Tag: cyberlaw

Liabilities of WhatsApp group admins: A critical legal analysis from Indian legal perspectives by Dr.Debarati Halder

picture courtesy : Internet

Over the years we have witnessed gradual development of internet and digital communication technology and rapid over flow of users of the same who may or may not know the digital socio-legal culture. This internet and digital communication technology that I have mentioned here, primary includes WhatsApp. When this platform started becoming popular in India since 2014-15 onwards, it also became popular platform to form opinions, disseminate news including fake news, harassing remarks for group members and other individuals who may not be group members but may be known to one or other group members. Soon Indian users could get connected with users from other jurisdictions through WhatsApp and the groups formed on the basis of WhatsApp became better connected than networks of people connected on Offline. Consider groups like law teachers’ groups, or groups formed on the basis of common interest like terrace gardeners, animal lovers, theological groups, chartered public vehicle commuters’ groups, health service providers groups etc.: members did not necessarily stay in the same locality, did not work in the same organization or may not speak the same vernacular language. But what bonded them was their common interest. This was some thing more popular than Facebook which was ruling internet during 2012-18 era. Slowly WhatsApp became more popular with specific service people like the IPS or IAS association (non official groups) and judicial officers’ groups. The popularity grew because individuals could actually control who would view their opinion and images that may have been ‘consensually’ shared by the members. It must not be however forgotten that WhatsApp has also notoriously become a platform for several online crimes including crimes against State, against individuals, cybercrimes against women[1] and children,[2] economic crimes,[3] cyber terrorism[4] etc.

Understanding stronger confidentiality setup of WhatsApp, soon workplaces and schools also started their own WhatsApp groups. Presently almost all organizations, schools and educational institutes have their respective division /unit/team-based WhatsApp groups. Some of these groups are moderated and monitored by senior members of the organization or the HR department member or the creator of the group or teachers (in case they are the creators/members of the said groups). The bright side of the story is, people can get the necessary information in their hand phones (which may include WhatsApp services) and they may not necessarily look into their mails unless it is for immediate verification necessity.  Mails now have become more official and WhatsApp groups are more personal. The negative aspect is quick circulation of offensive, harassing and unwanted contents.

Here comes the question of liabilities of three groups especially regarding creation, publication and circulation of offensive and unwanted contents. These liabilities may vary according to the age of the creators/publishers/circulators and position of the creators/publishers/circulators. ‘Position’ here necessarily means the website who is hosting the communication, the admin who is moderating or who may have created the group and general members who may be the creators/publishers/circulators of the content.  This three groups are as follows:

Let me first start with the website. WhatsApp as the web platform of the communications or Facebook as the parent company facilitating WhatsApp, may seek their excuse from any legal tangle in case of creation, circulation, publication of any offensive contents by virtue of Due Diligence clause which they exercise in almost cases of creation/circulation/publication of contents which are offensive. For this purpose, we need to understand the Indian version of Due Diligence law which can be found in S.79 of the Information Technology Act, 2000(amended in2008); the first two subclauses address the points which may be used by the websites. To summaries:

Websites or intermediaries who provide services including web hosting services, search engines etc (as per S.(w) of the Information technology Act, 2000(amended in 2008), may not be liable for any third-party activities carried out on their web platforms if such activity (which includes creation/publication/circulation etc. of any offensive, harassing etc. contents) is not initiated by the website, the website dies not select the receiver of the transmission and the website does not select or modify the information contained in the transmission. The website or the intermediary will also be excused from the third party liability in case the same has practiced due diligence as per the laws, rules and guidance as has been mandated by the Indian government. These Rules are mentioned in Information Technology (Intermediaries guidelines) Rules, 2011, which have further been suggested for amendment. [5] As such, these Rules include the following responsibilities of the intermediary or the web platform:

  • Publishing of Rules, regulations, privacy policies and user agreements which will clearly make the user understand that posting/transmission of/uploading/modification  etc of contents which may be grossly harmful, harassing, blasphemous, defamatory, obscene, pornographic, paedophilic, libellous, invasive of another’s privacy, hateful, or racially, ethnically objectionable, disparaging, relating or encouraging money laundering or gambling, or otherwise unlawful in any manner whatever;  harm minors in any way;  infringes any patent, trademark, copyright or other proprietary rights;  violates any law for the time being in force;  deceives or misleads the addressee about the origin of such messages or communicates any information which is grossly offensive or menacing in nature; impersonates another person;  contains software viruses or any other computer code, files or programs designed to interrupt, destroy or limit the functionality of any computer resource; threatens the unity, integrity, defence, security or sovereignty of India, friendly relations with foreign states, or public order, or causes incitement to the commission of any cognisable offence or prevents investigation of any offence or is insulting any other nation. threatens public health or safety; promotion of cigarettes or any other tobacco products or consumption of intoxicant including alcohol and Electronic Nicotine Delivery System (ENDS) & like products that enable nicotine delivery except for the purpose & in the manner and to the extent, as may be approved under the Drugs and Cosmetics Act, 1940 and Rules made thereunder; (k) threatens critical information infrastructure.
  • Provide all support to the criminal justice machinery to disclose incidences of cyber security, the identity and all other relevant details of the harasser/originator of the offensive content.
  • Not to host/transmit/publish etc any information which the website management known to be illegal and offensive.
  • Provide periodic update on the policy of the web company related to users liabilities, rights and duties etc.
  • Take down reported content within considerable time of maximum 24 hours (as the draft Intermediary Guidelines (Amendment) Rules, 2018 indicates). [6]

In short, the web companies, intermediaries may not be directly liable for WhatsApp mess-ups that may be done by the individual users.

The second party which may attract the liability for publication/creation/circulation of any offensive content on the platform is the group admin. Now, let us first understand who are called as ‘group admins’:  WhatsApp provides certain features especially for group chats and this includes monitoring of the group by designated persons who are known as admins. Admins may not necessarily be the creators of the group. However, the latter may always remain as admin in spite of creation of multiple admins by him/her. Admins may have the power and authority to include and exclude members, block members, restrict the publication of comments[7] and create group policies which may be used to restrict a particular member/s in case of violation of the same.  Indian courts have in numbers of occasion, held that group admins may not be held liable for the activities of the members of the group in case the said admin had shown due diligence to restrict publication/circulation/creation of offensive comments.[8] This due diligence is however derived from the understanding of criminal law sanctions mixed with tortuous liabilities. For example, consider the followings:

  • If the group admin has not been made group admin consensually and he does not know the subject of discussion of the group, he may have a very narrow defence of being misled  by other admins/creator who forced him to join them in criminal activities like creation/publication/circulation of offensive contents which violate the existing laws of the Land.
  • If the group admin himself had not created/circulated any offensive content and had warned any user for not sharing/posting etc any content which is offensive, he may not be made liable for creating/sharing contents which may be offensive under any law if any member had even for some time (when the admin was not expected to watch/monitor the group) had posted/circulated some offensive content. But in such case, if the content falls in the category of child sexual abuse material which may be categorised under S.67B of the Information Technology Act, 2000(amended in 2008) or POCSO Act, the admin may not avail any excuse.
  • In case the group admin is a child, the question becomes tricky. If the group is specifically made by minors, the police, the prosecution and the court have to see who may have provided the basic assistance in accessing the web platform and the contents (including the offensive contents). Necessarily in such cases, courts may have to use the principles of vicarious liability because a child may not be eligible to own a SIM card unless an adult provides him the same. Here, the basic understandings of contract laws and age of maturity may be applied.[9] Now, let us see the case of the WhatsApp group of students of an elite school in Mumbai where minor students were discussing about child sexual abuse of their own female classmates:[10] parents may be made vicariously liable in such case, which actually did not take place, may be because here the parents of the accused children themselves alerted the school and restricted further violation of rights of those children who were targeted for the sexual fantasy of the adolescent boys. But here one needs to check whether personal information including images of the ‘victim children’ were disseminated unauthorizedly or not, or whether it was restricted only to the use of names. In both cases POCSO Act may be applied (in the latter case , Ss.11 (sexual harassment), 13(use of children for pornographic purposes) and S.14 (punishment for using children for pornographic purposes) of the POCSO Act may be narrowly applied.

However, if the group admin/s knowingly allow creation/circulation /publication of posts which may be offensive in nature, they may not get any excuse from the clutches law specifically made to punish the commitment of such acts like creation/circulation/dissemination of obscene images (S.67), sexually explicit contents (S.67A), voyeurism and sharing non-consensual images (S.66E of the Information Technology Act, 2000(amended in 2008) and S.354C of the Indian Penal Code, defamation (S.499, 500 Indian Penal Code), sharing information which has been restricted as seditious material under S.124A IPC or any other law which may restrict freedom of speech in the line of Article 19(2) of the Constitution of India, all of which may be read together with Ss.107 and 108 of the Indian Penal Code and S.84B of the Information Technology Act, 2000(amended din 2008)( laws related to abetment of offence ).

            Coming to the liability of the third group of users of WhatsApp, it may be seen that if a user/user create/publish/circulate any content which is offensive in nature, they may be liable as per the respective legal sanctions. However, the act of forwarding any content has also been considered as within the scope of defamation laws (under S.499/500 IPC ) or in case of online harassment of women and children, within the meaning of different kinds of offences recognised by law including voyeurism, stalking, non-consensual image sharing, indecent representation of women, child sexual abuse, grooming etc.

But the question larks on the issue of machine and artificial intelligence, which may make the admins responsible in case they may not be aware about the usage. For example, if the admin is a new user or not accustomed with the privacy and security features of WhatsApp, he may not be able to restrict certain ‘posts’ which may be published because of the machine intelligence: this may include certain words which the phone may suggest presuming the first few alphabets. He may neither be able to restrict a member which may have been suggested by the computer system of the platform and the device. Further, he might also not be able to remove certain posts which may have surfaced in the group due to resharing or forwarding by other members. Here, the group admin’s liability must be seen exclusively. Websites or intermediaries however would not be liable by virtue of the proviso clause of Rule 3 of the  Intermediary Guidelines Rules, 2011 (and also Amended draft version of 2018), which says  “……………….the following actions by an intermediary shall not amount to hosting, publishing, editing or storing of any such information as specified in subrule(2): (a) temporary or transient or intermediate storage of information automatically within the computer resource as an intrinsic feature of such computer resource, involving no exercise of any human editorial control, for onward transmission or communication to another computer resource; (b) removal of access to any information, data or communication link by an intermediary after such information, data or communication link comes to the actual knowledge of a person authorised by the intermediary pursuant to any order or direction as per the provisions of the Act.”           

As may be understood from the above, WhatsApp group admins therefore may not always claim to be immuned especially when they were aware of the group activities, they had not practiced due diligence from their side and they had published or forwarded offensive contents themselves for the wider circulation of the same.    


*Prof(Dr)Debarati Halder, LL.B.,  M.L., Ph.D(Law)(NLSIU) is the Managing Director (Hon) of Centre for Cyber Victim Counselling (www.cybervictims.org) .  She can be reached @debaratihalder@gmail.com

[1] See Halder D., & Jaishankar, K (2016.) Cyber crimes against women in India.

New Delhi: SAGE Publications. ISBN: 9789385985775 for understanding types of cyber crimes against women and laws.

[2] See Halder, D. (2018). Child Sexual Abuse and Protection Laws in India. New

Delhi: SAGE Publications. ISBN: 9789352806843, Halder D., & Jaishankar K. (2014). Patterns of Sexual Victimization of Children and Women in the Multipurpose Social Networking Sites. In C. Marcum and G. Higgins (Eds.), Social Networking as a Criminal Enterprise (pp. 129-143). Boca Raton, FL, USA: CRC Press, Taylor and Francis Group. ISBN 978-1-466-589797 for more understanding on types of cyber crimes against children.

[3] See for example, Kurowski, S., (2014). Using a whatsapp vulnerability for profiling individuals. In: Hühnlein, D. & Roßnagel, H. (Hrsg.), Open Identity Summit 2014. Bonn: Gesellschaft für Informatik e.V.. (S. 140-146). Available @ https://dl.gi.de/handle/20.500.12116/2633 Accesed on 21.01.2020

[4] See for example, Broadhurst, Roderic and Woodford-Smith, Hannah and Maxim, Donald and Sabol, Bianca and Orlando, Stephanie and Chapman-Schmidt, Ben and Alazab, Mamoun, Cyber Terrorism: Research Review: Research Report of the Australian National University Cybercrime Observatory for the Korean Institute of Criminology (June 30, 2017). Available at SSRN: https://ssrn.com/abstract=2984101 or http://dx.doi.org/10.2139/ssrn.2984101 Accessed on 20.01.2020

[5] By way of Intermediary Guidelines (Amendment) Rules, 2018

[6] The Intermediary Guidelines (Amendment) Rules, 2018 also mentions that if the intermediary has more than 50 fifty lakh users in India or is in the list of intermediaries specifically notified by the government of India, it shall:

(i) be a company incorporated under the Companies Act, 1956 or the Companies Act,2013;

(ii) have a permanent registered office in India with physical address; and

(iii) Appoint in India, a nodal person of contact and alternate senior designated

functionary, for 24×7 coordination with law enforcement agencies and officers to

ensure compliance to their orders/requisitions made in accordance with provisions

[7] For more understanding, see https://faq.whatsapp.com/en/android/26000118/?category=5245251 Accessed on 12.01.2020

[8] For example, see Ashish Bhalla vs Suresh Chawdhary & others, 2016. Accessed from http://delhihighcourt.nic.in/dhcqrydisp_o.asp?pn=242183&yr=2016 on 21.01.2020

[9] For understanding this, we need to see S.11 of the Indian Contract Act, which says minors, persons of unsound mind and persons disqualified by law may not be able to enter into any agreement.

[10] See India Today Webdesk. Schoolboys at posh Mumbai school talk about raping classmates, ‘gang bang’ in horrific WhatsApp chats. Available @https://www.indiatoday.in/india/story/mumbai-ib-school-students-whatsapp-chat-horror-1629343-2019-12-18 . Accessed on 21.01.2020

Gender and Internet : Web magazine for Cyber Law for women News Update for November 1st-25th, 2019

#endviolenceagainstwomen
https://medium.com/@UN_Women/when-it-comes-to-consent-there-are-no-blurred-lines-1dfd02cebe1

Iraqi women suffer cyber violence against women including sextortion, revenge porn, gender bullying and trolling, stalking etc as there are apparently no law to deter such offences and courts are not yet accustomed to see online crimes against women
https://www.news18.com/news/world/revenge-porn-sextortion-spreads-in-iraq-as-fear-of-honour-killing-death-sentence-daunt-women-2393499.html

New York Mother of female toddler born with Harlequin Ichthyosis, who tries to educate people through online platforms including Facebook, Instagram etc, gets severely bullied and harassed by another woman for a over an year. The harasser is now arrested.
https://kfiam640.iheart.com/content/2019-11-10-long-island-woman-arrested-for-cyber-bullying-toddler-with-rare-disorder/?fbclid=IwAR07iXTvo5xvcwggS-bY1tq3MiLfkdfhSy0EGzZiJ_eb2OhrqMVfg4fp3jE

Check old devices before selling/handing them over : Pakistani model/singer suffers privacy infringement as her private videos get leaked allegedly when she sold her old mobile phone device. Her nude images land in international porn sites.
https://www.desiblitz.com/content/pakistan-model-samara-chaudhrys-private-videos-leaked

Teen girls suffer silently as intermediaries have no answer against continued online sexual abuse of girls carried on through online platforms.
https://www.nytimes.com/interactive/2019/11/09/us/internet-child-sex-abuse.html?smid=fb-share&fbclid=IwAR0PldPtMV_qe-IAKzFx6xfhhV6n6_OtRndIlf0yAAm4ZKRPpf_ssNN-fa4&mtrref=www.facebook.com&gwh=AB89B80FF8D1630E35B974D77DE83488&gwt=pay&assetType=REGIWALL

Dublin man who withdrew from outside world and became a vigorous troll, gets jail term for 3 years for stalking and trolling 6 women who were journalists, authors. Prosecution and the court emphasized need for rehabilitation of the troll.
https://www.rte.ie/news/courts/2019/1114/1090892-harassment-case/

After pilots turning into peeping toms in the lavatory of aircraft, it is now a male nurse in Malta who was caught by the police for similar offence: female medical professionals become victim of voyeurism and privacy infringement resulting in creation of non consensual porn materials due to spycam installed in the washroom by male nurse.
https://www.maltatoday.com.mt/news/court_and_police/98580/nurse_who_spied_on_women_with_bathroom_cam_gets_threeyear_probation_and_5500_fine_#.XdvUougzZPY

Online job offers are not always legal especially for women: woman admits of being in a paid job which includes online sexual abuse of teens through Skype. She is charged with four counts for sexual abuse of children in UK.
https://www.unionjournalism.com/2019/11/11/uk-woman-was-paid-to-sexually-abuse-teen-girl-for-3-years-through-video-call-she-now-admits-of-her-crime/

YouTube, YouTubers and violation of privacy of women and children: The drama unfolds by Dr.Debarati Halder

picture credit : Internet

In recent years YouTube has won millions of hearts in India as a social media platform especially among women. This is because unlike other social media websites, YouTube has provided a platform to earn money based upon views and subscribers. Contents uploaded by users may be varied: it can be home decor, power point presentations of simplified versions of undergraduate subjects, subject lectures by professional teachers or amateur subject experts, cooking recipes, Do It Yourself (DIYs), home organisations, daily routines of home makers, technological solutions, how to do stuffs etc . Several women have used YouTube to earn money generated through the revenue that YouTube promises once the user can reach some criteria like getting 1000 subscribers or 4000 watch hours etc. [1] YouTube however would not lead the user to create contents that may earn more watch hours or subscribers. Users may go for market survey to understand which sorts of videos may attract more views, ,more subscribers etc. mostly new users including men and women may try to create videos on anything that they feel proper to share to the world. YouGTube , like Facebook and Instagram has features for allowing users to create videos for private sharing. This enables the users to share the video which may be watched only by those whom the creator chooses. The users may however go for wide circulation of their contents by not only making the videos public, but also by going live  whereby the users may directly communicate with their subscribers or may share information while live.  Even though going Live may be a feature specifically for improving the relationship between the user and his/her subscribers, live videos can be watched by the world wide audience even if they are not subscribers to that particular user.   Here, YouTube may not play a vital role to restrict uploading and sharing the contents unless the subscribers or  viewers may flag the content as inappropriate.  In short, YouTube may actually provide a wide platform to share anything including bullying videos, mashed up videos, child and woman abuse videos, birthing videos, adult sexual interaction videos and so on. While the adult sexual videos and birthing videos may not be universally accessible unless the user logs in to his/her YouTube accounts, other sorts of videos are accessible to all irrespective of age. YouTube however uses the due diligence clause to escape from any third party liability by providing notification which restricts children from viewing adult sexual contents or violent contents which may traumatise children. Hardly this  has any practical implication because children may access these videos by using email ids which may be created on the basis of fake age , or may even log in through their parents’ or friends’ email /YouTube ids.

My attention here is however attracted to the contents shared by YouTubers: I have been an avid watcher of YouTube since many years now. I have been following the changing trends of users in uploading the contents. Earlier it was more on creating mashed up videos which may have the potentials of violating the copyrights. Such videos have also been silently encouraged by actors, singers and producers because these actually publicise their work even though it may violate the laws. [2] But slowly, the content creators, especially women started becoming reviewers of products on YouTube as well. This included using of cosmetics, kitchen wares organisers etc that may be shown in the daily routine videos, home organisation videos or make up tutorials.[3]   Users not only get views and subscribers as may be needed for fulfilling the YouTube monetising criteria, they may also be connected with the brands manufacturing the products or dealers of the products who may wish to showcase their products through these non-professional videos. Several urban and rural women home makers have actually benefitted from this: consider Youtubers like Radhika Real Vlogs,[4] or simplelivingwithringlejain[5] who may be rural homemakers, but may have made a moderate to comfortable living because of their YouTube videos advertising about different brands including retailer brands.  Nonetheless, these YouTubers may also be victims of bullying and trolling for the quality of their videos, their pronunciation, lifestyle and even house decorations.

While these women may have made a landmark professional/personal achievement because of YouTube, they may unknowingly violate privacy of their own children or even spouses or other family members as they may be showing and informing the worldwide audience about their family members who may not may consent for such wide distribution of images of themselves. These YouTube videos may also be the subject matter of bullying and ridiculing the children of such YouTubers since these may stay on worldwide web for long time. YouTube videos may also create severe domestic violence for several reasons which include live fights between spouses which may be captured by third party YouTubers for fun and uploaded and circulated for getting more views; or airing of grievances by women YouTubers against the other spouses, without knowing the far-reaching consequences etc. These videos may attract huge views and opinions, comments in the nature of cyber bullying and also trolling targeting the YouTuber concerned or supporters of the same. Consider the case of two specific youtubers from Delhi, who are spouses in real life : the wife is a senior YouTuber whereas the husband is a recent Youtuber: They had severe altercations and started living apart. But this was not enough: both used YouTube to throw insults and humiliating words to each other and their teen daughter was allegedly dragged in between. The recent reports suggested that the teenager girl who  was staying with her father for couple of months after the separation, was beaten by the latter while on live and her t-shirt was torn in a manner which would show her inner wares.[6] The girl was beaten because she wanted to visit her mother. This video became viral as several supporters of the wife started showing the clippings through their own channels. Some had also informed ChildLine and the police who had rescued the teenager and sent her to her maternal grandmother.[7]  There are several other YouTubers who started discussing about incident using the profile name of the husband wife duo.[8] While the news report published in the local news media suggested that the teenager was often beaten by both the parents when they were drunk and she was forced to come on live which she refused many times, the news clipping did not mention about the name of the girl and that of her parents as S.74 of the Juvenile Justice Care and protection Act, 2015 prohibits publication of the identity of the child in need of care and protection or child in conflict with law. The provision reads as below:

S.74. Prohibition of publication of name, etc., of juvenile in conflict with law or child in need of care and protection involved in any proceeding under the Act.-1. No report in any newspaper, magazine, news-sheet or visual media of any inquiry regarding a juvenile in conflict with law or a child in need of care and protection under this Act shall disclose the name, address or school or any other particulars calculated to lead to the identification of the juvenile or child nor shall any picture of any such juvenile or child be published: Provided that for reasons to be recorded in writing, the authority holding the inquiry may permit such disclosure, if in its opinion such disclosure is in the interest of the juvenile or the child. 2. Any person who contravenes the provisions of sub-section (1), shall be liable to a penalty which may extend to twenty-five thousand rupees.

Now, let us understand the scope of this provision in the light of this particular case: the first subsection prohibits any report including news report, inquiry etc from disclosing the name, information etc of the concerned child. The second proviso extends the scope to ‘anyone’ who may contravene the prohibitory scope of S.74. Seen from the perspective of electronic media and the concept of citizen journalism, which gives every one right to share information, the term ‘anyone’ may literally include anyone including the good Samaritans who may have wanted to alert the concerned authorities, share their opinion against such acts of women and child abuse. Further, note the words “any other particulars calculated to lead to the identification of the juvenile or child nor shall any picture of any such juvenile or child be published” mentioned in the first sub clause. This may include the name of the concerned child and names of the parents. But apparently, this provision became a just a paper tiger in this case because those who had watched or subscribed to the videos of the couple had already known about the identity of the teenager because of the daily Lives put up by the parents and discussion about the girl in the videos posted by them. If one visits the comment section of the recent videos of both the parents in the recent past, it would be seen that commenters have taken the name of the girl, asked about her whereabouts and in some cases, some had also suggested about her changed behaviour after she had stayed with her respective parents separately. Nothing is confidential for those thousands of worldwide audiences now who had watched the parents daily and who had also witnessed the Live video where the girl was beaten up by the father.  In spite of repeated request by the mother of the girl, several YouTubers still did not take down videos mentioning about the name of the father (which broadly falls within the meaning of “any other particulars calculated to lead to the identification of the juvenile or child”) when this writeup was published. While the Juvenile Justice Care and Protection and Act provides a base rule, the concerned YouTubers may not be held solely responsible because the parents already violated the privacy of the teenager and encouraged thousands to watch the couple fight which had every potential to attract penal provisions for using words etc for harming the modesty of the wife under S.509 Indian Penal Code as well as defamation of both the wife and the husband under Sections 499 and 500 of the Indian Penal Code. YouTube on the other hand has not taken down the videos of either of the spouses or that of the other YouTubers  which may showcase the names of the parents and the child because it is guided by First Amendment of the US which may hardly be affected unless YouTube has been approached to take the videos down by concerned stakeholders.  

It is now a typical love triangle of three parties : YouTube, which is loved by all for providing such an open platform for airing opinions and consumption of real life family dramas, the YouTubers who may expect to get support, views, popularity and money because of participating in the trolling and independent discussions on such issues which may rip open privacy of general individuals including children and criminal justice machinery, most of whom may never know how to manage legalities of YouTube videos because they are completely ignorant of this new type of electronic media.  

But this is not a unique incident that attracts the attention of legal researchers, especially privacy law and speech law researchers. YouTubers, especially women YouTubers continue to violate privacy knowingly or unknowingly and provide more opportunity to trolls, bullies and offline perpetrators to victimise them because they may not be aware about the netiquettes of YouTube. Time has come that YouTube users become cautious of the contents uploaded by them and legalities attached with such uploading and sharing. In this festive season YouTube content uploading and sharing may have seen a steep rise. But it is upon YouTubers to control what must be shared and may not.

YouTube is more powerful than televisions, more demanded than movies and more devastating than what is generally apprehended.

Please note: Do not violate copyright of this blog. If you would like to use information provided in this blog for your own assignment/writeup/project/blog/article. This was first published in https://debaraticyberspace.blogspot.com/2019/10/youtube-youtubers-and-violation-of.html Please cite it as “Halder D. (2019), ” YouTube, YouTubers and violation of privacy of women and children: The drama unfolds” Published in https://debaraticyberspace.blogspot.com/2019/10/youtube-youtubers-and-violation-of.htm on 28-10-2019, reshared @https://internetlegalstudies.com/2019/10/28/youtube-youtubers-and-violation-of-privacy-of-women-and-children-the-drama-unfolds-by-dr-debarati-halder/


[1] For  more, see https://support.google.com/youtube/answer/72851

[2] For example see Halder D., & Jaishankar K. (2016) Celebrities and Cyber Crimes: An Analysis of the Victimization of Female Film Stars on the Internet. Temida – The journal on victimization, human rights and gender. 19(3-4), 355-372

[3] For example see https://www.youtube.com/watch?v=52c7V2yeRlo  , https://www.youtube.com/watch?v=wYdX1uZe1FM  , https://www.youtube.com/watch?v=3yuvcKc30ss https://www.youtube.com/watch?v=IdA6BZJvaEU etc.

[4] https://www.youtube.com/watch?v=bkcMmd-b1-Y

[5] https://www.youtube.com/watch?v=6Po5tE2qKxM

[6] See for better understanding of the case in https://www.amarujala.com/delhi-ncr/faridabad/drunk-parents-beat-student-faridabad-news-noi468791969

[7] See https://www.youtube.com/watch?v=LNG3lousHu4&t=167s where the Youtuber had informed that she called the police to report the video and provided the link of the media report of the incident.

[8] For example, see https://www.youtube.com/watch?v=xWS8FAa-MC4&t=48s . https://www.youtube.com/watch?v=MdrSLYGOTpE&t=14s

Court system under the Information Technology Act, 2000 (amended in 2008) by Dr.Debarati Halder

Often I have been asked by victims, stakeholders and students of law about the jurisdictions of the courts and court system as a whole under the Information Technology Act, 2000 (Amended in 2008). This query carries great significance especially at a time when subscribers, consumers and civil society members are facing numerous problems due to data theft, data diddling, and data leaking etc. by the body corporate, intermediary and service providers themselves. Such issues of piercing the veil of cyber security and data privacy due to inefficient data protection mechanism of the body corporate may in turn help individual predators and even criminal gangs to target individuals including women and children to make it a large scale offence. Let us consider the case of Facebook facial recognition case in the US : even though Facebook as a company has been strongly contesting the case, the federal appeals court has given a green signal  for this class suit whereby Facebook can be prosecuted for infringement of data privacy  and would be liable to pay a huge compensation to the petitioners.[1]  What we understand from here is, such cases in the field of cyber law, may be dealt by courts in the nature of civil cases as well as in the nature of criminal cases.

In India, the primary regulatory provision for cyber issues is the Information Technology Act, 2000(amended in 2008) (IT Act, 2000, amended in 2008). This provision indicates that there are two types of authorities and tribunals/courts who may handle cases in the nature of civil and criminal liabilities, i.e., civil and criminal court and tribunals . We may understand this typology by understanding the nature of the cases under the Information Technology Act first, which is as follows:

In the issue of civil nature of cases, the administrative tribunal system under the IT Act has three tiers.

As may be seen from the above flow chart, at the grass-root level is the Certifying Authorities. A licensed Certifying Authority (CA) who has been granted licence under S.24, issues the digital signature certificates. CAs are controlled by Controllers, who are appointed by central government under S.17 of the Act. This provision also mentions about the appointment deputy /assistant controllers who should work under the instructions of the Controller.

Functions and responsibilities of the controller can be discussed under three broader heads:

S.18 of the IT Act provides essential functions of the Controller. Apart from S.18, there are certain other provisions under the IT Act, which speaks about other responsibilities and powers of the Controller.  The functions under S.18 are as under:

  • Exercising supervision over the activities of the Certifying Authorities;
  • Certifying public keys of the Certifying Authorities;
  •  Laying down the standards to be maintained by the Certifying Authorities;
  • Specifying the qualifications and experience which employees of the Certifying Authority should possess;
  • Specifying the conditions subject to which the Certifying Authorities shall conduct their business;
  •  Specifying the contents of written, printed or visual materials and advertisements that may be distributed or used in respect of an Electronic Signature Certificate and the public key;
  • Specifying the form and content of an Electronic Signature Certificate and the key;
  • Specifying the form and manner in which accounts shall be maintained by the Certifying Authorities;
  •  Specifying the terms and conditions subject to which auditors may be appointed and the remuneration to be paid to them;
  •  Facilitating the establishment of any electronic system by a Certifying Authority either solely or jointly with other Certifying Authorities and regulation of such systems;
  •  Specifying the manner in which the Certifying Authorities shall conduct their dealings with the subscribers;
  •  Resolving any conflict of interests between the Certifying Authorities and the subscribers;
  •  Laying down the duties of the Certifying Authorities;
  •  Maintaining a database containing the disclosure record of every Certifying Authority containing such particulars as may be specified by regulations, which shall be accessible to public.

As such, other than the functions mentioned above, the Controller may also have the following powers and functions:

  • Controller may also recognize the foreign certifying authorities with prior approval from the government under S.19.
  • Controller is the authority to suspend license of the CA in case of any discrepancies in the function of the CA under S.25
  • Controller has power investigate contraventions or authorize any officer to do the same under S.28.
  • Controller may also access to computer and data under S.29 if he has reasonable cause to suspect for any contravention of the provisions etc.

Apart from this, controller also has powers for dispute resolution: As such, .controllers can take over matter for regulating and resolving any conflict of interests between the Certifying Authorities and the subscribers.

Adjudicators along with the controllers form the second tier of tribunal system for civil nature of cases under the IT Act.  Adjudicating officers are appointed by the Central Government under S.46 of the IT Act for holding inquiry (in the manner prescribed by the Central Government) in cases where any person has committed a contravention of any of the provisions of this Act or of any rule, regulation, direction or order made thereunder which renders him liable to pay penalty or compensation. Such officer should not be below the rank of a Director to the Government of India or an equivalent officer of a State Government.S.46 clearly mentions that no person shall be appointed as an adjudicating officer unless he possesses such experience in the field of Information Technology and legal or judicial experience as may be prescribed by the Central Government. The adjudicating officer appointed under S.46(1)  are empowered to exercise jurisdiction to adjudicate matters in which the claim for injury or damage does not exceed rupees five crore. In case the jurisdiction in respect of claim for injury or damage exceeds Rs. five crore, the jurisdiction to try such cases then shall vest with the competent court. Every adjudicating officer shall have the powers of a civil court which are conferred on the Cyber Appellate Tribunal under sub-section (2) of section 58. As such, all proceedings before the adjudicator (a) shall be deemed to be judicial proceedings within the meaning of sections 193 and 228 of the Indian Penal Code; (b) shall be deemed to be a civil court for the purposes of sections 345 and 346 of the Code of Criminal Procedure, 1973. And (c) shall be deemed to be a Civil Court for purposes of order XXI of the Civil Procedure Code, 1908

But, the adjudicating officer cannot fix the quantum of punishment (especially fines, damages and compensation) at his own whimsies and fancies. S.47 says while adjudging the quantum of compensation under Chapter IX, the adjudicating officer shall have due regard to the following three factors, namely –

  • the amount of gain of unfair advantage, wherever quantifiable, made as a result of the default;
  • the amount of loss caused to any person as a result of the default;
  • the repetitive nature of the default

As such, adjudicators are responsible to handle cases of data infringement, unauthorised access to computer, offences to the computer (of civil nature), and fraudulent data leaking cases etc. under chapter IX of the IT Act.

At the top tier of the tribunals for dealing with cases of civil nature under the Information Technology Act, 2000(amended in 2008) exists the Cyber Appellate Tribunal. S.48 of the Information Technology Act, 2000 (amended in 2008) stated that the central government shall by notification establish one or more appellate tribunals to be known as Cyber Appellate Tribunal. However, it has been observed by several cyber law practitioners that the Cyber Appellate Tribunals in some places in India were not functioning properly. As such, since 2017 The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) established under section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997), (TRAI Act) has substituted CAT & working as Appellate Tribunal for the purposes of IT Act. It also exercises the jurisdiction, powers and authority conferred on it by or under IT Act. The TDSAT shall consist of a Chairperson, and not more than two  members  to be appointed by the Central Government.[2] Prior to the coming into existence of  TDSAT within the meaning of Appellate tribunal under the IT Act, online High Court judges could  qualify  to be appointed as Chairpersons  of the cyber appellate tribunal as per S.50 of the IT Act. However,  presently  as per S.4 of the TRAI Act, the Chairperson and other members of the Authority shall be appointed by the Central Government  only if such candidate has special knowledge of, and professional experience in, telecommunication, industry, finance, accountancy, law, management or consumer affairs.  Further, a person who is, or has been, in the service of Government shall not be appointed as a member unless such person has held the post of Secretary or Additional Secretary, or the post of Additional Secretary and Secretary to the Government of India or any equivalent post in the Central Government or the State Government for a period of not less than three years (as per Proviso to S.4 of the TRAI Act). s. 57, IT Act, 2000(amended in 2008) speaks about the jurisdiction & limitations of the Appellate authority , which to large extent is practiced by the TDSAT now. According to S.57, any person aggrieved by an order made by controller or an adjudicating officer under this Act may prefer an appeal to Appellate Tribunal having jurisdiction in the matter. However, no appeal shall lie to the Appellate Tribunal from an order made by an adjudicating officer with the consent of the parties. Every appeal under 57(1) shall be filed within a period of forty-five days from the date on which a copy of the order made by the Controller or the adjudicating officer is received by the person aggrieved and it shall be in such form and be accompanied by such fee as may be prescribed. Appellate Tribunal may entertain an appeal after the expiry of the said period of forty-five days if it is satisfied that there was sufficient cause for not filing it within that period.

Court for dispute resolution of criminal nature: Information Technology Act, 2000(amended in 2008) does not specifically mention about any court which may handle cases of criminal nature under this Act. But S.77A of the Information Technology Act is mentionable here, which speaks  about  compounding of offences According to S.77A of the IT Act, 2000(amended in 2008), a court of competent jurisdiction may compound offences, other than offences for which the IT Act provides punishment for life or imprisonment for a term exceeding three years.  As per S.77A, the court however, shall not compound offences falling under the categories as below:

  • Where the accused is, by reason of his previous conviction, liable to either enhanced punishment or to a punishment of a different kind:
  • Where such offence affects the socio economic conditions of the country.
  •  Has been committed against a child below the age of 18 years or a woman.

S.77A(2) of the IT Act states that  a person accused of an offence under this Act may file an application for compounding in the court in which offence is pending for trial and the provisions of sections 265B and 265C of the Code of Criminal Procedure, 1973 (2 of 1974) shall apply. From the above discussion, it may be inferred that any competent criminal court under Cr.P.C which are competent to handle cases involving offences and punishments as has been prescribed under Chapter XI under the IT Act, may be considered as competent court for the purpose of this Act. Now, the question which may arise is, which criminal courts may handle cases of criminal nature under IT Act, 2000 (amended in 2008). For this, we may need to understand the patterns of punishments under Chapter XI of the IT Act, 2000 (amended in 2008). These can be listed as below:

  • Imprisonment for a term which may extend to two years, or with fine which may extend to one lakh rupees, or with both.
  • Imprisonment of either description for a term which may extend to three years or with fine which may extend to rupees one lakh or with both
  • Imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.
  • Imprisonment which may extend to three years or with fine not exceeding two lakh rupees, or with both
  • Imprisonment up to three years, or with fine which may extend up to two lakh rupees, or with both.
  • Imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both.
  • Imprisonment extending to imprisonment for life.
  • Imprisonment in first conviction of either description for a term which may extend to three years and with fine which may extend to five lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to five years and also with fine which may extend to ten lakh rupees.
  • On first conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to ten lakh rupees and in the event of second or subsequent conviction with imprisonment of either description for a term which may extend to seven years and also with fine which may extend to ten lakh rupees
  • Life imprisonment

Now, to find the answer as which court may try cases of criminal nature under the IT Act,  the above mentioned  list has to be matched with the powers of various criminal courts under Ss.28 & 29 of Cr.P.C. The powers of the courts under the Cr.P.C can thus be categorized as follows:

As such it may be understood that cybercrimes and offences recognised under Chapter XI with various degrees of punishment may be dealt by various criminal courts as has been discussed under Ss.28 and 29 of the Criminal Procedure Code. But, in such cases also, the aggrieved party (including the offender) may make an appeal to the appropriate courts including the Session’s court,  High Court and also to Supreme court. However, in case the offence includes any offence targeting children, then along with Information Technology Act, 2000(amended in 2008), provisions of Protection of Children from sexual offences Act may also be applied. In such cases, the offence may necessarily be dealt with by courts designated under POCSO Act : such courts may be Special Court or Children’s Court or the Sessions court itself.

Note: Please do not violate the copyright of this writeup. If you wish to use this writeup for your report/assignment/project etc, please refer it as Halder Debarati (2019) Court system under Information Technology Act, 2000 (amended in 2008). Published in http://www.internetlegalstudies.com on 12-08-2019

:


[1] For example see @https://www.theguardian.com/technology/2019/aug/09/facebook-facial-recognition-lawsuit-can-proceed-us-court?CMP=share_btn_fb&fbclid=IwAR3RvbLbL9TmFCkeBgypZORu4dRYnQNFvbWuFfIoQN1m-n80UlFO8_26qIk

[2] see http://dot.gov.in/actrules/telecom-regulatory-authority-indiatrai-act-1997

Gender and Internet: Cyber law magazine for women News Update for July 21-31, 2019

Court releases man accused of dating underage girl, on the ground that the accused was intellectually disabled, due to his disability he was attracted to internet dating sites and the concerned dating site clearly mentioned that no one below the age of 19 can be the member of the said site. The court also considered that the accused stopped communicating with the woman understanding that she may be under 14.
https://www.irishtimes.com/news/crime-and-law/man-released-without-charge-after-sting-in-cork-1.3970574

45 year old mom sentenced to 15 years prison sentence for allegedly trafficking her female children on internet
https://www.sunstar.com.ph/article/1816574

Man arrested by police for allegedly paying families to encourage children including girls to act in sexually explicit manner in front of cameras and sharing the contents with third parties for more child abuse. The man was also accused of destroying I-pad in an attempt to destroy evidences.
https://www.dailymail.co.uk/news/article-7300753/Monmouth-businessman-south-Wales-Jonathan-Kay-paid-families-Philippines-sex-abuse-children.html

Indian man gets arrested for allegedly accessing wife’s Facebook profile and posting derogatory obscene contents to vent out anger over bitter ending of the relationship with wife.
https://www.indiatoday.in/crime/story/hyderabad-man-who-posted-obscene-pictures-on-wife-s-facebook-arrested-1575546-2019-07-31

Weekly news update April 23-30, 2019

April 23-30

Four men arrested for wife swapping after woman files complaint in Kerala
https://www.newsnation.in/crime-news/kerala-wife-swapping-four-men-arrested-woman-files-complaint-fir-sexual-activities-sharechat-kayamkulam-article-222412.html

‘Digital Strip Searches’ for rape victims raise privacy issues in United Kingdom
https://www.forbes.com/sites/thomasbrewster/2019/04/29/police-ask-rape-victims-to-hand-over-phones–are-these-digital-strip-searches-necessary/#40f96668460a

Singapore’s voyeurism problem and cyber crimes against women
https://www.channelnewsasia.com/news/singapore/singapore-voyeurism-problem-spy-cam-sex-harassment-monica-baey-11487244

Trolling on Instagram photos: Should women restrain from uploading personal pictures?

CYBER CRIME AGAINST WOMEN BY DEBARATI HALDER

Image curtsy : Google

 

Off-late I have been getting to see many incidences of trolling on personal pictures of individuals, especially women on Instagram. These photos may include photos of young women and girls in trendy clothes, showing more skin than expected by orthodox societies. Such pictures may attract the attention of self-acclaimed moral police trolls who wish to condemn women for their choice of outfits; these trolls use extremely harsh words which may even go to the extent of threatening women for their choices. They may even broaden their harassment pattern by sharing the target pictures through different profiles to defame the victims, threat the victims and create many more morphed images of the victims and this may go on till the victims reach a stage to withdraw from the social media. This indeed generates various levels of criminal liability, some of which have been addressed by laws in India. Apart from self-acclaimed moral police trolls, several women have also complained of fashion police trolls who intentionally data mine and troll women, whose fashion sense according to the trolls is not upto the mark. Unlike the moral police trolls, the fashion police trolls  may not create security or life risking threats, but they may definitely target the reputation of the victims and  their self-esteem.

 

Now let us see what sorts of harm or damage can be done by both types of trolls:
trolling can creation of threat, intimidation
trolls necessarily create posts which are defamatory; these can be teasing remarks  and extremely  insulting comments
trolling can result in reputation damage, violation of privacy, unauthorised access to data, copyright violation (in certain cases)
Trolls are necessarily bullies. But bullying and trolling are not the same. Trolling can be more vicious than bullying. Trolling infact attracts more perpetrators and more victims in the same thread. These victims and perpetrators may not be known to  each other  previously; resultant, the new “victims” who may have joined the thread to support or disagree with the primary victim  may finally put all blames to the primary victim for the victimisation by way of trolling. Trolling is more public than bullying. As such the effects of trolling may be more traumatising than bullying. Trolling can not only damage reputation of the primary victims, trolls may go a long way to harass cyber bystanders or commenters who may support or disagree with the victims as well as with the trolls. The situation worsens if these bystanders or commenters are women; trolls may threaten these secondary victims with legal consequences (for aggravating the issues) which may force the latter to withdraw from social media just like the primary victims.
This may adversely affect women’s usage of Instagram : Instagram unlike Facebook may instantly help the user to get connected with people/group with common interest especially when the user uses the hashtags. The pictures/videos armed with hashtags may help the user to reach a wider audience. Several people including women aspiring to showcase their creativity in fashion industry, upcoming models, actors singers, anchors, performers etc, who use the platform for getting connected with the industry people, mentors and a wider audience, may suffer hugely if trolls attack them on Instagram. Victims may not only feel completely withdrawn, they may also be pulled into unnecessary legal tangles especially if the trolls misuse their pictures which may have been uploaded by the victims for promoting certain brands (which in turn may not appreciate such negative publicity of their product).
        But this in no way should mean that women should restrain from uploading pictures on Instagram. There are several ways to protect the privacy, reputation and the copyright of the pictures of the users :
1.  Women and girls should always opt for privacy options in Instagram. This may reduce the responsibility of the users and increase that of the website. The victims may directly charge the websites for not applying due diligence and  neglecting the security features which should have restricted unwanted people from infringing the privacy and copyrights. Further, in case the women wish to make the profiles open for public and had been harassed/trolled/stalked/unauthorisedly accessed etc, the victims must report the matter to the websites. The websites would not be letting the victim know the about the original identity of the harasser in case the profile is that of unknown person/s; but they would be duty bound to repair the damage, i.e. , restrict the unauthorised circulation of the image of the victim and generating anymore message that may harm the reputation of the victims. S.79(3) of the Information technology Act, 2000(amended in 2008) (exceptions to exemption from liability of intermediary in certain cases)  may be applied in such cases.
2.  Indian laws do not recognise online trolling and bullying as separate offences. This definitely had created problems for proper justice delivery to the victims. However, basing on the modus operandi for trolling several penal provisions may be applied; for instance, S.509 (punishment for harming the modesty of women), 507 (criminal intimidation by anonymous person), 499 and 500 (defamation and punishment for the same), 354D (punishment for stalking including cyber stalking) of the IPC may be used for posting intimidating, insulting, defamatory comments, stalking, creating threats etc.
3.  If trolling results in creation of Fake avatars especially sexually explicit contents, obscene contents etc, and if this involves unauthorised access to data, manipulation of data etc, the police may also apply provisions including Ss. 43(unauthorized access to the computer, data etc) 66 (punishment for computer related offences), 66C (punishment for fraudulently using password, unique identification features etc of any other person), 66D (punishment for cheating by impersonation), 66E (violation of privacy)(incase the picture has been used to create morphed pictures/images), 67 (punishment for creating sexually explicit contents), 67A (punishment for creating obscene contents ) of the Information technology Act, 2000(amended in 2008), S.354C IPC(punishment for voyeurism) etc. Police may also necessarily apply provisions from Indecent representation of women (prohibition )Act, 1986 for indicting the accused for indecent representation of the victim online.
Some of the above mentioned laws are non bailable and cognizable. This means that trolling may not be considered as a simple offence especially if it results in heavy offences including creation of sexually explicit contents ( the contents include not only the images, but the texts as well) etc. As such, women should not refrain from using Instagram fearing trolling. But they must be aware of their rights against trolling and the duties of the websites.
Let us unite against misogynist trolling. Let us spread the message that trolling, its modus operandi and its consequences should not be taken lightly and the criminal justice machinery must emphasise with the victims of trolling.

 

 Please Note: Do not violate copyright of this blog. If you would like to use informations provided in this blog for your own assignment/writeup/project/blog/article, please cite it as “Halder D. (2018), ” Trolling on Instagram photos: should women restrain from uploading personal pictures?” 15th January, 2019, published in http://debaraticyberspace.blogspot.com