Section 79 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 79 of the Information Technology Act, 2000 says that an intermediary shall not be liable for any third party information, data or communication link made available or hosted by it, on conditions set out in sub-sections (2) and (3). The exemption applies if one of the functions in sub-section (2) is met and the intermediary observes due diligence, and it does not apply in the cases in sub-section (3). This article follows the consolidated text consulted (the Act as amended by the Information Technology (Amendment) Act, 2008); later amendments and the current position should be checked.
Section 79(1) gives an intermediary an exemption from liability for third party information, data or communication link, "notwithstanding anything contained in any law for the time being in force" but subject to sub-sections (2) and (3). Sub-section (2) sets the conditions for the exemption, including due diligence and such other guidelines as the Central Government may prescribe. Sub-section (3) lists when it does not apply: conspiracy, abetment, aiding or inducement; and failure to expeditiously remove or disable access after actual knowledge or notification.
Sub-section (1): the exemption
The copy prints: "Notwithstanding anything contained in any law for the time being in force but subject to the provisions of sub-sections (2) and (3), an intermediary shall not be liable for any third party information, data, or communication link made available or hasted by him."
The copy prints "hasted" for "hosted" here and again in sub-section (2)(a); we flag the slip and do not correct it.
The Explanation defines the key term: "For the purposes of this section, the expression 'third party information' means any information dealt with by an intermediary in his capacity as an intermediary."
"Intermediary" is defined in section 2(1)(w) to mean, with respect to any particular electronic records, any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record, and it includes telecoms service providers, network service providers, internet service providers, web-hosting service providers, search engines, online payment sites, online-auction sites, online-market places and cyber cafes. Our article on section 2 of the IT Act explains the definition.
| Element | What the words say |
|---|---|
| Who | An intermediary |
| What it is not liable for | Any third party information, data, or communication link made available or hosted by it |
| Override | "Notwithstanding anything contained in any law for the time being in force" |
| Limit | "Subject to the provisions of sub-sections (2) and (3)" |
| Third party information | Any information dealt with by an intermediary in its capacity as an intermediary |
Sub-section (2): when the exemption applies
Sub-section (2) says the provisions of sub-section (1) shall apply if:
- (a) the function of the intermediary is limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored or hasted; or
- (b) the intermediary does not (i) initiate the transmission, (ii) select the receiver of the transmission, and (iii) select or modify the information contained in the transmission;
- (c) the intermediary observes due diligence while discharging his duties under this Act and also observes such other guidelines as the Central Government may prescribe in this behalf.
The copy prints "or" after clause (a) and no connector after clause (b). We flag the drafting slip and do not correct it. How clauses (a) to (c) combine is therefore a question of reading the sub-section as a whole, and this article does not resolve it. What is plain is that clause (c) is a separate requirement about due diligence and guidelines.
Clause (c) leaves the guidelines to be prescribed. Section 87(2)(z), as printed, speaks of "the guidelines to be observed by the intermediaries under sub-section (4) of section 79", although section 79 as printed has no sub-section (4) (the guidelines are in section 79(2)(c)). We flag the slip and do not correct it. Our article on sections 86 and 87 covers section 87.
Sub-section (3): when the exemption does not apply
Sub-section (3) says the provisions of sub-section (1) shall not apply if:
- (a) the intermediary has conspired or abetted or aided or induced, whether by threats or promise or otherwise, in the commission of the unlawful act;
- (b) upon receiving actual knowledge, or on being notified by the appropriate Government or its agency that any information, data or communication link residing in or connected to a computer resource controlled by the intermediary is being used to commit the unlawful act, the intermediary fails to expeditiously remove or disable access to that material on that resource without vitiating the evidence in any manner.
| Case | Words | Point to note |
|---|---|---|
| (a) | conspired or abetted or aided or induced | "whether by threats or promise or otherwise" |
| (b) | failure to expeditiously remove or disable access | After actual knowledge, or on being notified by the appropriate Government or its agency; "without vitiating the evidence in any manner" |
The sub-section prints no time limit for removal. It says "expeditiously". The Act does not say what counts as actual knowledge, and this article does not add a definition.
If you run a platform, a marketplace, a hosting service or an app where users post content, a legal consultation on how your complaint process, your take-down log and your terms of use line up with these words is a useful preparation.
The 2021 Rules, as originally notified
This part explains the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021. Later amendments are not covered here; check the current text of the Rules before acting.
Rule 7 of the Rules as originally notified says that where an intermediary fails to observe the Rules, "the provisions of sub-section (1) of section 79 of the Act shall not be applicable to such intermediary and the intermediary shall be liable for punishment under any law for the time being in force including the provisions of the Act and the Indian Penal Code." Rule 3(1)(d) refers to "clause (b) of sub-section (3) of section 79 of the Act". Our articles explain the rules in detail:
- Rules 1, 2 and 7: definitions, scope and non-observance
- Rule 3: due diligence and grievance redressal
- Rules 4 to 6: significant social media intermediary duties
The Indian Penal Code reference is quoted as printed; check the current penal law for the corresponding provision.
A worked example
Bazaar Ghar Private Limited, an invented online marketplace, hosts listings posted by sellers. A buyer tells the marketplace that a listing is being used to commit an unlawful act. On the words of section 79, the first question is whether the listing is third party information, which it is if the marketplace dealt with it in its capacity as an intermediary. The second is whether the conditions in sub-section (2) are met, including due diligence. The third is whether sub-section (3)(b) is engaged: has the marketplace received actual knowledge, or been notified by the appropriate Government or its agency, and has it failed to expeditiously remove or disable access without vitiating the evidence? The marketplace should therefore keep a record of the date of each notice, what it did, and how the evidence was preserved.
Need help with intermediary liability?
If you run an online platform and want your terms, complaint handling and take-down process reviewed against section 79, our team can help. Talk to us about a legal consultation.
Key takeaways
- Section 79(1) exempts an intermediary from liability for third party information, data or communication link made available or hosted by it, subject to sub-sections (2) and (3).
- Sub-section (2) sets conditions that include due diligence and observing such other guidelines as the Central Government may prescribe.
- Sub-section (3) removes the exemption for conspiracy, abetment, aiding or inducement, and for failure to expeditiously remove or disable access after actual knowledge or notification.
- Printing slips: "hasted" (twice), the connectors in sub-section (2), and the cross-reference in section 87(2)(z) to a sub-section (4) of section 79 that is not printed.
- Rule 7 of the 2021 Rules as originally notified links non-observance of the Rules to section 79(1); later amendments should be checked.
Read next
- Section 2 of the Information Technology Act, 2000: computer, data, information, intermediary and cyber security
- Rule 3 of the Intermediary Guidelines Rules, 2021: due diligence and grievance redressal
- Rules 4 to 6 of the Intermediary Guidelines Rules, 2021: significant social media intermediary duties
- Copyright Infringement Notice to an Online Platform: draft
Disclaimer: Based on a consolidated copy of the Information Technology Act, 2000 as amended by the Information Technology (Amendment) Act, 2008, on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as originally notified on 25 February 2021 and on the CERT-In Directions of 28 April 2022, read with the amendments made to the Act by the Jan Vishwas (Amendment of Provisions) Act, 2023 and by section 44 of the Digital Personal Data Protection Act, 2023, as consulted on 2 October 2026. Commencement notifications, other amendments, rules, directions and the current position of each provision are not covered and should be checked. This article is general information, not legal advice; check the official text before acting.
