What are the legal obligations of a cyber café owner in India?
I run a cyber café and want to know what records I am legally required to maintain and what happens if a customer commits a cyber crime using my systems. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.
What are the legal obligations of a cyber café owner in India? is governed in India primarily by Information Technology (Guidelines for Cyber Café) Rules, 2011 and Information Technology Act, 2000 – Section 79. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.
Under the IT (Guidelines for Cyber Café) Rules, 2011, every cyber café must register with a registration agency (as notified by the state government) and maintain identity records of every user, verified through a government-approved photo ID.
You must maintain a log register (physical or electronic) with user identity, terminal used, and login/logout times for at least one year, and retain this log for inspection by authorised officers.
You must also take reasonable steps to ensure the layout of terminals allows a clear view of the screens (partitions cannot fully enclose a terminal) as a due diligence measure against misuse for illegal content.
If a customer misuses a terminal to commit a cyber offence, you as the cyber café owner are not automatically liable, but failure to maintain the required logs/ID records can be treated as failure of due diligence, which could expose you to liability under Section 79 read with the 2011 Rules for enabling the offence.
Cooperate fully and promptly with police/cyber cell requests for your logs during any investigation, since refusal or destruction of these records itself can attract separate liability for obstructing investigation.
What to do next: 1) Register your cyber café with the applicable state registration agency; 2) Maintain photo ID and login/logout records for every user for at least one year; 3) Ensure screens are not fully partitioned from view; 4) Cooperate promptly with any police request for records during an investigation.
If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology (Guidelines for Cyber Café) Rules, 2011 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.
Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.