Legal liability of an open-source P2P messaging network developer and bootstrap server operator in India
1 Answer
Dear Client,
Considering the architecture outlined above, publishing open-source software and running a discovery server that has limited functionality is less risky than running a centralized messaging service that stores/transmits users' messages. However, because there is a discovery server in the equation, it becomes clear that one is not only an author of the software but also runs an online service that handles some data about the users (public keys, IP addresses, identifiers, and metadata about connections). Although one would not normally face any civil/criminal liabilities in case someone uses the software for illegal purposes without their permission, encouragement, or participation, the risk of being held liable may grow in case authorities find out that one knowingly facilitated the misconduct, disregarded any lawful demands, or had more control over communications than advertised. Depending on the exact implementation and scope of the project, clauses from the Information Technology Act, 2000, Digital Personal Data Protection Act, 2023, and intermediary-related principles may come into play. It is good to have such measures like privacy policy, terms of use, disclaimers, transparency documentation, abuse contact details, and proper technical knowledge about the capabilities of the server; however, all of them may help to show that your involvement in the process is minimal; yet, none of them can protect you from being legally responsible. Before launching it, it would be wise to have documented the data flow, reduced the data collection, made public your data retention policy, maintained records of the technical constraints of the server, developed a procedure to deal with any legal demands or governmental requests, and received advice from an Indian technology lawyer.
I hope this helps and if you have any further issues do not hesitate to contact us.