
Introduction
The internet has made Child Sexual Abuse Material (hereinafter referred to as “CSAM”) a profoundly transnational crime. A child may be located in India, the offender may operate from another jurisdiction, the platform may be incorporated in the United States, and the relevant electronic evidence may be stored across multiple servers. Yet, investigations continue to be constrained by legal frameworks built around territorial sovereignty, with cross-border evidence requests still largely routed through slow-moving instruments such as the India-US Mutual Legal Assistance Treaty in Criminal Matters officially known as “Treaty Between the Government of the Republic of India and the Government of the United States of America on Mutual Legal Assistance in Criminal Matters.”
This tension has recently come into sharper focus following concerns that India may need a formal data-sharing arrangement with the US to strengthen investigations into online CSAM. Reportedly, major US-based technology platforms continue to route reports concerning suspected CSAM through the US-based National Centre for Missing & Exploited Children (hereinafter referred to as “NCMEC”), while Indian authorities seek timely reporting and access to information necessary for domestic investigations. The issue is not merely one of technological cooperation. It represents a conflict between India’s interest in enforcing its criminal and intermediary obligations under statutes such as the Protection of Children from Sexual Offences Act, 2012 and the Information Technology Act, 2000, and the legal restrictions governing disclosure of data under US law, principally the Stored Communications Act.
The CSAM Reporting Chain and Its Jurisdictional Gap
The current reporting ecosystem is more complicated than it initially appears. Under US law, providers that become aware of certain apparent violations involving child sexual exploitation are required to report them to NCMEC’s CyberTipline, as mandated by Section 2258A of Title 18 of the United States Code. NCMEC functions as a clearinghouse and makes relevant reports and supplemental information available to appropriate domestic and foreign law-enforcement agencies. Significantly, the US statutory framework expressly contemplates the forwarding of reports to qualifying foreign law-enforcement agencies.
For India, however, the difficulty lies in the route through which information reaches domestic investigators. A suspected incident detected by a platform may travel from the platform to NCMEC, following which the report is routed through the relevant international law-enforcement mechanism before reaching the appropriate Indian agency. While NCMEC has maintained that its systems enable secure and rapid sharing, the recent concerns reported regarding possible delays demonstrate that the existence of a reporting mechanism is not equivalent to the existence of an efficient investigative mechanism.
In crimes involving children, this distinction is crucial. Digital evidence can disappear, accounts can be deleted, offenders can migrate across platforms and a delay in identifying a victim may mean continued exploitation. The legal system must therefore examine not only whether information is eventually shared, but also whether the reporting architecture is sufficiently transparent, accountable and swift.
When Indian Law Meets US Disclosure Restrictions
India’s position is rooted in a legitimate concern. A platform operating in India cannot necessarily treat reporting to a foreign organisation as a complete substitute for obligations imposed by Indian law, particularly the reporting and record-preservation duties under Section 15 of the POCSO Act and Section 67B of the Information Technology Act, 2000, read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. As reflected in the recent debate, Indian authorities have emphasised that suspected offences requiring reporting and investigation within India cannot be addressed solely by sending information into a foreign reporting ecosystem.
The platforms, however, confront a competing legal reality. Information held by US-based electronic service providers is subject to US law, including restrictions governing the disclosure of stored communications, principally the Stored Communications Act, 18 U.S.C. § 2701 et seq. The US framework does not simply permit a company to disregard domestic restrictions because another jurisdiction demands data. Section 2258A itself structures the reporting process around NCMEC and limits certain disclosures by providers, while also recognising disclosures to specified law-enforcement agencies and in response to legal process.
This creates what may be described as a compliance paradox. India may require meaningful cooperation with domestic authorities, while the platform may argue that directly transmitting particular categories of information to those authorities would expose it to legal constraints in the US.
The answer to this paradox cannot simply be to prosecute a local subsidiary and assume that criminal proceedings will produce data controlled elsewhere. Jurisdiction over a company is not always equivalent to practical control over the data sought. A local entity may not possess the relevant servers, accounts, communications or technical records. Consequently, domestic coercive measures, such as a notice for production of documents or electronic records under Section 94 of the Bharatiya Nagarik Suraksha Sanhita, 2023, or directions issued under Section 69 of the Information Technology Act, 2000, may establish legal accountability without necessarily solving the evidentiary problem.
The Limits of the Present Approach
The current discussion risks producing a false binary: either platforms directly hand over all information to Indian authorities, or India remains dependent upon a foreign intermediary. Neither position is entirely satisfactory. Direct and unrestricted access to platform data could undermine safeguards relating to privacy, legality and due process. At the same time, an opaque reporting chain in which authorities cannot identify where a report is delayed creates an equally serious accountability deficit.
Therefore, simply demanding “more data” may not be the correct policy response. India requires better access to legally obtainable, timely and actionable evidence, supported by a clear chain of responsibility.
Does India Need a Formal Data-Sharing Arrangement?
A formal India-US arrangement, of the kind the US CLOUD Act, 2018 enables through bilateral executive agreements between the US and qualifying foreign governments, could provide that missing legal bridge. However, such an agreement should not be conceived as an unrestricted mechanism through which Indian authorities obtain direct access to all data held by US technology companies. Its objective should instead be to establish a predictable framework for serious investigations involving defined offences, particularly child sexual exploitation. The framework could clarify the competent authorities, categories of permissible information, standards for requests, emergency procedures, preservation obligations and timelines for response.
Importantly, it could also address the gap between reporting and investigation. A CyberTip may alert authorities to suspected CSAM, but an effective prosecution may subsequently require additional subscriber information, account data, preservation of relevant records or other electronic evidence. These are distinct stages requiring different legal mechanisms.
The recent proposal regarding “supplementary tips” is relevant in this context. Where platforms cannot directly share protected content or communications with Indian authorities, they may potentially assist investigations through lawfully shareable metadata or other information relating to India-connected reports. Such a model recognises an important principle: legal cooperation need not begin only after every cross-border disclosure issue has been resolved. Information that can lawfully be shared may still enable investigators to preserve evidence, identify jurisdiction and initiate urgent protective action.
AMLEGALS Remarks
The demand for stronger action against online CSAM is unquestionably justified. However, the present controversy demonstrates that platform liability alone cannot resolve a structural problem of cross-border evidence. India can impose obligations upon intermediaries operating within its jurisdiction under the Information Technology Act, 2000 and the POCSO Act, 2012, but digital evidence does not necessarily remain within that jurisdiction merely because the service is available there.
A formal India-US data-sharing arrangement may therefore be necessary, not as a concession to technology companies, but as recognition that cross-border crime requires cross-border legal infrastructure. Yet, the agreement must be designed around more than access. It must ensure speed without arbitrariness, cooperation without surrendering sovereignty and child protection without weakening privacy and due process.
The question, therefore, is no longer whether India can demand more from global platforms. The more difficult and important question is whether India and the US can build a legal bridge capable of making child protection effective across borders without turning cross-border cooperation into borderless state access to personal data.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
