Author: Yashi Kesharwani
How do you react to discovering a non-consensual deepfake in India? A 24-hour emergency action plan
The initial realization of the existence of a digitally created likeness of oneself in a compromising or defamatory manner can be a very disorienting and disturbing experience. A structured and systematic approach is essential in order to limit the damage to one’s reputation and create a solid legal foundation. The first twenty-four hours are crucial to evidence preservation and the initiation of the formal legal and regulatory processes that are now possible under Indian law. The following action plan has been created to provide a sequential, hour-by-hour approach to the initial crisis stage.
The first hour of the process must begin with the preservation of evidence. This includes taking a screenshot of the webpage that the content is hosted on, as well as taking a series of screenshots or screen recordings that demonstrate the content within its context. If possible, the video file itself should be downloaded. At the same time, the time of discovery, the device used to discover the content, and any information related to the account from which the content was accessed should be recorded. This provides a chain of custody that is crucial for any legal action that may be taken later on. It is crucial to note the legal definition of the content. According to the 2025 amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, a ‘deepfake’ is defined as ‘synthetically generated information,’ which is ‘audio, visual, or text information that has been generated, modified, or manipulated using artificial intelligence to make it appear authentic.’ This definition of deepfakes separates malicious deepfakes from harmless digital edits, such as noise reduction and colour correction, which do not change the essence of the content.
After the evidence has been gathered, the following step is to engage the compulsory intermediary grievance process. The new IT Rules make it obligatory for social media platforms and other intermediaries to delete any synthetically generated content that has been reported as violative within three hours of receiving a complaint. One must first log on to the official grievance website of the hosting platform, whether Google, YouTube, or Instagram, and make a complaint with the necessary URLs and evidence gathered, clearly stating that the content is non-consensual and synthetically generated information, as defined under the IT Rules. This will initiate the legal obligation of the platform to take immediate action to remove the content, thus officially recording the violation. The three-hour window is an extremely effective mechanism for the immediate removal of content, but this requires a well-documented complaint.
After the complaint has been filed on the platform, the aggrieved party will then have to prepare and send the cease and desist letters. A legal notice must be sent to the identified perpetrator, if any, on the relevant provisions of Section 66E of the Indian Penal Code, which is an offense to violate privacy, and the consent provisions of the Digital Personal Data Protection Act (DPDPA) 2023. A notice may also be sent to the platform, reiterating the complaint and putting them on notice of their liability. These letters are helpful in establishing a paper trail of the efforts made by the aggrieved party, and may also help in establishing voluntary compliance before state enforcement becomes necessary. The language of the notice must be firm and refer to the relevant laws.
The next step is to involve the state apparatus by filing a First Information Report (FIR). The victim needs to contact the cyber-crime cell of their police district or the police station where the crime took place. The FIR needs to define the crime by mentioning sections 66C (punishment for identity theft), 66D (punishment for cheating by personation using computer resource), and 66E (violation of privacy) of the IT Act, 2000. It is also necessary to file the evidence that has been saved, such as screenshots, URLs, downloaded files, and copies of complaints filed on the platform. The FIR formally initiates the criminal justice system, which will help the police trace the origin of the deepfake and possibly track down the culprit. This step deals with the criminal aspect of the crime, which includes impersonation, fraud, and violation of privacy.
Lastly, in order to specifically deal with the misuse of personal biometric data, there is a parallel process available under the DPDPA. The DPDPA regulates the processing of personal data, which would include biometric data such as facial characteristics or voice patterns used to make a deepfake video. A formal complaint can be made to the Data Protection Board of India, alleging unconsented use of personal data for unauthorized purposes. The DPDPA gives the Data Protection Board of India the power to impose heavy penalties on data fiduciaries (which may include platforms) that do not live up to their obligations, with fines of up to ₹250 crore for serious offenses. This administrative complaint is made specifically for the data privacy violation, in addition to the criminal case filed through the FIR.
What is the advanced legal playbook after the initial takedown? Securing dynamic injunctions and long-term recourse
However, getting a takedown is only the first fight. The successful take-down of a dangerous deepfake work often leads to a longer war, as the more sophisticated attackers often re-post their work on new sites. This requires a move from a reactive approach to a sophisticated, proactive legal approach. The next important step, after following the enforcement playbook, is to ask for a dynamic injunction from a High Court.
This legal tool, commonly known as a John Doe order, allows victims to remove content from all platforms, even if they have not been discovered yet. In landmark cases, as seen in the Delhi High Court, these orders have been issued to proactively prevent the uploading of defamatory deepfake videos. This takes a formal writ petition with extensive evidence of the original incident, evidence of attempts to re-upload, and a clear case of why a standard takedown notice is inadequate. Although obtaining an order is a resource-intensive process, it is an effective way to end the cycle of harassment, which can take weeks to months, depending on the court’s docket and the complexity of the case.
Simultaneously, the victims must evaluate the options available for filing a case against the perpetrators for the damage caused to their reputation and psychology. A civil suit for defamation under Section 469 of the Indian Penal Code (IPC) enables the victims to seek compensation. The process involves filing a case in the competent court, which is normally the court in which the plaintiff is a resident or where the content was downloaded. The critical evidence required in such cases includes copies of the deepfake content preserved, reports from digital forensics confirming the content to be fake, evidence of the content’s dissemination and viewership, and testimony from witnesses about the effects of the content on the victim’s personal and professional life. The critical decision between a dynamic injunction and a defamation suit may depend on the urgency of the situation, with injunctions targeting the current dissemination of the content and suits targeting compensation for past dissemination.
In the case of deepfake operations that display elements of organized harassment or are a part of a larger cybercrime operation, the Bharatiya Nyaya Sanhita (BNS), 2023, provides a powerful criminal option. Section 111 of this act specifically deals with organized cybercrime, which may include organized deepfake attacks aimed at threatening, extorting, or defaming. The prosecution of this section is a serious process that begins with the filing of a First Information Report (FIR) with the police, encouraging them to probe the organized aspect of the crime. The punishment is very harsh, with imprisonment between three and five years, which is a measure of the seriousness of organized online harassment. This option indicates a strong state response but also involves ceding some control to public prosecutors and law enforcement agencies. The process takes a very long time, often several years, which must be considered in the overall strategy of the victims.
Apart from the conventional legal notices, strategic pressure on the intermediaries constitutes another foundation of the advanced playbook. The 2026 amendments to the IT Rules, particularly G.S.R. 120(E), are very stringent regarding the labelling and traceability requirements for platforms dealing with synthetic content. A victim can make use of this legislation by bringing it to the notice of the platforms that they have failed to comply with these particular requirements, thus jeopardizing the safe harbour provisions available to the intermediary under Section 79 of the IT Act. The legal rationale is that failure to comply with the labelling requirements amounts to a lack of due diligence on the part of the platform, which may make it liable for the deepfake content hosted on the platform.
The legal frontier is also expanding to cover personality rights and constitutional rights. Based on precedents such as the Supreme Court ruling in Shreya Singhal v. Union of India, which nullified Section 66A, one can make an argument for a broad interpretation of the right to privacy and harassment. This goes beyond the transactional nature of defamation cases to make a claim of a violation of one’s persona via AI-powered impersonation. A constitutional remedy petition can claim declaratory relief, holding that non-consensual deepfakes are violative of Article 21’s right to life and liberty. Though an untested and challenging course, it has the potential to influence future jurisprudence and provide greater safeguards against abuse.
Lastly, legal recourse must be accompanied by a comprehensive digital resilience strategy. This will include the use of privacy engineering techniques, such as digital provenance software that watermarks original content. The idea of an enforcement playbook will be incomplete without this proactive approach. Victims must keep a record of all events in great detail and store secure copies of evidence, as well as consider seeking pre-emptive legal advice to draft templates for responses. This multi-faceted approach, which combines immediate injunctions, strategic civil or criminal litigation, leveraging platforms, constitutional claims, and personal security, will provide a strong defence-in-depth strategy against deepfake abuse, seeking not only justice but also deterrence.
Hypothetical Template: Core Components of a Dynamic Injunction Application (John Doe Order)
Prayer for Relief | A straightforward prayer for relief seeking an order restraining all unknown parties (John Does) and intermediaries from uploading, sharing, or hosting the identified deepfake content or any variations thereof. |
| Statement of Facts | A chronological statement of facts surrounding the creation of the deepfake, the initial upload, takedown notices, and evidence of re-uploads or threats of further sharing. |
| Evidence Annexures | 1. Forensic analysis report confirming the content to be a deepfake. 2. URLs for the original and mirror uploads. 3. Copies of previous takedown notices and responses from the platforms. 4. Affidavits setting out the harassment harm. |
| Legal Grounds | Citing IT Rules (2025/26) on synthetic content, DPDPA provisions, IPC sections on defamation and cheating, and constitutional guarantees under Articles 19 and 21. |
Conclusion
To effectively deal with deepfake harassment in India, there has to be a multi-phase and multi-forum approach to enforcement. The first 24 hours of crisis response is critical to preserve evidence and initiate immediate removal actions, but it has to be followed up with more sophisticated legal remedies such as dynamic injunctions or civil/criminal litigation to obtain lasting relief.
Recommendations:
- The structured 24-hour action plan should be immediately activated upon identification to solidify evidence and engage all possible legal remedies.
- Legal advice from cyber law attorneys should be sought to develop a plan for the engagement of dynamic injunctions through either complementary civil or criminal remedies.
- A proactive digital resilience strategy should be employed, featuring content watermarking and monitoring solutions, to resist future attacks and enhance your legal position.