From Snapdeal to Physics Wallah: Is the CCPA Rewriting India's Safe Harbour Regime?
- Admin

- 2 days ago
- 7 min read
Author: Khushal Pandey, NLIU, Bhopal

Abstract
This article explores the evolving regulatory landscape of India’s digital economy and the growing pressure on the traditional safe harbour protection afforded to online intermediaries under Section 79 of the Information Technology Act, 2000. It focuses on the Central Consumer Protection Authority’s (CCPA) enforcement actions in early 2026, particularly its significant orders against Snapdeal (Ace Vector Limited) and PhysicsWallah Limited. By holding these platforms accountable for hosting non-compliant third-party products and employing manipulative interface designs commonly described as “dark patterns,” the CCPA has moved beyond the conventional notice-and-takedown framework that has long shaped intermediary liability in India.
The paper examines the resulting tension between the protections embedded in India’s cyber law framework and the obligations imposed through consumer protection regulations. In doing so, it considers the broader constitutional concerns raised by the use of delegated regulatory powers in an area traditionally governed by parliamentary legislation, particularly in light of Section 81 of the IT Act. The analysis also draws on findings from a June 2026 Datum Intelligence report to demonstrate the substantial economic and behavioural impact of deceptive interface practices on consumers. It argues that these developments reflect a decisive shift in the Indian e-commerce ecosystem from caveat emptor to caveat venditor. The paper concludes that legislative intervention is necessary to reconcile these competing legal frameworks and provide greater regulatory certainty for digital businesses operating in India.
Keywords: Safe Harbour Immunity; Information Technology Act; Central Consumer Protection Authority; Dark Patterns; E-Commerce Regulations; Intermediary Liability; Consumer Protection; Caveat Venditor.
Introduction
The structural architecture governing India’s digital economy is currently undergoing a significant administrative realignment. On June 1, 2026, the Central Consumer Protection Authority (CCPA) issued a definitive final order imposing a financial penalty of ₹5,00,000 on the prominent educational technology entity, Physics Wallah Limited, for the systemic employment of "dark patterns" designed to manipulate its student user base. Coming within months of the CCPA’s landmark February 2026 strict liability order against Snapdeal (Ace Vector Limited), this enforcement trend indicates a shift that extends far beyond routine consumer protection. It signals a targeted, executive deconstruction of the statutory safe harbour immunity traditionally guaranteed under Section 79 of the Information Technology (IT) Act, 2000.
For over two decades, the operational viability of digital intermediaries in India has relied on the legal fiction of passivity. Section 79 serves as a statutory shield, insulating platforms from vicarious liability for third-party content, listings, or structural infractions, provided they maintain basic due diligence and adhere to a reactive "notice-and-takedown" mechanism.However, by interpreting user-interface engineering, algorithmic optimisation, and checkout defaults as autonomous "unfair trade practices," the CCPA has unilaterally accelerated a transition from caveat emptor (let the buyer beware) to an unyielding regime of caveat venditor(let the seller beware). This paper evaluates the statutory friction arising from the CCPA’s 2026 enforcement paradigm and examines the constitutional validity of using subordinate consumer regulations to abrogate a plenary legislative immunity.
The 2026 Enforcement Blueprint: Evaluating Snapdeal and PhysicsWallah
To map the incremental erosion of safe harbour, one must examine the twin regulatory orders that have redefined the boundaries of platform passivity in 2026. The initial shift occurred on February 13, 2026, when the CCPA penalised Snapdeal for hosting non-BIS-compliant toys uploaded by third-party merchants. Snapdeal mounted a classic defence under Section 79, asserting its status as a marketplace e-commerce entity exercising zero possessory or qualitative control over vendor inventory.
The CCPA rejected this argument, establishing an active operational threshold for digital marketplaces. The Authority ruled that when an e-commerce platform algorithmically curates transactionsvia proprietary promotional mechanisms such as "Deal of the Day" tags, localised logistical fulfilment, and internal refund processing, it actively shapes the commercial stream. Consequently, the platform can no longer claim the status of a neutral communication link, rendering it vicariously liable for statutory product defects.
The June 2026 PhysicsWallah order extended this doctrine from physical product non-compliance to purely digital architecture. Under the oversight of Chief Commissioner Nidhi Khare and Commissioner Anupam Mishra, the CCPA evaluated user-experience (UX) design choices through the strict lens of the Guidelines for Prevention and Regulation of Dark Patterns, 2023.The Authority penalised two distinct interface manipulations under Section 2(47) of the Consumer Protection Act, 2019.
First, the platform engaged in "basket sneaking" and "confirm shaming" by implementing an automated, pre-selected ₹10 donation default in the user checkout cart, paired with emotionally manipulative text regarding children's education to dissuade users from deselecting the charge.
Second, it enforced "forced action" by conditioning access to advertised "free" courses upon the mandatory surrender of students' personal data, including mobile numbers and email credentials, despite such data possessing no functional relevance to the delivery of the course content.
By penalising these design choices as independent statutory violations, the CCPA established an important precedent: a digital interface is a first-party product engineered directly by the platform, entirely removing it from the protective ambit of intermediary safe harbour.
The Statutory Friction: Section 79 vs. The Consumer Protection Framework
The jurisdictional gridlock emerging from these 2026 orders highlights an operational conflict between a primary Act of Parliament and delegated, subordinate legislation. Under Section 79(1) of the IT Act, an intermediary is statutorily exempt from liability for any third-party information, data, or communication link made available by it. The Supreme Court of India, in Shreya Singhal v. Union of India(2015) 5 SCC 1, solidified this protection by ruling that an intermediary's immunity remains intact until it receives "actual knowledge",narrowly defined as a formal court order or an executive notificationflagging a specific illegality, and subsequently fails to expeditiously remove the offensive content.
Conversely, Rule 4(3) of the Consumer Protection (E-Commerce) Rules, 2020 categorically mandates that no e-commerce entity shall adopt any unfair trade practice in the course of its business.When the CCPA designates automated app features, pre-checked boxes, or predatory data-collection loops as unfair trade practices, it completely bypasses the protective "notice-and-takedown" buffer.
This sets up an irreconcilable statutory contradiction. Under cyber law, a platform is legally innocent until an external authority formally identifies a specific third-party infraction. Under consumer law, the exact same platform is deemed continuously liable the moment its proprietary algorithms go live with a manipulative interface, irrespective of any external notice or third-party intervention.
Constitutional Dimensions of Administrative Overreach
From an administrative law standpoint, the CCPA's current enforcement trajectory tests the limits of executive authority. It is a foundational constitutional principle that subordinate legislation cannot dilute, modify, or completely write out an explicit statutory immunity granted by a parent plenary legislation passed by Parliament.
This principle is reinforced by the explicit statutory architecture of the IT Act itself. Section 81 of the IT Act contains a robust non-obstante clause, declaring that the provisions of the Act shall have an overriding effect notwithstanding anything inconsistent contained in any other law for the time being in force.Therefore, when an administrative body like the CCPA uses its rule-making powers under the Consumer Protection Act to penalise an intermediary for algorithmic configurations, it is arguably encroaching upon the legislative domain.
This jurisdictional overreach is further highlighted by recent legislative updates. When the Ministry of Electronics and Information Technology (MeitY) notified the IT Intermediary Amendment Rules, 2026, it focused extensively on regulating generative artificial intelligence and deep-tech due diligence, conspicuously leaving the foundational safe harbour framework for digital commercial transactions unamended.This legislative silence has allowed the CCPA to fill the regulatory vacuum, bypassing the strict bounds of Section 79 by evaluating digital interface designs through the lens of strict consumer tort liability.
The Pragmatic Reality of the Modern Digital Interface
While digital platforms will likely mount significant constitutional challenges before appellate courts, the operational reality within India's digital market is that the traditional "passive intermediary" status has ceased to exist. The immediate necessity for this aggressive regulatory posture is underscored by empirical market data. A June 2026 report by Datum Intelligence revealed that despite major digital platforms submitting formal compliance self-declarations, manipulative user interfaces continue to divert an estimated ₹25,000 crore to ₹28,000 crore from Indian consumers annually. The report highlights an "awareness paradox" wherein 88% of online buyers actively recognise these deceptive patterns, yet the vast majority still succumb to them because checkout flows are algorithmically optimised to bypass consumer autonomy.
The CCPA’s enforcement strategy is a direct response to this economic landscape. The regulator's operational stance reflects an understanding that modern web applications are not passive pipelines. If an entity designs the user interface, curates product visibility via proprietary search optimisation, retains consumer data, and monetises transactions through platform commissions, it is operating as an active market gatekeeper. Consequently, the regulator will no longer permit platforms to escape liability by relying on hands-off technicalities originally designed for early internet service providers.
Conclusion
The CCPA’s targeted campaign against non-compliant products and manipulative interfaces, anchored by the Snapdeal and PhysicsWallah precedents, represents a major milestone for digital consumer rights. However, achieving consumer welfare by systematically undermining established statutory safe harbours introduces a high degree of regulatory unpredictability for the digital commercial sector.
Currently, digital enterprises are forced to operate under a split legal reality: they remain insulated as neutral hosts under cyber law, while simultaneously being penalised as principal offenders under consumer law for the exact same interface configurations. To resolve this structural gridlock, Parliament must intervene to harmonise the two regimes. Until Section 79 of the IT Act is amended to draw a clear statutory line between purely passive web hosts and heavily financialised, algorithmically driven marketplaces, the CCPA’s enforcement orders will continue to occupy a precarious legal position. For the modern digital entity, the lesson of 2026 is absolute: caveat emptor has been entirely eclipsed by caveat venditor. If it occurs on your interface, you bear the liability.
References
Statutes & Constitutional Provisions
The Consumer Protection Act, 2019 (Act 35 of 2019), s. 2(47).
The Information Technology Act, 2000 (Act 21 of 2000), s. 79.
The Information Technology Act, 2000 (Act 21 of 2000), s. 79(1).
The Information Technology Act, 2000 (Act 21 of 2000), s. 81.
Rules, Guidelines & Government Notifications
Consumer Protection (E-Commerce) Rules, 2020, r. 4(3).
Central Consumer Protection Authority, Guidelines for Prevention and Regulation of Dark Patterns, 2023 (notified on November 30, 2023).
Ministry of Electronics and Information Technology, The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (notified on February 10, 2026).
Judicial & Administrative Orders
Shreya Singhal v. Union of India, (2015) 5 SCC 1.
Central Consumer Protection Authority, Order in PhysicsWallah Limited, Case No. CCPA-2/94/2025-CCPA (Issued on June 1, 2026).
Central Consumer Protection Authority, Final Order against Snapdeal (Ace Vector Limited) (Issued on February 13, 2026).
Reports & Media Releases
Central Consumer Protection Authority, Press Release: "CCPA takes action against E-commerce entities for selling toys that violates mandatory Toys Quality Control Order 2020" (February 16, 2026).
Datum Intelligence, "Dark Patterns in India’s Online Marketplaces" (Report, June 2026).
Note - The information contained in this blog is for general informational purposes only. We endeavour to keep all content accurate, updated, and free from any form of misinformation or objectionable material. However, we shall not be responsible for any claims arising out of copyright infringement, plagiarism, or related issues; such responsibility lies solely with the respective authors. If you find any misinformation or objectionable content on this website, please report it to us at: editors.ilw@gmail.com




Comments