The TAKE IT DOWN Act is Public Law 119-12, enacted 19 May 2025. Section 3 gave covered platforms one year to stand up a notice-and-removal process, which is where the 19 May 2026 enforcement date comes from, and the FTC has been enforcing it since. Most operators arrive at the build with one number in hand — 48 hours — and no specification for the thing that starts it.
The specification exists. It is four clauses long, it is in the statute rather than in guidance, and it is worth reading in the original because the paraphrases drop things.
What makes an NCII removal request valid under the TAKE IT DOWN Act?
A removal request is valid when it contains four elements, in writing. Public Law 119-12 §3(a)(1)(B) requires that a notification and request for removal submitted through a covered platform’s process shall include a physical or electronic signature; an identification of the intimate visual depiction and information sufficient to locate it; a brief good-faith statement that the depiction is not consensual; and information sufficient to contact the person who filed. There is no fifth element, and a platform may not add one as a condition of validity.
That last point matters as much as the list. The four elements are a ceiling as well as a floor: an intake form that demands a government ID, a police report number or a platform account before it will accept a submission is not collecting a fifth statutory element, because there is no fifth statutory element. It is adding a barrier of its own making in front of an obligation the Act imposes on it.
Element 1: a physical or electronic signature
The statute requires “a physical or electronic signature of the identifiable individual (or an authorized person acting on behalf of such individual).” On a web form this is the field most often missing, because it looks like a formality next to the URL field and it is not one — it is the element that makes the submission a legal instrument rather than a message.
A typed full name in a dedicated field is an electronic signature, and it is the convention the DMCA notice form has used for a quarter of a century. A checkbox alone is weaker: it records assent to whatever text sits beside it but does not carry a name. The practical build is both — an attestation checkbox for the authorization question, and a text input where the filer types their name.
Element 2: identification of the depiction, and enough information to locate it
The statutory phrase is “an identification of, and information reasonably sufficient for the covered platform to locate, the intimate visual depiction.” A direct URL satisfies this cleanly. A description of a post the filer saw last month does not, and a platform is not required to run an investigation to convert one into the other.
The word doing the work is reasonably. It sets the bar at what a platform can act on, not at forensic precision, and it cuts both ways: a request naming a specific thread and timestamp on a service with search is locatable even without a canonical link. A form should accept multiple URLs per request, because a single depiction is routinely posted to several places at once and splitting that into separate submissions splits the audit trail for one incident.
Element 3: a good-faith statement that the depiction is not consensual
The full clause asks for “a brief statement that the identifiable individual has a good faith belief that any intimate visual depiction identified under clause (ii) is not consensual, including any relevant information for the covered platform to determine the intimate visual depiction was published without the consent of the identifiable individual.”
Summaries of the Act routinely stop that sentence at “good faith belief” and drop the clause after the comma. The dropped half is the operative one for a platform: it is the invitation for the filer to supply the context that lets the platform decide, which is the difference between a report a reviewer can act on and a bare assertion. A form that offers only a checkbox here collects the belief and none of the information. Pre-filling an editable statement and leaving room to add to it collects both.
Element 4: information sufficient to contact the individual
The statute asks for “information sufficient to enable the covered platform to contact the identifiable individual (or an authorized person acting on behalf of such individual).” An email address is the ordinary answer.
This element is also the hinge for the obligation the FTC layers on top of the statute in its business guidance: platforms should issue an identifying number for each request so that the filer, the platform and law enforcement are discussing the same image, and should tell the filer whether the content was removed or, if not, why. Neither is possible without a contact route, which is why a form that treats the contact field as optional quietly forfeits the ability to comply with the tracking guidance as well.
When does the 48-hour clock actually start?
On receipt of a valid removal request. §3(a)(3) reads: upon receiving a valid removal request through the established process, a covered platform shall, as soon as possible but not later than 48 hours after receiving such request, remove the depiction and make reasonable efforts to identify and remove any known identical copies.
Two consequences follow, and they point in opposite directions. An incomplete submission does not start a 48-hour clock — which is a reason to log completeness at intake rather than argue about it afterwards. But “as soon as possible” sits in front of the 48 hours, so 48 is a deadline and not an allowance; a platform that could have acted in two hours and used forty-seven has not obviously complied by finishing inside the window. The defensible position is a timestamped record showing when a complete request arrived and when the content came down.
What an intake form must not require
Two things, both of which small platforms build in by accident. The first is an account: the FTC states that “TIDA’s protections are not limited to individuals who hold an account on your platform,” and in-product reporting flows are almost always behind a login, so the reporting route has to exist outside it. The second is duplicate reporting: the FTC is explicit that people who file a request “do not need to report duplicate images” — finding known identical copies is the platform’s job, inside the same 48 hours.
The fuller list of platform-side obligations, in the FTC’s own order, is in the companion piece on how a small platform complies with the TAKE IT DOWN Act.
What if you remove content and the request turns out to be wrong?
The statute answers this directly, and it is the provision least often quoted in coverage of the Act. §3(a)(4) provides that a covered platform “shall not be liable for any claim based on the covered platform’s good faith disabling of access to, or removal of, material claimed to be a nonconsensual intimate visual depiction … regardless of whether the intimate visual depiction is ultimately determined to be unlawful or not.”
Read plainly, the risk is asymmetric by design. Acting in good faith on a request that later proves unfounded is shielded; failing to act on a valid one is an unfair or deceptive practice under §18(a)(1)(B) of the FTC Act, carrying civil penalties the FTC currently states at $53,088 per violation. A review process calibrated to avoid wrongful removals at the cost of missing the window is calibrated against the only one of the two outcomes that is actually penalised.
The four fields, as a form
| Statutory element | Field | Required |
|---|---|---|
| §3(a)(1)(B)(i) — signature | Typed full name, as an electronic signature | Yes |
| §3(a)(1)(B)(ii) — identification | One or more URLs locating the depiction | Yes |
| §3(a)(1)(B)(iii) — good-faith statement | Editable statement, plus room for supporting context | Yes |
| §3(a)(1)(B)(iv) — contact information | Email address for status and outcome | Yes |
| §3(a)(1)(A) — filed by the individual or an authorized person | Attestation checkbox | Yes |
| FTC guidance — request tracking | Identifying number issued on submission | Guidance, not statute |
Where TrustDesk fits
TrustDesk is a hosted NCII report intake form with the 48-hour clock and an append-only evidence log behind it. The form collects all four statutory elements and the authorization attestation, issues a tracking code on submission, emails the operator with one-click Removed and Rejected links, and writes every step — intake, signature, operator notification, decision, removal — to a log that cannot be edited after the fact. It sits outside any login, because the people who need it usually do not have one.
The policy text that has to be published alongside it — the “clear and conspicuous” notice §3(a)(2) requires — is free, with no account, from the generator on the pricing page. If the question you are actually weighing is whether to build this yourself, hand it to counsel, or host it, that comparison is in counsel, build, or hosted desk.
Every quotation on this page is from the enrolled text of Public Law 119-12 as published by the Government Publishing Office, read on 1 August 2026: the TAKE IT DOWN Act, full text. The penalty figure and the two “must not require” points are from the FTC’s business guidance, read the same day.