Rajamrit Das, 5th year, SLS Hyderabad
Over the past few months, India has introduced various laws regulating different online sectors, from Fintech to online gaming. However, what about online dating apps, which house not only impersonations but also various cybercrimes, including, but not limited to, fraud, financial scams, privacy breaches, extortion, and emotional manipulation?
While we swipe left or right, the hackers just clicking right may secure all our data on its fingertips. The biggest question that arises is how far-fetched the firewall of these dating apps is in protecting our sensitive data. Every now and then, incidents of financial fraud occur through these dating apps. In a recent report of India Today, a man from Bengaluru lost INR 1.29 Crores over an investment scam through emotional manipulation by a woman he met over a dating app. Before moving ahead to understand the remedies in such cases we should look forward to few crucial aspects of these dating apps.
DATING PLATFORMS AN UNREGULATED INTERMEDIARY
For the past few years, there has been a rapid increase in cybercrimes and data theft through dating apps. However, the question that still remains is which statutes regulate these entities and impose accountability. The Information and Technology Act, 2000, and its Rules thereunder along with the data protection laws are the primarily laws to regulated these entities, however the detailed mechanism under these statues still remains constricted.
The dating apps are designated as a “Significant Social Media Intermediary”, since the number of users being hosted on this platform are significantly above 50 Lakh (5Million) as of 2025. The term “Significant Social Media Intermediary” is defined as an Intermediary platform which primarily or solely enables online interaction between Users and allows them to create, upload, share, modify or access and disseminate Content, and has the number of registered users beyond the threshold notified by the Central Government.
The current threshold as notified by the Central Government, stands at 50 Lakh (5 million) and the combined registered users across the dating platforms are significantly above the threshold limit as of 2025, which thereby classifies the online dating apps as Significant Social Media Intermediaries, with platforms like Tinder and Bumble having significant market share.
The statutes mandate the following compliance to be made by the Significant Social Media Intermediaries (hereinafter referred to as the “Intermediary”) to safeguard the rights and information of the users:
- Due Diligence: The Intermediary shall on its e-platforms (whether website or mobile applications) explicitly mention and shall make reasonable efforts to prohibit the uploading, sharing, disseminating, or transmitting or even publication of obscene contents on its platform and take measures to prevent impersonations of individuals as per Rule 3(1).
- Grievance Redressal Mechanism: The Intermediary shall publish the name and contact details of its Grievance Officer on the website along with mechanism procedure through which users or a victim may make appropriate complaints and the complaint shall be acknowledged within 24 (twenty-four) hours along with the issue resolved within 15 (fifteen days) as per Rule 3(2).
- Message Identification: The Intermediary providing message transmission services shall enable the identification of the first originator of that information supplemented with a copy of such information in digital format as per Rule 4(2).
- Information Regulation: The Intermediary also needs to install technology-based filters like Artificial Intelligence (A.I) or automated tools that intercept and eliminate information describing obscene materials proactively as per Rule 4(4).
- Verifiable Account System: The Intermediary shall enable the users to voluntarily verify their accounts through measures including but not limited to email-id and Indian registered mobile numbers and shall issue a verification mark, visible to other users as per Rule 4(7).
Post the enforcement of the DPDP Act, 2023 and the rules thereunder, Intermediary will further be classified as Data Fiduciary and has few additional obligations to inform users of collecting and processing their personal and sensitive personal data, implement protective measures to protect the data, use the data for legitimate purposes and implement a grievance redressal mechanism in case of data breach and to notify the same within 72 (Seventy-Two) hours.
However, despite these structured frameworks, many dating platforms fail to comply with the basic compliance requirements, leading to cybercrimes through impersonation, allowing the posting of obscene content due to classifying them as “Sensual” and not implementing measures to protect the personal data of its users. This creates a grey area, where its becomes difficult for the authorities to regulate these entities due to the defense of them being merely an Intermediary rather than a Significant Data Fiduciary to evade accountability and additional compliance requirements to safeguard users on its platforms.
THE GREY AREA: LEGISLATIVE GAPS IN IMPOSING ACCOUNTABILITY TO THE DATING PLATFORMS
Online dating platforms have now become hubs for cyber fraud and misrepresentation. Every year, more than fifty such incidents are recorded across India, in a recent incident, a woman was duped of INR 68,500 by a man she met on a dating app, who impersonated him as a London based marine engineer, and won her trust through weeks of regular communications via chats and long phone calls and photographs of him in marine uniform with helicopter stories. The man informed that he would meet her in person and received a call from an unknown number claiming to be the airport’s customs department, due to his luggage being held up for expensive gifts. However, the woman demanded the receipts for the earlier payments, but none were produced.
Similarly, a fifty-year professional was defrauded of INR 73,42,000 by a woman he met on Bumble, who convinced him for investing in a fraudulent stock trading platform through regular communications. Consequently, the fraudsters also use emotional manipulation to extort huge amounts from individuals, in once such incident, an individual was defrauded of INR 1,29,00,000 by a woman he met on a dating app through emotional manipulations on the pretext on building an old-age home in his father’s name. Globally, in the United Kingdom, victims have lost GBP 106,000,000 through romance fraud in the hope of finding life partners on dating and matrimonial platforms.
These instances under the Indian criminal laws constitute the offense of Cheating by personation, as per Section 319 of the Bharatiya Nayay Sanhita, 2023, which, though, attracts a punishment of five years imprisonment with fine but often excludes the accountability of the dating platforms that facilitate these instances, due to the failure in regulating the information and users hosted. The very instance of incorporation beings when users upon platforms can extract the photographs and personal data of individuals such as name, age, contact, gender and other personal identifiable information through the dating apps. The A.I have also seen a sharp increase in the A.I generated images, wherein fraudsters not only impersonate non-living individuals but also disseminate AI-generated obscene content on the platform. To regulate the same the Meity through its proposed amendments which aims to regulate these AI-generated content by imposing obligations upon the Intermediary to obtain user declaration, deploy reasonable technical measures to verify the same and issue notice to label such content, along with additional due diligence to regulate such content.
THE WAY FORWARD
Primarily, these platforms shall implement technical measures, preventing screenshots which would effectively constrain the impersonations of individuals to a greater extent. Consequently, the platform shall implement A.I tools to effectively detect and flag A.I content and auto disable the user profile, disseminating the same. Consequently, the central government shall reduce the legislative gaps through amendments to the Information Technology Act, 2000 and rules there under by making the Intermediary to pay fine equivalent to the fraud amount due to the failure in due diligence. The Intermediary shall also be restricted to reserve data of users till 180 (One Hundred Eighty) days post their account deletion, which violates the privacy laws of India. The provisions of the current statutory provisions need to be flexible enough to increase accountability upon these platforms, with every proposed legislation aiming to regulate A.I shall have effective and explicit provisions regarding the platforms which generate, hosts and shares such content. The platform further shall implement real time user verification, wherein users are required to click and upload a real time photograph in order to verify the users authenticity and deploy the know your customer mechanism to ensure genuineness of the platform.
CONCLUSION
The Dating Platform still remains a significant, unregulated area, which enjoys leverage due to their status as Intermediary, the statutes must be amended to impose accountability on these platforms to reduce the instances of Cyber frauds. The state shall implement strict penalties for the non-compliances, by issuing standard operating procedures for these entities and constituting a board to regulate the Significant Social Media Intermediaries, considering the large number of registered user, the state shall also notify the platforms as Significant Data Fiduciaries. The platforms shall inform users about any duplicate account with their personal identifiable information to reduce instances of cyber-crime. In an era where individuals are glued to their devices and prefer interacting online rather than in-person, a statute regulating these entities and complementing the Information & Technology Act,2000 and the Digital Personal Data Protection Act, 2023 is the need of the hour.
