Fake social-media account impersonating you — how to get it taken downA fake social-media account that impersonates a real person engages four overlapping regimes — Section 66D of the IT Act, 2000 (cheating by personation by computer resource), Rule 3(2)(b) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (24-hour impersonation takedown), the Section 79 safe-harbour conditionality after Shreya Singhal, and Section 69A blocking. This piece sets out how the four interact and the working route to takedown. Twenty-four hours, three statutes, one identityto reclaim
[ Everyday Law ]

Fake social-media account impersonating you — how to get it taken down

A fake social-media account that impersonates a real person engages four overlapping regimes — Section 66D of the Information Technology Act, 2000 (cheating by personation by computer resource), Rule 3(2)(b) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (twenty-four-hour impersonation takedown), the Section 79 safe-harbour conditionality after Shreya Singhal v Union of India, and the Section 69A government-blocking power. This piece sets out how the four interact and the working route to takedown.

Impersonation on a social-media platform is not, in Indian law, a single offence with a single remedy. It engages two parallel statutory architectures that have evolved in tension with each other over the last decade. The first is the IT Act offences regime — Section 66D (cheating by personation by computer resource) and Section 66C (identity theft) — backed by the cognate crimes in the Bharatiya Nyaya Sanhita, 2023: Section 319 (cheating by personation) and Section 356 (defamation, where the impersonating account also defames). The second is the intermediary-liability and content-takedown architecture — Section 79 of the IT Act (safe harbour for intermediaries), the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Section 69A blocking power. The two run on different time-scales and different evidentiary requirements; a careful complainant invokes both. This piece sets out how the architecture works in 2026, after Shreya Singhal v Union of India, (2015) 5 SCC 1, Christian Louboutin SAS v Nakul Bajaj, 2018 SCC OnLine Del 12215, and the 2024 Bombay High Court ruling in Kunal Kamra v Union of India, 2024 SCC OnLine Bom 360.

The offence — Section 66D IT Act and the BNS overlay

Section 66D of the Information Technology Act, 2000 reads: "Whoever, by means for any communication device or computer resource cheats by personating, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees." The provision was inserted by the 2008 amendment. Its drafting is functional rather than elegant — it captures any cheating that is achieved through a computer resource by means of personation, irrespective of whether the personated person is real or fictitious, and irrespective of whether the impersonation has produced a downstream pecuniary loss at the time the offence is investigated. The cheating need only be in train.

Section 66C of the IT Act runs in parallel — it criminalises the fraudulent or dishonest use of the electronic signature, password or any other unique identification feature of any other person. Where the fake account uses the victim's photograph as a profile picture, lifts the victim's biographical content, or appropriates handles closely modelled on the victim's identity, Section 66C is in play; it does not require the additional ingredient of cheating that Section 66D imports.

The general criminal-law overlay is supplied by the Bharatiya Nyaya Sanhita, 2023. Section 319 BNS [Sections 416 and 419 IPC] is the cheating-by-personation offence in its general form, punishable with imprisonment up to five years and a fine; the section is more capacious than Section 66D because it does not require a computer-resource mediation. Section 318 BNS [Section 415 read with Section 420 IPC] is the parent cheating offence. Where the fake account also disseminates defamatory content about the victim, Section 356 BNS [Sections 499 and 500 IPC] is engaged — the section continues the common-law definition of defamation, with the recognised exceptions, and is now non-cognizable and bailable as before. Where the fake account uses morphed or sexually explicit imagery, Section 67 of the IT Act and Section 79 BNS [Section 354A and Section 354D IPC] are added.

The investigation runs under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 [Section 154 CrPC], with the proviso that for IT Act offences the investigating officer must be of the rank of Inspector or above (Section 78 IT Act). The criminal route — slow, custodial-light because Section 66D is bailable, and territorially complicated where the impersonator's location is unknown — is rarely the fastest path to relief. The faster path is the intermediary-takedown route under the IT Rules 2021.

Section 79 IT Act — safe-harbour conditionality after Shreya Singhal

The intermediary-liability architecture in India turns on Section 79 of the IT Act, which grants intermediaries (social-media platforms, hosting services, ISPs, search engines) a conditional immunity from liability for third-party content. Section 79(1) supplies the immunity; Section 79(2) lays down the conditions — the intermediary's function must be limited to providing access to a communication system, the intermediary must not initiate the transmission, select the receiver, or modify the information, and the intermediary must observe due diligence and comply with the guidelines prescribed by the Central Government. Section 79(3) cuts down the immunity — it is lost if the intermediary has conspired in or abetted the unlawful act, or if, upon receiving actual knowledge or being notified by the appropriate government or its agency that any information residing on its computer resource is being used to commit the unlawful act, the intermediary fails to expeditiously remove or disable access.

The Supreme Court's reading of Section 79(3)(b) in Shreya Singhal v Union of India, (2015) 5 SCC 1, is the constitutional pivot. The Court held that "actual knowledge" in Section 79(3)(b) must be read down to mean knowledge from a court order or a government notification under Section 69A — and not, as the older reading had it, knowledge from a private complaint by a user. The effect of the read-down was structural — a private user's takedown request to an intermediary does not, of itself, expose the intermediary to liability for non-removal. The intermediary remains within the safe harbour unless and until a court orders takedown or the government issues a Section 69A blocking direction.

The Shreya Singhal read-down has been the doctrinal anchor for every subsequent intermediary-liability ruling. The Delhi High Court in Myspace Inc v Super Cassettes Industries Ltd, 2016 SCC OnLine Del 6382 and the broader e-commerce intermediary jurisprudence in Christian Louboutin SAS v Nakul Bajaj, 2018 SCC OnLine Del 12215, applied the framework to commercial-content disputes — the Louboutin ruling, by Pratibha Singh J, drew a sharper line between "passive intermediaries" (mere conduits, fully within the safe harbour) and "active intermediaries" (platforms that curate, promote or warrant content, with a thinner safe harbour). The active/passive distinction continues to inform the takedown framework — platforms that algorithmically promote impersonating accounts have, in the recent High Court decisions, been treated as more proximate to the harm than platforms that merely host.

The IT Rules 2021 and the twenty-four-hour impersonation takedown

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — notified in February 2021 and progressively amended — are the operational architecture for content takedown in India. They are framed under Section 87(2) of the IT Act read with Section 79(2)(c), and they specify the due-diligence obligations that an intermediary must observe to retain its safe harbour. The Rules apply to all intermediaries and impose enhanced obligations on Significant Social Media Intermediaries (SSMIs) — those with over fifty lakh registered users in India.

Rule 3 lays down the due-diligence obligations. Rule 3(1)(b) requires the intermediary's terms of service to prohibit specified categories of unlawful content — including content that impersonates another person, is grossly harmful, violates intellectual property rights, or is paedophilic, defamatory, or invasive of privacy. Rule 3(1)(c) requires the intermediary to inform users at least once a year of the consequences of violating the terms.

Rule 3(2) is the operational provision for grievance redressal. Rule 3(2)(a) requires every intermediary to publish on its website and mobile app the name and contact details of the Grievance Officer, who must be a person resident in India. Rule 3(2)(a)(i) sets the timeline — the Grievance Officer must acknowledge a complaint within twenty-four hours and dispose of it within fifteen days. Rule 3(2)(b) is the impersonation-specific provision — it requires the intermediary to remove or disable access to any content that "exposes the private area of such individual, shows such individual in full or partial nudity or shows or depicts such individual in any sexual act or conduct, or is in the nature of impersonation in an electronic form, including artificially morphed images of such individual" within twenty-four hours of the complaint. The twenty-four-hour clock under Rule 3(2)(b) is the single most important practical provision for an impersonation victim — it bypasses the slow Grievance Officer process and imposes a strict same-day-or-next-day takedown obligation on the platform.

The 2022 amendment to the Rules introduced Rule 3A — the Grievance Appellate Committee (GAC). A user whose grievance has been decided adversely by the Grievance Officer (or whose grievance has not been decided within fifteen days) has a right of appeal to the GAC within thirty days. The GAC is required to dispose of the appeal within thirty days. Three Committees were constituted in early 2023 under the Ministry of Electronics and Information Technology. The GAC framework — the central executive-arm appellate mechanism over private platform decisions — was the principal subject of constitutional challenge in the 2023 amendments litigation that culminated in Kunal Kamra v Union of India, 2024 SCC OnLine Bom 360.

Kunal Kamra arose from a different limb of the 2023 amendments — the introduction of the Fact-Check Unit under Rule 3(1)(b)(v), authorising a government-notified body to identify "fake, false or misleading" information about government business and to require intermediaries to act on it. The Bombay High Court, on the split verdict of Patel J (against) and Neela Gokhale J (for) followed by the tie-breaker ruling of Chandurkar J (against), struck down the Fact-Check Unit amendment as unconstitutional under Articles 14 and 19(1)(a) of the Constitution. The ruling has not displaced Rule 3(2)(b) or Rule 3A — both continue to operate — but it has signalled that the constitutional ceiling on intermediary regulation, articulated in Shreya Singhal, remains a live constraint. A pending challenge to other limbs of the Rules continues before the Supreme Court.

Section 69A blocking — the government route, not the user route

Section 69A of the IT Act and the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009 supply the government's content-blocking power. The provision authorises the Central Government to direct any agency or intermediary to block public access to any information generated, transmitted, received, stored or hosted in any computer resource, in the interest of the sovereignty and integrity of India, defence of India, security of the State, friendly relations with foreign States, public order, or for preventing incitement to the commission of any cognizable offence.

The Section 69A power is constitutionally valid — Shreya Singhal v Union of India, (2015) 5 SCC 1 upheld it together with the 2009 Blocking Rules, on the reasoning that the provision is narrowly drawn, contains procedural safeguards (a designated officer, a review committee, a written-reasons requirement), and is confined to the Article 19(2) heads. But it is a government-driven mechanism. A private individual cannot directly invoke Section 69A to have an impersonating account blocked; the route is through a representation to the designated officer of the Ministry of Electronics and Information Technology, and the decision is the State's, not the complainant's. Section 69A is therefore the right tool when the impersonating account is also a vehicle for incitement to violence, communal mobilisation, or threats to public order — situations in which the State interest aligns with the victim's. For an ordinary identity-protection complaint, Rule 3(2)(b) is the better instrument.

The Karnataka High Court's 2022 ruling in X Corp (formerly Twitter Inc) v Union of India and the subsequent appellate developments have clarified that intermediaries are bound to comply with Section 69A directions and have a limited right to challenge the directions where they are not channelled through the procedural framework of the 2009 Rules. The wider question of the transparency of the Section 69A process — whether the affected user has a right to be heard before her content is blocked — remains contested, with the academic commentary uniformly in favour of a stronger procedural-due-process reading and the Government's position resting on the confidentiality clauses of the 2009 Rules.

The takedown roadmap — what to do in the first seventy-two hours

The takedown process for a fake impersonating account is a matter of parallel filings, not sequential ones. Each filing has its own time-scale and its own threshold of proof.

Step 1 — Evidence preservation. Before notifying the platform, capture the impersonating account through dated screenshots (URL bar visible), a screen recording of the profile and a representative selection of posts, and where possible a notarised affidavit annexing the captures. The Wayback Machine and similar archive services can be used to create third-party-witnessed records of the profile state on the date of discovery. This is the foundational evidence for both the platform complaint and the FIR; an impersonation case lost at the evidentiary stage is invariably one in which the account was deleted before contemporaneous captures were made.

Step 2 — File the in-platform impersonation report under Rule 3(2)(b). All Significant Social Media Intermediaries — Meta (Facebook and Instagram), X, YouTube, LinkedIn, Snap, Threads — have impersonation-specific reporting forms. The report must identify the impersonating account by URL, identify the victim by their authentic account or by ID proof, and assert impersonation under Rule 3(2)(b). The platform's twenty-four-hour clock under Rule 3(2)(b) runs from the time the complaint is received. Where the platform has a verified-account programme (blue tick, business verification), the verified victim's report attracts a faster track in practice, though not as a matter of legal entitlement.

Step 3 — File the grievance with the Grievance Officer under Rule 3(2)(a). Independently of the in-platform impersonation report, file a written grievance with the platform's Grievance Officer (resident in India, contact details published on the platform's website per Rule 3(2)(a)). The Officer must acknowledge within twenty-four hours and dispose of the grievance within fifteen days under Rule 3(2)(c). The Grievance Officer route is the procedural predicate for the subsequent appeal to the GAC.

Step 4 — File the FIR under Section 173 BNSS. The criminal complaint runs in parallel, not after. The FIR is registered with the local cybercrime cell or the police station having territorial jurisdiction; invoke Sections 66C and 66D of the IT Act and Sections 319 and 356 of the BNS [Sections 416, 419 and 499 IPC], with Section 67 IT Act added where the impersonation involves morphed sexual imagery. If the SHO refuses to register the FIR, the remedies under Section 173(3) BNSS [Section 154(3) CrPC] (representation to the Superintendent of Police) and Section 175 BNSS [Section 156(3) CrPC] (direction by the Magistrate) are sequential. Lalita Kumari v Government of Uttar Pradesh, (2014) 2 SCC 1 holds that FIR registration is mandatory where the information discloses a cognizable offence — Sections 66C, 66D and 319 BNS all are.

Step 5 — Mirror at the National Cybercrime Reporting Portal. File the impersonation complaint at cybercrime.gov.in. The portal is mirrored to the State cybercrime cell and produces a complaint reference number that is useful as documentary support in subsequent platform escalations.

Step 6 — Escalate to the Grievance Appellate Committee under Rule 3A. If the Grievance Officer's decision is adverse, or if the fifteen-day disposal window expires without action, file an appeal to the GAC within thirty days at the GAC online portal. The GAC is required to dispose of the appeal within thirty days. The GAC's orders are binding on the intermediary; non-compliance results in the loss of Section 79 safe harbour. Where the impersonating content has already been disposed of as a Rule 3(2)(b) twenty-four-hour matter, the GAC route is typically not required; it becomes critical for the slower defamation- and harassment-adjacent complaints where the platform takes the view that the content does not meet the Rule 3(2)(b) threshold.

Step 7 — The civil and writ overlay. A John Doe (Ashok Kumar) injunction before the High Court of jurisdiction is available where the impersonating account is one of many unidentified accounts, where rapid takedown is essential, and where the criminal route is too slow. The Delhi High Court has, since the early 2010s, granted dynamic injunctions that bind not only the identified defendant but a class of similar future infringers — a framework grounded in the Christian Louboutin SAS v Nakul Bajaj active-intermediary doctrine. Where a State authority is complicit (a fake account masquerading as an officer, abetted by State inaction), a writ petition under Article 226 of the Constitution can be filed, invoking the informational-privacy framework of Justice K S Puttaswamy (Retd) v Union of India, (2017) 10 SCC 1.

Where the platforms diverge — practice in 2026

The IT Rules 2021 set a floor; the platforms diverge above the floor. The practical 2026 landscape is worth a candid sketch.

Meta's Facebook and Instagram operate the most mature impersonation-reporting flows, with verified-account fast-tracks and an internal twenty-four-hour service-level for the Rule 3(2)(b) category. Reports filed by an authentic account about another account using the same name, photograph, or handle tend to receive same-day disposition; reports filed without an authentic linked account tend to receive slower disposition. X (formerly Twitter) operates a parental-impersonation policy that was substantially tightened after the 2022–23 verification-system changes; impersonation reports against verified accounts (blue checkmarks) receive priority, but the platform's broader content-moderation reductions have affected throughput. YouTube's impersonation channel is documented but slower in practice for non-monetised channels; the DMCA-adjacent route for content lifted from the victim's own channel runs faster than the impersonation route. LinkedIn's professional-identity standard gives impersonation reports a relatively high priority. Snap, Threads and the newer platforms have variable maturity; the Rule 3(2)(b) twenty-four-hour clock is uniformly applicable but uniformly contested in practice.

Two emerging issues deserve mention. The first is the AI-generated impersonation problem — accounts that use generative-AI-produced imagery of the victim, deepfake video or voice, and AI-rewritten biographies. The Rule 3(2)(b) language ("artificially morphed images of such individual") is broad enough to cover the AI overlay, and the early Delhi High Court orders in the deepfake-celebrity disputes (the Anil Kapoor v Simply Life India, 2023 SCC OnLine Del 6914 personality-rights line) confirm that the doctrinal framework adapts. But the evidentiary thresholds for AI-generated material — verifying authenticity, attributing creation, identifying the propagating account — are higher and the takedown timelines slip in practice.

The second is the cross-border platform problem. Where the impersonating account is hosted by a platform that has not appointed an Indian Grievance Officer, the Rule 3(2)(b) clock is unenforceable in practical terms. The Section 79 safe-harbour loss is the formal remedy — and the Government has used the threat of safe-harbour loss to secure compliance — but the victim's individual remedy depends on the platform's voluntary participation in the Indian framework. The DPDP Act, 2023, when fully operationalised through 2025–2026, will add a horizontal data-protection overlay that places a stronger compliance obligation on the platforms, including foreign-headquartered ones, but the interaction with the IT Rules 2021 framework is still being worked out.

Open questions and unresolved doctrinal tensions

Three doctrinal questions remain unresolved in 2026.

The first is the precise scope of Rule 3(2)(b)'s "in the nature of impersonation" language. The platforms have read the phrase narrowly to require identity-deception of a recognisable real person; the academic and consumer-protection commentary has pressed for a broader reading that captures parody and satire-shading-into-impersonation. The High Courts have not yet drawn a consolidated line, and there is some divergence between the Delhi, Bombay and Karnataka rulings on parody accounts.

The second is the constitutionality of the GAC under Rule 3A. The Government's position is that the GAC is an executive grievance-appellate mechanism with no judicial functions; the civil-society challenge — pending in different forms before different High Courts — is that the GAC's binding power over private platform decisions, the executive composition of the GAC (no judicial member), and the absence of an explicit statutory anchor in the IT Act, place it in tension with the separation-of-powers framework. Kunal Kamra v Union of India, 2024 SCC OnLine Bom 360, on the Fact-Check Unit limb, has not directly settled the GAC question but has set up the analytical framework within which it will be resolved.

The third is the future of Section 79 safe-harbour itself. The 2023 amendments to the Rules, the parallel Digital India Act drafts circulated by MeitY, and the Supreme Court's pending consideration of the broader intermediary-liability framework all point to a recalibration. Whether the recalibration will preserve the Shreya Singhal read-down of Section 79(3)(b), tighten it (towards a notice-and-takedown standard with thinner safe harbour), or replace Section 79 entirely with a new statutory regime, is the central open question of Indian internet law in 2026.

For the individual victim, however, the 2026 framework is workable. Rule 3(2)(b) supplies a twenty-four-hour takedown clock that is enforceable in practice on the major platforms. Section 66D and the BNS overlay supply the criminal route. Section 69A is held in reserve for the State-interest cases. The constitutional ceiling — Shreya Singhal and the post-Puttaswamy informational-privacy framework — disciplines the architecture. A complainant who works the four regimes in parallel, with the evidence preserved at the outset and the filings synchronised in the first seventy-two hours, has a serious prospect of reclaiming her identity on the platform within days, and of holding the impersonator to account in the criminal courts over the longer arc.