[codicts-css-switcher id=”346″]

Global Law Experts Logo
intermediary contracts india

Intermediary Contracts in India (2026): Drafting Due‑diligence, Content‑moderation & Liability Clauses Under the IT Rules

By Global Law Experts
– posted 2 hours ago

Intermediary contracts india have become an increasingly important compliance instrument for digital platforms as India’s intermediary framework, anchored in the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and their subsequent amendments, converts broad statutory duties into concrete, auditable contractual obligations. The framework sets due‑diligence expectations, has introduced requirements around synthetic and AI‑generated (including “deepfake”) content, prescribes grievance‑handling and takedown timelines, and reinforces record‑keeping duties in the day‑to‑day operation of platforms. For platform counsel, marketplace operators, SaaS vendors and moderation providers, the practical consequence is that the safe‑harbour protection afforded under Section 79 of the Information Technology Act, 2000 depends heavily on what your contracts actually say and require.

This guide translates those obligations into workable clause language, operational checklists and a liability‑allocation matrix.

Quick answer: This guide translates India’s intermediary obligations into practical contract clauses and operational checklists for platforms, vendors and counsel to meet due‑diligence, moderation and synthetic‑content compliance requirements.

Introduction: Why intermediary rules make contracts the compliance frontline

Regulatory duties do not enforce themselves. When a regulator or court examines whether an intermediary observed the due diligence required to retain safe harbour, the first evidence they will look for is documentary: onboarding records, vendor obligations, audit logs, takedown timestamps and the contractual architecture that governs everyone in the content supply chain. That is why intermediary contracts india have moved from the back office to the compliance frontline. A platform that has published a strong public policy but failed to bind its vendors and moderation partners to matching obligations has a dangerous gap between what it promises and what it can prove.

India’s intermediary rules build on the safe‑harbour regime in Section 79 of the IT Act and the due‑diligence conditions long associated with intermediary liability. They also intersect with data‑protection obligations arising under the Digital Personal Data Protection Act, 2023 (implementation of which is being phased in through subordinate rules). The result is a layered compliance burden that must be reflected across master service agreements, vendor onboarding packs, terms of service and moderation service agreements. This article is written for the people who have to make those documents work: in‑house counsel updating platform contracts, marketplace operators renegotiating vendor terms, and moderation and verification providers being asked to accept new obligations.

Because the intermediary rules and data‑protection rules continue to evolve, every specific rule number, threshold and timeline should be verified against the current text notified by the Ministry of Electronics & Information Technology (MeitY) and published in the Gazette of India before it is cited in an executed agreement.

Key obligations for intermediaries, what platforms must do

Before drafting, counsel need a clear map of the substantive duties the contract must operationalise. India’s intermediary framework broadly groups the relevant obligations into four categories, with additional expectations layered onto significant social media intermediaries. Editorial and legal teams should confirm the exact rule numbers and timelines against the operative notification before citing specific provisions in any executed agreement, because pinpoint accuracy on rule numbers and timelines is essential for enforceable clauses.

Due‑diligence and onboarding

Intermediaries must observe the prescribed due‑diligence conditions to retain safe‑harbour protection. In contract terms, this means onboarding checks on vendors and content service providers, clear notification of prohibited categories of content, and mechanisms that ensure users are informed of the platform’s rules, privacy policy and user agreement. Contracts should require every vendor in the chain to acknowledge the platform’s policies, warrant compliance with applicable law, and accept the platform’s right to enforce the rules downstream. Due diligence is not a one‑time event; it is a continuing condition, and intermediary contracts india should reflect that continuity rather than treating onboarding as a closed step.

Moderation, grievance handling and takedown timelines

The rules require intermediaries to operate a grievance‑redressal mechanism, to acknowledge and resolve complaints within prescribed windows, and to act on valid notices and court or government orders. Contracts must convert these statutory windows into binding service levels for whoever actually performs the moderation function, whether that is an in‑house team, an outsourced moderation provider, or an automated system supplied by a vendor. Where the operative rule expresses a timeline in hours or days for a given category, the contract’s SLA should mirror it exactly, with a margin that allows the platform to remain compliant even if a vendor is at the edge of its own service commitment.

Always confirm the current timelines against the notified rules, as they differ by category of content and by class of intermediary.

Synthetic content and labelling requirements

A developing feature of India’s intermediary framework is the treatment of synthetic and AI‑generated content, including manipulated media and “deepfakes”. MeitY has issued advisories and proposed amendments requiring intermediaries and content providers to identify and, in appropriate cases, label synthetically generated or altered content. Because the precise labelling and metadata obligations are still being finalised through amendment, counsel should track the current notified position. Contractually, synthetic‑media compliance already has a direct dimension: vendors who supply generative tools, and users or creators who submit content, can be bound to labelling and disclosure obligations, and platforms should reserve the right to verify and to remove non‑compliant material.

Record retention

Finally, the rules reinforce record‑keeping expectations. Intermediaries must retain certain information and records of the actions they take, and must be able to produce those records to demonstrate compliance and to assist lawful requests. Contractually, this translates into log‑retention obligations, audit access rights and evidence‑preservation duties imposed on vendors and moderation partners, so that the platform can meet its own record‑keeping burden without gaps. Retention periods should track the periods required under the operative rules and any applicable data‑protection requirements.

Who needs to be named in intermediary contracts india? Parties, roles and definitions

Poor definitions are a common cause of failed liability allocation. Because the rules impose graduated duties, contracts must be precise about which entity plays which role. The following model definitions can be adapted, but each should be checked against the operative statutory definitions before execution.

  • Intermediary. Any entity that, on behalf of another person, receives, stores or transmits an electronic record, or provides any service with respect to that record, within the meaning of the Information Technology Act, 2000. The contract should name which party is the intermediary for the purposes of the arrangement, since only that entity can rely on Section 79 safe harbour.
  • Significant social media intermediary (SSMI). Where the platform crosses the registered‑user threshold notified by the Government that triggers enhanced obligations, the contract should declare that status and allocate the additional duties (such as appointing a resident grievance officer, a chief compliance officer and a nodal contact person, and traceability duties where applicable) accordingly.
  • Content service provider. A party that generates, curates or supplies content, including creators, publishers and syndication partners, who must be bound to labelling, IP and lawful‑content warranties.
  • Vendor. Any supplier of technology, infrastructure or services to the platform, including generative‑AI tool providers, whose outputs or systems can affect compliance.
  • Moderation service provider. A party that reviews, actions, escalates or appeals content decisions on the platform’s behalf, and who must be bound to the moderation SLA india and evidence‑logging duties.

A sample definitional clause might read: “‘Moderation Service Provider’ means any person engaged by the Platform to review, classify, escalate, remove or restore User Content, and includes any automated system supplied for that purpose, and such person shall for all purposes of this Agreement be treated as acting on behalf of the Platform in performing the Due‑Diligence Obligations.” Naming roles this precisely ensures that when regulators ask who was responsible for a given decision, the intermediary contracts india point to a clearly identified party with clearly identified duties.

Contractual due‑diligence, audits and vendor obligations

This is the operational heart of any compliant arrangement. What contractual due‑diligence and audit rights should vendors accept, and what is genuinely reasonable to demand? The answer is a proportionate package: onboarding checks, continuous monitoring, remediation obligations and access to evidence, all balanced against reasonable notice and confidentiality protections for the vendor.

Pre‑onboarding checks

Before any vendor is granted access, the contract should require the platform to conduct, and the vendor to cooperate with, documented onboarding due diligence. A model clause: “Prior to the Effective Date and as a condition of continued engagement, the Vendor shall complete the Platform’s onboarding questionnaire, provide evidence of its content‑handling policies, and warrant that its systems and personnel comply with the Due‑Diligence Obligations under applicable law and this Agreement.” An onboarding checklist should capture the vendor’s data‑handling practices, moderation capabilities, sub‑processor list, and any use of generative or synthetic‑content technology.

Continuous monitoring and audits

Due diligence continues after onboarding. Contracts should reserve audit rights that are risk‑calibrated: periodic audits on a defined schedule (for example, annual), plus triggered audits following a material incident or a regulatory notice. A sample audit clause: “The Platform may, on not less than the agreed notice period, audit the Vendor’s compliance with this Agreement no more than once per contract year, save that the Platform may conduct an additional audit at any time upon a Compliance Trigger, including receipt of a regulatory notice, a material breach, or a credible complaint concerning User Content.” For high‑risk vendors, the clause should extend to remote log access and, in defined cases, on‑site inspection.

Remediation timelines

An audit right is only useful if it is coupled with a duty to fix what it finds. Contracts should specify remediation timelines proportionate to the severity of the finding, for example, immediate remediation for issues affecting the platform’s statutory compliance, and a longer cure window for administrative shortfalls. Persistent or material non‑compliance should be an express termination trigger. This is where intermediary contracts india protect the platform’s safe‑harbour position: the ability to show a documented remediation and, if necessary, termination pathway is strong evidence that the intermediary observed due diligence.

Evidence and log access

Because record‑keeping is a statutory expectation, the vendor should be contractually bound to generate, retain and surrender evidence. A model clause: “The Vendor shall maintain complete and tamper‑evident logs of all content‑moderation actions, including timestamps, the identity of the actioning system or person, the notice or trigger relied upon, and the outcome, and shall retain and make such logs available to the Platform for the retention period required under applicable law.”

Content‑moderation and takedown clauses, drafting practical SLAs

Content‑moderation clauses india are where statutory timelines meet operational reality. The contract must specify exactly how a notice is received, how quickly it is actioned, how a user can contest a decision, and when a matter is escalated to law enforcement. Vague drafting here directly undermines safe‑harbour protection, because a platform that cannot demonstrate timely action cannot demonstrate the due diligence the rules require.

Takedown notice mechanics

The contract should define the notice format, the mandatory contents of a valid notice, and the acknowledgement and action timelines. A model takedown clause: “On receipt of a valid Notice, court order or authorised government direction, the Moderation Service Provider shall acknowledge receipt within the Acknowledgement Window and shall action, or refer for escalation, the identified content within the applicable Action Window, in each case in accordance with the timelines mandated under applicable law. ” The exact hours or days should be inserted from the operative rule text once verified against the current MeitY notification, and the SLA should build in a compliance buffer.

Note that, following Shreya Singhal v Union of India (2015), an intermediary is generally required to act on actual knowledge in the form of a court order or a notification by the appropriate Government or its agency, rather than on private complaints alone in respect of unlawful‑content categories governed by that ruling.

Counter‑notice and appeals

Procedural fairness matters. The Supreme Court’s decision in Shreya Singhal v Union of India (2015) established important safeguards against arbitrary content restriction, and contracts should preserve a fair grievance, counter‑notice and appeal path. A model clause: “A User whose content has been removed or restricted may submit a Counter‑Notice within the Appeal Window, and the Grievance Officer shall determine the appeal within the Grievance Resolution Window, recording reasons for the decision.” Users also retain the ability to escalate certain disputes to the Grievance Appellate Committee(s) constituted under the intermediary rules. Building appeal timelines into the moderation SLA india both supports the grievance‑mechanism requirement and reduces the risk of over‑removal.

Escalation to law enforcement

Certain categories of content require escalation rather than mere removal. The contract should require the moderation partner to identify and escalate such categories, to preserve associated evidence, and to notify the platform’s designated officer. This ensures the platform can meet its own reporting obligations without relying on informal channels.

Category / trigger Contractual action required Drafting note
Valid takedown notice / court order / authorised government order Acknowledge, review and action within the SLA window mirroring the applicable rule Insert exact statutory timeline from the verified notification
Emergency / imminent‑harm notice Immediate action and escalation to the designated officer No cure period; treat as highest priority
User grievance / counter‑notice Log, review and decide within the prescribed grievance window Record reasons; preserve audit trail; note appellate route
Content requiring law‑enforcement escalation Escalation, evidence preservation and platform notification Bind vendor to preservation and reporting duties

Synthetic and AI‑generated content: labelling, verification and contractual controls

The synthetic‑content position in India is developing through advisories and proposed amendments and, for many platforms, is the hardest area to operationalise. How should platform contracts allocate liability for synthetic or AI‑generated content? The answer begins with clear labelling and verification duties, cascades warranties down to vendors and creators, and reserves the platform’s right to remove content that cannot be verified. Because the precise obligations remain subject to change, verify the current notified requirements before finalising fixed labelling standards.

Labelling and metadata clause

A model labelling clause: “Where any User Content or Vendor Output is generated or materially altered by artificial intelligence, the submitting party shall apply the prescribed synthetic‑content label and shall embed or preserve provenance metadata identifying the content as synthetic, in accordance with the labelling standards required under applicable law.” Synthetic‑media compliance india depends on this obligation being enforceable against the party best placed to know how the content was created, usually the creator or the generative‑tool vendor, not the platform.

Vendor warranty and audit

Where a vendor supplies a generative model or tool, the contract should include a warranty that the tool applies or supports labelling and provenance, and an audit right to verify it. A model clause: “The Vendor warrants that its generative systems apply, or enable the Platform to apply, the labelling and metadata required by applicable law, and shall on request demonstrate the operation of such labelling to the Platform’s reasonable satisfaction.” This warranty is the contractual anchor for any downstream indemnity relating to mislabelled synthetic content.

User content submission terms

Terms of service must also carry the obligation. Platform terms of service india should require users to declare when content is synthetic, prohibit the removal of applied labels, and reserve the platform’s right to label, restrict or remove content that appears synthetic but is unlabelled. Coupling this with the moderation SLA helps ensure that unlabelled synthetic content is caught and actioned within a defined window.

Liability allocation, indemnities and insurance

Intermediary‑liability questions ultimately reduce to a single practical exercise: who bears the cost when content causes harm, breaches IP, violates privacy or attracts a regulatory penalty? Effective drafting allocates operational responsibility to the party with control, backs that allocation with indemnities, and caps exposure sensibly while carving out the risks that should never be capped.

Indemnity triggers

Indemnities should be triggered by the events each party controls: breach of the labelling warranty by a vendor, failure to meet a moderation SLA by a moderation provider, submission of unlawful or infringing content by a user or creator. A model indemnity trigger: “Each party shall indemnify the other against Losses arising from that party’s breach of its Due‑Diligence Obligations, its content warranties, or its labelling and provenance obligations under this Agreement.”

Caps and carve‑outs

Liability caps are appropriate for ordinary contractual risk but should not extend to categories where the law and public policy demand full accountability. Standard carve‑outs from any cap should include wilful misconduct, breaches of confidentiality and data‑protection obligations, IP infringement, and regulatory penalties attributable to a party’s non‑compliance. Data‑protection carve‑outs are particularly important given the overlapping obligations under the Digital Personal Data Protection Act, 2023.

Insurance minimums

For higher‑risk vendors and moderation partners, contracts should require minimum insurance cover, including cyber and professional‑indemnity cover appropriate to the exposure, with the platform named as an additional insured where relevant and evidence of cover produced on request.

Aspect Platform Vendor Moderator User / Creator
Default responsibility Overall compliance & safe‑harbour posture Tool/output compliance & labelling capability Timely, accurate moderation per SLA Lawful, correctly labelled content
Recommended indemnity Limited; back‑to‑back pass‑through where possible Indemnity for labelling & system‑compliance breach Indemnity for SLA failure & wrongful action Indemnity for unlawful/infringing/unlabelled content
Liability cap Negotiated aggregate cap Cap with carve‑outs Cap tied to fees, with carve‑outs Typically uncapped for unlawful content
Carve‑outs Data breach, IP, regulatory penalties Wilful misconduct, IP, data breach Wilful misconduct, gross negligence Fraud, unlawful content, IP infringement
Insurance Portfolio cover Cyber + professional indemnity minimums Professional indemnity minimums Not applicable

Safe‑harbour preservation and contractual compliance risk

Can platforms preserve safe‑harbour protection if their contract terms do not reflect their intermediary obligations? The honest answer is that they place that protection at serious risk. Section 79 of the IT Act conditions safe harbour on the observance of due diligence and on the intermediary not conspiring in, abetting or failing to act expeditiously on the required knowledge; the jurisprudence, most notably Shreya Singhal v Union of India (2015), confirms that intermediaries operate within a structured framework of duties and safeguards. Where a platform’s contracts are silent on the very obligations the law imposes, a regulator or court may reasonably conclude that the platform did not observe the required due diligence.

Representations and warranties

Contracts should include express representations that each party will comply with applicable law and the platform’s policies, and specific warranties covering content lawfulness and synthetic‑content labelling. A model representation: “Each party represents and warrants that it will comply with the Due‑Diligence Obligations and all applicable law, including the requirements relating to content moderation, takedown timelines, and synthetic‑content labelling.”

Cooperation and notification

Safe‑harbour arguments are strengthened by demonstrable cooperation. Contracts should require vendors and moderation partners to notify the platform promptly of any regulatory contact, complaint or incident, and to cooperate in responding. A model clause: “The Vendor shall notify the Platform without undue delay of any regulatory notice, complaint or incident affecting compliance, and shall cooperate fully in the Platform’s response.”

Termination and remediation rights

Finally, the platform must retain the right to remediate and, ultimately, to terminate a non‑compliant counterparty. The ability to point to enforcement powers actually exercised is powerful evidence of a functioning compliance system, and it is one of the strongest reasons why intermediary contracts india should never treat compliance clauses as boilerplate.

Practical negotiation tips and red flags for in‑house counsel

When negotiating, insist on the non‑negotiables and be pragmatic on the rest. Counsel should insist on: audit rights with triggered escalation; log retention and evidence access; labelling warranties from generative‑tool vendors; and uncapped or high‑cap treatment for data breach, IP infringement and regulatory penalties. Reasonable concessions include the audit notice period, the frequency of routine audits, and mutually agreed confidentiality protections around inspection.

  • Red flag. A vendor that resists any log access or evidence‑preservation duty, this directly undermines the platform’s record‑keeping obligation.
  • Red flag. Blanket liability caps with no carve‑outs for regulatory penalties or data breaches.
  • Red flag. No labelling warranty from a supplier of generative or synthetic‑content technology.
  • Red flag. Moderation SLAs expressed in vague terms rather than mirroring the statutory windows.

Where a legacy vendor contract fails these tests, put it on a defined remediation timeline and, if the vendor will not accept the necessary obligations, plan an orderly transition.

Comparison table: clause examples, Platform vs Vendor vs Moderator

Clause area Platform Vendor Moderator
Due diligence Sets policies and enforces downstream Warrants compliance; completes onboarding Acknowledges policies; applies them in decisions
Takedown response Owns statutory compliance Ensures tools enable timely action Actions within the mandated SLA window
Synthetic labelling Reserves right to label/remove Warrants labelling capability Flags and actions unlabelled synthetic content
Audit access Holds audit & trigger rights Grants log & system access Maintains and surrenders decision logs

Model clause pack

The clauses above are drafting starting points, not finished agreements. Each must be tailored to the specific arrangement, the exact operative rule numbers and timelines in the current MeitY notification, and the commercial balance between the parties. All model language should be reviewed and adapted by a qualified lawyer before use; nothing here constitutes legal advice on any specific matter.

Conclusion and next steps

Well‑drafted intermediary contracts india are a load‑bearing wall of platform compliance under India’s intermediary framework. The regulatory duties will be judged by what your documents require and what your logs can prove, which is why moderation SLAs, labelling warranties, audit rights and carefully allocated liability are not optional refinements but core protections for safe harbour. Use the following seven‑point checklist to act:

  1. Review and update your terms of service, privacy policy and user agreements for grievance, prohibited‑content and (as they develop) synthetic‑content labelling requirements.
  2. Renegotiate vendor and moderation contracts to include due‑diligence, audit and evidence obligations.
  3. Establish a risk‑calibrated audit schedule with triggered‑audit rights.
  4. Brief and equip moderation teams to meet the mandated grievance, takedown and appeal windows.
  5. Test synthetic‑content labelling and provenance across all content pathways.
  6. Confirm insurance minimums and indemnity carve‑outs for data, IP and regulatory exposure.
  7. Update the board on residual compliance risk and the remediation timeline for non‑compliant vendors.

Confirm every rule number, timeline and citation against the official MeitY notification and Gazette text before executing any agreement, and schedule a review cadence so your intermediary contracts india keep pace with future amendments.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mitakshara Goyal at Svarniti Law Offices, a member of the Global Law Experts network.

Sources

  1. Ministry of Electronics & Information Technology (MeitY)
  2. The Gazette of India (eGazette)
  3. India Code, Government of India Consolidated Statutes
  4. Supreme Court of India
  5. Ministry of Law & Justice, Legislative Department

FAQs

What do India's intermediary rules require of platforms?
India’s intermediary framework imposes layered duties: due diligence to retain safe harbour, a grievance‑redressal mechanism, action on valid notices and court or government orders within prescribed windows, identification and labelling expectations for synthetic content (as these develop), and record‑keeping obligations. Intermediary contracts india should reflect these duties through vendor obligations, moderation SLAs, audit rights and defined notice procedures. Confirm the current requirements against the notified rules.
It is risky. Regulators and courts will assess whether the platform observed due diligence, and missing contractual obligations increase enforcement risk. Include explicit compliance representations, indemnities and audit rights to strengthen any safe‑harbour argument under Section 79 of the IT Act.
Allocate primary operational responsibility to the content creator or vendor, retain pass‑through rights, and require warranties, indemnities and minimum insurance. Maintain carve‑outs for wilful misconduct and regulatory penalties so those exposures are never capped.
Reasonable rights include onboarding checks, periodic and triggered audits, remote log access, on‑site inspection in high‑risk cases, remediation timelines and termination on material breach, all balanced with appropriate notice and confidentiality protections for the vendor.
Mirror the statutory timelines in the current rule text: prompt action on court and authorised government orders and defined SLAs for grievance handling, with clear counter‑notice and appeal windows. Specify evidence requirements and escalation duties so the platform can prove compliance. Always verify the operative timelines before drafting, as they vary by content category and class of intermediary.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Intermediary Contracts in India (2026): Drafting Due‑diligence, Content‑moderation & Liability Clauses Under the IT Rules

Send welcome message

Custom Message