loaderimg
image
Cyber Law

Deepfake in India: What Legal Action Can You Take Against Fake Photos and Videos?

Share this article WhatsApp Facebook X

Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.

A fake photo or video of you — generated or altered using AI to make it look real — is circulating online, whether it’s your face placed on someone else’s body, a fabricated video making it look like you said something you never said, or explicit content that doesn’t actually feature you at all. India recently tightened its legal framework specifically for this, and here’s exactly what you can do.

India’s New Deepfake Rules: What Changed

The Ministry of Electronics and Information Technology notified amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 via Gazette notification on 10 February 2026, effective 20 February 2026. These amendments formally define “synthetically generated information” — content artificially or algorithmically created, generated, modified, or altered using a computer resource in a manner that appears reasonably authentic — and bring it squarely within platform obligations for the first time.

Key Protections Under the New Rules

  • Mandatory labelling — platforms offering content-generation tools must label synthetic visual content covering at least 10% of the screen area, permanently visible; synthetic audio must be labelled for the first 10% of its duration, and these labels cannot be removed by users or intermediaries
  • Fast-tracked takedowns — intermediaries must remove unlawful synthetic content within just 3 hours of a valid court order or government direction, down from the earlier 36-hour standard, and content in the most harmful categories can require removal in as little as 2 hours
  • Loss of safe harbour — platforms that fail to meet these obligations risk losing the legal protection (safe harbour) that has historically shielded them from liability for user-generated content

Criminal Provisions That Still Apply

  • Section 66C, IT Act — identity theft, where your likeness/identity is used without authorization
  • Section 66E, IT Act — privacy violation, for deepfakes depicting private-area imagery
  • Section 67A, IT Act — publishing sexually explicit material, carrying up to 5 years imprisonment for a first offence, squarely covering deepfake explicit content
  • Section 353, Bharatiya Nyaya Sanhita, 2023 — statements conducing to public mischief, relevant for deepfakes spreading false information
  • Section 356, BNS — defamation, where the deepfake damages your reputation

Responding to a Deepfake: Process at a Glance

01
Preserve Evidence
Screenshot/download before reporting
02
Report to the Platform
Fast-tracked removal now applies
03
File a Cybercrime Complaint
cybercrime.gov.in or 1930
04
Send a Legal Notice
If the creator is identifiable
05
Pursue Civil Remedies
Injunction and/or damages
Step 1: Preserve Evidence Before It's Removed

Screenshot or download the content, the account/page that posted it, the URL, and any comments or shares — do this before reporting, since a successful takedown removes your ability to capture it afterward.

Step 2: Report It to the Platform

Use the platform’s dedicated reporting tool. Under the February 2026 amendments, platforms must act on unlawful synthetic content covered by a valid direction within 3 hours (as little as 2 hours for the most harmful categories) — significantly faster than the general grievance timeline.

Step 3: File a Cybercrime Complaint

Call 1930 or file at cybercrime.gov.in, citing the applicable IT Act and BNS provisions based on the deepfake’s content (explicit, defamatory, identity-based fraud, etc.).

Step 4: Send a Legal Notice If the Creator Is Identifiable

If you can identify who created or is circulating the deepfake, a lawyer’s legal notice demanding removal and warning of the applicable criminal and civil consequences often accelerates resolution.

Step 5: Pursue Civil Remedies for Ongoing Harm

A civil suit seeking an injunction (to stop further circulation) and damages remains available independent of any criminal complaint, particularly useful where the content keeps resurfacing across platforms.

Need Legal Help? Get expert legal help from experienced professionals with ApniLaw legal services across India. Advertisement

The mandatory labelling requirement matters even beyond your own case — because platforms offering AI content-generation tools must now permanently label synthetic output, a growing share of deepfakes will carry built-in evidence of their artificial origin, which can materially strengthen both your platform report and any legal complaint. If the content you’re dealing with lacks a label it should legally carry, that absence itself is worth flagging to the platform as a separate compliance failure.

It’s worth understanding that the 3-hour (or 2-hour) fast-track applies specifically to content already found unlawful via a valid court order or government direction — for a fresh report you’re filing directly with a platform, the general grievance timelines (24-hour acknowledgment, 15-day resolution) may apply first, unless the content also falls into the private-area/nudity/impersonation category that separately carries its own 2-hour obligation. In practice, clearly harmful deepfakes are usually actioned quickly by platforms regardless of the precise legal timeline, given the reputational and regulatory risk of not doing so.

If the deepfake is sexually explicit or intimate in nature, treat this with the same urgency as the fastest-track category — Section 67A carries serious criminal penalties for whoever created or shared it, and you’re entitled to the same expedited platform response as genuine non-consensual intimate imagery cases.

Need Immediate Legal Help?

Get Legal Help from ApniLaw Sponsored

Platform Report vs Cybercrime Complaint vs Civil Suit

Choosing Your Response

RouteBest For
Platform reportFast removal — now backed by mandatory 2-3 hour takedown windows for the worst cases
Cybercrime.gov.in / 1930Formal criminal complaint, investigation, and tracing the creator
Civil suitOngoing/recurring circulation, or seeking monetary damages

Where Do You File?

Platform reports go through the app/website’s own tools. Criminal complaints go through cybercrime.gov.in or your local cyber cell. Civil suits are filed before the appropriate civil court.

Does It Cost Anything?

Platform reporting and filing a cybercrime complaint are both free. A lawyer’s legal notice or civil litigation involves professional fees that scale with the case’s complexity.

Can You Do This Without a Lawyer?

Platform reporting and the cybercrime complaint are both designed for direct use without a lawyer. Professional help matters for a legal notice, civil suit, or if the content keeps resurfacing despite repeated takedowns.

What Happens After You Report?

  • The platform reviews your report against the new synthetic-content obligations and its own policies, actioning it within the applicable window
  • A cybercrime complaint triggers investigation, which can trace the content back to its creator even from an anonymous or fake account
  • Platforms that fail to comply with takedown/labelling obligations risk losing their safe harbour protection, which adds regulatory pressure toward fast compliance
  • Civil or criminal proceedings, if pursued, follow the normal court process for their respective outcomes (compensation vs. punishment)

Need professional legal help with this?

Find a Lawyer on Vidyoday

If the deepfake is being used to threaten or extort you, see our guide on online blackmail. If it’s damaging your broader personal or professional reputation, our guide on online reputation damage covers additional remedies.

Key Takeaways

  • India’s February 2026 IT Rules amendment formally regulates “synthetically generated information,” bringing deepfakes within mandatory platform obligations.
  • The most harmful synthetic content must now be taken down within 2-3 hours of a valid order — far faster than the earlier 36-hour standard.
  • Synthetic content is increasingly required to carry permanent labels — a missing label on AI-generated content is itself a compliance failure worth flagging.
  • Multiple criminal provisions apply depending on the deepfake’s nature — identity theft, privacy violation, obscenity, defamation, or public mischief.

Frequently Asked Questions

Context matters — clearly satirical content may be treated differently, but a deepfake that misrepresents you, causes harm, or is sexually explicit remains illegal regardless of the creator’s stated intent.

You can still report it to the platform and file a cybercrime complaint — investigators have tools to trace content back to its source even when the uploading account is anonymous.

No — the rules are new and compliance is still developing across the industry; treat suspicious content skeptically regardless of whether it carries a label.

Yes — platforms that fail to meet their takedown and labelling obligations under the new rules risk losing their safe harbour protection, which exposes them to greater liability.

Public figures have the same core legal protections against deepfakes, particularly explicit or defamatory content, though courts weigh public interest considerations somewhat differently for their public conduct.

Yes — sharing or transmitting the content can independently trigger liability under the same provisions, particularly for explicit or defamatory deepfakes.

There’s no individual legal right to demand proactive scanning, though larger platforms increasingly deploy detection tools voluntarily given their new regulatory obligations.

The original deepfake file/link, the account that posted it, any metadata available, screenshots with timestamps, and a record of your platform report and its outcome — all of this strengthens both a cybercrime complaint and any civil action.

Vidyoday
Vidyoday Editorial Team
Cyber Law & Digital Safety
Reviewed and published by Vidyoday.
Disclaimer:

This article is for general information only and does not constitute legal advice. If the content is sexually explicit or you are being threatened, contact 1930 or the police (100) immediately. Consult a cyber lawyer for guidance specific to your situation.

Leave a Comment