Every country that has built a large digital population eventually faces the same question: what should platforms be required to do, and what is left to users, markets, and design? India is no exception. It now has nearly 900 million internet users, foreign platforms that collect billions of dollars in domestic advertising, and a legal framework that is still catching up with the speed and scale of attention extraction.

The good news is that the framework is no longer blank. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, impose due diligence on intermediaries. The Digital Personal Data Protection Act, 2023, creates rights over personal data. Other countries offer templates: the European Union’s Digital Services Act, the United Kingdom’s Online Safety Act, and Australia’s Online Safety Act all go further in some respects. The question is not whether regulation matters; it is what regulation can and cannot do.

Point C1 Regulation can set a floor for platform accountability by mandating transparency, due process, and data protection, but it cannot by itself make substance-oriented design the default.

What India’s Rules Cover

The IT Rules 2021 require all intermediaries to follow a code of due diligence: publish terms of use, appoint grievance officers, and act on court or government orders. Significant social media intermediaries—those above a user threshold—face additional obligations: appoint compliance and nodal contact officers resident in India, publish monthly compliance reports, and enable user grievance redressal, including appeals to government-appointed Grievance Appellate Committees.

Point C2 The IT Rules 2021 focus on content takedown, user grievances, and traceability rather than on the design defaults—autoplay, infinite scroll, algorithmic ranking—that drive attention extraction.

The Digital Personal Data Protection Act, 2023, shifts the frame from content to data. It defines data principals and data fiduciaries, requires notice and consent for data processing, grants rights of access, correction, erasure, and grievance redressal, and provides for a Data Protection Board and penalties for breaches.

Point C3 The DPDP Act 2023 establishes individual rights over digital personal data; the DPDP Rules, 2025, and the Data Protection Board became operational in late 2025, but phased implementation and enforcement capacity are still unfolding.

Both laws are real progress compared with the earlier patchwork. They create obligations, penalties, and institutions. But neither directly addresses the business model that converts attention into advertising revenue, nor the design patterns that make extraction frictionless.

How the Global Floors Compare

The EU Digital Services Act is the most comprehensive of the recent frameworks. It applies tiered obligations to intermediary services, online platforms, and very large online platforms. It requires risk assessments, independent audits, algorithmic transparency, data access for researchers, and a ban on dark patterns that distort user choice. Penalties can reach 6% of global annual turnover.

Feature India (IT Rules 2021 + DPDP Act 2023) EU (DSA) UK (OSA 2023) Australia (OSA 2021)
Primary focus Content takedown, user grievances, data protection Illegal content, systemic risk, transparency Duty of care: illegal and child-harm content Online safety, takedown powers, standards
Algorithmic transparency Limited Required for very large platforms Required for risk assessment Limited
Independent oversight Grievance Appellate Committees; Data Protection Board operational Digital Services Coordinators + Commission Ofcom eSafety Commissioner
Duty of care / systemic risk Not explicit Explicit for very large platforms Explicit for regulated services Implicit via safety expectations
Maximum penalties Fines under IT Act; DPDP penalties up to ₹250 crore Up to 6% global turnover Up to 10% global revenue + senior manager liability Civil penalties and infringement notices

Sources: MeitY IT Rules 2021 and DPDP Act 2023; EU Regulation 2022/2065; UK Online Safety Act 2023; Australia Online Safety Act 2021. The comparison is illustrative and not exhaustive.

Point C4 The EU Digital Services Act goes further than India’s current framework by requiring systemic risk assessments, algorithmic transparency, and independent oversight for very large online platforms.

The UK Online Safety Act 2023 takes a different path. It imposes a duty of care on regulated services to protect users, especially children, from illegal and harmful content. Ofcom sets codes of practice, and failure to comply can lead to fines of up to 10% of global revenue and, in serious cases, criminal liability for senior managers.

Australia’s Online Safety Act 2021 empowers the eSafety Commissioner, an independent regulator, to issue takedown notices for unlawful content, set basic online safety expectations, and investigate platforms that fail to protect users. It also includes cyberbullying and image-based abuse schemes.

Point C5 The UK Online Safety Act and Australia’s eSafety model introduce duty-of-care or safety-standard approaches that India has not yet adopted for attention-economy harms.

No framework is perfect. The DSA’s effectiveness depends on enforcement by the European Commission and member-state coordinators. The UK OSA’s definition of harm has drawn free-speech concerns. Australia’s system is complaints-driven and resource-constrained. But they share one feature India’s current framework lacks: an explicit mandate to assess and mitigate systemic risks, including those arising from recommendation algorithms and engagement metrics.

What Regulation Can Do: Harms, Not Defaults

Regulation is good at a particular class of problems: clearly defined harms with identifiable victims and enforceable penalties. Child sexual abuse material, non-consensual intimate images, terrorist content, and incitement to violence fall into this class. So do certain data breaches and opaque data practices. The IT Rules, DPDP Act, and global counterparts all address these harms.

Government takedown activity in India has grown sharply since the IT Rules took effect. A 2025 analysis by the Software Freedom Law Centre found that platforms have become “more trigger-happy” with removals, especially after the Grievance Appellate Committees began operating in early 2023. Meta’s bi-annual transparency reports show large and rising volumes of content actioned at the government’s request.

Point C6 Regulation is better at removing illegal content and protecting personal data than at changing the engagement metrics, ad-supported business models, and default designs that drive attention extraction.

This matters because attention extraction is not, in most cases, illegal. A feed that ranks by engagement, an autoplaying video, a streak notification, or a red-dot badge does not violate the IT Rules or the DPDP Act. It may be psychologically powerful, economically consequential, and socially costly, but it is largely lawful. Regulation can punish the worst outcomes; it cannot easily compel a better default.

The Enforcement Gap

Even within its existing scope, Indian regulation faces an enforcement gap. The DPDP Act’s Data Protection Board became operational in late 2025, but its caseload, staffing, and effectiveness are still unfolding. The Grievance Appellate Committees handle only a tiny fraction of the grievances raised against platforms. The IT Rules require compliance officers and reports, but they do not require platforms to disclose how their recommendation systems work or to test them for systemic risk.

Accountability mechanisms are also thin. Meta’s Oversight Board, an external appeals body, receives cases from around the world, but Central and South Asia account for a small share of its docket relative to the region’s share of Meta’s user base. This is a proxy, not proof, of underinvestment in local-language safety and dispute resolution.

None of this means regulation is futile. It means the floor is lower than it looks. A law on paper is not enforcement in practice. A takedown process is not transparency. A grievance officer is not algorithmic accountability.

Beyond the Floor: Design and Business Models

If regulation is a floor, what builds the ceiling? The answer is almost everything else: product design, metrics, business models, internal governance, public pressure, and competition.

A platform can comply with the IT Rules and still optimise for watch time. It can honour DPDP consent requirements and still harvest micro-behavioural signals to personalise feeds. It can publish a transparency report and still refuse to share data with independent researchers. Compliance is necessary; it is not sufficient.

Point C7 Effective protection of attention and promotion of substance likely requires regulation plus design changes, alternative business models, public pressure, and internal platform accountability.

This is why the rest of this arc matters. Friction, chronological feeds, and user-chosen algorithms are design changes. Subscriptions, patronage, and public funding are business-model changes. Whistleblowers, researchers, journalists, and civil society create external pressure. Employees and shareholders create internal pressure. Regulation can enable or accelerate all of these, but it cannot replace them.

Sources and Method

This article draws on primary legal texts and official explanations: the Indian IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 as notified by MeitY and explained in a PIB FAQ; the Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, as published by MeitY; the EU Digital Services Act (Regulation 2022/2065); the UK Online Safety Act 2023; and Australia’s Online Safety Act 2021 and eSafety Commissioner guidance. It also uses the Software Freedom Law Centre’s 2025 analysis of Meta, X, and ShareChat takedown data, and Meta Oversight Board reports as proxies for platform accountability. Where implementation details are still unfolding, the text notes the uncertainty.

Open Questions

  • Should Indian law explicitly require algorithmic risk assessments for large platforms?
  • Can a duty-of-care model be adapted to India’s constitutional framework without over-broad censorship?
  • What design changes could regulators mandate without becoming paternalistic?
  • How should platform transparency requirements distinguish between illegal content and lawful-but-extractive design?
  • What institutions does India need to enforce attention-economy rules at the scale of its user base?
Article guideImportant points and sources7 pointsShow guideHide guide
  1. C001core · high · verifiedRegulation can set a floor for platform accountability by mandating transparency, due process, and data protection, but it cannot by itself make substance-oriented design the default.
  2. C002core · high · verifiedThe IT Rules 2021 focus on content takedown, user grievances, and traceability rather than on the design defaults—autoplay, infinite scroll, algorithmic ranking—that drive attention extraction.
  3. C003core · medium-high · verifiedThe DPDP Act 2023 establishes individual rights over digital personal data; the DPDP Rules, 2025, and the Data Protection Board became operational in late 2025, but phased implementation and enforcement capacity are still unfolding.
  4. C004landscape · high · verifiedThe EU Digital Services Act goes further than India’s current framework by requiring systemic risk assessments, algorithmic transparency, and independent oversight for very large online platforms.
  5. C005landscape · high · verifiedThe UK Online Safety Act and Australia’s eSafety model introduce duty-of-care or safety-standard approaches that India has not yet adopted for attention-economy harms.
  6. C006core · medium-high · verifiedRegulation is better at removing illegal content and protecting personal data than at changing the engagement metrics, ad-supported business models, and default designs that drive attention extraction.
  7. C007framing · medium-high · verifiedEffective protection of attention and promotion of substance likely requires regulation plus design changes, alternative business models, public pressure, and internal platform accountability.
SourcesSources used9 sourcesShow sourcesHide sources

Look closer

Sources and notes

Open detailsClose details

These notes collect the sources, counterpoints, and review status behind the article's important points. Read the essay first; open this when you want to check something.

Confidence reflects how strongly the sources support the point (low / medium / high). Status describes the point's role (e.g., core, argument, landscape). Sources link to supporting material;counterpoints note boundary conditions or conflicting findings.

C001highcore

Regulation can set a floor for platform accountability by mandating transparency, due process, and data protection, but it cannot by itself make substance-oriented design the default.

verifiedreviewed 2026-07-18

Sources (2)
Counterpoints (1)
  • Some jurisdictions, such as the EU under the DSA, are experimenting with systemic-risk obligations that may indirectly affect design defaults; the boundary between floor and design is evolving.

C002highcore

The IT Rules 2021 focus on content takedown, user grievances, and traceability rather than on the design defaults—autoplay, infinite scroll, algorithmic ranking—that drive attention extraction.

verifiedreviewed 2026-07-18

Sources (2)
Counterpoints (1)
  • Amendments to the IT Rules have added deepfake labelling and senior-official takedown authorisation, showing incremental expansion into design-adjacent obligations.

C003medium-highcore

The DPDP Act 2023 establishes individual rights over digital personal data; the DPDP Rules, 2025, and the Data Protection Board became operational in late 2025, but phased implementation and enforcement capacity are still unfolding.

verifiedreviewed 2026-07-18

Sources (2)
Counterpoints (1)
  • Enforcement capacity, staffing, and early Board caseload remain uncertain; compliance timelines for different entities are phased.

C004highlandscape

The EU Digital Services Act goes further than India’s current framework by requiring systemic risk assessments, algorithmic transparency, and independent oversight for very large online platforms.

verifiedreviewed 2026-07-18

Sources (1)
Counterpoints (1)
  • The DSA’s effectiveness depends on enforcement capacity and member-state coordination; it is still early in implementation.

C005highlandscape

The UK Online Safety Act and Australia’s eSafety model introduce duty-of-care or safety-standard approaches that India has not yet adopted for attention-economy harms.

verifiedreviewed 2026-07-18

Sources (2)
Counterpoints (1)
  • Both models face free-speech and over-reach concerns, and their scope does not automatically cover lawful-but-extractive design either.

C006medium-highcore

Regulation is better at removing illegal content and protecting personal data than at changing the engagement metrics, ad-supported business models, and default designs that drive attention extraction.

verifiedreviewed 2026-07-18

Sources (2)
Counterpoints (1)
  • Some design-related obligations exist, such as bans on dark patterns in the DSA and proposed age-appropriate design in other jurisdictions; the line between harm and design is not fixed.

C007medium-highframing

Effective protection of attention and promotion of substance likely requires regulation plus design changes, alternative business models, public pressure, and internal platform accountability.

verifiedreviewed 2026-07-18

Sources (2)
Counterpoints (1)
  • It is possible that a sufficiently prescriptive regulatory regime could change design directly; no major jurisdiction has yet tested that approach at scale.

Review recordHow this was madeShow detailsHide details

Created 2026-07-05 by human. Policy: policy:default v1.0.0.

Researched, drafted, and structured with AI agents; approved for publication by a human reviewer.

✓ Approved hash matches current article

Reviews

  • humanapproved2026-07-05

    Scope: thesis, claims, tone, privacy, sources

    contentHash: f27b70499ea313a6…

    Human author approved publication.

  • humanapproved2026-07-18

    Scope: article

    contentHash: d521b4881a4842b9…

    Re-approved by maintainer after the meta#61 P2 series migration (hardcoded kicker strip + arc reorder; no prose change beyond the kicker line; issue #124 instruction).