Every country that has built a large digital population eventually faces the same question: what should platforms be required to do, and what is left to users, markets, and design? India is no exception. It now has nearly 900 million internet users, foreign platforms that collect billions of dollars in domestic advertising, and a legal framework that is still catching up with the speed and scale of attention extraction.
The good news is that the framework is no longer blank. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, impose due diligence on intermediaries. The Digital Personal Data Protection Act, 2023, creates rights over personal data. Other countries offer templates: the European Union’s Digital Services Act, the United Kingdom’s Online Safety Act, and Australia’s Online Safety Act all go further in some respects. The question is not whether regulation matters; it is what regulation can and cannot do.
Point C1 Regulation can set a floor for platform accountability by mandating transparency, due process, and data protection, but it cannot by itself make substance-oriented design the default.
What India’s Rules Cover
The IT Rules 2021 require all intermediaries to follow a code of due diligence: publish terms of use, appoint grievance officers, and act on court or government orders. Significant social media intermediaries—those above a user threshold—face additional obligations: appoint compliance and nodal contact officers resident in India, publish monthly compliance reports, and enable user grievance redressal, including appeals to government-appointed Grievance Appellate Committees.
Point C2 The IT Rules 2021 focus on content takedown, user grievances, and traceability rather than on the design defaults—autoplay, infinite scroll, algorithmic ranking—that drive attention extraction.
The Digital Personal Data Protection Act, 2023, shifts the frame from content to data. It defines data principals and data fiduciaries, requires notice and consent for data processing, grants rights of access, correction, erasure, and grievance redressal, and provides for a Data Protection Board and penalties for breaches.
Point C3 The DPDP Act 2023 establishes individual rights over digital personal data; the DPDP Rules, 2025, and the Data Protection Board became operational in late 2025, but phased implementation and enforcement capacity are still unfolding.
Both laws are real progress compared with the earlier patchwork. They create obligations, penalties, and institutions. But neither directly addresses the business model that converts attention into advertising revenue, nor the design patterns that make extraction frictionless.
How the Global Floors Compare
The EU Digital Services Act is the most comprehensive of the recent frameworks. It applies tiered obligations to intermediary services, online platforms, and very large online platforms. It requires risk assessments, independent audits, algorithmic transparency, data access for researchers, and a ban on dark patterns that distort user choice. Penalties can reach 6% of global annual turnover.
| Feature | India (IT Rules 2021 + DPDP Act 2023) | EU (DSA) | UK (OSA 2023) | Australia (OSA 2021) |
|---|---|---|---|---|
| Primary focus | Content takedown, user grievances, data protection | Illegal content, systemic risk, transparency | Duty of care: illegal and child-harm content | Online safety, takedown powers, standards |
| Algorithmic transparency | Limited | Required for very large platforms | Required for risk assessment | Limited |
| Independent oversight | Grievance Appellate Committees; Data Protection Board operational | Digital Services Coordinators + Commission | Ofcom | eSafety Commissioner |
| Duty of care / systemic risk | Not explicit | Explicit for very large platforms | Explicit for regulated services | Implicit via safety expectations |
| Maximum penalties | Fines under IT Act; DPDP penalties up to ₹250 crore | Up to 6% global turnover | Up to 10% global revenue + senior manager liability | Civil penalties and infringement notices |
Sources: MeitY IT Rules 2021 and DPDP Act 2023; EU Regulation 2022/2065; UK Online Safety Act 2023; Australia Online Safety Act 2021. The comparison is illustrative and not exhaustive.
Point C4 The EU Digital Services Act goes further than India’s current framework by requiring systemic risk assessments, algorithmic transparency, and independent oversight for very large online platforms.
The UK Online Safety Act 2023 takes a different path. It imposes a duty of care on regulated services to protect users, especially children, from illegal and harmful content. Ofcom sets codes of practice, and failure to comply can lead to fines of up to 10% of global revenue and, in serious cases, criminal liability for senior managers.
Australia’s Online Safety Act 2021 empowers the eSafety Commissioner, an independent regulator, to issue takedown notices for unlawful content, set basic online safety expectations, and investigate platforms that fail to protect users. It also includes cyberbullying and image-based abuse schemes.
Point C5 The UK Online Safety Act and Australia’s eSafety model introduce duty-of-care or safety-standard approaches that India has not yet adopted for attention-economy harms.
No framework is perfect. The DSA’s effectiveness depends on enforcement by the European Commission and member-state coordinators. The UK OSA’s definition of harm has drawn free-speech concerns. Australia’s system is complaints-driven and resource-constrained. But they share one feature India’s current framework lacks: an explicit mandate to assess and mitigate systemic risks, including those arising from recommendation algorithms and engagement metrics.
What Regulation Can Do: Harms, Not Defaults
Regulation is good at a particular class of problems: clearly defined harms with identifiable victims and enforceable penalties. Child sexual abuse material, non-consensual intimate images, terrorist content, and incitement to violence fall into this class. So do certain data breaches and opaque data practices. The IT Rules, DPDP Act, and global counterparts all address these harms.
Government takedown activity in India has grown sharply since the IT Rules took effect. A 2025 analysis by the Software Freedom Law Centre found that platforms have become “more trigger-happy” with removals, especially after the Grievance Appellate Committees began operating in early 2023. Meta’s bi-annual transparency reports show large and rising volumes of content actioned at the government’s request.
Point C6 Regulation is better at removing illegal content and protecting personal data than at changing the engagement metrics, ad-supported business models, and default designs that drive attention extraction.
This matters because attention extraction is not, in most cases, illegal. A feed that ranks by engagement, an autoplaying video, a streak notification, or a red-dot badge does not violate the IT Rules or the DPDP Act. It may be psychologically powerful, economically consequential, and socially costly, but it is largely lawful. Regulation can punish the worst outcomes; it cannot easily compel a better default.
The Enforcement Gap
Even within its existing scope, Indian regulation faces an enforcement gap. The DPDP Act’s Data Protection Board became operational in late 2025, but its caseload, staffing, and effectiveness are still unfolding. The Grievance Appellate Committees handle only a tiny fraction of the grievances raised against platforms. The IT Rules require compliance officers and reports, but they do not require platforms to disclose how their recommendation systems work or to test them for systemic risk.
Accountability mechanisms are also thin. Meta’s Oversight Board, an external appeals body, receives cases from around the world, but Central and South Asia account for a small share of its docket relative to the region’s share of Meta’s user base. This is a proxy, not proof, of underinvestment in local-language safety and dispute resolution.
None of this means regulation is futile. It means the floor is lower than it looks. A law on paper is not enforcement in practice. A takedown process is not transparency. A grievance officer is not algorithmic accountability.
Beyond the Floor: Design and Business Models
If regulation is a floor, what builds the ceiling? The answer is almost everything else: product design, metrics, business models, internal governance, public pressure, and competition.
A platform can comply with the IT Rules and still optimise for watch time. It can honour DPDP consent requirements and still harvest micro-behavioural signals to personalise feeds. It can publish a transparency report and still refuse to share data with independent researchers. Compliance is necessary; it is not sufficient.
Point C7 Effective protection of attention and promotion of substance likely requires regulation plus design changes, alternative business models, public pressure, and internal platform accountability.
This is why the rest of this arc matters. Friction, chronological feeds, and user-chosen algorithms are design changes. Subscriptions, patronage, and public funding are business-model changes. Whistleblowers, researchers, journalists, and civil society create external pressure. Employees and shareholders create internal pressure. Regulation can enable or accelerate all of these, but it cannot replace them.
Sources and Method
This article draws on primary legal texts and official explanations: the Indian IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 as notified by MeitY and explained in a PIB FAQ; the Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, as published by MeitY; the EU Digital Services Act (Regulation 2022/2065); the UK Online Safety Act 2023; and Australia’s Online Safety Act 2021 and eSafety Commissioner guidance. It also uses the Software Freedom Law Centre’s 2025 analysis of Meta, X, and ShareChat takedown data, and Meta Oversight Board reports as proxies for platform accountability. Where implementation details are still unfolding, the text notes the uncertainty.
Open Questions
- Should Indian law explicitly require algorithmic risk assessments for large platforms?
- Can a duty-of-care model be adapted to India’s constitutional framework without over-broad censorship?
- What design changes could regulators mandate without becoming paternalistic?
- How should platform transparency requirements distinguish between illegal content and lawful-but-extractive design?
- What institutions does India need to enforce attention-economy rules at the scale of its user base?
Related in This Series
- The Attention Extraction — the diagnosis: how India’s digital dividend became a cognitive deficit.
- By the Numbers: What Indians Actually Do Online — a data-forward map of India’s digital time budget.
- The Generational Bet — the stakes: will India build the AI age or scroll through it?
- The Substance Builder — individual practice: turning dead time into small acts of creation.
- Designing for Substance — systemic design: platform incentives and the attention economy.
- Attention, Substance, and the AI Moment — the series guide and reading paths.
Article guideImportant points and sources7 pointsShow guideHide guide
- C001core · high · verifiedRegulation can set a floor for platform accountability by mandating transparency, due process, and data protection, but it cannot by itself make substance-oriented design the default.
- C002core · high · verifiedThe IT Rules 2021 focus on content takedown, user grievances, and traceability rather than on the design defaults—autoplay, infinite scroll, algorithmic ranking—that drive attention extraction.
- C003core · medium-high · verifiedThe DPDP Act 2023 establishes individual rights over digital personal data; the DPDP Rules, 2025, and the Data Protection Board became operational in late 2025, but phased implementation and enforcement capacity are still unfolding.
- C004landscape · high · verifiedThe EU Digital Services Act goes further than India’s current framework by requiring systemic risk assessments, algorithmic transparency, and independent oversight for very large online platforms.
- C005landscape · high · verifiedThe UK Online Safety Act and Australia’s eSafety model introduce duty-of-care or safety-standard approaches that India has not yet adopted for attention-economy harms.
- C006core · medium-high · verifiedRegulation is better at removing illegal content and protecting personal data than at changing the engagement metrics, ad-supported business models, and default designs that drive attention extraction.
- C007framing · medium-high · verifiedEffective protection of attention and promotion of substance likely requires regulation plus design changes, alternative business models, public pressure, and internal platform accountability.
SourcesSources used9 sourcesShow sourcesHide sources
- Gazette of India: Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021government-regulation
- PIB FAQs on Part II of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021government-press-release
- MeitY: Digital Personal Data Protection Act, 2023government-act
- MeitY: Digital Personal Data Protection Rules, 2025government-regulation
- EUR-Lex: Regulation (EU) 2022/2065 — Digital Services Actinternational-regulation
- UK Government: Online Safety Act 2023 Explainergovernment-regulation
- eSafety Commissioner: Online Safety Act 2021 Fact Sheetgovernment-regulation
- SFLC.in: Data Analysis of Meta, X, and ShareChat on Content Takedownwatchdog-report
- Meta Oversight Board: 2023 Annual Report Shows Board’s Impact on Metaplatform-accountability-report
Look closer
Sources and notes
Open detailsClose details
Look closer
Sources and notes
These notes collect the sources, counterpoints, and review status behind the article's important points. Read the essay first; open this when you want to check something.
Confidence reflects how strongly the sources support the point (low / medium / high). Status describes the point's role (e.g., core, argument, landscape). Sources link to supporting material;counterpoints note boundary conditions or conflicting findings.
Regulation can set a floor for platform accountability by mandating transparency, due process, and data protection, but it cannot by itself make substance-oriented design the default.
verifiedreviewed 2026-07-18
- Sources (2)
“The IT Rules 2021 impose due diligence, grievance redressal, and compliance obligations on intermediaries, creating a baseline of accountability.”
Gazette of India: Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021direct“The DPDP Act 2023 establishes rights and obligations around personal data, adding a data-protection floor.”
MeitY: Digital Personal Data Protection Act, 2023direct
- Counterpoints (1)
Some jurisdictions, such as the EU under the DSA, are experimenting with systemic-risk obligations that may indirectly affect design defaults; the boundary between floor and design is evolving.
The IT Rules 2021 focus on content takedown, user grievances, and traceability rather than on the design defaults—autoplay, infinite scroll, algorithmic ranking—that drive attention extraction.
verifiedreviewed 2026-07-18
- Sources (2)
“The rules prescribe due diligence for intermediaries, additional diligence for significant social media intermediaries, grievance redressal, and compliance reporting.”
Gazette of India: Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021direct“The FAQ explains that the rules aim at an open, safe and trusted internet and accountability of intermediaries, including social media intermediaries.”
PIB FAQs on Part II of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021direct
- Counterpoints (1)
Amendments to the IT Rules have added deepfake labelling and senior-official takedown authorisation, showing incremental expansion into design-adjacent obligations.
The DPDP Act 2023 establishes individual rights over digital personal data; the DPDP Rules, 2025, and the Data Protection Board became operational in late 2025, but phased implementation and enforcement capacity are still unfolding.
verifiedreviewed 2026-07-18
- Sources (2)
“The Act provides for rights of data principals, obligations of data fiduciaries, a Data Protection Board, and penalties, with the Central Government appointing dates for different provisions.”
MeitY: Digital Personal Data Protection Act, 2023direct“The DPDP Rules, 2025, notified on 13 November 2025, operationalized the Data Protection Board of India and laid out procedural rules for implementing the Act.”
MeitY: Digital Personal Data Protection Rules, 2025direct
- Counterpoints (1)
Enforcement capacity, staffing, and early Board caseload remain uncertain; compliance timelines for different entities are phased.
The EU Digital Services Act goes further than India’s current framework by requiring systemic risk assessments, algorithmic transparency, and independent oversight for very large online platforms.
verifiedreviewed 2026-07-18
- Sources (1)
“The DSA imposes additional obligations on very large online platforms and search engines, including systemic risk assessments, independent audits, and transparency of recommendation algorithms.”
EUR-Lex: Regulation (EU) 2022/2065 — Digital Services Actdirect
- Counterpoints (1)
The DSA’s effectiveness depends on enforcement capacity and member-state coordination; it is still early in implementation.
The UK Online Safety Act and Australia’s eSafety model introduce duty-of-care or safety-standard approaches that India has not yet adopted for attention-economy harms.
verifiedreviewed 2026-07-18
- Sources (2)
“The UK Online Safety Act 2023 imposes duties on regulated services to protect users from illegal content and content harmful to children, enforced by Ofcom.”
UK Government: Online Safety Act 2023 Explainerdirect“Australia’s Online Safety Act 2021 gives the eSafety Commissioner powers to set expectations, issue takedown notices, and investigate platforms for failing to protect users.”
eSafety Commissioner: Online Safety Act 2021 Fact Sheetdirect
- Counterpoints (1)
Both models face free-speech and over-reach concerns, and their scope does not automatically cover lawful-but-extractive design either.
Regulation is better at removing illegal content and protecting personal data than at changing the engagement metrics, ad-supported business models, and default designs that drive attention extraction.
verifiedreviewed 2026-07-18
- Sources (2)
“Analysis of platform transparency reports shows a sharp increase in content takedowns in India after the IT Rules and Grievance Appellate Committees took effect.”
SFLC.in: Data Analysis of Meta, X, and ShareChat on Content Takedowndirect“Even the more expansive DSA focuses largely on illegal content, transparency, and systemic risk rather than prescribing specific substance-oriented design defaults.”
EUR-Lex: Regulation (EU) 2022/2065 — Digital Services Actindirect
- Counterpoints (1)
Some design-related obligations exist, such as bans on dark patterns in the DSA and proposed age-appropriate design in other jurisdictions; the line between harm and design is not fixed.
Effective protection of attention and promotion of substance likely requires regulation plus design changes, alternative business models, public pressure, and internal platform accountability.
verifiedreviewed 2026-07-18
- Sources (2)
“The Oversight Board’s limited case share from Central and South Asia highlights the need for stronger internal and external accountability mechanisms in large user markets.”
Meta Oversight Board: 2023 Annual Report Shows Board’s Impact on Metaindirect“The DSA’s researcher data-access and transparency provisions are designed to enable public and civic pressure, suggesting regulation works best alongside external scrutiny.”
EUR-Lex: Regulation (EU) 2022/2065 — Digital Services Actindirect
- Counterpoints (1)
It is possible that a sufficiently prescriptive regulatory regime could change design directly; no major jurisdiction has yet tested that approach at scale.
Review recordHow this was madeShow detailsHide details
Created 2026-07-05 by human. Policy: policy:default v1.0.0.
Researched, drafted, and structured with AI agents; approved for publication by a human reviewer.
✓ Approved hash matches current article
Reviews
- humanapproved2026-07-05
Scope: thesis, claims, tone, privacy, sources
contentHash:
f27b70499ea313a6…Human author approved publication.
- humanapproved2026-07-18
Scope: article
contentHash:
d521b4881a4842b9…Re-approved by maintainer after the meta#61 P2 series migration (hardcoded kicker strip + arc reorder; no prose change beyond the kicker line; issue #124 instruction).
Machine-readable files
The same points, sources, and relationships are also available as structured files for agents and tools. The JSON follows thepublication record schema.