UPSC Darpan

Internal SecurityGS322 September 2026

Google Follows Meta in Reporting Child Sexual Abuse Material Directly to MHA’s I4C, Bypassing US Clearinghouse

Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें

The news

New Delhi. Google India will report all child sexual abuse material (CSAM) detected on its platforms directly to the Indian Cyber Crime Coordination Centre (I4C), a Google spokesperson told The Economic Times on Monday, September 21. CSAM means any photograph, video or other material depicting the sexual abuse or exploitation of a child; courts and child-rights bodies now prefer this term to “child pornography”, which wrongly suggests consent. The I4C, an office attached to the Ministry of Home Affairs, manages the National Cyber Crime Reporting Portal. The move comes days after Meta, which owns Facebook, WhatsApp and Instagram, agreed to report child sexual abuse cases to appropriate law enforcement agencies in India; the ET says both companies will now proactively report such material. “Google is deeply committed to fighting CSAM online and preventing its platforms from being used to create, store or distribute such material,” the spokesperson said, adding: “As part of our ongoing discussions with the Government of India, we have respectfully proposed to operationalise the provision of relevant information to the I4C in cases related to CSAM.” The ET explains that Google was always legally obliged to report these crimes, but it currently sends CyberTipline reports to the National Center for Missing & Exploited Children (NCMEC), a U.S.-based non-profit that has historically forwarded them to law enforcement in various countries, and that this roundabout process creates delays and makes catching perpetrators difficult. The paper reports growing official concern: the National Commission for Protection of Child Rights (NCPCR) and the National Human Rights Commission had begun independent enquiries into advertisements of child-abuse content on Meta-owned platforms in India, and Meta India managing director and country head Arun Srinivas had been summoned by the NCPCR twice in the previous month. An official told the ET last week that the Ministry of Electronics and Information Technology (MeitY) has also been engaging with other platforms to proactively identify and remove such content. Google says it uses automated detection and human review, besides reports from users and third parties such as NGOs. In an ET podcast, lawyer Sajan Poovayya argues that algorithmic amplification — platforms’ recommendation systems pushing content to more users — and weak enforcement remain the real gaps. The syllabus link is GS3 on the role of media and social networking sites in internal security challenges and cyber security.

The chain in one line: U.S. law requires platforms to report CSAM to NCMEC’s CyberTipline → NCMEC forwards Indian cases to Indian authorities, causing delays → CSAM advertisements on Meta platforms prompt NCPCR and NHRC enquiries and summons to Meta India’s head → Meta agrees to report directly to Indian law enforcement → Google follows by proposing direct reporting to the MHA’s I4C

Static syllabus linkage

  1. The IT Act punishes CSAM more severely than other obscene content. Section 67B of the Information Technology Act, 2000, inserted in 2008, punishes publishing or transmitting material depicting children in sexually explicit acts, as well as creating, collecting, seeking, browsing, downloading, advertising or exchanging such material, and facilitating online abuse of children. The punishment is imprisonment of up to five years and a fine of up to ₹10 lakh on first conviction, and up to seven years and a fine of up to ₹10 lakh on a subsequent conviction. Section 79 gives intermediaries safe harbour from liability for third-party content only if they observe due diligence. Under the IT Rules, 2021, significant social media intermediaries must endeavour to deploy technology-based measures, including automated tools, to proactively identify child sexual abuse material.
  2. POCSO makes storing, sharing and failing to report CSAM offences. Section 15 of the Protection of Children from Sexual Offences Act, 2012, as amended in 2019, punishes storing or possessing pornographic material involving a child without deleting, destroying or reporting it to the designated authority, as well as storing it for transmission or for commercial purposes. In Just Rights for Children Alliance v. S. Harish (2024), the Supreme Court held that viewing, possessing or storing such material can be an offence under Section 15 of POCSO and Section 67B of the IT Act, and urged Parliament to replace the term “child pornography” with “child sexual exploitative and abuse material”. Section 19 of POCSO requires any person who knows of an offence to report it to the police or the Special Juvenile Police Unit.
  3. The I4C coordinates cyber policing in a federal system where police is a State subject. Police and public order are in the State List of the Seventh Schedule, so cybercrime investigation is mostly done by State police. The Ministry of Home Affairs set up the Indian Cyber Crime Coordination Centre, inaugurated in January 2020, to coordinate the response of law enforcement agencies across States, and it runs the National Cyber Crime Reporting Portal and the 1930 helpline for financial fraud. Direct reports from platforms to the I4C can therefore be routed quickly to the State police with jurisdiction. The National Commission for Protection of Child Rights is a statutory body under the Commissions for Protection of Child Rights Act, 2005.
  4. NCMEC became the world’s CSAM clearinghouse because of U.S. law. Under U.S. federal law, electronic service providers based in the United States must report apparent child sexual abuse material they become aware of to the CyberTipline run by the National Center for Missing & Exploited Children, a private non-profit. NCMEC then refers reports involving other countries to the authorities there. Since 2019, reports relating to India have been received by Indian authorities through an arrangement between the National Crime Records Bureau and NCMEC and passed to State police. Because the largest platforms are American, most reports of CSAM involving Indian users have travelled through the U.S. before reaching India.

Why UPSC loves this

  1. The syllabus names social media and cyber security explicitly. GS3 lists the “role of media and social networking sites in internal security challenges” and “basics of cyber security”. UPSC has asked about cyber threats, the IT Act and the regulation of intermediaries. A shift in how platforms report child-abuse material brings together cyber policing, child rights and platform regulation.
  2. Prelims tests institutions and their parent ministries. Questions on which ministry runs the I4C or CERT-In, which Act sets up NCPCR, and which section of the IT Act deals with an offence are typical. The distinction between the I4C under the Ministry of Home Affairs and CERT-In under MeitY is a common trap.
  3. Links to GS2 and ethics. Child protection is a GS2 theme on vulnerable sections, and the balance between privacy, encryption and child safety is a GS4 dilemma. The Supreme Court’s 2024 judgment on POCSO gives an up-to-date legal anchor.

Prelims nuggets

  • Section 67B of the Information Technology Act, 2000 punishes publishing, transmitting, browsing, downloading or exchanging material depicting children in sexually explicit acts.
  • The Indian Cyber Crime Coordination Centre (I4C) functions under the Ministry of Home Affairs and manages the National Cyber Crime Reporting Portal.
  • Section 15 of the POCSO Act, 2012, as amended in 2019, punishes storage or possession of child pornographic material without deleting, destroying or reporting it.
  • Under the IT Rules, 2021, a significant social media intermediary shall endeavour to deploy technology-based measures, including automated tools, to proactively identify child sexual abuse material.
  • The National Commission for Protection of Child Rights is a statutory body constituted under the Commissions for Protection of Child Rights Act, 2005.
  • Section 79 of the IT Act, 2000 exempts an intermediary from liability for third-party information only if it observes due diligence and does not initiate, select or modify the transmission.
  • ‘Police’ and ‘public order’ are subjects in the State List of the Seventh Schedule of the Constitution.

Analysis

  1. Direct reporting is a gain in speed, and speed is what child protection needs. The ET is right that the NCMEC route creates delays: a report generated in India travels to a U.S. non-profit, is processed there and then comes back. For a child who is being abused now, every day matters. Direct reporting to the I4C, which can pass it immediately to State police, shortens the chain. It also gives Indian authorities the same data at the same time as it reaches the U.S., rather than depending on another country’s priorities. This is a practical gain that does not need new legislation.
  2. Pressure from statutory commissions, not a new law, produced the change. The sequence is telling: NCPCR and NHRC enquiries, two summons to Meta India’s head, then Meta’s agreement, then Google’s. Statutory commissions used their power to summon and question to obtain a result that years of rules had not. This shows that the existing framework — Section 79 due diligence, the IT Rules and POCSO — is adequate on paper and weak in enforcement. The counter-view is that such pressure is ad hoc, and that a clear rule applying to all platforms would be fairer and more durable than company-by-company negotiation.
  3. More reports will mean nothing without capacity in State police. Platforms detect material in very large volumes, and a shift to direct reporting will send many more reports to Indian agencies. Police is a State subject, and many State cyber cells are understaffed and lack forensic tools and trained officers. If reports pile up unexamined, faster reporting will simply move the delay from the U.S. to India. The I4C’s value lies in triage — identifying the reports that point to a child in danger now — and in building State capacity, not just in receiving data.
  4. Removal and reporting do not fix amplification. Poovayya’s point in the ET podcast is that the real gap lies in algorithms that push harmful content to more users and in weak enforcement. Reporting deals with material after it is found; it does not stop recommendation systems from spreading it or advertising systems from carrying it, which is what the NCPCR enquiry into Meta concerned. A serious response would require platforms to audit how their recommendation and advertising systems handle child-abuse content. That is harder to agree than a reporting channel, which is perhaps why it has not been agreed.
  5. Data sovereignty here serves children, but the principle can be stretched. Direct reporting to an Indian agency is a form of data sovereignty — Indian data reaching Indian law enforcement without passing through another country. In the case of CSAM, there is little privacy argument against it, because the material is illegal everywhere. The risk is that the same channel is later expanded to other content where the case is less clear, such as political speech. Keeping the arrangement limited to CSAM, with clear safeguards and audit, would protect both children and the credibility of the channel.

Possible Mains question

“Child sexual abuse material online is a borderless crime policed through national systems.” In the light of Google and Meta agreeing to report such material directly to Indian authorities, examine the legal and institutional framework for tackling online child sexual abuse in India and suggest measures to strengthen it. (15 marks, 250 words)

Model approach

  1. Introduction. State the development: Google, following Meta, will report CSAM directly to the I4C under the Ministry of Home Affairs instead of relying only on NCMEC in the U.S.
  2. Body — legal framework. Explain Section 67B and Section 79 of the IT Act, the IT Rules, 2021 on proactive detection, Section 15 of POCSO as amended in 2019, and the Supreme Court’s 2024 judgment on possession and terminology.
  3. Body — institutional framework. Describe the I4C, the National Cyber Crime Reporting Portal, State police as the investigating agency, the NCPCR under the 2005 Act, and the earlier route through NCMEC and the NCRB.
  4. Body — gaps and measures. Discuss delays in the old route, State cyber-cell capacity, algorithmic amplification and advertising, victim identification and rehabilitation, and the risk of mission creep; suggest triage protocols, training and forensic labs, audits of recommendation systems, and clear limits on the reporting channel.
  5. Conclusion. Conclude that protecting children online needs cooperation between platforms, the Centre and States, with speed of action matched by capacity and safeguards.

Administrator's brainstorm

You are Superintendent of Police in charge of a district cyber cell. The I4C forwards a platform report showing a child in your district is being abused and the material is being shared. What do you do?

I would treat it as an emergency, since a child may be in danger now. I would form a small team with a woman officer, trace the account and location through the platform and service providers under legal process, and coordinate with the Child Welfare Committee and the district child protection unit for the child’s rescue and care. I would register an FIR under POCSO and the IT Act and preserve digital evidence carefully. The child’s identity must be protected throughout, as POCSO requires.

As a Joint Secretary in MeitY, other platforms ask whether they too must report directly to the I4C. How do you respond?

I would explain that the IT Act and the IT Rules already require due diligence and, for large platforms, proactive detection of CSAM, and that direct reporting to Indian law enforcement is the most effective way to meet these obligations. I would offer a standard technical format and a single point of contact with the I4C so that the burden is low. I would also make clear that the channel is limited to CSAM and illegal material of this kind. A consistent approach across platforms is fairer than separate negotiations.

An interview board asks: should platforms be required to break end-to-end encryption to detect child abuse material?

This is a genuine conflict between privacy and child safety, both of which are protected values. Breaking encryption for everyone would weaken security for all users, including children, and could be misused for surveillance. Better approaches include detection on unencrypted parts of services, reporting tools for users, metadata-based signals and strong investigation once a report is made. The law should push platforms to do everything possible short of breaking encryption, and review the balance as technology changes.