Introduction
The global crisis of child sexual abuse material (CSAM) has acquired a distinctly technological dimension over the past decade. What was once circulated through physical media and clandestine networks now flows through the mainstream internet infrastructure: encrypted messaging applications, social media platforms, cloud storage services, and peer-to-peer sharing networks. India occupies an unenviable position in this landscape. Reports forwarded to Indian law enforcement agencies from the National Centre for Missing and Exploited Children (NCMEC) CyberTipline have placed India consistently among the top recipients globally of reports concerning CSAM hosted by, uploaded by, or involving Indian users and accounts.
This article examines India’s legislative framework for addressing CSAM, the critical role of NCMEC CyberTipline reports in India’s enforcement ecosystem, the significant gap between reports received and investigations successfully concluded, the obligations of social media intermediaries under the Information Technology Rules 2021, and the structural weaknesses in India’s enforcement architecture that prevent effective investigation and prosecution of CSAM offences under the Protection of Children from Sexual Offences Act, 2012.
Legal Framework
The primary criminal prohibition on CSAM in India is contained in Section 14 of the POCSO Act, which creates the offence of using a child for pornographic purposes, and Section 15, which specifically criminalises the storage or possession of child pornographic material for commercial purposes or for the purpose of distribution, transmission, or display. The 2019 amendment to Section 15 significantly expanded its reach by adding three distinct punishable scenarios: storage for commercial purposes (Section 15(1)), failure to delete or report on coming into possession of CSAM (Section 15(2)), and storage for actual use or distribution (Section 15(3)), each carrying escalating minimum and maximum sentences.
Concurrently, the Information Technology Act, 2000 contains Section 67B, which specifically prohibits publishing or transmitting material that depicts children in sexually explicit conduct in electronic form. Section 67B goes further than mere prohibition of end-user conduct; it also criminalises facilitating the online abuse of children and the cultivation or grooming of children for the purpose of such abuse. The penalty is up to five years’ imprisonment for a first conviction and up to seven years for subsequent convictions.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 impose specific obligations on “significant social media intermediaries,” defined as platforms with more than five million registered users in India. Under Rule 4(4), these intermediaries are required to endeavour to deploy technology-based measures, including automated tools or other mechanisms, to proactively identify information depicting rape, child sexual abuse, or conduct of a sexually explicit nature involving children. The Rules specifically mention PhotoDNA and equivalent hash-matching technologies as the standard for compliance.
POCSO Section 19 imposes a mandatory reporting obligation on any person who learns that a POCSO offence has been committed or is likely to be committed. Section 19(7) specifically addresses reporting by internet service providers and mandates that such providers who discover child pornographic material on their platform must report it to the designated authority within 24 hours. Failure to report is a criminal offence under Section 21.
Judicial Developments
The Supreme Court in Prajwala v. Union of India (2015, and subsequent orders through 2021) directed the government to constitute a committee to identify ways to eliminate child pornography, rape, and gang rape images and videos from social media platforms and to establish a system for reporting and removing such content. The Court’s directions led to the development of the CyberTipline forwarding arrangement between NCMEC and the Central Bureau of Investigation (CBI) as the designated nodal Indian agency for receiving NCMEC reports.
The Madras High Court in S. Harish v. Inspector of Police (2019) addressed the question of whether merely viewing CSAM online without downloading or storing it constituted a criminal offence, holding that mere viewing did constitute an offence under Section 67B of the IT Act because the accessing of such material sustained demand and constituted publication in electronic form. This judgment, while progressive, was subsequently reviewed, and the question of criminalising mere viewing without possession remains contested in Indian courts.
Several High Courts have addressed the intermediary liability question in the context of CSAM, generally holding that once a platform has actual knowledge of CSAM on its platform and fails to act expeditiously to remove it, the immunity from liability under Section 79 of the IT Act is lost. The 2021 IT Rules’ active proactive monitoring obligations for significant social media intermediaries further erode the “mere conduit” defence that platforms might otherwise invoke.
Contemporary Issues and Analysis
The NCMEC CyberTipline operates as a global reporting hub to which US-based technology platforms are legally required to report CSAM under the US PROTECT Our Children Act. In 2022, NCMEC received over 32 million reports globally, a significant proportion of which were forwarded to law enforcement agencies including those in India. India has in recent years been among the top five countries receiving CyberTipline reports, with the CBI receiving hundreds of thousands of forwarded reports annually.
The enforcement gap is the most troubling aspect of this architecture. Of the reports forwarded to the CBI, a fraction result in FIR registration, a smaller fraction still result in completed investigations, and prosecutions and convictions are a small subset of the investigated cases. Research and media investigations have documented this gap repeatedly, with law enforcement agencies attributing it to resource constraints, technical capacity deficits in digital forensics, jurisdictional complexities in cases involving foreign-based platforms, and the sheer volume of reports that overwhelm investigative capacity.
The structural problem in the NCMEC model as applied to India is that US-based platforms report to NCMEC, which then forwards to Indian agencies, introducing delays and information loss. The reports forwarded may contain metadata, account information, and image hashes but may not contain the actual CSAM material, which the platform may have already deleted from its servers before Indian investigators seek it through mutual legal assistance treaty (MLAT) procedures. MLAT requests to the United States are notoriously slow, often taking twelve to twenty-four months, by which time digital evidence may be unavailable or inaccessible.
The requirement under IT Rules 2021 Rule 4(4) for significant social media intermediaries to deploy PhotoDNA or equivalent hash-matching technology represents an important regulatory step. PhotoDNA, originally developed by Microsoft and now administered through NCMEC’s hash-sharing database, allows platforms to compare uploaded images against known CSAM hash values without viewing the actual content, thereby enabling automated detection and removal. The weakness is that India has no national CSAM hash database maintained by a domestic agency; platforms must rely on NCMEC’s database, which is primarily curated based on CSAM reported by US-based organisations and may not include Indian-produced material not yet captured in the global database.
The IT Rules 2021’s compliance monitoring mechanism is also underdeveloped. While the Rules require intermediaries to submit monthly compliance reports, the Ministry of Electronics and Information Technology (MeitY) has not established a systematic audit or verification process to confirm that CSAM-detection technologies are actually being deployed effectively and that the proactive monitoring obligation is being genuinely fulfilled rather than merely paper-complied with.
A particularly concerning emerging challenge involves end-to-end encrypted messaging platforms such as WhatsApp and Telegram, which present significant CSAM distribution channels. CSAM shared on end-to-end encrypted platforms is invisible to the platform’s automated detection systems because the content is encrypted at the device level. This creates a structural enforcement void that law enforcement agencies in India, like their counterparts globally, have not been able to bridge without resorting to measures that raise significant privacy concerns.
Comparative and International Perspective
The United Kingdom’s Internet Watch Foundation (IWF) provides an instructive model. The IWF is a self-regulatory body that maintains a national hash-matching database of known CSAM, receives public reports of CSAM URLs, works with internet service providers to block access to known CSAM URLs, and shares its database with global partners including NCMEC. UK-based internet service providers are required to use the IWF’s blocking lists under a combination of regulatory obligation and voluntary agreement. The IWF’s active “notice and takedown” architecture means that CSAM identified by the IWF is removed from UK-hosted servers within hours. Critically, the IWF also proactively crawls the internet to identify CSAM rather than relying purely on user reports.
Australia’s eSafety Commissioner, established under the Online Safety Act 2021, has enforcement powers that represent perhaps the strongest national framework for CSAM removal. The Commissioner can issue Basic Online Safety Expectations to online service providers, requiring them to take reasonable steps to minimise CSAM on their platforms. Failure to comply with the Commissioner’s removal notices or expectations can result in civil penalties of up to AU$555,000 for companies and AU$111,000 for individuals per day of non-compliance. The Commissioner can also conduct proactive investigations into platform safety practices.
The United States EARN IT Act (enacted 2022) creates a framework for eliminating Section 230 liability protections for platforms that fail to report and remove CSAM, creating a powerful legal incentive for aggressive proactive monitoring. The Act establishes best practices developed by a commission of law enforcement and technology experts that platforms must follow to retain their civil immunity.
Canada’s online harms framework, proposed as the Online Harms Act (Bill C-63, 2024), specifically designates CSAM as a category of manifestly harmful content requiring expedited removal within 24 hours of platform notification, with the possibility of 24-hour emergency removal orders for particularly severe material.
Practical and Policy Implications
India’s current enforcement architecture is characterised by a significant mismatch between the volume of CSAM reports received and the investigative capacity to act on them. Without substantial investment in specialised cybercrime investigation units equipped with digital forensics capabilities, CSAM investigation will remain a nominal rather than a genuine law enforcement priority. The CBI’s nodal agency function needs to be supported by trained investigators in every state, given that CSAM production and consumption is geographically distributed.
The MLAT bottleneck requires a policy-level solution. India should negotiate bilateral digital evidence sharing agreements with major platform-hosting jurisdictions, particularly the United States, that allow for expedited sharing of account and content data in CSAM cases without the delays inherent in the formal MLAT process. The US CLOUD Act provides a framework for such bilateral agreements, and India’s negotiations toward a CLOUD Act agreement should be treated as a high priority in cybercrime diplomacy.
Victim identification, which requires expertise in recognising environmental and contextual clues in CSAM images, is a specialised function that India has not institutionalised. The lack of a dedicated victim identification unit comparable to INTERPOL’s Victim Identification Group means that CSAM victims whose images circulate online may not be identified and may not receive the protection, rescue, and rehabilitation they require.
Suggestions and Reforms
India should establish a national CSAM hash database maintained by MeitY or a designated authority such as the Indian Cyber Crime Coordination Centre (I4C), seeded with hashes from NCMEC’s database and expanded through contributions from Indian law enforcement investigations. This database should be mandatorily integrated into the content-upload pipelines of all significant social media intermediaries operating in India.
Section 15 of the POCSO Act should be amended to clarify the obligations of intermediaries more specifically, imposing a mandatory proactive detection obligation backed by criminal liability for officers in default. The current framework’s reliance on IT Rules 2021 is inadequate because Rules can be amended or interpreted away more easily than statutory provisions.
A dedicated CSAM Investigation Unit should be established within the CBI with the mandate to coordinate NCMEC report follow-up, maintain the national CSAM database, and provide investigative support to state police. State police cybercrime units should be mandatorily trained in CSAM investigation protocols developed in coordination with INTERPOL’s online child exploitation team.
Legislative action is needed to require platforms to preserve CSAM-related user data for a minimum of two years after a report is made to NCMEC, ensuring that Indian investigators can access it through legal process even if the platform has deleted the material from active servers.
Finally, India should ratify the Council of Europe’s Budapest Convention on Cybercrime (which India joined as an Observer state) and its associated Lanzarote Convention on Protection of Children against Sexual Exploitation, which would provide enhanced legal frameworks for international cooperation in CSAM investigations and prosecutions.
Conclusion
India’s legal framework for addressing CSAM is textually comprehensive but operationally weak. The POCSO Act and IT Act provide the substantive prohibitions; the IT Rules 2021 impose proactive obligations on intermediaries; and the NCMEC CyberTipline furnishes a stream of actionable intelligence. The failure lies in translating these inputs into effective investigation and prosecution. The gap between India’s position as one of the top global recipients of CSAM-related reports and its comparatively limited prosecution record is a measure of systemic enforcement failure, not merely resource constraint.
Closing this gap requires a combination of institutional investment in specialised investigative capacity, technical infrastructure in the form of a national CSAM hash database, legal reforms to strengthen intermediary obligations, and diplomatic engagement to resolve the cross-border evidence access bottleneck. Child sexual abuse material represents the documentary record of ongoing crimes against real children. India’s enforcement response must treat it with the urgency that reality demands.