ImpactMojoDigital Rights & AI 101www.impactmojo.in
ImpactMojo 101 Series · Free Forever
Digital
Rights
& AI 101
Rights online, internet shutdowns, platform rules, surveillance, digital public infrastructure, and what AI means for welfare, work and elections: law, evidence and a risk assessment for development practitioners in South Asia
100 SlidesSouth Asia FocusFree ForeverRights and AI
ImpactMojoDigital Rights & AI 101www.impactmojo.in
What we cover
01
Rights online: the starting point
Slides 3–10
02
Speech and privacy in the Indian Constitution
Slides 11–19
03
Internet shutdowns in South Asia
Slides 20–27
04
Blocking, intermediaries and platform rules
Slides 28–36
05
Surveillance, spyware and facial recognition
Slides 37–44
06
Digital public infrastructure and the divide
Slides 45–53
07
Online harms: gender-based violence and children
Slides 54–61
08
What AI systems are and how they fail
Slides 62–69
09
AI in welfare, work and elections
Slides 70–77
10
Governing AI: the EU, India and global standards
Slides 78–86
11
A digital-rights and AI risk assessment
Slides 87–94
12
Summing up and where next
Slides 95–99
ImpactMojoDigital Rights & AI 101www.impactmojo.in
01
Section One
Rights online: the starting point
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Digital rights are human rights exercised through technology
A digital right is an existing human right as it applies when people speak, organise, learn, earn, prove who they are or receive welfare through a network. There is no separate catalogue. The right to free expression covers a WhatsApp forward. The right to privacy covers a biometric record. The right to food covers a ration card that depends on an online authentication. What changes online is scale, speed and who sits in the middle: a telecom operator, a platform, a government database.
Digital rights
The rights to expression, information, privacy, association, equality and due process, and the economic and social rights that now depend on digital systems, applied to conduct that runs through networks, devices and data.
Rights-holders
Users and non-users alike: the woman whose ration needs a fingerprint match, the student whose exam centre loses its connection, the person who never went online but whose face is in a police database.
Duty-bearers
The state first, through ministries, police and regulators. Then private intermediaries, which carry out state orders and write their own rules, and which human rights law increasingly expects to respect rights.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Two articles of the 1948 Declaration that now govern the internet
The Universal Declaration of Human Rights predates the internet by decades, yet two of its articles were drafted broadly enough to travel. Article 19 protects expression through any media and regardless of frontiers, which covers a post read in another country. Article 12 protects privacy and correspondence, which covers messages, call records and location data. Read them side by side, because most digital disputes set one against the other or against a claim of security.
Everyone has the right to freedom of opinion and expression; this right includes freedom to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers.
Universal Declaration of Human Rights, Article 19 (1948)
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation.
Universal Declaration of Human Rights, Article 12 (1948)
The binding versions sit in Articles 19 and 17 of the International Covenant on Civil and Political Rights. Resolution 20/8, on the next slide, ties online expression to both texts.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The Human Rights Council: the same rights offline and online
The UN Human Rights Council settled the basic principle in 2012 and has repeated it since. Its resolutions are not treaties, so they do not bind a state the way a Covenant does. They matter because the Council adopted them without a vote, so no member objected to the wording, and because UN experts and national courts cite them when they read the treaties.
ResolutionAdoptedWhat it says
20/8, The promotion, protection and enjoyment of human rights on the Internet5 July 2012, without a voteAffirms that the same rights that people have offline must also be protected online, in particular freedom of expression
32/13, same title1 July 2016, without a voteCondemns unequivocally measures to intentionally prevent or disrupt access to or dissemination of information online in violation of international human rights law
Source: resolution texts A/HRC/RES/20/8 and A/HRC/RES/32/13, read on RightDocs (HURIDOCS). The 2016 wording is the one advocates quote against internet shutdowns, covered in Section 03.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Four families of digital rights a programme will meet
Lists of digital rights run long. For field work four families cover almost every case. Each one has a home in the Indian Constitution, which is why later sections keep returning to Articles 14, 19 and 21. The examples are from South Asian practice and each one appears again later in the deck with its source.
FamilyConstitutional home in IndiaWhere it shows up in development work
Access and connectivityNo standalone right to internet access; Anuradha Bhasin (2020) protects speech and trade through the internet under Article 19(1)(a) and (g)Internet shutdowns, the gender gap in phone ownership, offline fallbacks for welfare
Expression and informationArticle 19(1)(a), limited only by Article 19(2)Blocking orders, takedowns of NGO content, the fact check unit, deepfakes in elections
Privacy and dataArticle 21, as read in Puttaswamy (2017)Beneficiary databases, biometric authentication, surveillance, facial recognition
Equality and due processArticles 14 and 21Algorithms that cut people from welfare lists without notice or a hearing
A fifth set, economic and social rights, runs through all four: food, work and social security now reach many people only through digital systems.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Why a development programme cannot treat digital rights as somebody else's job
Many programmes now deliver through digital channels: payments by direct benefit transfer, attendance by app, grievance by toll-free number and portal, training by WhatsApp. Each channel creates two kinds of exposure. The programme can be harmed by a rights violation it did not cause, such as a shutdown that stops payments. It can also cause harm itself, by collecting more data than it needs or by trusting a score it cannot explain.
Harms done to the programme
A district shutdown during exams halts cash transfers. A blocking order takes down a campaign page. A platform removes a survivor support group after mass reporting. None of these is the programme's fault, and each needs a plan.
Harms done by the programme
A beneficiary list leaks. A photo of a child is posted with her village named. An eligibility score drops a widow from a pension list. These are duties the organisation owes, and a donor or court will ask about them.
The practical tool for both is the risk assessment in Section 11. The sections before it give you the law and the evidence you will need to fill it in.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The three-part test for any limit on a digital right
Most digital rights may be limited. Speech can be restricted for public order, privacy can yield to criminal investigation. What human rights law and the Indian Supreme Court both require is that a limit pass a test. The wording differs between the Human Rights Committee in Geneva and the Supreme Court in Delhi. The structure is the same, and it is the single most useful idea in this deck.
01
LEGALITY: a law, public and precise, authorises the measure
→
02
LEGITIMATE AIM: the measure pursues a purpose the law allows, such as public order
→
03
NECESSITY: no less restrictive measure would do the job
→
04
PROPORTIONALITY: the harm to the right is in balance with the benefit
In Indian law
Puttaswamy (2017) set out legality, legitimate aim and proportionality for privacy. Anuradha Bhasin (2020) applied proportionality to internet suspension. Section 02 reads both.
How to use it
Put any measure your programme faces, or proposes, through the four steps in order. A measure that fails at step one fails outright, however good its aim.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
How this deck fits with three other ImpactMojo decks
This deck was written to sit beside three existing decks and to repeat as little of them as possible. It covers the rights side (courts, shutdowns, blocking, surveillance, access) and the society side of AI (bias, welfare automation, labour, elections, governance). The others go deeper on ethics, data protection compliance and day-to-day use of generative AI.
Read alongside
Digital Ethics 101 covers privacy by design, Aadhaar and exclusion, data colonialism and misinformation. Data Protection & the DPDP Act 101 is the compliance manual for the 2023 Act and the 2025 Rules.
And for daily AI use
GenAI for Practitioners 101 teaches prompting, hallucination checks and an organisational AI policy. This deck asks the prior question: whether an AI system should touch a decision about people at all.
All dates and figures in this deck are stated as of October 2026. Law in this field moves monthly, so check the date on any rule before you rely on it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
02
Section Two
Speech and privacy in the Indian Constitution
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Article 19(1)(a) and the eight grounds in Article 19(2)
Article 19(1)(a) guarantees every citizen freedom of speech and expression. Article 19(2) lets the state impose reasonable restrictions only on listed grounds. The list is closed: a restriction that does not fit one of the grounds fails, however sensible it looks. That is why so many digital speech cases turn on whether a law was tied to one of these words.
Ground in Article 19(2)A digital case it has been used for
Sovereignty and integrity of India; security of the StateBlocking of apps and accounts under IT Act s69A
Friendly relations with foreign StatesBlocking of content about another country
Public orderInternet suspension during protests, the ground examined in Anuradha Bhasin
Decency or moralityObscenity offences in IT Act ss67 and 67A
Contempt of court; defamationTakedown of posts about judges or private persons
Incitement to an offenceBlocking of posts calling for violence
Annoyance, inconvenience and offence are absent from the list. That gap is what decided Shreya Singhal, on the next slide.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Shreya Singhal v Union of India (2015): section 66A falls
Section 66A of the Information Technology Act 2000 made it an offence to send, by computer or phone, information that was grossly offensive, or that caused annoyance, inconvenience or insult. The Court found its expressions completely open-ended, so almost any critical post could fall within them. On 24 March 2015 the Supreme Court struck it down. The words were too vague for a citizen to know what was forbidden, and the harms they named did not fit any ground in Article 19(2).
Section 66A of the Information Technology Act, 2000 is struck down in its entirety being violative of Article 19(1)(a) and not saved under Article 19(2).
Shreya Singhal v Union of India, Supreme Court, 24 March 2015, para 119
The vagueness point
A criminal law must tell people in advance what is punishable. Words like annoyance depend on the reader, so the same post can be lawful in one police station and a crime in another.
The chilling point
A vague law deters lawful speech, because people stay silent rather than risk arrest. The Court counted that deterrence as a harm in itself.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
What Shreya Singhal upheld, which matters as much as what it struck
The same judgment upheld the two powers that now carry most online content control in India. Practitioners often remember only the first half of the case. The second half explains why blocking orders and takedown requests remain lawful in principle, and what conditions attach to them.
ProvisionHolding in Shreya Singhal (2015)What it means now
IT Act s66AStruck down in its entiretyNo prosecution can rest on it; it is dead law
IT Act s69A and the Blocking Rules 2009Constitutionally validThe Centre may block content for reasons in writing, through a committee procedure
IT Act s79 (intermediary safe harbour)Valid, with s79(3)(b) read downA platform must act on actual knowledge from a court order or a government notification tied to Article 19(2)
IT (Intermediaries Guidelines) Rules 2011Valid, subject to the same reading downReplaced in 2021 by the IT Rules, Section 04
The reading down of s79 is why a private complaint alone does not oblige a platform to remove your content. Keep this in mind when a takedown arrives (Section 04).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Puttaswamy v Union of India (2017): privacy is a fundamental right
On 24 August 2017 a nine-judge bench of the Supreme Court held unanimously that privacy is protected by the Constitution. The case arose from the challenge to Aadhaar, when the Attorney General argued that two older benches had denied any such right. The Court overruled both. Every later argument about data, surveillance and digital identity in India starts from this order.
The right to privacy is protected as an intrinsic part of the right to life and personal liberty under Article 21 and as a part of the freedoms guaranteed by Part III of the Constitution.
Justice K.S. Puttaswamy (Retd) v Union of India, order of the nine-judge bench, 24 August 2017
What was overruled
M P Sharma v Satish Chandra (eight judges) and Kharak Singh v State of UP (six judges), to the extent they held that the Constitution does not protect privacy.
What it covers
The plurality opinion of Justice Chandrachud describes privacy as spatial control, decisional autonomy and informational control. Informational control is the part that governs databases and apps.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Legality, legitimate aim, proportionality: Puttaswamy's three-fold test
Puttaswamy did more than declare a right. The plurality opinion of Justice Chandrachud set out a three-fold requirement that any state intrusion on privacy must meet, and later benches have applied it to Aadhaar, to surveillance and to internet suspension. It is the Indian version of the test on slide 9, and it is the frame to use when a government scheme asks your programme for beneficiaries' data.
01
LAW: the intrusion must rest on a law, which an executive instruction does not satisfy
→
02
NEED: the law must pursue a legitimate state aim
→
03
PROPORTION: the means must be proportionate to the aim
Why legality comes first
A scheme guideline or an office memorandum is not a law passed by a legislature. Data collection that rests only on such a document is exposed at the first step.
Legitimate aims the Court accepted
The plurality opinion names a vital state interest in making sure scarce public resources reach those who qualify, which covers most welfare data collection. The aim is rarely the weak point; proportion usually is.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The Aadhaar judgment (2018): upheld for welfare, limited for private use
A five-judge bench decided the Aadhaar challenge itself on 26 September 2018. The majority upheld the Aadhaar Act for welfare benefits and subsidies, applying the Puttaswamy test. It struck down the part of section 57 that let a body corporate or a private person demand Aadhaar authentication under a contract, which is why a phone company or a bank can no longer make Aadhaar a condition of service on its own say-so.
What the majority accepted
Using Aadhaar to target subsidies and benefits from the Consolidated Fund of India is a legitimate aim, and authentication for that purpose is proportionate.
What it did not settle
Exclusion when authentication fails. The fingerprint that will not match, the network that drops, the elderly hand worn smooth by labour. These are failures of practice, and they are where programmes meet Aadhaar most often.
This deck does not repeat the exclusion evidence. Digital Ethics 101 covers authentication failure and the case for a non-digital fallback in its Section 6.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Anuradha Bhasin v Union of India (2020): the internet and proportionality
After the changes to Jammu and Kashmir's status on 5 August 2019, the internet was suspended across the region. Anuradha Bhasin, executive editor of the Kashmir Times, could not publish the Srinagar edition. The Supreme Court decided her petition on 10 January 2020. It did not order the internet restored, which disappointed many. What it did was set rules that now bind every suspension order in India.
What the Court held
  • Expression through the internet is part of Article 19(1)(a)
  • Any restriction must satisfy Article 19(2) and be proportionate
  • An order suspending internet services indefinitely is impermissible
  • Suspension orders must be published so that people can challenge them
What it directed
  • Publish all suspension orders in force and future orders
  • Review committees to review suspensions every seven working days
  • Review all existing suspension orders forthwith
  • Revoke orders not in line with the judgment
Source: Anuradha Bhasin v Union of India, Supreme Court, 10 January 2020, paras 26 and 152.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Four neighbours, four speech laws written since 2024
India is one of several South Asian states rewriting online speech law at the same time. The neighbours are moving in different directions, and a regional programme cannot assume one country's rules carry across a border. Check the current status in each country before you rely on this table: two of these laws are under revision.
CountryLawWhat changedStatus as of October 2026
BangladeshCyber Security Ordinance 2025Repealed the Cyber Security Act 2023; recognises internet access as a civic rightGazetted 21 May 2025 by the interim government; check its standing after the 2026 Parliament
PakistanPrevention of Electronic Crimes (Amendment) Act 2025New s26A: false information likely to cause fear, panic or unrest, up to three years and Rs 2 million fineIn force from 29 January 2025
Sri LankaOnline Safety Act No. 09 of 2024Created an Online Safety Commission over prohibited statementsIn force since February 2024; amendments under consultation in 2025
NepalSocial media registration requirementAt least 26 social media platforms blocked in 2025Triggered mass protests met with lethal force (Access Now 2026)
Sources: Prothom Alo (gazette report, May 2025); Deccan Herald/PTI, 29 January 2025; ICJ submission, 12 September 2025; Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
03
Section Three
Internet shutdowns in South Asia
ImpactMojoDigital Rights & AI 101www.impactmojo.in
What counts as a shutdown, and why the form matters
A shutdown is a deliberate disruption of internet or mobile services by, or on the orders of, an authority, aimed at a population or a place. It need not be total. Some of the most damaging forms leave a connection in place but make it useless. The form matters to a programme because each one breaks different things, and because the legal route to challenge it differs.
Full or regional blackout
All mobile and fixed internet off in a district or a state. Payments, telemedicine, online classes and grievance portals stop together. Voice calls and SMS may survive, which is why an SMS fallback is worth designing.
Mobile data only
Broadband stays on for offices and banks; mobile data goes off. Since most rural users are online only through mobile data, this falls hardest on them.
Throttling
Speeds cut to 2G levels. Text loads, video and document uploads fail. Harder to prove and easy for authorities to deny.
Platform blocks
One or more apps blocked while the rest of the internet works. Nepal blocked at least 26 social media platforms in 2025 (Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026)).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
2025: the highest number of shutdowns ever recorded
Access Now, a digital rights organisation that coordinates the #KeepItOn coalition, has counted shutdowns every year since 2016 from reports by its partners, network measurement and the press. Its count for 2025 was the highest in its records. The Asia Pacific region, which in its classification includes South Asia and Myanmar, accounted for most of them.
313
shutdowns worldwide in 2025
Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026)
52
countries imposed at least one
Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026)
195
in Asia Pacific, across 11 countries
Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026)
How to read the count
A shutdown is counted per order or event, so one long regional blackout and one two-hour exam shutdown each count as one. The count measures how often authorities reach for the tool, which is different from how many people lose access.
For comparison
Access Now's 2024 report counted 296 shutdowns in 54 countries, a record at the time; its 2025 report revises the 2024 total to 304. Not a single day of 2025 passed without at least one shutdown somewhere (Access Now, KeepItOn report on internet shutdowns in 2024; Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026)).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Shutdowns in South Asia and Myanmar, 2024 and 2025
Internet shutdowns counted by Access Now (2024 as revised)
Access Now, KeepItOn dataset, 2024 and 2025 sheets (updated 31 March 2026)
Myanmar's military imposed at least 95 shutdowns in 2025, many in areas of active conflict. India imposed 65, down from 84 in 2024, still more than one a week. Pakistan imposed 20, against 22 in 2024 (the 2024 report first counted 21). The 2024 figures in the chart are Access Now's revised ones; for Myanmar, India and Nepal the revision changed nothing.
Bangladesh imposed 5 shutdowns in 2024, including the blackout during the July quota-reform protests. Access Now's 2025 release gives no Bangladesh count; it records instead that advocacy there led to proposed legislation to prohibit shutdowns altogether.
India's fall from 84 to 65 is real. Read the trend with the level, and ask how many people each order reached, which the count does not show.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Protests, conflict, exams: the stated reasons
Authorities give a small set of reasons, and Access Now's annual reports track them. Each reason has a different link to the Article 19(2) grounds and a different answer under the proportionality test. An exam shutdown, for example, protects the integrity of a test by cutting off millions of people who are not sitting it, which is hard to call the least restrictive means.
Stated reasonSouth Asian exampleProportionality question
Protests and political unrestBangladesh, July 2024 quota-reform protestsWas the blackout limited in area and time, and published?
Active conflictMyanmar, most of its 95 shutdowns in 2025Did it cut off information people needed to stay safe?
Exam cheatingIndia: five exam shutdowns during government job exams in 2024, matching its 2018 recordCould invigilation or jammers in exam halls do the job instead?
Religious events and securityPakistan: mobile suspensions during MuharramWas a targeted measure available?
Platform regulationNepal: 26 platforms blocked in 2025 over registration rulesWas blocking the least restrictive way to enforce registration?
Sources: Access Now, KeepItOn report on internet shutdowns in 2024 (exams, Bangladesh, Pakistan); Access Now, KeepItOn report on internet shutdowns in 2025 (31 March 2026) (Myanmar, Nepal).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
What a shutdown breaks inside a development programme
Shutdowns are often discussed as a free-speech issue. For a development programme they are also an operations issue. A shutdown in a district can stop the mechanisms that carry entitlements to people, and the people hit hardest are those with no alternative channel. The table is a planning aid: it lists functions that depend on connectivity and the fallback each one needs. It carries no figures because no reliable Indian estimate of these costs exists for recent years.
FunctionWhat fails during a shutdownFallback to plan in advance
Ration and pension authenticationOnline biometric match at the shop or the bank pointOffline or manual authentication with a register, as allowed by the scheme
Cash transfers and wagesPayment confirmation and withdrawals at agentsCash advance policy and an agreed grace period with the department
Monitoring and data collectionSync from field apps; dashboards go staleApps that store offline; paper forms with later entry
Helplines and grievance portalsChat and web channelsVoice and SMS numbers, which often survive a data shutdown
Remote learning and telemedicineVideo sessions and uploadsDownloaded content; radio; phone consultations
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The Telecommunications Act 2023 and the suspension rules
Until 2024 shutdowns were ordered under section 5(2) of the Indian Telegraph Act 1885 and the 2017 suspension rules that Anuradha Bhasin examined. The Telecommunications Act 2023 replaced the Telegraph Act. Its section 20, in force from 26 June 2024, lets the Central or a State Government suspend telecommunication services on the occurrence of a public emergency or in the interest of public safety. The Internet Freedom Foundation notes that section 20 is almost identical to the old section 5.
FeatureTelecommunications (Temporary Suspension of Services) Rules 2024
Who may orderThe Union Home Secretary or a State Home Secretary; in unavoidable cases a Joint Secretary to the Central Government or above, authorised by them, and confirmed within 24 hours
How longAt most 15 days per order
WhereThe order must state the geographic area
ReviewA review committee meets within five days and may set the order aside
PublicationThe order must be published and state its reasons, which tracks Anuradha Bhasin
Sources: Telecommunications Act 2023, s20; Internet Freedom Foundation, 25 June 2024; Telecommunications (Temporary Suspension of Services) Rules 2024, G.S.R. 724(E), 22 November 2024, rr2, 3 and 5.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
A shutdown plan for a programme, in five steps
A plan written before a shutdown is worth far more than one written during it, when phones are down and staff cannot reach each other. The five steps below fit on one page and can be added to any programme's risk register. Step four uses the publication duty from Anuradha Bhasin: an unpublished order is itself a breach of what the Supreme Court directed.
01
MAP: list every function that needs connectivity (use the table two slides back)
→
02
FALLBACK: agree offline routes with the department before they are needed
→
03
COMMUNICATE: a phone tree and an SMS list so staff and participants get instructions
→
04
DOCUMENT: record dates, area and effects; ask for the order under the RTI Act if it is not published
→
05
REPORT: share documented effects with a digital rights group or the State Human Rights Commission
What documentation is for
Courts decide on evidence. A log of missed payments, closed health sessions and cancelled exams turns a general complaint into a proportionality argument.
A caution
Staff should not use VPNs or satellite devices in a way that breaks a lawful order. Ask a lawyer before you advise anyone to work around a shutdown.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
04
Section Four
Blocking, intermediaries and platform rules
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The four IT Act sections behind most online content control
The Information Technology Act 2000 is the main statute for online content in India. Four of its sections do most of the work. Two let the state act directly (interception and blocking), one lets it collect traffic data for cyber security, and one sets the terms on which platforms escape liability for what users post. Learn these four numbers and most news stories about takedowns become readable.
SectionWhat it allowsWho actsPenalty for non-compliance
s69Interception, monitoring or decryption of information in a computer resourceCentral or State GovernmentUp to seven years for a person who fails to assist
s69ABlocking public access to informationCentral Government, for reasons recorded in writingUp to seven years and fine for an intermediary that fails to comply
s69BMonitoring and collecting traffic data for cyber securityCentral GovernmentUp to three years and fine for an intermediary that fails to assist
s79Safe harbour: an intermediary is not liable for third-party content if it meets conditionsPlatforms, subject to the IT RulesLoss of the safe harbour
Source: Information Technology Act 2000, ss69, 69A, 69B and 79, as amended (text read on Indian Kanoon).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
How a blocking order under section 69A works
Section 69A lets the Central Government direct any agency or intermediary to block public access to information when it is satisfied that this is necessary or expedient in the interest of sovereignty and integrity, defence, security of the State, friendly relations with foreign States or public order, or to prevent incitement to a cognizable offence relating to these. The grounds track Article 19(2), which is one reason the Supreme Court upheld the section in 2015.
The safeguards
Reasons must be recorded in writing. The 2009 Blocking Rules route requests through a designated officer and a committee, and provide for a hearing to the originator or intermediary where they can be identified.
The weak point
The Blocking Rules keep requests and actions confidential. The person whose content is blocked may never see the order or know the reason, which makes a challenge in court hard to mount.
If your organisation's page or post disappears in India with a notice citing a legal demand, ask the platform for the order and the section relied on, and keep every message. Slide 36, at the end of this section, gives a full checklist.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Section 79: why platforms are not liable for every post
Section 79 protects an intermediary from liability for content it hosts or carries, provided it does not start or modify the transmission and it observes due diligence. The protection is lost if, on receiving actual knowledge, it fails to remove unlawful content. Shreya Singhal read actual knowledge narrowly: a court order, or a notification from the appropriate government, relating to the grounds in Article 19(2).
Why the narrow reading protects users
If any complaint counted as knowledge, platforms would remove anything reported to avoid risk. Mass reporting by a hostile group could then silence a women's rights page or a Dalit news channel without any legal finding.
Why the state wants more
Governments argue that court orders are too slow for viral harm such as deepfakes or calls to violence. The 2021 IT Rules and their later amendments tighten the due diligence a platform must show to keep the safe harbour.
Due diligence is the lever. Each new obligation in the IT Rules is enforced by the threat that a platform which ignores it loses section 79 protection and becomes liable as if it had published the content itself.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The IT Rules 2021: due diligence, grievance officers, traceability
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 replaced the 2011 guidelines. They set due diligence for all intermediaries and heavier duties for large social media intermediaries, and a code for digital news and streaming. For development organisations the parts that matter most are the grievance route a user can use and the rules on what users may not post.
Duties that help users
  • Publish rules and a privacy policy in plain terms
  • Appoint a grievance officer and act on complaints within set times
  • Remove intimate images of a person on complaint, quickly
  • Give notice and a chance to respond before some removals by large platforms
Duties that raise rights concerns
  • Identify the first originator of messages on large messaging services, on order
  • Rule 3(1)(b) lists categories of content users must not share, in broad words
  • A government fact check unit added by the 2023 amendment, later struck down
  • Shorter takedown deadlines added in 2026
The originator rule is contested by messaging companies because end-to-end encryption would have to change to comply. Watch for court rulings on it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The fact check unit and the Bombay High Court
An amendment of 6 April 2023 to Rule 3(1)(b)(v) required platforms to make reasonable efforts not to host information about the business of the Central Government that a government fact check unit identified as fake, false or misleading. Comedian Kunal Kamra and others challenged it. The Bombay High Court's division bench split, so the case went to a third judge.
01
31 JAN 2024: split decision; Justice G.S. Patel strikes the rule down
→
02
Justice Neela Gokhale upholds it, so the bench is divided
→
03
20 SEP 2024: Justice A.S. Chandurkar, as third judge, agrees with Patel J
→
04
26 SEP 2024: the bench declares the amendment unconstitutional and strikes it down
Why it fell
Justice Chandurkar found the rule violated Articles 14, 19(1)(a) and 19(1)(g), went beyond the IT Act, and that the words fake, false or misleading, left undefined, were vague and overbroad.
The lesson
The state may not be the judge of truth about its own business. The same vagueness reasoning that killed section 66A in 2015 decided this case.
Source: Kunal Kamra v Union of India, Bombay High Court, judgment of 26 September 2024 reciting the third judge's opinion of 20 September 2024.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The 2026 amendment: labels for synthetic content and a three-hour clock
On 10 February 2026 MeitY notified amendments to the IT Rules that bring synthetically generated information, including deepfakes, inside the rules. They took effect on 20 February 2026, giving platforms ten days to comply. Two changes matter for development organisations, which both make and suffer from synthetic media.
Labels and provenance
Platforms that offer tools to create synthetic content must label it and carry provenance information, and must take reasonable technical steps to prevent synthetic content that breaks the law, such as child sexual abuse material or impersonation.
Three hours
Intermediaries must act on government or court orders, including takedowns, within three hours of receipt. The earlier window was 36 hours. Three hours leaves little time to check whether an order is lawful.
If your programme uses AI-generated images or voices in awareness material, label them clearly now. The ECI applies similar rules to campaign material (Section 09). Source: IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, G.S.R. 120(E), Gazette of India, 10 February 2026, rules 1 and 3.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
X Corp v Union of India (2025): the Sahyog portal challenge fails
X Corp, formerly Twitter, asked the Karnataka High Court to declare that blocking orders can issue only under section 69A with its procedural safeguards, and that section 79(3)(b) gives no separate power to order takedowns. It also challenged the Sahyog portal, a government system through which many agencies send removal notices to platforms. On 24 September 2025 a single judge of the High Court rejected the petition.
What the court held
Notices under section 79(3)(b) and Rule 3(1)(d) through the portal are lawful. Article 19 is available only to citizens, so X Corp, a foreign company, could not rely on it. The court's view: a platform operating in India must follow Indian law.
Why it matters to NGOs
Removal notices through the portal can come from many agencies without the committee procedure of the Blocking Rules. Your content may be removed on a notice you never see. X Corp's appeal was pending before a division bench in 2026; check its status before relying on the ruling.
Source: X Corp v Union of India, Karnataka High Court, WP 7405 of 2025, 24 September 2025, paras 17.7 and 25 (read on Indian Kanoon); MediaNama, March 2026, on the appeal.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
A checklist for an organisation whose content is blocked or removed
Development organisations post survivor testimony, reports on police conduct, election monitoring and campaign material. All of these can be removed, sometimes lawfully, sometimes through mass reporting, sometimes by mistake. The steps below follow the legal routes covered in this section, in the order they are usually useful.
StepWhat to doLegal hook
1. PreserveScreenshot the notice, the content and the dates; export the page dataEvidence for any later challenge
2. Identify the basisAsk the platform which law or order it relied onIT Rules 2021 grievance process
3. Platform appealUse the platform's appeal and its India grievance officerIT Rules 2021, grievance officer duties
4. Government routeIf a section 69A order is cited, ask for a hearing and the orderBlocking Rules 2009
5. Appellate committeeAppeal a grievance officer's decisionGrievance Appellate Committees under the IT Rules
6. CourtWrit petition in a High Court with a lawyerArticles 19(1)(a) and 226
Keep a backup of everything you publish. A removed page with no backup is lost even if you win the appeal.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
05
Section Five
Surveillance, spyware and facial recognition
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Who can intercept communications in India, and who checks
India has three statutory routes to intercept or monitor communications. All three are authorised by the executive and reviewed by executive committees. None requires a warrant from a judge before the interception begins. This is the feature digital rights groups criticise most, and it explains why the Pegasus case reached the Supreme Court: a person under surveillance has no way to know of it, and so no way to challenge it.
PowerStatuteAuthorised by
Interception, detention or disclosure of messages on a public emergency or in the interest of public safetyTelecommunications Act 2023, s20(2)Central or State Government, or an officer specially authorised
Interception, monitoring or decryption of information in a computer resourceIT Act 2000, s69Central or State Government, or an officer specially authorised
Monitoring and collecting traffic dataIT Act 2000, s69BCentral Government, for cyber security
What the law requires
Grounds tied to security and public order, reasons in writing, and review committees of senior officials.
What it lacks
Prior judicial approval, notice to the person after the fact, and any published statistics on how many orders are issued each year.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Manohar Lal Sharma v Union of India (2021): the Pegasus order
In July 2021 an international media investigation reported that phone numbers of Indian journalists, opposition politicians and activists appeared on a list of possible targets for Pegasus, a spyware product sold to governments. Petitions reached the Supreme Court. The Union government declined to say on affidavit whether it had used the software, citing national security. On 27 October 2021 the Court appointed its own technical committee.
National security cannot be the bugbear that the judiciary shies away from, by virtue of its mere mentioning.
Manohar Lal Sharma v Union of India, Supreme Court, 27 October 2021, para 49
The committee
Three technical experts, overseen by retired Supreme Court judge Justice R.V. Raveendran, assisted by former IPS officer Alok Joshi and a cyber security expert.
The principle
The state may decline to share information that would harm security, but it must justify that refusal on oath. An omnibus claim of national security does not end judicial review.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The Pegasus committee's report: malware, but no conclusion
The committee examined phones submitted by people who believed they had been targeted and reported to the Supreme Court in 2022. On 25 August 2022 Chief Justice N.V. Ramana read parts of the report in court. The findings were inconclusive on the question that mattered most, and the Court recorded a finding about the government's conduct during the inquiry.
29
phones examined by the technical committee
LiveLaw, Pegasus probe committee report, 25 August 2022
5
found infected with some malware
LiveLaw, 25 August 2022
0
conclusively shown to be Pegasus
LiveLaw, 25 August 2022
On cooperation
The Chief Justice read out that, according to the committee, the Government of India did not cooperate with it.
What a practitioner takes from this
Spyware leaves few traces, and an investigation without the state's records can rarely settle who used it. Prevention is cheaper than proof: update phones and protect high-risk staff.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Facial recognition in Indian policing: what the police told the court
Delhi Police obtained facial recognition software after the Delhi High Court, in Sadhan Haldar v NCT of Delhi, allowed it to help trace missing children. In a reply to an RTI request in February 2020, the police named that judgment as the legal basis for its use of the technology. By then the same software was being used in other policing, including at protests. Its accuracy, as the police and the government themselves reported, was low.
2%
accuracy reported by Delhi Police for the system on trial, 2018
Internet Freedom Foundation, Project Panoptic case study, citing affidavits in the Delhi High Court
<1%
accuracy in 2019, when it could not tell boys from girls
Internet Freedom Foundation, Project Panoptic, citing the Ministry of Women and Child Development
Purpose drift
A tool justified by one humane aim (finding missing children) moved to another (identifying people in crowds) without a new law or a new court order.
Legality gap
No statute in India authorises police facial recognition as such. Under Puttaswamy, an intrusion must rest on a law; a court order about missing children is a thin base for crowd identification.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Why being watched changes what people do, and what that costs
Surveillance harms people even when no one is arrested. Someone who believes a protest will be filmed and matched to a database may stay home. A health worker who believes her messages are read may stop reporting a supervisor's abuse. Courts call this the chilling effect, and the Supreme Court relied on it in Shreya Singhal. For development work it shows up as silence in exactly the places where voice is the point.
Where programmes see it
  • Low turnout at public hearings and social audits
  • Community members refusing to be photographed or recorded
  • Survivors avoiding online support groups
  • Field staff unwilling to document police conduct
What reduces it
  • Collect less: no faces or names where they add nothing
  • Tell people exactly who will see their data, and keep to it
  • Use end-to-end encrypted channels for sensitive reports
  • Offer anonymous routes for grievances
The point is practical. A programme that makes people feel watched will get worse data and less participation, whatever its intentions.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Surveillance by design: what your programme collects can be used by others
NGOs rarely think of themselves as surveillance actors. Yet many hold location data, phone numbers, photographs, caste and religion fields, and case notes on survivors and activists. That data can be demanded by authorities, stolen by attackers or shared by a vendor. The safest record is the one never made. The table sets common programme data against the way it could be misused.
Data a programme often holdsHow it could be misusedSafer design
GPS points of household visitsMapping of a minority settlementStore at village level unless needed
Photos at community meetingsMatching faces to protest footagePhotograph hands and materials, or seek consent per photo
Caste and religion fieldsTargeting, exclusion, profilingCollect only where the analysis needs it; separate from names
Survivor case notesExposure to the abuser or to policeEncrypt, restrict access, delete on a schedule
WhatsApp group membershipLists of activistsUse broadcast lists; hide numbers; review admins
The DPDP duties that will require much of this (minimisation, security, erasure) apply from 13 May 2027. Start now; Data Protection & the DPDP Act 101 has the templates.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Aadhaar and exclusion: the question to ask of any ID requirement
Digital identity is where surveillance and welfare meet. A unique ID makes it easier to stop duplicate claims and to pay people directly. It also links records across systems, and when authentication fails the person carries the cost. The Aadhaar judgment of 2018 upheld its use for subsidies and benefits; it did not decide what happens to the person whose fingerprint will not match on the day the ration is due.
The proportionality question
For any ID requirement in your programme, ask whether the same aim could be met with less data or with an alternative proof. If yes, the requirement fails the third step of the Puttaswamy test as a matter of design, whatever a court might say.
Where to read more
Digital Ethics 101 covers Aadhaar enrolment, authentication failure and the case for a non-digital fallback in detail. This deck does not repeat it.
01
NEED: is identity proof required for this benefit at all?
→
02
MINIMUM: which proof, and how little data from it?
→
03
FALLBACK: what happens when it fails, and who decides?
ImpactMojoDigital Rights & AI 101www.impactmojo.in
06
Section Six
Digital public infrastructure and the divide
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Digital public infrastructure: shared rails that others build on
Digital public infrastructure (DPI) is the name India uses for shared digital systems, built or backed by the state, on which public and private services run. Identity, payments and document exchange are the classic three. The design choice is that many apps connect to one rail, so a farmer can be paid by any bank through UPI and show a certificate from any department through DigiLocker.
SystemWhat it doesWho runs itRights question it raises
AadhaarUnique identity and authenticationUIDAI, a statutory authorityExclusion when authentication fails; linking of records
UPIInstant account-to-account paymentsNPCIFraud, grievance and redress for small users
DigiLockerIssued documents held and shared digitallyMeitYConsent to share, and who can see what
ONDCOpen network linking buyer and seller appsA government-backed network companyWhether small sellers gain or the largest apps still dominate
DPI is infrastructure, so the rights questions are mostly about governance: who decides the rules, who hears complaints, and what happens to those who cannot use it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
UPI at scale: a public payment rail used billions of times a month
The Unified Payments Interface lets any bank account send money to any other through a phone number or a QR code. It is run by the National Payments Corporation of India, which publishes monthly volumes. By 2026 it carries a large share of small payments in India, including many made by street vendors and self-help groups with whom development programmes work.
24.07 bn
UPI transactions in September 2026
NPCI data, reported by IANS, 1 October 2026
Rs 29.37 lakh cr
value of those transactions
NPCI data, reported by IANS, 1 October 2026
802 mn
average transactions per day in September 2026
NPCI data, reported by IANS, 1 October 2026
What it made possible
Low-cost transfers between ordinary accounts, payments to vendors without card machines, and a record of income that a woman running a small business can show a lender.
What it brought with it
Fraud by fake payment requests and QR codes. NCRB counted fraud as the motive in 72.6% of cybercrime cases in 2024 (Section 07). Redress for a small loss is slow and often absent.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
DigiLocker and ONDC: documents and markets on shared rails
Two other rails reach development work directly. DigiLocker holds documents issued by departments, such as mark sheets, driving licences and caste certificates, so that a person can share them without carrying paper. ONDC is a network that lets a seller listed on one app be found by a buyer on another. One is a document wallet, the other a market protocol, and each raises its own rights question.
DigiLocker
The government told the Rajya Sabha in August 2026 that DigiLocker has more than 72.43 crore registered users, and that UMANG, the app for government services, has more than 11.66 crore. The rights question is consent: who asks for which document, and whether a person can refuse.
Source: Free Press Journal, reporting a written reply by IT Minister Ashwini Vaishnaw, August 2026.
ONDC
The promise is that a women's producer collective can sell through any buyer app, on terms it can compare. The test, for a programme, is whether its members' sales and margins rise. Order figures are published by ONDC and change monthly; use the latest release.
Both are opt-in for users. Watch for schemes that make them a condition of a benefit, which turns a convenience into a gate.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Five governance questions to ask of any digital rail
India promotes its DPI model abroad, and other South Asian governments are building similar systems. Whether a rail serves people well depends less on the technology than on the rules around it. These five questions apply to a national system and equally to a state scheme portal or an NGO's own beneficiary app.
QuestionWhat good looks likeWarning sign
Who sets the rules?Rules made under a statute, published, open to commentRules in circulars that change without notice
Who hears complaints?A named grievance officer with time limits and an appealA helpline that only logs calls
What happens on failure?A manual fallback written into the scheme rulesBenefit denied until the system works
What data does it keep?Minimum data, stated retention, no reuse without lawLogs kept indefinitely and shared across departments
Can people opt out?An alternative route that is not punishedDigital-only access to an entitlement
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Who is online: women and men in NFHS-6 (2023-24)
Adults aged 15-49 who have ever used the internet (%)
IIPS, NFHS-6 (2023-24) National Fact Sheet, May 2026
The sixth National Family Health Survey, fielded in 2023-24 and published in May 2026, found that 64.3% of women aged 15-49 had ever used the internet, almost double the 33.3% in NFHS-5 (2019-21). For men the figure is 80.5%.
The gap is widest in rural India: 58.6% of rural women against 77.1% of rural men. NFHS-6 also found that 63.6% of women have a mobile phone they themselves use.
Ever used is a low bar. A woman who once watched a video on her husband's phone counts. Meaningful use, with her own device, privacy and skills, is lower, and no national survey measures it directly.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The household picture: CMS Telecom 2025
The Comprehensive Modular Survey: Telecom, part of the 80th round of the National Sample Survey, was fielded from January to March 2025 across 34,950 households. It measures household access and the digital skills of individuals. Its headline numbers are high, and the press note's own caveat applies: the survey is designed for national estimates, so state figures carry wide margins.
86.3%
households with internet access within the premises
MoSPI, Comprehensive Modular Survey: Telecom 2025 (NSS 80th round), press note 29 May 2025
85.5%
households with at least one smartphone
MoSPI, Comprehensive Modular Survey: Telecom 2025 (NSS 80th round), press note 29 May 2025
92.7%
rural 15-29 year olds who used the internet in the last three months (urban 95.7%)
MoSPI, Comprehensive Modular Survey: Telecom 2025 (NSS 80th round), press note 29 May 2025
85.1%
of 15-29 year olds sent a message with an attached file (77.7% in CAMS 2022-23)
MoSPI, Comprehensive Modular Survey: Telecom 2025 (NSS 80th round), press note 29 May 2025
Read carefully
A household counts as connected when any member is. A household with one smartphone, held by a son, counts as connected while his mother and sister are not.
Skills are uneven
Sending an attachment is a basic task. Filling an online form, spotting a fake payment request or changing privacy settings are harder, and they are what a digital-by-default scheme demands.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
South Asia's mobile internet gender gap, measured by GSMA
The GSMA, the mobile industry's association, surveys women and men in low and middle income countries every year. Its 2026 report, published on 10 June 2026, found the gap narrowing slightly in 2025, with South Asia still among the two regions where it is widest. Use the current edition: methods change between reports, so comparing a 2025 figure with a 2026 figure can mislead.
25%
women in South Asia less likely than men to use mobile internet
GSMA, Mobile Gender Gap Report 2026 (10 June 2026)
810 mn
women in LMICs not using mobile internet
GSMA, Mobile Gender Gap Report 2026
2–3x
how much wider the gap typically is in rural areas
GSMA, Mobile Gender Gap Report 2026
The barriers GSMA reports
Handset affordability, literacy and digital skills, and, once online, safety and security concerns, the cost of data and poor coverage.
For programme design
If a service reaches women only through a smartphone app, assume a quarter fewer women than men can use it, and more in rural areas. Design a voice, SMS or assisted route from the start.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
From ever online to meaningfully connected
The surveys on the last three slides count whether people have used the internet. A rights approach asks a harder question: can a person use it to claim what they are owed, safely and on their own terms? That depends on device ownership, privacy within the household, language, skills, cost and safety. A woman who must ask her husband to fill her pension form online has access in the survey sense and none in the rights sense.
Five tests of meaningful access
  • Own device, used privately
  • Affordable data for regular use
  • Content and interfaces in her language
  • Skills to complete the task without help
  • Safety from harassment once online
What a programme can do
  • Budget for devices or data where use is required
  • Train on the actual task (a scheme form), with women trainers
  • Offer assisted access points with privacy
  • Measure use by each woman, beyond household connection
For the wider case on the digital divide, including disability and language, see Digital Ethics 101 Section 7 and Data Feminism 101.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
07
Section Seven
Online harms: gender-based violence and children
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Cybercrime in India: NCRB's 2024 figures
The National Crime Records Bureau's Crime in India 2024, released on 7 May 2026, recorded more than one lakh cybercrime cases in a year for the first time. These are cases registered by police, so they measure what was reported and recorded, which is a fraction of what happened. Fraud dominates the count. Sexual exploitation is a small share of cases and a large share of the harm to women and children.
1,01,928
cybercrime cases registered in 2024, up 17.9% from 86,420 in 2023
NCRB, Crime in India 2024, Vol II, Table 9A.1
72.6%
of cases with fraud as the motive (73,987)
NCRB, Crime in India 2024, Vol II, Table 9A.3
3,190
cases with sexual exploitation as the motive
NCRB, Crime in India 2024, Vol II, Table 9A.3
Rate
The cybercrime rate rose from 6.2 to 7.3 cases per lakh population between 2023 and 2024 (NCRB).
Why the count misleads
Reporting depends on police capacity and on whether a victim trusts the station. States with better helplines record more crime. A high count can mean better access to justice.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Technology-enabled gender-based violence and the law that applies
Violence against women increasingly runs through phones: images shared without consent, a partner tracking her location, threats in comments, fake profiles. Indian criminal law covers most of these, spread across two statutes. The Bharatiya Nyaya Sanhita 2023 replaced the Indian Penal Code from 1 July 2024 and carries the general offences; the IT Act carries the electronic ones.
Form of harmMain provisionWhat it covers
Capturing or sharing intimate imagesIT Act s66E; BNS s77 (voyeurism)Capturing, publishing or transmitting images of a private area or private act without consent
Monitoring a woman's online activityBNS s78 (stalking)A man who monitors a woman's use of the internet, email or other electronic communication
Publishing sexually explicit materialIT Act ss67 and 67AObscene and sexually explicit material in electronic form
Material depicting childrenIT Act s67B; POCSO Act 2012Child sexual abuse material
Impersonation and fake profilesIT Act s66DCheating by personation using a computer resource
Sources: Bharatiya Nyaya Sanhita 2023 and Information Technology Act 2000, texts read on Indian Kanoon.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
BNS section 78: monitoring as stalking
The stalking offence is worth reading in full because it names the most common form of digital control in intimate relationships. Many women do not know that a partner who installs tracking software, reads her messages or demands her passwords may be committing an offence. Note the limits too: the section is written for a man stalking a woman, and it carries an exception for lawful crime prevention.
Any man who ... monitors the use by a woman of the internet, e-mail or any other form of electronic communication, commits the offence of stalking.
Bharatiya Nyaya Sanhita 2023, section 78(1)(ii)
In a programme
Safety planning with survivors should include a phone check: unknown apps, shared accounts, location sharing, and who knows the PIN. Train staff to do this gently and with consent.
The gender limit
The wording protects women from men. Harassment of trans persons or between women must be pursued under other provisions, such as criminal intimidation or IT Act s66E.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Why women do not report, and what a programme can change
The NCRB count of sexual exploitation cases is small next to the scale of harassment women describe. The gap has known causes. Each cause suggests a design response that a programme can take without waiting for police reform. Taken together, the pairs on this slide amount to a simple referral pathway that most women's groups can set up in a month.
Why cases are not reported
  • Fear that family will take away her phone
  • Shame, and fear the images will spread further
  • Police who advise her to stay offline
  • No knowledge of which law applies
  • Platforms that do not respond in her language
What helps
  • A trained contact who can explain options privately
  • Help to report the content to the platform first, quickly
  • A referral list of lawyers and the cybercrime portal
  • Evidence preservation before deletion
  • Peer support that does not depend on the platform
The IT Rules 2021 require platforms to act on a complaint about intimate images of a person. That route is often faster than a police case, and can run alongside it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
UN General Comment No. 25 (2021): children in the digital environment
The Committee on the Rights of the Child issued General Comment No. 25 on children's rights in relation to the digital environment, dated 2 March 2021. It reads the Convention on the Rights of the Child, which every South Asian state has ratified, into digital life. The Committee consulted children while drafting it, and its opening paragraph reports that children described digital technologies as vital to their lives.
What the General Comment asks of states
  • Apply the best interests of the child to digital policy
  • Protect children from exploitation and abuse online
  • Protect their privacy, including from commercial profiling
  • Secure their access to information and their right to be heard
The tension for programmes
Protection and participation pull against each other. Blocking every risk would cut children off from learning and from help. The General Comment asks for both, balanced by age and capacity, which is the same evolving capacities idea found in Article 5 of the Convention.
Source: CRC/C/GC/25, 2 March 2021, UN Treaty Body Database. For the wider framework see Child Rights 101.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Children's data under the DPDP Act: what applies when
The DPDP Act 2023 treats everyone under 18 as a child. Section 9 requires verifiable consent of a parent or lawful guardian before processing a child's personal data, and bars tracking, behavioural monitoring and targeted advertising directed at children. These are among the core duties, so they apply only from 13 May 2027 under G.S.R. 843(E) of 13 November 2025. They are not in force as of October 2026.
DateWhat commences (G.S.R. 843(E), 13 November 2025)
13 November 2025Definitions, the Data Protection Board (ss18-26), and s44(3) amending the RTI Act
13 November 2026Section 6(9) and section 27(1)(d)
13 May 2027Core duties and rights (ss3-17), including s9 on children and the s17 exemptions; penalties (ss27-34)
Do not wait for May 2027. A programme that photographs children, runs a WhatsApp group for adolescents or uses an EdTech app should already ask for parental consent and collect the minimum. Data Protection & the DPDP Act 101 covers the detail.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Digital safeguarding for programmes that work with children
Most child protection policies in NGOs were written for physical contact. Digital work adds new risks: staff in private chats with children, photos posted with locations, apps that collect data the organisation never sees. The table turns General Comment No. 25 and the coming DPDP duties into practice. It is a minimum; Safeguarding & PSEA 101 has the full framework.
RiskSafeguardWho checks
One-to-one chats between staff and childrenGroup channels only, with two adults presentSafeguarding lead
Photos that reveal identity or locationNo faces or names of at-risk children; strip location dataCommunications team
Third-party apps collecting children's dataReview the app's privacy policy and data flows before useProgramme manager
Online abuse disclosed to staffWritten reporting route, preserved evidence, referral listSafeguarding lead
Children's own online safetyAge-appropriate sessions on privacy and reporting, designed with themEducation staff
ImpactMojoDigital Rights & AI 101www.impactmojo.in
08
Section Eight
What AI systems are and how they fail
ImpactMojoDigital Rights & AI 101www.impactmojo.in
An AI system, explained for non-technical practitioners
Most AI systems in public life are prediction machines. They learn patterns from past data and use them to produce an output for a new case: a score, a category, a match or a piece of text. They work by resemblance: they find what past cases with similar features looked like, which is powerful when the past is a good guide and harmful when the past was unfair.
AI system (working definition)
Software that infers from the data it receives how to generate outputs such as predictions, content, recommendations or decisions, which can influence people or environments. This is close to the wording used in the EU AI Act and the OECD.
01
DATA: past records, labelled with an outcome
→
02
TRAINING: the system finds patterns linking features to the outcome
→
03
MODEL: the patterns, stored as numbers
→
04
OUTPUT: a score or label for a new person
→
05
DECISION: a human or a rule acts on the output
The decision step is where rights attach. Ask who acts on the output, and whether they can override it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Four kinds of AI a development practitioner will meet
The word AI covers systems that work in quite different ways and carry different risks. Sorting them by what they produce is more useful than sorting them by technique. Generative AI gets the headlines; scoring and matching systems make more decisions about poor people's lives. The examples are typical uses in South Asian programmes and public services.
KindWhat it producesExample in developmentMain rights risk
ScoringA number predicting risk or needRanking households for a benefit; credit scoring for microloansWrongful exclusion; bias from proxies
ClassificationA categoryFlagging duplicate or ineligible beneficiariesFalse positives that cut people off
Matching and recognitionA link between two records or facesFacial recognition; record linkage across databasesWrong matches; surveillance
GenerativeText, images, audioChatbots for scheme information; drafting reportsConfident wrong answers; deepfakes
For safe daily use of generative tools, see GenAI for Practitioners 101. This deck focuses on systems that decide about people.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Three doors through which bias enters an AI system
Algorithmic bias is a systematic error that falls harder on some groups than others. It is rarely the result of a programmer's prejudice. It enters through ordinary choices that look technical. Each door below has a matching question you can ask a vendor or a government department, even if you cannot read a line of code.
1. The data
If past data under-represents a group, or records the effects of past discrimination, the system learns them. Ask: whose records trained this, and who is missing?
2. The target
The outcome the system predicts may be a poor proxy for what you care about, such as cost for need. Ask: what exactly does the score predict?
3. The deployment
A system tested in one population is used on another, or staff treat a score as final. Ask: where was it tested, and who can override it?
Your bargaining power
These questions belong in the terms of any procurement or partnership. A vendor that cannot answer them has not done the work.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
A health algorithm that predicted cost and missed need
Ziad Obermeyer and colleagues studied a commercial algorithm used by US health systems to pick patients for extra care. It was trained to predict future health care costs, on the reasoning that sicker people cost more. Because less money had been spent on Black patients with the same illness, the algorithm ranked them as lower risk. The paper appeared in Science in October 2019.
17.7%
share of Black patients flagged for extra help by the algorithm
Obermeyer, Powers, Vogeli and Mullainathan, Science 366:447-453 (2019)
46.5%
share if the disparity were remedied
Obermeyer et al., Science (2019)
The general lesson
The authors warn that convenient proxies for ground truth can be an important source of bias in many contexts. Cost stood in for illness; the gap between them was the history of unequal access.
The South Asian parallel
A targeting model trained on past scheme enrolment learns who was enrolled, which reflects who could reach the office. Households excluded before will be scored as less eligible.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Facial analysis error rates by gender and skin type
Maximum error rates of commercial gender classifiers (%)
Buolamwini and Gebru, Gender Shades, PMLR 81 (2018)
Joy Buolamwini and Timnit Gebru tested three commercial gender classification systems on a new dataset balanced by gender and skin type. Darker-skinned women were the most misclassified group, with error rates of up to 34.7%. The maximum error rate for lighter-skinned men was 0.8%.
The systems were sold as accurate because they were accurate on average. Averages hid the group on which they failed, a group under-represented in the data used to build them.
Ask for error rates broken down by gender, age and skin tone before any face-based system is used on your participants. Delhi Police's own reported figures are on the facial recognition slide in Section 05.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Illustrative: why a 95% accurate fraud flag can still hurt most of the people it flags
Accuracy figures mislead when the thing being detected is rare. Suppose a state uses a model to flag ineligible pension claimants, and suppose only 2% of 1,00,000 claimants are actually ineligible. The model is right 95% of the time for both groups. The numbers below are Illustrative, built to show the arithmetic; they describe no real scheme.
IllustrativeActually ineligible (2,000)Actually eligible (98,000)
Flagged as ineligible1,900 (correct)4,900 (wrongly flagged)
Not flagged100 (missed)93,100 (correct)
The result
Of 6,800 people flagged, 4,900, about 72%, are eligible. If flags lead to automatic suspension, most people cut off are entitled to the pension.
The design fix
Treat a flag as a reason to check. Put the burden of verification on the department, and keep paying until the check is done.
This is the arithmetic behind the Telangana case in Section 09.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
If you cannot see the reason, you cannot contest the decision
Due process in Indian administrative law requires that a person affected by a decision be told the reason and be heard. Automated systems strain both. The reason may sit in a model nobody in the department can explain, or in a vendor contract marked confidential. A person dropped from a list may not even know that a system was involved. Contestability, the practical ability to challenge an output, has to be designed in.
How opacity arises
  • Complex models whose logic is hard to state
  • Trade secrecy claimed by vendors
  • No notice that a system was used
  • Staff who cannot override the output
What contestability needs
  • Notice to the person that a system contributed
  • A plain-language reason, with the data relied on
  • A human review with power to reverse
  • Continued benefit while review is pending
Article 14 (non-arbitrariness) and the principles of natural justice give these needs a legal footing in India even without an AI statute.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
09
Section Nine
AI in welfare, work and elections
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Telangana's Samagra Vedika: an algorithm that decided who was poor
Samagra Vedika is a data system that links records across Telangana's departments to build a profile of each resident. The state used it to find ineligible welfare claimants, for example people who owned a car. An investigation by Al Jazeera and The Reporters' Collective, supported by the Pulitzer Center's AI Accountability Network, found that it wrongly matched poor people to assets they did not own, and that officials trusted the system over the person.
1.86 mn+
food security cards cancelled by Telangana, 2014-2019
Tapasya, Kumar Sambhav and Divij Joshi, Al Jazeera with The Reporters' Collective, 24 January 2024
142,086
fresh applications rejected without notice in the same period
Tapasya, Kumar Sambhav and Divij Joshi, Al Jazeera with The Reporters' Collective, 24 January 2024
Bismillah Bee
A 67-year-old widow in a Hyderabad slum was denied rations because the system matched her late husband Syed Ali, a rickshaw puller, to Syed Hyder Ali, a car owner. Her case reached the Supreme Court.
Where the burden fell
Once excluded, people had to prove they were entitled. The algorithm's output was treated as the default truth, and the person as the one who had to rebut it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
When the Supreme Court ordered a check, the errors showed
In April 2022, in a case first filed by activist S.Q. Masood on behalf of excluded families, the Supreme Court ordered Telangana to verify in the field all 1.9 million cards deleted since 2016. The investigation obtained the progress figures to July 2022. Even on this partial count the error rate exceeded the state's own claim that wrong matches happened in under five per cent of cases and had mostly been corrected.
491,899
applications received for re-verification
Tapasya, Kumar Sambhav and Divij Joshi, Al Jazeera with The Reporters' Collective, 24 January 2024
205,734
processed by July 2022
Tapasya, Kumar Sambhav and Divij Joshi, Al Jazeera with The Reporters' Collective, 24 January 2024
15,471
approved, so wrongly rejected
Tapasya, Kumar Sambhav and Divij Joshi, Al Jazeera with The Reporters' Collective, 24 January 2024
7.5%+
minimum share of processed cards wrongly rejected
Tapasya, Kumar Sambhav and Divij Joshi, Al Jazeera with The Reporters' Collective, 24 January 2024
The 7.5% is a floor. It counts only people who knew to apply, managed to apply, and had their case processed. Those who gave up are in no figure.
The arithmetic is the illustrative base-rate table of Section 08 made real: a rare target, a system with errors, and a decision rule that cut people off on a flag.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Five design rules for automated eligibility, from the evidence
Telangana is one case, and the same pattern appears wherever an automated flag is allowed to end a benefit. The rules below are drawn from the Samagra Vedika evidence, the Obermeyer study and the Puttaswamy test. They apply equally to a state system and to an NGO that scores households for a livelihoods programme or a scholarship.
RuleWhyWhat it looks like in practice
A flag starts a check, and the benefit continues meanwhileErrors concentrate on the poor, who cannot rebut themBenefit continues until a human verifies in the field
Give notice and a reasonNatural justice; Article 14A letter or SMS naming the data relied on
Publish error ratesAccuracy claims must be testableShare of flags overturned on review, each quarter
Test on the people it will judgeGender Shades: averages hide failing groupsError rates by caste, gender, disability, district
Keep a non-digital routeAuthentication and data failA named officer who can approve on documents
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Data work: the people who label what AI learns from
AI systems learn from data that people have labelled: this image shows a pedestrian, this text is abusive, this answer is better than that one. Much of this work is done through online platforms and outsourcing firms, much of it in the Global South, including India. It is low-paid, often precarious, and sometimes harmful: moderators and labellers view violent and sexual material for hours.
US$1.32–2
hourly take-home pay of Kenyan workers labelling data for OpenAI via Sama
Billy Perrigo, TIME, 18 January 2023
142 → 777
digital labour platforms worldwide, 2010 to 2020
ILO, World Employment and Social Outlook 2021 (23 February 2021)
Half
of online platform workers earn less than US$2 an hour
ILO, World Employment and Social Outlook 2021
Why this is a rights issue
Fair pay, safe work, freedom of association and social security apply to data workers as to any others. The ILO found platform workers often lack all four.
For livelihoods programmes
Data work is offered to rural youth and women as a digital job. Check pay per hour actually worked, exposure to harmful content and who holds the contract before promoting it.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Gig work, algorithmic management and the new Labour Codes
For delivery riders and drivers, the boss is often an algorithm: it allocates orders, sets pay per task, rates workers and can deactivate an account. The four Labour Codes came into force on 21 November 2025. The Code on Social Security 2020, one of the four, defines gig workers (s2(35)) and platform workers (s2(61)) and provides for social security schemes for them (s114), the first national labour law in India to name them.
What the Code on Social Security does
Recognises gig and platform workers as categories, provides for schemes on life and disability cover, health and old age (s114(1)), and for aggregator contributions of 1-2% of annual turnover, capped at 5% of what the aggregator pays these workers (s114(4)). The detail sits in rules and schemes, so check what has been notified in your state.
What it leaves open
Algorithmic deactivation without a reason, opaque pay formulas, and ratings that punish workers for delays they did not cause. These are due process questions about an algorithm, and the Code says little about them.
For the wider labour picture, see Work, Labour & Livelihoods 101.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The Election Commission's rules on AI in campaigns
Generative AI makes it cheap to put words in a candidate's mouth. The Election Commission of India has issued a sequence of advisories to political parties and, in 2026, directions to platforms. They use the Model Code of Conduct and the IT Act and IT Rules, since there is no election-specific AI statute. Each step tightened the last.
DateInstrumentMain requirement
January 2025Advisory to political partiesLabel images, video and audio generated or significantly altered by AI
24 October 2025Advisory before the Bihar electionsLabels such as AI-Generated covering at least 10% of the visible area; misleading synthetic content removed from party handles within three hours
19 April 2026Instructions during the assembly elections in Assam, Kerala, Tamil Nadu, Puducherry and West BengalPlatforms to act on unlawful or misleading content, including AI material, within three hours of a report; over 11,000 posts or URLs acted on (removals, FIRs, clarifications, rebuttals) after the 15 March schedule
Sources: MediaNama, 17 January 2025, 28 October 2025 and 22 April 2026; All India Radio News, 25 October 2025; Scroll, April 2026.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
When a deepfake targets your staff, partners or community
Deepfakes are used for more than elections. Voice clones of relatives ask for money. Fake videos of activists are used to discredit them. Synthetic intimate images are used against women journalists and community leaders. A response has to move fast, because the 2026 IT Rules give platforms three hours to act on an order, and harm spreads faster still.
01
SAVE: capture the content, link, account and time before it is deleted
→
02
REPORT: to the platform as synthetic or impersonation content, and to its grievance officer
→
03
COMPLAIN: the national cybercrime portal or police, citing IT Act s66D or s66E as relevant
→
04
CORRECT: a short public statement from a trusted voice, without reposting the fake
→
05
SUPPORT: care for the person targeted, who carries most of the harm
Verification habits
Check the source account, look for the original, use reverse image search, and be wary of audio that arrives without video.
Your own use
If you use synthetic voices or faces in campaigns, label them as the ECI and the IT Rules expect, and never imitate a real person.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
10
Section Ten
Governing AI: the EU, India and global standards
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Four ways to govern AI, and where South Asia sits
Governments and international bodies have chosen different instruments. The European Union passed a binding regulation. India has chosen guidelines plus existing law, on the view that a separate AI law is not needed yet. UNESCO and the OECD set standards that states sign up to without enforcement. For a South Asian organisation all four can apply at once, depending on where its donors, users and vendors are.
InstrumentTypeAdoptedBinding?
EU AI Act, Regulation (EU) 2024/1689Regulation, risk-basedIn force 1 August 2024Yes, in the EU and for systems used there
India AI Governance GuidelinesGuidelines plus existing lawsReleased by MeitY, 5 November 2025No; existing laws are
UNESCO Recommendation on the Ethics of AIGlobal standardNovember 2021, 193 member statesNo
OECD AI PrinciplesIntergovernmental principlesMay 2019, updated May 2024No
India is not an OECD member. Every South Asian state, as a UNESCO member, took part in adopting the UNESCO Recommendation.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The EU AI Act sorts AI systems into four levels of risk
The EU AI Act regulates by use. The same model may be banned in one use and unregulated in another. Its four levels are set out by the European Commission. Several high-risk uses are exactly the ones development programmes care about: access to essential public services and benefits, education, and employment.
LevelRuleExamples given by the Commission
Unacceptable riskBanned (eight practices since February 2025; the 2026 Omnibus adds two from 2 December 2026)Social scoring; harmful manipulation; untargeted scraping of faces; emotion recognition at work and in education; from December 2026, AI that generates non-consensual intimate images or child sexual abuse material
High riskStrict duties: risk management, data quality, human oversight, registrationAccess to essential public and private services, such as credit scoring; education; employment; law enforcement
Transparency riskDisclosure dutiesChatbots must say they are AI; deepfakes must be labelled
Minimal or no riskNo new rulesSpam filters; AI in video games
Sources: European Commission, AI Act policy page (digital-strategy.ec.europa.eu), read October 2026; Regulation (EU) 2026/1744, Article 1(7) (EUR-Lex).
ImpactMojoDigital Rights & AI 101www.impactmojo.in
When each part of the EU AI Act applies, after the 2026 Omnibus
The Act applies in stages. In July 2026 the EU adopted the Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It postponed the main high-risk duties. Older summaries that give 2 August 2026 for the high-risk rules are now out of date.
DateWhat applies
1 August 2024The Act enters into force
2 February 2025Prohibited practices; AI literacy duty (since reworded by the Omnibus)
2 August 2025Duties for general-purpose AI models
2 August 2026Most transparency duties under Article 50
2 December 2026Two new bans (AI-generated non-consensual intimate images; child sexual abuse material); marking deadline for generative systems already on the market
2 December 2027High-risk systems in Annex III uses (postponed from 2 August 2026)
2 August 2028High-risk AI in products under Annex I (postponed from 2 August 2027)
Sources: Regulation (EU) 2026/1744, OJ L, 24 July 2026, Articles 1 and 4 (EUR-Lex); European Commission AI Act page.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Why a South Asian NGO should know the EU AI Act
The EU Act applies to providers and deployers who place AI on the EU market or whose AI outputs are used in the EU, wherever they are based. Most South Asian programmes will never be directly covered. The Act still reaches them in three ways, and it is the most detailed public statement of what responsible AI requires, which makes it a useful checklist even where it has no legal force.
Indirect reach
  • European donors may write its standards into grant terms
  • Vendors selling into the EU build to its rules
  • Research partners in the EU must comply when outputs are used there
Borrowing its ideas
  • Its high-risk list maps onto welfare, education and jobs
  • Its duties (human oversight, data quality, logs) make a good procurement checklist
  • Its bans name practices to avoid anywhere, such as social scoring
In India, using the EU list as a benchmark is a choice with no legal force. Say so in your policy, so staff know which standard they are being held to.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The India AI Governance Guidelines (November 2025)
MeitY released the India AI Governance Guidelines on 5 November 2025. They were drafted by a committee chaired by Prof. Balaraman Ravindran of IIT Madras. Their central position is that existing laws on information technology, data protection, consumer protection and criminal law can govern most AI uses, so a separate AI law is not needed at this stage given the current assessment of risks.
The seven sutras
  • Trust is the foundation
  • People first
  • Innovation over restraint
  • Fairness and equity
  • Accountability
  • Understandable by design
  • Safety, resilience and sustainability
Institutions proposed
An AI Governance Group (AIGG) for a whole-of-government approach, supported by a Technology and Policy Expert Committee, and an AI Safety Institute for technical expertise, with sector regulators keeping enforcement powers. The sutras are adapted from the RBI's FREE-AI committee report.
Source: India AI Governance Guidelines, MeitY, November 2025; PIB release 2186639, 5 November 2025. Note the third sutra: India has chosen to favour innovation where risks are balanced.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
The IndiaAI Mission: public money for compute, data and models
On 7 March 2024 the Union Cabinet approved the IndiaAI Mission, with a budget outlay of Rs 10,371.92 crore. Its components include public AI compute of 10,000 or more GPUs, better data quality, support for indigenous foundation models, startup financing and tools for safe and trusted AI. The rights questions sit inside these components: which data trains the models, and whose languages and needs are served.
Rs 10,371.92 cr
IndiaAI Mission outlay approved by the Cabinet
PIB, Cabinet approves IndiaAI Mission, 7 March 2024
10,000+
GPUs of public AI compute planned
PIB, 7 March 2024
Opportunity
Public compute and Indian-language models could make AI tools usable for people who do not read English, which matters for any chatbot a programme might deploy.
Questions to ask
Were people asked before their data trained a public model? Are models tested on dialects and on women's and Dalit speakers? Who audits the safe and trusted AI tools themselves?
ImpactMojoDigital Rights & AI 101www.impactmojo.in
UNESCO's Recommendation and the OECD Principles
Two non-binding texts give shared vocabulary across countries. They are the standards a development organisation can cite in any South Asian country, because they do not depend on national law. Neither creates a remedy for a harmed person. Both are useful for writing an organisational AI policy that donors and partners will recognise.
UNESCO Recommendation on the Ethics of AI (2021)
Adopted in November 2021 by UNESCO's 193 member states, the first global standard on AI ethics. It holds that AI must respect human rights and human dignity, grounded in principles such as transparency, fairness, environmental sustainability and human oversight.
OECD AI Principles (2019, updated 2024)
Adopted in May 2019 and updated in May 2024 to reflect new technology. They promote AI that is innovative and trustworthy and that respects human rights and democratic values.
Sources: UNESCO, Ethics of Artificial Intelligence page; OECD.AI, AI Principles overview; both read October 2026.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
AI and personal data under the DPDP Act, phase by phase
India has no AI statute, so the Digital Personal Data Protection Act 2023 is the main law that will govern AI built on personal data. Its commencement is staged under G.S.R. 843(E) of 13 November 2025, and the DPDP Rules 2025 (G.S.R. 846(E)) follow the same phasing. As of October 2026 the duties that matter most for AI (notice, consent, purpose, accuracy, erasure) are not yet in force.
AI questionDPDP provisionApplies from
May we train a model on beneficiary records?Consent or a legitimate use (ss4-7)13 May 2027
Must the data be accurate if it drives a decision?Fiduciary duty on completeness and accuracy (s8)13 May 2027
Children's data in an EdTech or chatbot tools9: parental consent; no tracking or targeted ads13 May 2027
Research use of personal dataExemption in s17(2)(b), on conditions13 May 2027
Who will hear complaints?Data Protection Board (ss18-26)In force since 13 November 2025
Do not tell partners that the research exemption or any duty is already in force. Plan now so that systems comply on 13 May 2027.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
11
Section Eleven
A digital-rights and AI risk assessment for your programme
ImpactMojoDigital Rights & AI 101www.impactmojo.in
When a programme should run a digital-rights and AI assessment
An assessment is a structured set of questions asked before a digital tool goes live, and asked again when it changes. It need not be long. Its value lies in forcing the questions in this deck to be answered by named people before participants carry the risk. Run it at the triggers below, and keep the answers on file: a donor, an ethics committee or, from May 2027, the Data Protection Board may ask for them.
01
NEW TOOL: any app, portal, chatbot or dashboard that touches participants' data
→
02
NEW USE: existing data used for a new purpose, such as targeting
→
03
AUTOMATION: any score, flag or match that feeds a decision about a person
→
04
SCALE-UP: a pilot moving to more districts or a new population
→
05
INCIDENT: a breach, a shutdown, a complaint or a takedown
Who should be in the room
The programme lead, someone who handles data, a safeguarding or legal contact, and at least two people from the community the tool will serve.
How long it takes
For a small tool, a half-day workshop with this deck's checklists. For a system that scores people, longer, with a test on real cases before launch.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Checklist part 1: the rights questions
The first half of the assessment applies to every digital tool, whether or not it uses AI. Each question links back to a section of this deck, so a team that is unsure of an answer knows where to look. Answer in writing. A question marked no or unsure becomes an action with an owner and a date, entered in the programme's risk register.
QuestionSectionYes / No / Unsure
Is there a lawful basis for every data field we collect, and could we do without any of them?02, 05
Have we mapped what fails in a shutdown, with a fallback agreed with the department?03
Do we have a plan if our content is blocked or removed, with backups?04
Could our data help anyone watch or profile participants, and have we minimised it?05
Can women, older people and non-readers use the tool without help, or with private help?06
Do we have a route for online harassment and a children's safeguarding rule?07
Will we meet the DPDP duties that apply from 13 May 2027?07, 10
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Checklist part 2: the AI questions
The second half applies when the tool includes a model that scores, classifies, matches or generates. These questions come from the failure cases in Sections 08 and 09 and from the duties the EU sets for high-risk systems, used here as a benchmark. A vendor or partner who cannot answer a question is itself a finding: write it down.
QuestionEvidence to ask for
What exactly does the output predict, and is that the thing we care about?The target variable, in plain words
On whose data was it trained and tested, and who is missing?Data description; test populations
What are its error rates for women, older people, caste groups, disability?Disaggregated test results
Who acts on the output, and can they override it?Process map; override records
Will affected people be told, given a reason and able to contest?Notice text; review procedure
What happens while a contested decision is reviewed?Written rule that benefits continue
For generative tools: how are wrong answers caught and corrected?Testing log; escalation route
ImpactMojoDigital Rights & AI 101www.impactmojo.in
From answers to action: a decision table
A checklist produces findings; a team still has to decide. The table converts the pattern of answers into one of four decisions. It is deliberately conservative where a system decides about people's entitlements, because the evidence in Section 09 shows how errors fall on those least able to contest them. Adapt the thresholds to your setting, and record the decision and the reasons.
Pattern of answersRisk levelDecision
Information only; no personal data; no decision about peopleLowProceed; review yearly
Personal data, but no automated decision; minor gaps with ownersMediumProceed once actions are done
Score or flag influences an entitlement; human review exists and worksHighPilot with field verification of every adverse flag; publish error rates
Score or flag can end an entitlement without review; or error rates unknown for key groupsUnacceptable as designedDo not deploy; redesign so a flag only triggers a check
Children's data or survivor data with any gap in consent or securityHighPause until fixed
The unacceptable row is a design verdict, and redesign usually saves the project. A tool that helps staff decide whom to visit first is far safer than one that decides who is paid.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Illustrative worked example: a WhatsApp chatbot for pension eligibility
Illustrative. A women's rights NGO in one district plans a WhatsApp chatbot. Widows type or speak a few answers (age, district, whether they hold a ration card) and the bot tells them which state and central pension schemes they may qualify for, and which documents to bring to the block office. Version two would add a likely eligible score that the NGO would share with the block office to speed up approvals. The NGO, the district and the figures in this example are made up for teaching.
What the team wants
  • Reach widows who cannot visit the office
  • Cut wasted trips for missing documents
  • Help the block office prioritise applications
What the assessment must test
  • Can widows without their own phone use it?
  • Is answer quality checked against scheme rules?
  • What happens to a widow scored as unlikely?
  • What data does WhatsApp and the vendor see?
Note the shift between versions. Version one gives information to the person. Version two passes a judgment about her to an authority. The assessment treats them as two different tools.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Illustrative worked example: what the assessment found
Illustrative. The team ran both checklists in a half-day workshop with six widows from two villages, the block office's data entry operator and the NGO's programme lead. The table records the main findings and the actions agreed. Each action has an owner, which is the difference between an assessment and a discussion.
FindingRiskAction agreed
Four of six widows use a son's phoneExclusion; no privacyAdd a missed-call voice line and assisted help at self-help group meetings
Bot answers drafted from a 2024 scheme circularWrong eligibility adviceMonthly check against current rules; date shown in every answer
Version two score trained on past approvalsLearns who reached the office before (Obermeyer pattern)Drop the score; send a document checklist instead
Chats kept by the vendor indefinitelyData exposure; future DPDP breachContract: delete after 90 days; no reuse for training
No route if a widow is wrongly told she is ineligibleLost entitlementEvery answer ends with a helpline number and 'you may still apply'
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Illustrative worked example: the decision and how it will be monitored
Illustrative. Using the decision table, the team rated version one Medium and version two Unacceptable as designed. It launched version one after the agreed actions and replaced the score with a document checklist that the widow herself carries to the office. The block office gets nothing from the bot, which removes the risk that a score quietly becomes a gate. The team set four indicators to watch.
Monitoring indicators
  • Share of users who are women using their own phone
  • Applications filed per 100 users, by village
  • Answers found wrong at the monthly check
  • Complaints received and resolved
Review triggers
  • Any proposal to share chat data with the government
  • A change in scheme rules
  • A shutdown lasting more than a day in the district
  • The DPDP duties commencing on 13 May 2027
The final design does less than version two promised, and it carries far less risk of cutting an entitled widow off. Teams that run this assessment often reach the same trade.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
12
Section Twelve
Summing up and where next
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Ten points to carry from this deck
Rights online
  • The same rights apply offline and online (HRC 20/8, 2012)
  • Any limit must pass legality, legitimate aim, necessity and proportionality
  • Privacy is a fundamental right (Puttaswamy, 2017); section 66A is dead law (Shreya Singhal, 2015)
  • Indefinite internet suspension is impermissible and orders must be published (Anuradha Bhasin, 2020)
  • India imposed 65 shutdowns in 2025: plan offline fallbacks before you need them
AI and society
  • An AI system predicts from past data, and inherits the past's unfairness
  • Check what a score predicts: cost stood in for illness in Obermeyer (2019)
  • Ask for error rates by group: averages hid a 34.7% error in Gender Shades (2018)
  • A flag should start a check while the benefit continues (Telangana, 2014-2022)
  • DPDP core duties apply from 13 May 2027; the EU high-risk rules from 2 December 2027
Each point carries its source on the slide where it was introduced. If you remember one method from the whole deck, make it the four-step test on slide 9: it works for a shutdown order, a takedown, a surveillance request and an eligibility algorithm alike, and it is the frame the Supreme Court itself uses. The checklists in Section 11 are that test turned into questions a programme team can answer.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Words used in this deck
Terms in the order they appear. Several are legal terms with a precise meaning in Indian law, and using them loosely in a proposal or a court filing causes confusion. Where a term comes from a statute, the section is given so that you can read it in full. The others are terms of art in digital rights and AI research.
TermMeaning
IntermediaryA service that carries or hosts others' content, such as a telecom operator or social media platform (IT Act s2(1)(w))
Safe harbourProtection from liability for user content, on conditions (IT Act s79)
Blocking orderA direction to block public access to information (IT Act s69A)
SuspensionA temporary shutdown of telecom services (Telecommunications Act 2023, s20)
ProportionalityThe test that a limit on a right is no greater than needed for a legitimate aim
Synthetically generated informationAI-generated or altered content that appears real (IT Rules, 2026 amendment)
ProxyA measurable variable used in place of the thing a model should predict
High-risk AI systemIn the EU AI Act, a system in a listed sensitive use, subject to strict duties
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Questions practitioners ask, answered briefly
Can we be prosecuted for sharing a post that turns out to be false?
Not under section 66A, which is gone. Other offences, such as defamation or promoting enmity under the BNS, can apply. Check before sharing, and correct quickly.
Does the DPDP Act stop us using AI on beneficiary data today?
Its core duties apply only from 13 May 2027. Ethics, donor terms and Puttaswamy apply now. Design as if the duties were already in force.
Is it safe to use a free chatbot with participants?
Only for general information with no personal data, after checking its answers in your language. Section 11 and GenAI for Practitioners 101 explain why.
Can we refuse a department's demand for our beneficiary list?
Ask for the law that requires it and the purpose. Without a law, Puttaswamy's first step fails. Get legal advice before refusing.
These answers are general information as of October 2026 and are not legal advice for a particular case. Laws, rules and judgments in this field change often, and several of those cited here are under appeal or revision.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Where next: related 101 decks
Go deeper on digital topics
Digital Ethics 101 for privacy by design, Aadhaar and misinformation. Data Protection & the DPDP Act 101 for compliance step by step. GenAI for Practitioners 101 for safe daily use of AI tools. Data Feminism 101 for power in data. Post-Truth Politics 101 for disinformation.
Rights, ethics and practice
Human Rights 101 for the treaties and the UN system. Indian Constitution 101 for Articles 14, 19 and 21. Research Ethics 101 for consent in studies. Child Rights 101 and Safeguarding & PSEA 101 for children online. Governance & Accountability 101 for RTI and grievance routes.
Suggested order: Human Rights, then Data Protection & the DPDP Act, then GenAI for Practitioners. Read Child Rights before any digital programme with children.
ImpactMojoDigital Rights & AI 101www.impactmojo.in
Digital Rights & AI 101
Test every limit, check every score, keep a way back for people
100 slides·12 sections·CC BY-NC-ND