When The Laws Prioritise Content Regulation Over Accountability

Deepfake abuse against women in India — accountability gap under DPDP Act 2023 and IT Rules 2026 analysis by CRGCL
Authored by Padmini Majhi, an Independent Researcher.

Reports and Statistics on Deepfake Abuse Against Women

While we have a robust judicial system to protect women’s rights and dignity in homes and workplaces, the existing legal framework is inadequate against the deepfake abuse a woman faces. The 2019 study from Deeptrace/Sensity found that 96% of the deepfake videos were non-consensual pornographic videos. According to the Security Hero Report 2023, 98% of deepfake videos are pornographic, and 99% of victims are women. The volume of deepfake pornographic videos itself rose sharply by 464% from 2022 to 2023, from 3,725 to 21,019 videos.

A 2025 report by the Rati Foundation, an India-based NGO,  said that 10% of all calls to its online abuse helpline, Meri Trustline, were related to deepfakes or AI-generated images and videos. An AI-safety-adjacent firm, pi-labs, reveals that 93% of deepfake victims around the globe are women. In deepfake videos, victims range from school-aged girls to younger professionals between the ages of 18 and 30 years, with cities like Bengaluru emerging as a hotspot. Despite this reality, the government frames policies solely by scrutinising content, rather than by protecting women’s dignity. If the law only removes the unlawful content without holding the perpetrator accountable, then women’s dignity will pay the price for the government’s failure.

Structural Gap in the DPDP Act 2023

The Digital Personal Data Protection Act, 2023 was introduced to protect individuals’ privacy rights. The Act states that a Data Principal’s consent is needed by the Data Fiduciary to process their data. This Act also talks about the risks of unauthorised data collection by the government and companies. The concern is how the data can harm the Data Principal.

The original DPDP draft bill 2022 in Clause 2(10) had specifically defined “harm” where a person could suffer harm through any bodily harm, distortion or identity theft, harassment, prevention of lawful gain or causation of significant loss.  While preparing the 2023 Bill, the government omitted the definition “harm” before introducing it in Lok Sabha on 3 August 2023. The deletion of the definition of “harm” removed the statutory vocabulary through which non-financial harm could be recognised.

Since “harm” has no statutory definition, Section 2(p) of the DPDP Act, 2023 only recognises “loss”  defined in terms of financial or property, leaving very little scope to tackle damaged reputation, psychological trauma, and social shaming done upon women through deepfake videos. But it does raise the question of who should be held accountable for deepfake-related crimes.

Lack of Accountability

Beyond the missing statutory definition of “harm”, the Act’s scope is also limited to Data Fiduciaries and Processors, leaving the individual creator out of the Act. The Act only regulates the Data Fiduciaries, the platforms which decide how the data is used, and Data Processors who process personal data on behalf of the Data Fiduciary. But a person who downloads publicly available images from a platform, runs them through a deepfake image generator tool, and later publishes them on social media platforms doesn’t come under the ambit of the Act. There’s no term defined in the Act for how the private individual uses the data publicly available on the social media platforms.

In the DPDP Act, 2023, Section 3(c)(ii) states that this Act does not apply to the personal data made publicly available by the Data Principal, where a woman’s photograph shared publicly on social media platforms requires no consent from the Data Principal which means, the very data used to create the deepfake of the downloaded image is itself out of the purview of the Act. Since the DPDP Act doesn’t reach the individual creator, accountability must instead rely on existing criminal provisions that address such conduct, but they have their own limitations.

Certain provisions already exist that criminalise the making and circulation of deepfakes, for instance, Section 66C (Identity theft), Section 66D (Cheating by personation), Section 66E (Violation of privacy), Section 67 (Publishing/transmitting obscene material in electronic form), Section 67A (Publishing/transmitting material containing sexually explicit act, in electronic form) of the IT Act, 2000. Similarly, Section 318 (Cheating), Section 336 (Forgery), Section 356 (Defamation) of the Bharatiya Nyaya Sanhita, 2023 criminalise the deepfake-related conduct too.

In the case State of West Bengal v. Animesh Boxi (2018), the convict, Animesh Boxi, obtained intimate pictures of his former romantic partner by hacking her phone and uploaded the explicit media to pornographic sites after their relationship ended. The accused was convicted under Sections 66C, 66E, 67 and 67A of the IT Act, 2000. Similarly, in the 2023 Rashmika Mandanna deepfake case, a deepfake of the actor was created and circulated, leading to an FIR registered under Section 66C and 66E of the IT Act, 2000; the accused was later arrested, though no conviction has been secured.

Because both the IT Act, 2000, and the BNS, 2023, are technology-neutral laws, they were not specifically framed to address Synthetically Generated Information (SGI) and deepfake-related crimes. This is illustrated in Boxi’s case, where the hacked photos of the victim published on pornographic sites were real photos and not AI-generated content, which means it doesn’t actually fall under deepfake-related crimes.

In the landmark judgment of State of West Bengal v. Animesh Boxi, the court ordered that the victim should be paid compensation under the State’s Victim Compensation Scheme. However, no dedicated civil remedy exists under the IT Act, 2000, and BNS, 2023.

Short-Term Solution

For the first time, the government introduced the definition of Synthetically Generated Information (SGI) to tackle crime committed through deepfake-generating tools.

Under Rule 3(3), the intermediaries must deploy technical measures to prevent SGI-generated content like Non-Consensual Intimate Imagery (NCII), false documents, and impersonation. Tools like AI image generators, AI video generators, and voice cloning tools are covered in IT Rules, 2026. Under Rule 3(2)(b), content like nudity, sexual content, sexually morphed images and impersonation can be taken down within two hours.

For every SGI under Rule 3(3)(a)(ii), the intermediaries must include a watermark and a label that it is an AI-generated image or video. Also, under Rule 3(3)(b), the content’s metadata cannot be removed or modified, which can help the agencies to track the creator of AI-generated content.

Under Rule 3(1)(ca)(i), the intermediaries are required to inform users that unlawful SGI creation may attract punishment under provisions of the IT Act, 2000, the Bharatiya Nyaya Sanhita, 2023, the Representation of the People Act, 1951, the Indecent Representation of Women (Prohibition) Act, 1986, the Sexual Harassment of Women at Workplace (Prevention, Prohibition, And Redressal) Act, 2013, and the Immoral Traffic (Prevention) Act, 1956.

If the user violates the SGI provisions, under Rule 3(1)(ca)(ii), the unlawful content gets blocked or taken down; their account can be suspended or terminated, but the platform must preserve evidence; the platform must identify the violating user and disclose their identity to the complainant who is the victim. Also, such offences are required to be reported to the respective authorities in accordance with the law.

However,  the IT Rules, 2026, including Rule 3(1)(ca)(i), are executive rules drafted under Section 87 of the IT Act, 2000. Under administrative law, executive rules cannot create new criminal offences or jail terms. Consequently, the absence of direct criminal punishment for deepfake creators within the IT Rules is not a policy failure, but a structural limitation of delegated rulemaking. Does taking down a deepfake deliver justice to women? Is it enough to fight against the cruelty of those who perpetrate such abuse?

The Contradiction over Who Pays the Price

After the deepfake is taken down, it doesn’t remove the trace from people’s minds. After it was published on social media platforms, some people may have downloaded it and shared it in Telegram or WhatsApp groups. It can even reach workplace groups or community groups. It only removes the original post from the web and not the copies that had already been shared and downloaded.

After it has been widely circulated, people question the woman’s integrity, but never question the source of the content or even try to reason with the truth. In the workplace, she may even lose her job, but certain routes exist, like her employment contract or service rules, the Industrial Relations Code, 2020, and the POSH Act, 2013. Although these aren’t tailored for situations involving deepfake-related crimes, proving that the deepfake image is not real itself is the biggest hurdle to cross, and she may lose the job before she even gets the chance to prove her innocence. Society never sees her the same way.

But even after the removal, what a woman faces is never a concern for the people who saw the deepfake. She is mentally, emotionally, and physically affected. After losing her job, she isolates herself from her friends, family and society. The removal of AI-generated content does not undo the damage done to women’s dignity.

In the MeitY guidelines on AI governance report 2025, the government stated seven sutras for AI system governance. Under the sutra “People First”, the AI ecosystem should be built and deployed where users benefit from the technology they built to serve humans. Humans should have full control over the AI ecosystem and supervise it to maintain accountability.

The fifth sutra is “Accountability”, to ensure the AI ecosystem is built on people’s trust. The AI Developers and Deployers should ensure that the system they built is reliable and accountable, based on due diligence and risk of harm. Accountability can also be imposed by policy frameworks and technical and market-influenced mechanisms.

Sutra “Accountability” treats harm as the ground for assigning responsibilities for AI Developers and Deployers. Yet, the same government that adopted this framework removed the statutory definition of “harm” when the DPDP Act 2023 was enacted. The government failed to consider people as the primary criterion while framing the policies in the DPDP Act, 2023 and the IT Amendment Rules, 2026.

Conclusion

Both the DPDP Act, 2023, and the IT Rules, 2026, impose obligations on the intermediaries for deepfake-related harm, but these obligations are enforced through civil penalties, not criminal sanctions. The perpetrator can be punished under certain criminal provisions like the IT Act or the BNS, but the existing law has not been framed to address violations involving synthetic media content. A further gap lies in the exemption that Section 3(c)(ii) of the DPDP Act grants for publicly available data. Also, the IT Rules, 2026, cannot create criminal liability for the perpetrator because it is subordinate legislation framed under its parent legislation, the IT Act, 2000.    

Section 3(c)(ii) of the DPDP Act, 2023, should be amended to limit the exemption for publicly available data when it is used to generate non-consensual synthetic media. Furthermore, the definition of harm must be expanded to recognise identity distortion, impersonation, damage to human dignity, and the distribution of non-consensual intimate imagery. Establishing a statutory civil right under the DPDP Act, 2023 – modelled after the US DEFIANCE Act, currently before Congress would allow victims to claim monetary compensation and reputational harm.

Separately, drawing from Section 138 of the UK’s Data (Use and Access) Act, 2025, Parliament should introduce a dedicated criminal offence under the Bharatiya Nyaya Sanhita, 2023, to hold perpetrators criminally liable.

Disclaimer:

This post is intended solely for general information and educational purposes. It does not constitute legal advice and should not be relied upon as a substitute for advice tailored to specific facts or circumstances. For guidance on a particular matter, please consult a qualified legal professional.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts