that fails to comply |
| s69B | Monitoring and collecting traffic data for cyber security | Central Government | Up to three years and fine for an intermediary that fails to assist |
| s79 | Safe harbour: an intermediary is not liable for third-party content if it meets conditions | Platforms, subject to the IT Rules | Loss of the safe harbour |
| Step | What to do | Legal hook |
|---|---|---|
| 1. Preserve | Screenshot the notice, the content and the dates; export the page data | Evidence for any later challenge |
| 2. Identify the basis | Ask the platform which law or order it relied on | IT Rules 2021 grievance process |
| 3. Platform appeal | Use the platform's appeal and its India grievance officer | IT Rules 2021, grievance officer duties |
| 4. Government route | If a section 69A order is cited, ask for a hearing and the order | Blocking Rules 2009 |
| 5. Appellate committee | Appeal a grievance officer's decision | Grievance Appellate Committees under the IT Rules |
| 6. Court | Writ petition in a High Court with a lawyer | Articles 19(1)(a) and 226 |
| Power | Statute | Authorised by |
|---|---|---|
| Interception, detention or disclosure of messages on a public emergency or in the interest of public safety | Telecommunications Act 2023, s20(2) | Central or State Government, or an officer specially authorised |
| Interception, monitoring or decryption of information in a computer resource | IT Act 2000, s69 | Central or State Government, or an officer specially authorised |
| Monitoring and collecting traffic data | IT Act 2000, s69B | Central Government, for cyber security |
| Data a programme often holds | How it could be misused | Safer design |
|---|---|---|
| GPS points of household visits | Mapping of a minority settlement | Store at village level unless needed |
| Photos at community meetings | Matching faces to protest footage | Photograph hands and materials, or seek consent per photo |
| Caste and religion fields | Targeting, exclusion, profiling | Collect only where the analysis needs it; separate from names |
| Survivor case notes | Exposure to the abuser or to police | Encrypt, restrict access, delete on a schedule |
| WhatsApp group membership | Lists of activists | Use broadcast lists; hide numbers; review admins |
| System | What it does | Who runs it | Rights question it raises |
|---|---|---|---|
| Aadhaar | Unique identity and authentication | UIDAI, a statutory authority | Exclusion when authentication fails; linking of records |
| UPI | Instant account-to-account payments | NPCI | Fraud, grievance and redress for small users |
| DigiLocker | Issued documents held and shared digitally | MeitY | Consent to share, and who can see what |
| ONDC | Open network linking buyer and seller apps | A government-backed network company | Whether small sellers gain or the largest apps still dominate |
| Question | What good looks like | Warning sign |
|---|---|---|
| Who sets the rules? | Rules made under a statute, published, open to comment | Rules in circulars that change without notice |
| Who hears complaints? | A named grievance officer with time limits and an appeal | A helpline that only logs calls |
| What happens on failure? | A manual fallback written into the scheme rules | Benefit denied until the system works |
| What data does it keep? | Minimum data, stated retention, no reuse without law | Logs kept indefinitely and shared across departments |
| Can people opt out? | An alternative route that is not punished | Digital-only access to an entitlement |
| Form of harm | Main provision | What it covers |
|---|---|---|
| Capturing or sharing intimate images | IT Act s66E; BNS s77 (voyeurism) | Capturing, publishing or transmitting images of a private area or private act without consent |
| Monitoring a woman's online activity | BNS s78 (stalking) | A man who monitors a woman's use of the internet, email or other electronic communication |
| Publishing sexually explicit material | IT Act ss67 and 67A | Obscene and sexually explicit material in electronic form |
| Material depicting children | IT Act s67B; POCSO Act 2012 | Child sexual abuse material |
| Impersonation and fake profiles | IT Act s66D | Cheating by personation using a computer resource |
| Date | What commences (G.S.R. 843(E), 13 November 2025) |
|---|---|
| 13 November 2025 | Definitions, the Data Protection Board (ss18-26), and s44(3) amending the RTI Act |
| 13 November 2026 | Section 6(9) and section 27(1)(d) |
| 13 May 2027 | Core duties and rights (ss3-17), including s9 on children and the s17 exemptions; penalties (ss27-34) |
| Risk | Safeguard | Who checks |
|---|---|---|
| One-to-one chats between staff and children | Group channels only, with two adults present | Safeguarding lead |
| Photos that reveal identity or location | No faces or names of at-risk children; strip location data | Communications team |
| Third-party apps collecting children's data | Review the app's privacy policy and data flows before use | Programme manager |
| Online abuse disclosed to staff | Written reporting route, preserved evidence, referral list | Safeguarding lead |
| Children's own online safety | Age-appropriate sessions on privacy and reporting, designed with them | Education staff |
| Kind | What it produces | Example in development | Main rights risk |
|---|---|---|---|
| Scoring | A number predicting risk or need | Ranking households for a benefit; credit scoring for microloans | Wrongful exclusion; bias from proxies |
| Classification | A category | Flagging duplicate or ineligible beneficiaries | False positives that cut people off |
| Matching and recognition | A link between two records or faces | Facial recognition; record linkage across databases | Wrong matches; surveillance |
| Generative | Text, images, audio | Chatbots for scheme information; drafting reports | Confident wrong answers; deepfakes |
| Illustrative | Actually ineligible (2,000) | Actually eligible (98,000) |
|---|---|---|
| Flagged as ineligible | 1,900 (correct) | 4,900 (wrongly flagged) |
| Not flagged | 100 (missed) | 93,100 (correct) |
| Rule | Why | What it looks like in practice |
|---|---|---|
| A flag starts a check, and the benefit continues meanwhile | Errors concentrate on the poor, who cannot rebut them | Benefit continues until a human verifies in the field |
| Give notice and a reason | Natural justice; Article 14 | A letter or SMS naming the data relied on |
| Publish error rates | Accuracy claims must be testable | Share of flags overturned on review, each quarter |
| Test on the people it will judge | Gender Shades: averages hide failing groups | Error rates by caste, gender, disability, district |
| Keep a non-digital route | Authentication and data fail | A named officer who can approve on documents |
| Date | Instrument | Main requirement |
|---|---|---|
| January 2025 | Advisory to political parties | Label images, video and audio generated or significantly altered by AI |
| 24 October 2025 | Advisory before the Bihar elections | Labels such as AI-Generated covering at least 10% of the visible area; misleading synthetic content removed from party handles within three hours |
| 19 April 2026 | Instructions during the assembly elections in Assam, Kerala, Tamil Nadu, Puducherry and West Bengal | Platforms to act on unlawful or misleading content, including AI material, within three hours of a report; over 11,000 posts or URLs acted on (removals, FIRs, clarifications, rebuttals) after the 15 March schedule |
| Instrument | Type | Adopted | Binding? |
|---|---|---|---|
| EU AI Act, Regulation (EU) 2024/1689 | Regulation, risk-based | In force 1 August 2024 | Yes, in the EU and for systems used there |
| India AI Governance Guidelines | Guidelines plus existing laws | Released by MeitY, 5 November 2025 | No; existing laws are |
| UNESCO Recommendation on the Ethics of AI | Global standard | November 2021, 193 member states | No |
| OECD AI Principles | Intergovernmental principles | May 2019, updated May 2024 | No |
| Level | Rule | Examples given by the Commission |
|---|---|---|
| Unacceptable risk | Banned (eight practices since February 2025; the 2026 Omnibus adds two from 2 December 2026) | Social scoring; harmful manipulation; untargeted scraping of faces; emotion recognition at work and in education; from December 2026, AI that generates non-consensual intimate images or child sexual abuse material |
| High risk | Strict duties: risk management, data quality, human oversight, registration | Access to essential public and private services, such as credit scoring; education; employment; law enforcement |
| Transparency risk | Disclosure duties | Chatbots must say they are AI; deepfakes must be labelled |
| Minimal or no risk | No new rules | Spam filters; AI in video games |
| Date | What applies |
|---|---|
| 1 August 2024 | The Act enters into force |
| 2 February 2025 | Prohibited practices; AI literacy duty (since reworded by the Omnibus) |
| 2 August 2025 | Duties for general-purpose AI models |
| 2 August 2026 | Most transparency duties under Article 50 |
| 2 December 2026 | Two new bans (AI-generated non-consensual intimate images; child sexual abuse material); marking deadline for generative systems already on the market |
| 2 December 2027 | High-risk systems in Annex III uses (postponed from 2 August 2026) |
| 2 August 2028 | High-risk AI in products under Annex I (postponed from 2 August 2027) |
| AI question | DPDP provision | Applies from |
|---|---|---|
| May we train a model on beneficiary records? | Consent or a legitimate use (ss4-7) | 13 May 2027 |
| Must the data be accurate if it drives a decision? | Fiduciary duty on completeness and accuracy (s8) | 13 May 2027 |
| Children's data in an EdTech or chatbot tool | s9: parental consent; no tracking or targeted ads | 13 May 2027 |
| Research use of personal data | Exemption in s17(2)(b), on conditions | 13 May 2027 |
| Who will hear complaints? | Data Protection Board (ss18-26) | In force since 13 November 2025 |
| Question | Section | Yes / No / Unsure |
|---|---|---|
| Is there a lawful basis for every data field we collect, and could we do without any of them? | 02, 05 | |
| Have we mapped what fails in a shutdown, with a fallback agreed with the department? | 03 | |
| Do we have a plan if our content is blocked or removed, with backups? | 04 | |
| Could our data help anyone watch or profile participants, and have we minimised it? | 05 | |
| Can women, older people and non-readers use the tool without help, or with private help? | 06 | |
| Do we have a route for online harassment and a children's safeguarding rule? | 07 | |
| Will we meet the DPDP duties that apply from 13 May 2027? | 07, 10 |
| Question | Evidence to ask for |
|---|---|
| What exactly does the output predict, and is that the thing we care about? | The target variable, in plain words |
| On whose data was it trained and tested, and who is missing? | Data description; test populations |
| What are its error rates for women, older people, caste groups, disability? | Disaggregated test results |
| Who acts on the output, and can they override it? | Process map; override records |
| Will affected people be told, given a reason and able to contest? | Notice text; review procedure |
| What happens while a contested decision is reviewed? | Written rule that benefits continue |
| For generative tools: how are wrong answers caught and corrected? | Testing log; escalation route |
| Pattern of answers | Risk level | Decision |
|---|---|---|
| Information only; no personal data; no decision about people | Low | Proceed; review yearly |
| Personal data, but no automated decision; minor gaps with owners | Medium | Proceed once actions are done |
| Score or flag influences an entitlement; human review exists and works | High | Pilot with field verification of every adverse flag; publish error rates |
| Score or flag can end an entitlement without review; or error rates unknown for key groups | Unacceptable as designed | Do not deploy; redesign so a flag only triggers a check |
| Children's data or survivor data with any gap in consent or security | High | Pause until fixed |
| Finding | Risk | Action agreed |
|---|---|---|
| Four of six widows use a son's phone | Exclusion; no privacy | Add a missed-call voice line and assisted help at self-help group meetings |
| Bot answers drafted from a 2024 scheme circular | Wrong eligibility advice | Monthly check against current rules; date shown in every answer |
| Version two score trained on past approvals | Learns who reached the office before (Obermeyer pattern) | Drop the score; send a document checklist instead |
| Chats kept by the vendor indefinitely | Data exposure; future DPDP breach | Contract: delete after 90 days; no reuse for training |
| No route if a widow is wrongly told she is ineligible | Lost entitlement | Every answer ends with a helpline number and 'you may still apply' |
| Term | Meaning |
|---|---|
| Intermediary | A service that carries or hosts others' content, such as a telecom operator or social media platform (IT Act s2(1)(w)) |
| Safe harbour | Protection from liability for user content, on conditions (IT Act s79) |
| Blocking order | A direction to block public access to information (IT Act s69A) |
| Suspension | A temporary shutdown of telecom services (Telecommunications Act 2023, s20) |
| Proportionality | The test that a limit on a right is no greater than needed for a legitimate aim |
| Synthetically generated information | AI-generated or altered content that appears real (IT Rules, 2026 amendment) |
| Proxy | A measurable variable used in place of the thing a model should predict |
| High-risk AI system | In the EU AI Act, a system in a listed sensitive use, subject to strict duties |