Information Technology Act, 2000

Cyber Cafe Guidelines Rules 2011: Registration, Identity and Logs

The cyber cafe was the anonymous public terminal of the early internet, and the 2011 Guidelines answered the anonymity with identity and logging: register the cafe, identify every user, keep the records, and lay the place out so it can be inspected. A cyber cafe is an intermediary, so compliance is the price of its safe harbour. Topic 73 placed the 2011 Rules in context; this note, as asked, covers the cyber cafe guidelines on their own.

1. The Framework

Source, purpose and consequence

Figure 1: Source, purpose and consequence

  • Source and status. The Information Technology (Guidelines for Cyber Cafe) Rules, 2011, notified on 11 April 2011 under s.79(2) read with s.87; a cyber cafe falls within the definition of an intermediary, so these are its due-diligence conditions (Topics 67, 73)
  • Purpose. Traceability of the users of shared public terminals, where the machine is not tied to any one person, the same anonymity problem the s.80 public-place search power addresses from the enforcement side (Topic 83)

2. The Duties

From registration to inspection

Figure 2: From registration to inspection

  • Registration. Every cyber cafe must register with a registration agency notified by the State Government and display its unique registration, bringing the trade into a licensed, identifiable set.
  • Identification of users. The cafe must identify every user against a photographic identity document, keeping a copy; a minor without such a document may be allowed only when accompanied by an adult who is identified, the core anti-anonymity duty.
  • Logs and history. A log register records each user's identity, the time in and out and the machine used, and the system keeps the browsing history and logs; these records are retained for a minimum of one year and made available to authorities (Topic 62)
  • Physical layout. Partitions and cubicles are limited to a stated height and screens are positioned for visibility, so the premises cannot be used for concealed activity and can be inspected.
  • Inspection. An officer authorised by the registration agency may inspect the cafe and its records at any time to verify compliance.

3. The Consequence

  • Safe harbour on the line. Because the cyber cafe is an intermediary, these Guidelines are its due-diligence obligations under s.79: failure to register, identify users or keep logs is a due-diligence failure that forfeits the s.79 safe harbour, exposing the cafe to liability for its users' unlawful acts (Topics 67, 99)
  • The investigative value. The logs and identity records are the first evidence in cybercrime traced to a public terminal, feeding the s.78 investigation and the s.80 search, and the one-year retention is calibrated to the life of such investigations (Topics 83, 86)
  • The declining context. As personal devices and mobile data displaced the cyber cafe, the Rules matter less in daily life but remain live law and a standard examination topic, and the same identity-and-log logic reappears in later intermediary and SSMI obligations (Topics 74, 76)

⚠ Exam trap

Fix the four duties, registration, identification of users against photo ID, logs and browsing history retained at least one year, and an inspectable physical layout, and the minors rule, no ID means only with an identified accompanying adult. Place the Rules under s.79(2) with s.87 and remember the consequence: a cyber cafe is an intermediary, so non-compliance forfeits its safe harbour, which is why these are called guidelines yet bite like conditions.

4. Frequently Asked Questions

What do the Cyber Cafe Guidelines Rules 2011 require?

That every cyber cafe register with a State-notified registration agency and display its registration; identify each user against a photographic identity document and keep a copy, serving minors without ID only when accompanied by an identified adult; maintain a log register of users with times and machine used, retain the browsing history and system logs for at least one year, and make them available to authorities; keep partitions and screens within a visibility-permitting layout; and submit to inspection. Because a cyber cafe is an intermediary, these are its due-diligence obligations under Section 79, and non-compliance forfeits its safe harbour.

5. Related Topics

  • Topic 73: IT Rules 2021 Framework. The intermediary rules family.
  • Topic 83: Section 80. The public-place search power over cyber cafes.