CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
UPDATES
PRACTICE AREAS
PEOPLE
News and Articles
privacy compliance mistakes,
Common Data Privacy Compliance Mistakes Businesses Should Avoid
Data privacy compliance is becoming an important business responsibility in India. As organisations collect more customer, employee and user information, even a small process failure can create legal, operational and reputational consequences. The most common privacy compliance mistakes do not always arise from deliberate misconduct. They often result from outdated policies, poor data visibility, weak vendor controls or a failure to connect legal requirements with everyday business processes. For Indian businesses, the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 provide the principal framework for digital personal data protection. The Rules were notified by the Ministry of Electronics and Information Technology in November 2025, with different provisions coming into force at different stages. Understanding common mistakes early can help businesses build practical privacy controls before compliance gaps become expensive problems. What Does Privacy Compliance Mean for an Indian Business? Privacy compliance involves more than publishing a privacy policy. A business needs to understand what personal data it collects, why it processes the data, who receives it, where it is stored, how it is secured and when it should be erased. Under the DPDP Act, organisations deciding the purpose and means of processing personal data are generally treated as Data Fiduciaries. Organisations processing data on their behalf may act as Data Processors. This distinction matters because responsibilities can extend across internal teams and external technology providers. For example, an online retailer may collect customer information through its website, transfer it to a payment provider, store account information with a cloud provider and use a marketing platform for communications. Each connection creates a data flow requiring appropriate oversight. Mistake 1: Treating a Privacy Policy as Complete Compliance One of the most common privacy compliance mistakes is assuming a well drafted privacy policy solves the compliance problem. It does not. A privacy notice describes processing. It does not automatically make the underlying processing lawful or secure. A company may state that personal information is deleted when no longer required. Yet its systems may retain old customer records indefinitely. A policy may promise appropriate security while employees continue using shared accounts or unrestricted spreadsheets. The real test is whether business practices match what the organisation communicates. Businesses should therefore review privacy documents alongside their actual technology systems, contracts and internal procedures. Current compliance commentary similarly identifies the gap between written policies and operational controls as a recurring weakness. Mistake 2: Using a Generic Privacy Policy A copied privacy policy may appear convenient, especially for a startup. It can also create significant problems. A generic document may refer to information the business does not collect while failing to disclose information it actually processes. It may describe rights or processing methods which do not match the organisation's systems. The better approach is to map actual data practices first. The privacy notice should then be prepared around the business model, technology environment, processing purposes and applicable legal requirements. A privacy notice should also be reviewed whenever the business introduces a major new product, tracking technology, vendor or processing purpose. Mistake 3: Not Knowing Where Personal Data Is Stored A business cannot properly protect information it cannot locate. Personal data often exists in more places than management realises. Customer relationship systems, cloud storage, employee devices, email accounts, spreadsheets, marketing platforms, support tools, application logs and backups may all contain personal information. Vendor systems can create another layer of complexity. A business may know its primary customer database but have limited visibility over information copied into third party systems. This can make it difficult to respond properly to correction, erasure or access related requests. A data inventory should therefore identify major data stores, purposes, owners, users, vendors and retention periods. Mistake 4: Assuming All Data Is Automatically Covered by Consent Consent is important, but businesses should not treat it as a universal answer. The DPDP Act provides for processing based on consent as well as specified legitimate uses. Where consent is relied upon, it needs to meet the statutory requirements. The business should understand precisely why consent is being obtained and what processing it relates to. A common operational problem occurs when one broad consent statement is used for several unrelated purposes. Businesses should instead examine whether each processing activity has an appropriate legal basis and whether the notice and consent mechanism accurately reflect the intended processing. Mistake 5: Making Consent Difficult to Withdraw Obtaining consent is only one part of consent management. Businesses also need a practical mechanism for withdrawal where consent is the basis for processing. If a user can provide consent in one simple step but must navigate several complicated screens to withdraw it, the process may create compliance and customer experience concerns. The DPDP Rules establish requirements concerning notices and mechanisms for exercising rights and withdrawing consent. Businesses should therefore test their consent journeys from a user's perspective.  Mistake 6: Ignoring Employee and Recruitment Data Privacy programmes often focus heavily on customers. Employee information can receive less attention. Recruitment forms, CVs, identity documents, payroll information, attendance records, performance records and workplace communications can all involve personal data. HR teams should understand how information is collected, used, stored and shared. The same principle applies to former employees and unsuccessful candidates where relevant records remain in organisational systems. A privacy programme should therefore cover workforce data rather than focusing only on customer facing activities. Mistake 7: Underestimating Vendor and Third Party Risk A business remains exposed when personal data is transferred to external technology providers. Cloud platforms, CRM systems, payment providers, payroll vendors, analytics services and customer support platforms can all process personal data. Yet businesses sometimes select vendors based almost entirely on price and functionality. Privacy and security should form part of vendor assessment. Contracts should clearly address the permitted processing, confidentiality, security expectations, incident reporting, cooperation and handling of information when the relationship ends. Businesses should also maintain an up to date record of major processors and the information shared with them. Mistake 8: Keeping Personal Data Indefinitely “Keep it just in case” is a poor data governance strategy. Retaining unnecessary personal information increases the volume of information exposed if an incident occurs. It can also make rights requests more difficult to fulfil. Businesses should define retention periods based on the purpose of processing, legal requirements and legitimate business needs. The DPDP framework includes obligations relating to erasure and specific retention requirements under the Rules. Deletion should also extend beyond the main database where appropriate. Businesses should consider archives, shared drives, application environments and other systems containing copies of personal information. Mistake 9: Ignoring Data Security Privacy and security are closely connected, but they are not identical. A business may have strong cybersecurity controls yet still process information for unclear purposes or retain it longer than required. At the same time, poor security can directly increase privacy risk. Section 8 of the DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. Businesses should consider access controls, authentication, encryption where appropriate, monitoring, backups, vulnerability management and employee security practices. Security controls should be proportionate to the organisation's data and risk profile. Mistake 10: Having No Data Breach Response Plan Many businesses think about breach response only after an incident occurs. By then, valuable time may already be lost. A business should know how employees report suspected incidents, who investigates them, who assesses affected systems and who manages regulatory and individual communications. The DPDP Rules establish breach related obligations, including requirements concerning intimation to the Data Protection Board and affected Data Principals. An incident response plan should therefore be tested rather than merely documented. A short tabletop exercise can reveal whether legal, technology, communications and management teams understand their respective responsibilities. Mistake 11: Forgetting Children's Personal Data  Children's data requires additional attention under the DPDP framework. The Act defines a child as an individual who has not completed eighteen years of age. It establishes additional requirements concerning verifiable parental consent and restricts certain forms of processing involving children. Businesses operating education platforms, gaming services, children's applications or other products likely to be used by minors should assess these requirements during product design. Age assurance and parental consent should not be added as an afterthought. Mistake 12: Assuming GDPR Compliance Automatically Means DPDP Compliance Some Indian businesses have already implemented GDPR programmes because they serve European customers. Those controls can provide a useful foundation. They do not automatically establish compliance with Indian law. The DPDP Act uses its own terminology, statutory framework and obligations. The Indian implementation timeline also follows a specific structure under the Act and Rules. Businesses should map existing privacy controls against the actual Indian requirements rather than simply declaring themselves DPDP compliant because they have a GDPR policy. Mistake 13: Failing to Update Privacy Documents After Business Changes Privacy practices evolve quickly. A company may introduce a new analytics tool, launch an application, start collecting location information, integrate an AI service or appoint a new marketing vendor. If the privacy notice remains unchanged, it may no longer accurately describe processing. A privacy review should therefore form part of the business change process. Product launches, acquisitions, new vendors, major technology changes and new markets should trigger a privacy assessment where relevant. Mistake 14: Providing Privacy Training Only Once Employees are often the first people handling personal information. Yet many organisations provide privacy training only during onboarding. Employees may later move between departments or begin using new systems. Their responsibilities can change significantly. Training should therefore be practical and role specific. Marketing teams need guidance on customer communications and data use. HR teams need guidance on employee information. Technology teams need security and access control awareness. Customer support teams need to recognise privacy requests. Mistake 15: Treating Privacy Compliance as a One Time Project Perhaps the biggest mistake is considering privacy compliance finished once the first audit is completed. Privacy is an ongoing business process. Technology changes. Vendors change. Laws evolve. Products expand. Data volumes increase. The DPDP Rules, 2025 themselves establish a phased implementation structure, with different provisions taking effect at different times. Businesses should therefore maintain a compliance calendar and review their controls periodically. How Businesses Can Prevent Privacy Compliance Mistakes The best way to reduce privacy errors is to connect legal requirements with operational controls. The process can begin with a data mapping exercise. The business should then identify its processing purposes, review its privacy notices, assess consent mechanisms, map vendors and establish retention rules. Next, the organisation should review security controls and create an incident response process. Responsibilities should be assigned internally. Privacy should not sit entirely with one person who has no control over technology, procurement or product decisions. For organisations considering privacy compliance lawyers, the most useful legal review is usually one connected to actual business processes. Legal advice should help translate statutory requirements into practical controls rather than simply produce another policy document. A Practical Privacy Compliance Review A useful internal review should ask several straightforward questions. Can the business identify all major categories of personal data it processes? Can it explain why each category is collected? Does its privacy notice accurately reflect those activities? Can it demonstrate consent where consent is relied upon? Can users exercise applicable rights through a practical process? Does the business know which vendors receive personal data? Are access permissions reviewed regularly? Are retention and deletion rules implemented in practice? Can the organisation respond quickly to a suspected breach? Can it demonstrate compliance through appropriate records? If the answer to several questions is no, the organisation may have a meaningful privacy gap even if it has a polished privacy policy. Why Privacy Mistakes Can Become Business Risks Privacy failures can create more than regulatory exposure. They can delay enterprise contracts. Customers may hesitate to use a service. Investors may raise questions during due diligence. Vendors may require additional contractual protections. A serious incident can also consume management time and damage reputation. For growing organisations, weak privacy governance can become increasingly difficult to correct because data flows multiply as the business expands. Early investment in proper governance can therefore be more efficient than attempting to reconstruct privacy controls after a major incident. Businesses seeking support from corporate compliance lawyers should consider privacy as part of wider corporate governance rather than treating it as a standalone technology issue. Conclusion Most privacy failures are preventable. The biggest risk arises when businesses assume compliance exists because a privacy policy has been published or a consent box has been added to a website. Effective privacy governance requires much more. Businesses need visibility over their data, clear processing purposes, appropriate consent mechanisms, reliable vendor controls, sensible retention practices and reasonable security safeguards. They also need processes capable of responding to individual rights requests and personal data breaches. For Indian businesses, the DPDP Act, 2023 and DPDP Rules, 2025 provide the central framework. The official legislation and Rules should be consulted when determining the current legal position because the framework has phased commencement and detailed requirements. Frequently Asked Questions (FAQs) Q1. What are the most common privacy compliance mistakes businesses make? The most common mistakes include using generic privacy notices, failing to map personal data, relying on poorly designed consent mechanisms, overlooking vendor risk, retaining information indefinitely, ignoring employee data and failing to prepare for breaches. Q2. Is having a privacy policy enough for compliance? No. A privacy policy is only one part of a broader compliance framework. The organisation's actual practices, systems, contracts and security measures should align with its stated privacy commitments. Q3. Does every business need consent before processing personal data? Not necessarily. The DPDP Act recognises consent as well as specified legitimate uses. Businesses should identify the appropriate statutory basis for each processing activity. Q4. How often should a business review its privacy compliance? There is no universal review frequency suitable for every organisation. A review should occur periodically and whenever significant changes occur in products, technology, vendors, processing purposes or applicable law. Q5. What should businesses do after discovering a data breach? The business should activate its incident response process, assess the incident, contain the issue, preserve relevant evidence and determine applicable notification and reporting obligations under the DPDP framework and any other applicable law. Q6. Are startups required to think about privacy compliance? Yes. A startup's size does not automatically remove privacy considerations. Early privacy governance can also prevent expensive restructuring when the customer base, technology environment and data volume increase. Q7. Does the DPDP Act apply to employee data? Personal data processed in digital form can fall within the Act's framework, subject to the Act's scope and applicable provisions. Businesses should therefore assess employee and recruitment data rather than assuming privacy compliance concerns only customers. Q8. Does children's data have additional protection? Yes. The DPDP Act contains additional requirements for processing children's personal data, including verifiable parental consent and restrictions on specified forms of processing. Q9. What is the biggest privacy compliance mistake? There is no single mistake applicable to every business. However, treating compliance as paperwork rather than an operational system is a recurring problem. A policy cannot compensate for unknown data flows, weak security, unmanaged vendors or ineffective rights processes.
business privacy requirements
How Businesses Can Comply with India's Data Protection Laws?
Businesses in India now need to treat privacy as an operational and governance issue, not simply a matter of publishing a privacy policy. Business privacy requirements increasingly affect how organisations collect customer information, manage employee records, use software vendors, respond to data requests and handle security incidents. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 form the central framework, while sector specific regulations and cyber security requirements can also apply. Since implementation is phased, businesses have an important opportunity to build their compliance framework before the main substantive obligations take effect. Top Four Search Results Reviewed for “Business Privacy Requirements” Search results for this topic vary considerably because the exact phrase “business privacy requirements” is not a standard Indian statutory term. Current results and closely related Indian privacy searches largely focus on DPDP compliance checklists, business readiness, consent, privacy notices, security, Data Principal rights and implementation timelines. The common search intent is practical. Businesses want to know whether the law applies to them, what they need to change, how consent should work, what documents are required, how data breaches should be handled and how much time they have to prepare. A stronger compliance guide also needs to distinguish statutory obligations from recommended governance measures and explain the phased commencement of the framework. What Are India's Data Protection Laws? India's principal general law for digital personal data is the Digital Personal Data Protection Act, 2023, commonly called the DPDP Act. Parliament enacted it on 11 August 2023. Its purpose is to regulate the processing of digital personal data while recognising an individual's right to protect personal data and the legitimate need for lawful processing. The Act uses three central concepts. A Data Principal is the individual to whom personal data relates. A Data Fiduciary is the person or organisation deciding the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary. For most businesses, the practical question is simple: if the organisation decides why customer, employee or user information is collected and how it will be used, it is likely to have Data Fiduciary responsibilities. The DPDP Rules, 2025 provide detailed operational requirements under the Act. MeitY notified the Rules on 14 November 2025. Who Needs to Comply? The DPDP Act can apply to organisations processing digital personal data in India. It can also apply to processing outside India where the processing is connected with offering goods or services to individuals in India. This makes the framework relevant to more than Indian incorporated companies. An overseas SaaS provider serving Indian customers may need to consider the Act. An Indian ecommerce platform will need to examine its customer data practices. A company employing staff in India must consider how it handles employee information. A startup using cloud applications can also have privacy obligations even if it has a small team. The scale of the organisation does not, by itself, determine whether privacy law is relevant. The nature of the processing matters. Start With a Personal Data Inventory The first practical step towards compliance is understanding what personal data the organisation actually handles. A business should identify the information collected through websites, mobile applications, customer forms, payment systems, recruitment portals, email campaigns, support desks and internal systems. The exercise should go beyond listing databases. The business should understand why information is collected, who can access it, where it is stored, which vendors receive it and when it is deleted. A data inventory often reveals unexpected processing. Marketing teams may use analytics tools. Human resources may upload employee information to cloud platforms. Sales teams may maintain contact databases in spreadsheets. Customer support teams may store conversation records. Each activity should be examined rather than assuming the company's main database represents the entire privacy landscape. Identify the Purpose of Each Processing Activity Purpose is central to effective privacy governance. Businesses should be able to explain why they need each category of personal data. A company collecting a telephone number for account verification should not automatically assume it can use the same information for every future marketing purpose. The purpose should be specific enough to guide employees and systems. This also helps businesses avoid excessive collection. If a service can operate without collecting a particular piece of information, the organisation should consider whether collecting it creates unnecessary legal and security exposure. Review the Legal Basis for Processing The DPDP Act provides for processing based on consent as well as certain legitimate uses specified under Section 7. This distinction is important. Businesses should not assume consent is required for every processing activity. Equally, they should not treat the existence of a business purpose as a substitute for the requirements imposed by the Act. Where consent is used, the organisation should ensure it meets the statutory requirements. Consent should be capable of being demonstrated. Businesses should therefore maintain appropriate records showing when consent was obtained and for which purpose. The consent mechanism should also allow withdrawal in accordance with the Act and Rules. Build a Clear Privacy Notice A privacy notice should explain what personal data is being processed and why. It should be written in language users can understand. It should not be buried behind complicated legal terminology. The DPDP Rules, 2025 provide specific requirements concerning notices. The framework expects notices to provide clear information concerning the personal data involved and the purpose for processing. Businesses should compare their privacy notice with their actual technology environment. If a website uses advertising technology, analytics tools, customer relationship management software or third party forms, the notice should reflect the actual processing arrangements. An outdated notice can create risk because it gives individuals an inaccurate picture of how their information is handled. Make Consent Practical and Auditable A consent mechanism should be designed as part of the user journey. Businesses should avoid relying on vague statements such as consent to “all business purposes”. The purpose should be sufficiently clear for the individual to understand what is being authorised. Consent records should also be retained in a form capable of demonstrating what happened. For example, a business may need to establish which version of its notice was presented, when consent was provided and whether the individual subsequently withdrew it. This becomes particularly important when organisations use multiple websites, applications or customer databases. Establish a Process for Data Principal Rights The DPDP Act gives Data Principals several rights, including rights concerning access to information, correction and erasure in specified circumstances, grievance redressal and nomination. Businesses need an operational mechanism for handling these rights. A customer should not have to contact five different departments to correct inaccurate information. The organisation should establish an internal route for receiving requests, verifying the requester, locating relevant data, determining the response and maintaining appropriate records. Customer support teams should understand when a routine customer complaint may actually involve a statutory privacy request. Strengthen Data Security Privacy compliance cannot be separated from information security. Section 8 of the DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The appropriate safeguards will depend on the organisation's size, systems, data and risk profile. Businesses should consider access controls, authentication, encryption where appropriate, system monitoring, secure backups, vulnerability management and appropriate incident response procedures. The goal is not simply to have a security policy. The organisation should be able to demonstrate reasonable security measures through actual technical and organisational controls. Prepare for Data Breaches A breach response plan should exist before an incident occurs. Businesses should know who receives an internal incident report, who assesses the scope of the incident and who decides whether regulatory or individual notifications are required. The DPDP Rules establish requirements concerning breach intimation to affected Data Principals and the Data Protection Board. Businesses should also consider separate cyber security obligations. CERT In's directions under Section 70B of the Information Technology Act require specified cyber security incidents to be reported within six hours of noticing the incident or being informed about it. This is a useful reminder that Indian privacy compliance cannot be assessed by looking at the DPDP Act alone. Review Contracts With Data Processors Modern businesses rarely process all personal data internally. Cloud providers, payroll companies, CRM platforms, payment providers, marketing tools and customer support vendors can all process personal information. Businesses should therefore review contracts with such providers. The agreement should address the permitted processing, confidentiality, security, incident reporting, cooperation and appropriate handling of personal data when the relationship ends. Vendor selection should also involve privacy considerations. A business should know what data a vendor receives and whether the vendor's systems create unnecessary exposure. This is especially important when several SaaS applications are connected to the same customer database. Control Internal Access to Personal Data Not every employee needs access to every customer record. Businesses should adopt role based access wherever practical. Employees should receive access appropriate to their responsibilities. Access should also be reviewed when employees change roles or leave the organisation. Shared passwords, uncontrolled spreadsheets and unrestricted administrator accounts can create avoidable privacy risks. Privacy governance is therefore closely linked with basic information security discipline. Establish Retention and Deletion Practices Keeping personal data indefinitely increases exposure. Businesses should identify how long different categories of information need to be retained for business, contractual, statutory or regulatory reasons. The DPDP Rules contain specific provisions concerning retention and erasure in certain circumstances and also provide special retention periods for specified classes of Data Fiduciaries. A sensible retention programme should therefore connect legal requirements with actual system functionality. If information is no longer needed, the business should have a controlled process for deletion or appropriate anonymisation where legally suitable. Pay Special Attention to Children's Data Children receive enhanced protection under the DPDP Act. A child is defined as an individual who has not completed eighteen years of age. Section 9 requires verifiable parental consent before processing children's personal data, subject to applicable provisions and exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being and places restrictions concerning tracking, behavioural monitoring and targeted advertising. The Rules provide additional requirements concerning verification of parental consent and identify specified exemptions for certain classes of organisations and purposes. Educational platforms, gaming services, healthcare providers and children's applications should therefore assess these requirements during product design. Determine Whether You Could Become a Significant Data Fiduciary The DPDP Act creates additional obligations for Significant Data Fiduciaries. Designation can take into account factors including the volume and sensitivity of personal data processed, risks to Data Principals and potential impacts involving national interests and public order. Significant Data Fiduciaries have additional responsibilities, including appointing a Data Protection Officer based in India, appointing an independent data auditor and undertaking specified impact assessments and audits. A business should monitor its processing profile as it grows. A company which begins as a small consumer application may eventually process enough information to require a substantially stronger governance structure. Examine Cross Border Data Flows Businesses with international operations should map cross border data movement. The DPDP Act permits the Central Government to restrict transfers of personal data to specified countries or territories through notification. This does not create a blanket requirement for all personal data to remain physically in India. Instead, organisations should understand where data is stored, who can access it and whether overseas group companies or technology vendors are involved. Cloud architecture should therefore be considered during privacy assessments. Consider Sector Specific Regulations The DPDP framework does not operate in isolation. Banks and financial institutions may have additional RBI requirements. Securities market entities may have SEBI obligations. Insurance businesses may need to consider IRDAI requirements. Telecommunications, healthcare, education and other regulated sectors can also involve additional privacy, security and record keeping obligations. A business should therefore identify its sector before preparing a generic compliance programme. Build Privacy Into Business Operations Privacy should not remain the responsibility of one legal or technology employee. Marketing teams decide how customer information is collected. Human resources manages employee information. Procurement selects vendors. Technology teams control access and security. Customer support handles individual requests. Each function therefore has a role. For businesses planning data protection legal services, the most useful approach is often to integrate legal analysis with technology and operational processes rather than treating privacy as a document exercise. Understand the Implementation Timeline The DPDP Act and Rules use phased commencement. The Act was enacted in 2023, but Section 1 itself provides for different commencement dates for different provisions. The Government's November 2025 notification brought several institutional provisions into force while scheduling the major substantive provisions for eighteen months after 13 November 2025. The Rules also follow a phased structure. Some provisions commenced upon publication, while other requirements have commencement dates one year or eighteen months after notification. MeitY provides the official Rules and enforcement timeline on its website. For businesses, the practical message is clear: the compliance programme should begin before the main obligations become operational. Common Mistakes Businesses Should Avoid A common mistake is assuming a privacy policy equals compliance. It does not. Another mistake is collecting excessive personal information without clearly defined purposes. Businesses also overlook personal data stored in spreadsheets, emails, messaging systems and third party applications. Some organisations rely on vendor contracts without checking whether vendors actually maintain appropriate security controls. Another weakness is the absence of evidence. A company may have a policy requiring deletion but no system capable of demonstrating whether deletion occurs. A mature programme therefore connects legal requirements with people, processes, contracts and technology. What Should a Business Do First? A practical starting point is a privacy gap assessment. The organisation should identify its data flows, processing purposes, legal bases, vendors, security controls, retention practices and user rights processes. It can then prioritise high risk areas. For example, a company processing children's data or financial information may need more immediate attention than a business processing limited contact information. The organisation should document the findings and assign responsibility for remediation. This creates an evidence trail and gives management a clearer view of privacy risk. Why Privacy Compliance Matters Beyond Legal Risk Privacy governance can influence more than regulatory exposure. Customers increasingly ask how their information is handled. Enterprise clients may require privacy representations during procurement. Investors may examine privacy controls during due diligence. Poor data governance can also make business expansion harder because new markets, new technology systems and new vendors create additional data flows. For businesses undertaking corporate legal compliance services, privacy should therefore sit alongside contracts, employment law, corporate governance and sector specific obligations. Conclusion Complying with India's data protection framework requires more than adding a privacy policy to a website. Businesses need to understand what personal data they collect, why they collect it, where it goes, who can access it and how long it should remain in their systems. They also need practical processes for consent, individual rights, vendor management, security, breach response and deletion. The DPDP Act, 2023 and DPDP Rules, 2025 provide the central framework, but sector specific regulations and cyber security requirements can create additional obligations. The phased implementation gives businesses time to prepare. The strongest approach is to use this period to conduct a data inventory, review processing purposes, update notices, assess vendors, strengthen security controls and establish an internal privacy governance process. Businesses should also monitor official Government notifications because commencement dates and regulatory guidance can affect the practical compliance position. The official Digital Personal Data Protection Act on India Code and Digital Personal Data Protection Rules, 2025 published by MeitY should remain the primary sources for determining the current statutory position. For businesses, privacy compliance is ultimately part of sound corporate governance. When personal data is handled responsibly from the beginning, organisations are better placed to manage regulatory change, protect customer trust and scale their operations with greater confidence. Frequently Asked Questions (FAQs)   Q1. What are the main business privacy requirements in India? The core requirements arise from the DPDP Act and Rules and can include lawful processing, appropriate notice, valid consent where relied upon, security safeguards, breach response, Data Principal rights, children's data protection, vendor governance and appropriate retention practices. Q2.Does the DPDP Act apply to small businesses? Potentially, yes. Applicability depends on the nature of processing and the statutory scope rather than simply the number of employees. Q3.Is a privacy policy mandatory for every business? Businesses should assess their specific statutory obligations and processing activities. More importantly, a privacy notice should accurately explain relevant processing where the framework requires notice. Publishing a generic privacy policy does not by itself establish compliance. Q4.Does every processing activity require consent? No. The Act provides for consent as well as certain legitimate uses under Section 7. Businesses should identify the appropriate statutory basis for each processing activity. Q5.What is a Data Fiduciary? A Data Fiduciary is the person or organisation deciding the purpose and means of processing personal data. Q6.What is a Data Processor? A Data Processor processes personal data on behalf of a Data Fiduciary. Q7.What rights do Data Principals have? The Act provides rights including access to information concerning personal data, correction and erasure in specified circumstances, grievance redressal and nomination. Q8.How should businesses prepare for a data breach? Businesses should establish an incident response process, identify responsible personnel, maintain appropriate security controls and understand both DPDP notification requirements and other cyber incident reporting obligations. Q9.Does the DPDP Act apply to foreign companies? It can apply to processing outside India where the processing is connected with offering goods or services to Data Principals in India. Q10.Are children's data subject to additional requirements? Yes. The DPDP Act provides enhanced protection for children's personal data, including verifiable parental consent and restrictions on certain forms of processing. Q11.What is a Significant Data Fiduciary? It is a Data Fiduciary designated by the Central Government based on factors specified in the Act. Such entities have additional governance, audit and impact assessment obligations. Q12.What are the maximum penalties under the DPDP Act? The Schedule provides penalties of up to ₹250 crore for specified failures concerning reasonable security safeguards. Other contraventions can attract penalties of up to ₹200 crore or ₹50 crore depending on the provision involved.
Digital Personal Data Protection Act,
The Digital Personal Data Protection Act, 2023 Explained in Simple Terms
The Digital Personal Data Protection Act is India's principal legislation governing the processing of digital personal data. For businesses, the law changes how customer, employee, user and other personal information must be collected, used, stored and shared. The framework is built around a balance between individual privacy and lawful use of data. The Act was enacted in 2023, while the Digital Personal Data Protection Rules, 2025 provide the operational framework for several obligations. Importantly, implementation is phased, so businesses need to distinguish between provisions already in force and provisions scheduled to commence later.This guide explains the law in practical language, with particular attention to what businesses need to understand before reviewing their privacy policies, contracts, technology systems and internal processes. What Is the Digital Personal Data Protection Act, 2023? The Digital Personal Data Protection Act, 2023, commonly called the DPDP Act, is India's dedicated statutory framework for digital personal data protection. Parliament enacted the legislation on 11 August 2023. Its stated purpose is to regulate the processing of digital personal data while recognising both an individual's right to protect personal data and the need for organisations to process information for lawful purposes. In practical terms, the law asks businesses to answer several basic questions. Why are you collecting someone's personal data? Have you provided an appropriate notice? Do you have a lawful basis for processing it? Are you collecting more information than necessary? Is the information secure? Can the individual exercise their statutory rights? What happens when the purpose for collection ends? These questions sit at the centre of the new compliance framework. When Does the DPDP Act Apply? The Act primarily concerns digital personal data. It applies to processing within India where personal data is collected in digital form. It also covers information collected in non digital form and subsequently digitised. The law can also apply outside India where processing is connected with offering goods or services to Data Principals in India. This means a foreign company serving Indian customers may need to consider the Indian framework even if its headquarters, servers or parent company are located overseas. There are exclusions. Personal data processed by an individual for a personal or domestic purpose falls outside the Act. Certain publicly available personal data is also excluded in circumstances specified by Section 3. The important point for businesses is scope. A company should assess its actual processing activities rather than assuming the law applies only to technology companies. A manufacturer with an employee database, an online retailer with customer accounts and a professional services firm managing client contacts can all have relevant processing activities. The Three Main Players Under the DPDP Act The Act uses terminology which businesses need to understand. A Data Principal is the individual to whom personal data relates. For a child, the statutory framework also recognises the parent or lawful guardian in the relevant context. A Data Fiduciary is the organisation or person deciding the purpose and means of processing personal data. This is broadly comparable to the concept of a data controller under some international privacy regimes, although the legal frameworks are not identical. A Data Processor processes personal data on behalf of a Data Fiduciary. For example, an online retailer may determine why customer information is collected and how it is used. The retailer may engage a cloud provider or software company to process the information. The retailer can therefore be the Data Fiduciary while the external service provider acts as a Data Processor. The distinction matters because responsibility does not disappear simply because processing is outsourced. What Does “Processing” Mean? Processing is broader than simply collecting information. The Act covers operations such as collection, recording, organisation, storage, adaptation, retrieval, use, sharing, disclosure, transmission, dissemination, restriction, erasure and destruction of digital personal data. This broad definition has practical consequences. A business processes personal data when a customer creates an account. It also processes data when the information is stored in a cloud platform, shared with a payment provider, accessed by customer support staff or deleted after the account is closed. Businesses therefore need to examine the complete data lifecycle. Consent Under the DPDP Act Consent is one of the most important concepts in the Act. Where consent is relied upon, it must be free, specific, informed, unconditional and unambiguous. It must involve a clear affirmative action and relate to the specified purpose for which the information is being processed. This means businesses should reconsider vague consent mechanisms. A pre selected box or a general statement hidden within lengthy terms may not provide the same level of clarity as an appropriately designed consent process. The Rules add further requirements around notices and consent mechanisms. Businesses should also remember one important point: consent is not necessarily required for every processing activity. The Act recognises specified legitimate uses and other statutory grounds. The correct approach is to identify the legal basis for each significant processing activity. What Is a Privacy Notice? A privacy notice tells the Data Principal how their information will be handled. The DPDP framework requires businesses to provide relevant information concerning processing. The 2025 Rules add detail regarding the manner in which notices should be presented. A good notice should be clear enough for an ordinary user to understand. It should not merely reproduce technical or legal terminology. It should explain the purpose of processing, the information involved and how the individual can exercise relevant rights. More importantly, the notice should accurately reflect the organisation's actual practices. If a company says information is used only to provide a service but its marketing team later uses the same information for unrelated advertising, the organisation may create a significant compliance gap. Rights of Data Principals The DPDP Act gives individuals specific rights concerning their personal data. These include rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination. For businesses, these rights require operational processes. An organisation should know who receives a request, how the identity of the requester is verified, which department investigates it, how the response is prepared and how the action is recorded. This becomes particularly important for businesses handling large customer databases. A privacy policy may provide a contact address, but the organisation still needs an internal workflow capable of responding to legitimate requests.  What Happens When a Person Withdraws Consent? The Act provides individuals with the ability to withdraw consent. The withdrawal mechanism should be as easy as the mechanism through which consent was given. The consequences of withdrawal also need to be understood. If an individual withdraws consent, the business must assess whether another lawful basis permits continued processing. If not, relevant processing should cease and applicable erasure requirements should be considered. This is one reason consent management should be integrated with business systems rather than treated as a standalone legal document. Special Rules for Children's Data The DPDP Act gives children additional protection. A child is generally an individual who has not completed eighteen years of age. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian, subject to prescribed exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being. It further restricts tracking and behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. For educational technology companies, gaming platforms, children's applications and other services likely to be used by minors, these provisions require specific attention. Security Obligations Under the Act A business cannot comply merely by obtaining consent. The Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The 2025 Rules provide additional detail regarding security safeguards, including measures relating to organisational and technical controls. Businesses should therefore examine access controls, authentication, encryption where appropriate, monitoring, security testing, incident management and vendor security. Security should be proportionate to the nature and volume of personal data involved. A company holding millions of customer records will generally require a more mature security programme than a small business maintaining a limited customer database.  What Is a Personal Data Breach? The Act defines a personal data breach broadly. It includes unauthorised processing and accidental or unlawful disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data which compromises its confidentiality, integrity or availability. This means a breach is not necessarily a dramatic cyberattack. An employee sending a customer database to the wrong recipient, unauthorised access to an internal system or accidental disclosure of information can potentially create a data protection incident. Businesses therefore need an internal reporting and response mechanism. Legal, security and management teams should know how an incident is escalated and what information needs to be preserved. Data Retention and Erasure The DPDP framework also addresses what happens when personal data is no longer required. Businesses should not treat every piece of information as an asset which must be stored indefinitely. Retention should be linked to the purpose for which the information was collected and any other legal requirement requiring continued retention. For example, a customer database may contain inactive accounts, old marketing records and information retained purely because no one has reviewed it. A proper retention schedule helps businesses identify information which should be removed. Deletion should also be considered across relevant systems, including third party platforms where applicable. Significant Data Fiduciaries The Act creates a special category known as a Significant Data Fiduciary. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as significant based on factors including the volume and sensitivity of personal data, risks to India's sovereignty and integrity, electoral democracy, security of the State, public order and other relevant considerations. Significant Data Fiduciaries have additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor and conducting specified assessments and audits. Large digital platforms and organisations processing significant volumes of sensitive information should therefore monitor whether this category becomes relevant to them. What Is the Data Protection Board of India? The DPDP Act establishes the Data Protection Board of India. The Board is intended to serve as the principal enforcement and adjudicatory body under the framework. The Government established the Board as a body corporate under Section 18. The Board's role includes dealing with contraventions and matters connected with enforcement of the Act. The framework also provides an appeal mechanism. The Telecom Disputes Settlement and Appellate Tribunal is identified as the Appellate Tribunal under the Act. For businesses, this means data protection is no longer simply a matter of internal corporate policy. There is a statutory enforcement structure behind the obligations. Penalties Under the DPDP Framework The financial consequences can be substantial. The Schedule to the Act provides for penalties of up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Certain breaches concerning notification of personal data breaches and children's data can attract penalties of up to ₹200 crore. Other specified breaches can attract penalties of up to ₹50 crore. These figures represent statutory maximums. They do not mean every breach results in the maximum penalty. The enforcement framework considers relevant circumstances when determining an appropriate penalty. Still, the potential exposure makes privacy governance a board level business concern for organisations handling substantial volumes of personal data. How the DPDP Rules, 2025 Fit Into the Framework? The Act establishes the legal framework. The Rules provide practical detail. The Government notified the Digital Personal Data Protection Rules, 2025 in November 2025. The Rules cover areas such as notice requirements, consent mechanisms, security safeguards, breach notifications, rights management, registration of Consent Managers and obligations relevant to Significant Data Fiduciaries. The Rules also provide a phased implementation period. This gives organisations time to adapt their systems. It does not mean businesses should wait until the final commencement date before starting their compliance work. Technology changes can take months. Contract revisions can take longer where multiple vendors or international group entities are involved. Understanding the Phased Commencement The DPDP Act does not become fully operational through a single commencement date. The Government's notification provides different commencement dates for different provisions. Sections 2, 18 to 26, 35 to 43 and specified parts of Section 44 commenced on 13 November 2025. Other provisions are scheduled to commence one year later, while the main operational provisions, including Sections 3 to 5 and Sections 7 to 17, are scheduled to commence eighteen months after 13 November 2025. This phased structure is important when writing internal compliance plans. A business should identify whether a requirement is currently operational, scheduled for commencement or already applicable through another existing law or sectoral regulation. Does the DPDP Act Replace Every Other Privacy Requirement? No. The DPDP framework needs to be read alongside applicable sectoral laws and regulations. Financial institutions, insurers, telecommunications companies, healthcare businesses and other regulated entities may have additional requirements concerning information security, outsourcing, technology systems and data management. The constitutional right to privacy also remains relevant. In Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the Supreme Court recognised privacy as a constitutionally protected right. The judgment remains an important part of India's broader privacy jurisprudence. Businesses should therefore avoid treating the DPDP Act as an isolated compliance exercise. What Should Businesses Do Now? The most useful starting point is a data inventory. A business should identify the personal data it collects, the purpose of collection, the systems in which it is stored, the people who can access it and the third parties who receive it. The organisation should then review its privacy notices and consent mechanisms. The next stage should involve vendor contracts. Cloud service providers, payroll companies, analytics platforms, customer relationship management systems and marketing providers can all form part of the data processing chain. Businesses should also establish a breach response procedure, a retention framework and a process for handling Data Principal requests. Finally, legal requirements should be mapped against actual technology. A privacy policy cannot protect a business if the application's underlying architecture collects or shares information in a different manner. Organisations handling substantial or complex data flows may also benefit from advice from top-rated data privacy lawyers, particularly where international transfers, children's data, technology vendors or regulatory investigations are involved.  Why DPDP Compliance Is Also a Commercial Issue Data protection affects more than regulatory risk. Investors may examine how a business acquired its customer database. Enterprise clients may ask for privacy warranties before signing a contract. Buyers conducting due diligence may review consent records, security incidents and vendor agreements before acquiring a company. A weak privacy framework can therefore create commercial friction. A mature data governance programme can make transactions easier because the business can demonstrate how personal information is collected, used, protected and deleted. This is especially relevant for companies planning international expansion. Businesses should also consider privacy when drafting technology contracts, employment documents and commercial agreements. A best corporate law firm can help integrate privacy obligations into wider corporate and contractual structures. Conclusion The Digital Personal Data Protection Act represents a significant development in India's privacy framework. It places greater responsibility on organisations which decide why and how digital personal data is processed. For businesses, the most important lesson is simple: privacy compliance should be built into operations rather than added after a problem occurs. Organisations should understand their data flows, establish appropriate legal bases for processing, provide meaningful notices, maintain suitable consent mechanisms, protect personal data, respect individual rights and establish procedures for breaches and deletion. The DPDP Rules, 2025 now provide much of the operational detail required to translate the Act into business practice. However, implementation is phased, so organisations should verify the commencement status of individual provisions before setting compliance deadlines. The official Digital Personal Data Protection Act, 2023 on India Code and DPDP Rules and official MeitY publications should remain the primary sources for checking the statutory text and current implementation position. Frequently Asked Questions (FAQs) Q1. What is the Digital Personal Data Protection Act, 2023? The Digital Personal Data Protection Act, 2023 is India's principal statutory framework for regulating the processing of digital personal data. It establishes obligations for Data Fiduciaries and rights for Data Principals, together with an enforcement mechanism and financial penalties. Q2. Who needs to comply with the DPDP Act? The Act can apply to organisations processing digital personal data in India and, in certain circumstances, organisations outside India offering goods or services to individuals in India. Q3. Is consent always required under the DPDP Act? No. Consent is one lawful basis for processing. The Act also recognises specified legitimate uses and other statutory circumstances. Businesses should assess the appropriate legal basis for each processing activity. Q4. What is a Data Fiduciary? A Data Fiduciary is an entity or person which determines the purpose and means of processing personal data. Q5. What rights do individuals have under the DPDP Act? Data Principals have rights relating to access to information, correction and erasure, grievance redressal and nomination, subject to the Act and applicable Rules. Q6. Does the DPDP Act protect children's data? Yes. Section 9 provides additional protection for children's personal data, including requirements concerning verifiable parental consent and restrictions on certain tracking, behavioural monitoring and targeted advertising activities. Q7. What is the maximum penalty under the DPDP Act? The highest scheduled penalty is up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Other contraventions have separate statutory maximums. Q8. Does the DPDP Act apply to foreign companies? It can apply where processing outside India is connected with offering goods or services to Data Principals in India. Q9. What is a Significant Data Fiduciary? It is a Data Fiduciary or class of Data Fiduciaries notified by the Central Government based on specified factors. Such entities face additional governance, audit and accountability obligations. Q10. When should businesses begin preparing for DPDP compliance? Businesses should begin preparation before the relevant provisions become operational. Data mapping, contract reviews, system changes and consent mechanisms can require considerable time.
Data Protection Laws,
Data Protection Laws in India: A Complete Guide for Businesses
Businesses operating in India increasingly depend on personal data for customer acquisition, employee management, payments, marketing, analytics and digital services. As a result, Data Protection Laws have become an important part of corporate compliance rather than a matter limited to the information technology department. India now has a dedicated statutory framework through the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The framework is being introduced through a phased commencement structure, making it important for businesses to understand both the law and its implementation timeline. This guide explains the present Indian data protection framework, the obligations businesses need to prepare for, the continuing relevance of the earlier legal regime, sector specific requirements, penalties, children's data, cross border processing and practical steps for compliance. Top Four Ranking Resources for “Data Protection Laws” Search results for this subject are changing quickly because India's new privacy regime is moving from legislation towards implementation. The following resources provide useful coverage of the current framework: Data Protection Laws and Regulations 2026: India Data Protected: India Data protection and cybersecurity laws in India Data Protection Laws in India: Complete Guide for Businesses The leading material generally covers the DPDP Act, scope, consent, individual rights, security, breach notification, children's data, cross border transfers and enforcement. A stronger business focused approach also needs to explain the phased commencement of the new regime and how organisations should manage the transition from the older framework. How India's Data Protection Framework Has Evolved India's privacy framework did not begin with the DPDP Act. For many years, protection of personal information was spread across the Information Technology Act, 2000, the Information Technology Rules, contractual principles, sectoral regulations and constitutional jurisprudence. Section 43A of the Information Technology Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 were particularly relevant to businesses handling sensitive personal data. The framework required reasonable security practices and addressed matters such as privacy policies, consent and disclosure of sensitive information. The constitutional position also changed significantly with the Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. A nine Judge Bench recognised privacy as a constitutionally protected right linked to liberty, dignity and autonomy. The Court also held privacy is not absolute and restrictions must satisfy constitutional requirements including legality, legitimate need and proportionality. The DPDP Act represents a major shift because it establishes a dedicated statutory framework for digital personal data. What Are the Main Data Protection Laws in India? The principal modern framework is the Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025. The DPDP Act received Presidential assent on 11 August 2023. It establishes the concepts of Data Fiduciaries and Data Principals and regulates the processing of digital personal data. Its provisions address lawful processing, notice, consent, legitimate uses, security safeguards, children's data, Significant Data Fiduciaries, individual rights, cross border processing and enforcement. The Government notified the DPDP Rules, 2025 in November 2025. The Rules provide operational detail for several obligations under the Act. They also introduce a phased implementation timetable rather than making every obligation effective on the same day. This distinction is important. A business should not describe the entire DPDP framework as immediately enforceable in the same way across all provisions. Understanding the DPDP Act's Phased Implementation The commencement notification dated 13 November 2025 divides the Act into different implementation stages. Several institutional provisions, including provisions relating to the Data Protection Board, commenced on 13 November 2025. Certain other provisions are scheduled to commence one year later. The core provisions dealing with processing, notice, consent, general obligations, children's data, Significant Data Fiduciaries, individual rights, exemptions and penalties are scheduled to commence eighteen months after 13 November 2025, which falls on 13 May 2027. The Rules follow a similar phased structure. Rules 1, 2 and 17 to 21 commenced upon publication. Rule 4 is scheduled one year after publication, while Rules 3, 5 to 16, 22 and 23 are scheduled eighteen months after publication. For businesses, the practical lesson is simple. Preparation should begin before the compliance deadline. Privacy notices, contracts, consent architecture, data inventories and technical controls cannot always be redesigned immediately. Who Is Covered by the DPDP Act? The Act applies to the processing of digital personal data within India where the data is collected in digital form or is digitised subsequently. It can also apply to processing outside India where such processing is connected with offering goods or services to Data Principals in India. This makes the law relevant to foreign businesses serving Indian customers, even where the technical infrastructure or parent organisation is located overseas. The key regulated entity is the Data Fiduciary. In simple terms, this is the person or organisation which determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary. Businesses therefore need to consider their own processing activities as well as the external vendors handling data on their behalf. What Counts as Personal Data? The DPDP Act adopts a broad concept of personal data. It concerns data about an individual who is identifiable by or in relation to such data. Examples can include a person's name, telephone number, email address, identification information, account details, employment information, customer records and other information connected with an identifiable individual. Importantly, the Act focuses on digital personal data. A business should therefore examine how paper records become digitised and subsequently enter its information systems. Businesses should not limit their assessment to customer databases. Employee records, recruitment platforms, vendor contacts, marketing databases, website enquiries and customer support systems can also contain personal data. Consent and Lawful Processing Consent is a central part of the DPDP framework. Where consent is relied upon, the Act requires it to be free, specific, informed and unambiguous, with a clear affirmative action. A Data Principal must also be able to withdraw consent. The processing undertaken following consent must remain connected with the purpose for which consent was obtained. This has practical consequences for website forms and applications. A statement buried in lengthy terms and conditions may not provide a sound basis for a consent based processing activity. Businesses should instead consider whether their notice clearly explains the relevant purpose and whether the user can understand what they are agreeing to. The Act also recognises certain legitimate uses. Therefore, consent is not the only possible ground for every processing activity. Businesses should identify the appropriate legal basis rather than automatically seeking consent for everything. Notice Requirements for Businesses Transparency is a fundamental part of the framework. The DPDP Act requires notice to be given in connection with the processing of personal data. The Rules provide further detail concerning the form and content of notices. A good privacy notice should be understandable to its intended audience. It should explain what personal data is being processed, the purpose of processing and the relevant rights and mechanisms available to the Data Principal. The notice should also match reality. If a privacy policy says information is collected only for account administration but the business subsequently uses the same information for targeted marketing, the organisation may create a mismatch between its published position and actual processing. Rights of Data Principals Individuals are referred to as Data Principals under the DPDP Act. The framework provides rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination. Businesses therefore need operational processes for responding to rights requests. It is not enough to place an email address in a privacy policy. The organisation should determine who receives requests, how identity is verified, how requests are logged, which internal teams respond and how deadlines are monitored. A central register of privacy requests can help create an audit trail. Children's Data Receives Additional Protection The DPDP Act imposes additional obligations concerning children's personal data. A child is generally defined as an individual who has not completed eighteen years of age. The Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being. It prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. Businesses operating educational platforms, gaming services, children's applications and other products likely to be used by minors therefore require specific compliance controls rather than relying solely on a general privacy policy. Security Safeguards and Data Breaches Security is not merely a technical consideration under the DPDP framework. Section 8 requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. The Rules provide further requirements concerning security safeguards and breach response. A mature compliance programme should therefore connect legal requirements with actual security controls. Access management, encryption where appropriate, authentication, monitoring, vulnerability management, incident response and vendor security should be assessed according to the nature and volume of data processed. The organisation should also have a documented breach response procedure. A legal team should not discover the incident for the first time after a technical team has already taken external action. Data Retention and Erasure Data protection is not only about how information is collected. It also concerns how long information remains in an organisation's systems. The DPDP framework places importance on erasure once the purpose for which personal data was processed is fulfilled, unless retention is necessary for a legal purpose. Businesses should therefore create retention schedules. For example, information collected for a temporary marketing campaign should not necessarily remain indefinitely in a CRM system. Former employee information, customer accounts and inactive user profiles may also require separate retention assessments. Data deletion should extend beyond the main production database where appropriate. Backups, archives and third party systems should also be considered. Significant Data Fiduciaries The DPDP Act creates a separate category known as a Significant Data Fiduciary. The Government may notify an organisation or class of organisations as Significant Data Fiduciaries based on factors specified in the Act, including the volume and sensitivity of personal data processed, risk to the sovereignty and integrity of India, risk to electoral democracy, security of the State, public order and other relevant factors. Significant Data Fiduciaries face additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor and undertaking specified assessments and audits. Businesses likely to fall within this category should not wait for notification before building suitable governance structures. Cross Border Data Processing International businesses should pay particular attention to Section 16 of the DPDP Act and the Rules concerning transfers and availability of personal data outside India. The Act permits the Central Government to restrict transfers of personal data outside India to notified countries or territories. The Rules also contemplate restrictions concerning making personal data available to foreign States or entities under their control. This does not mean every business must automatically store all personal data exclusively in India. Instead, organisations should understand the applicable restrictions, their infrastructure arrangements, group data flows and vendor locations. Cloud hosting agreements and intra group data sharing arrangements deserve particular attention where personal data moves across jurisdictions. Sector Specific Regulations Still Matter The DPDP Act does not eliminate every other regulatory obligation affecting personal information. Businesses in financial services, insurance, securities, healthcare, telecommunications and other regulated sectors may remain subject to sector specific requirements. For example, regulatory directions issued by authorities such as the Reserve Bank of India, Securities and Exchange Board of India and Insurance Regulatory and Development Authority of India can impose additional requirements concerning data security, outsourcing, technology governance and information handling. This creates a layered compliance environment. A fintech business should therefore assess both the DPDP framework and applicable financial sector requirements rather than treating the DPDP Act as its only privacy obligation. What Happens to the Earlier IT Act Framework? The transition from the older framework needs careful attention. Section 44(2) of the DPDP Act provides for omission of Section 43A of the Information Technology Act. However, this particular amendment has a later commencement date under the phased notification. It is scheduled to take effect on 13 May 2027. This is an important distinction for businesses preparing compliance policies in 2026. The older provisions should not simply be treated as having disappeared immediately after enactment of the DPDP Act. Organisations should assess the framework applicable to their activities during the transition period. Penalties for Non Compliance The DPDP Act provides for substantial financial penalties. The Schedule permits penalties of up to ₹250 crore for failure to take reasonable security safeguards, up to ₹200 crore for certain breach notification failures, and up to ₹200 crore for breaches concerning children's data. Significant Data Fiduciary failures can attract penalties of up to ₹150 crore. Other breaches can attract penalties of up to ₹50 crore. These figures represent statutory maximums rather than automatic fines. Section 33 requires the Board to consider factors including the nature, gravity and duration of the breach, the type of data affected, whether the breach is repetitive, any gain or loss involved, mitigation measures, proportionality and the likely impact of the penalty. The financial exposure is therefore significant, but the broader commercial consequences can also include customer disputes, contractual claims, investor concerns and reputational damage. How Businesses Can Prepare for Data Protection Compliance The first practical step is a data mapping exercise. A business should identify what personal data it collects, where it comes from, why it is processed, where it is stored, who can access it and which third parties receive it. The next step is to compare actual practices with privacy notices and contractual documents.Businesses should then review their consent mechanisms, retention practices, security controls, vendor agreements and incident response procedures. Contracts with Data Processors deserve particular attention. Organisations should establish clear responsibilities concerning security, confidentiality, breach reporting, assistance with rights requests and deletion or return of information.Businesses should also establish internal ownership. Privacy compliance usually involves legal, information technology, cybersecurity, human resources, marketing, product and procurement teams. Without defined responsibility, compliance gaps can remain unnoticed. For organisations requiring specialist advice, engaging best data privacy law firms may be appropriate where processing involves sensitive commercial operations, large datasets, international transfers or significant regulatory exposure. Why Data Protection Should Be Treated as a Business Function Privacy compliance can influence more than regulatory risk. A company preparing for investment may face questions concerning its customer database, employee information, technology vendors and international data flows. A company entering an enterprise contract may be required to provide detailed privacy assurances. A business preparing for an acquisition may need to demonstrate how its data was collected and whether its processing practices comply with applicable law. Privacy therefore has a direct connection with corporate value. A well organised data governance programme can make due diligence easier, reduce operational uncertainty and give management a clearer understanding of one of its most important business assets. A passionate corporate lawyer can also help connect privacy requirements with corporate contracts, employment documentation, technology agreements, intellectual property arrangements and broader governance requirements. Conclusion India's data protection framework has moved from a fragmented model towards a dedicated statutory regime. The DPDP Act, 2023 and DPDP Rules, 2025 provide the foundation for regulating digital personal data while recognising individual rights and placing accountability on organisations processing personal information.For businesses, compliance should not begin with rewriting a privacy policy. It should begin with understanding the data itself. Organisations should know what information they hold, why they collect it, how they use it, where it travels, which vendors process it and when it should be removed. They should also understand how the rules apply to children, international operations, security incidents and Significant Data Fiduciaries. The phased implementation of the DPDP framework gives businesses time to prepare. It does not remove the need for preparation. A sound privacy programme should ultimately connect legal requirements with actual business operations. When privacy notices, contracts, technology systems and internal processes all tell the same story, compliance becomes considerably more defensible. Frequently Asked Questions Q1. What are the main Data Protection Laws in India? The principal statutory framework for digital personal data is the Digital Personal Data Protection Act, 2023, together with the Digital Personal Data Protection Rules, 2025. The constitutional right to privacy and sector specific regulatory requirements also form part of India's wider privacy landscape. Q2. Is the DPDP Act currently applicable to all businesses? The Act has commenced in phases. Several institutional provisions came into force on 13 November 2025, while the principal operational provisions concerning processing and many business obligations are scheduled for 13 May 2027. Businesses should therefore distinguish between enacted provisions and provisions currently in force. Q3. What is a Data Fiduciary? A Data Fiduciary is an individual or organisation which determines the purpose and means of processing personal data under the DPDP framework. Q4. Is consent mandatory for every type of personal data processing? No. Consent is an important legal basis, but the DPDP Act also recognises specified legitimate uses. Businesses should determine the appropriate legal basis for each processing activity rather than assuming consent is always required. Q5. Does the DPDP Act apply to foreign companies? It can. The Act applies to processing outside India where the processing is connected with offering goods or services to Data Principals in India. Q6. What rights do individuals have under the DPDP Act? Data Principals have rights including access to information about their personal data, correction and erasure, grievance redressal and nomination, subject to the statutory framework. Q7. What is the maximum penalty under the DPDP Act? The highest scheduled penalty can extend to ₹250 crore for failure to take reasonable security safeguards. Other specified contraventions carry separate maximum penalties. The actual amount is determined following the statutory process and relevant factors. Q8. Does India have a separate law for children's personal data? The DPDP Act provides specific protections for children's personal data under Section 9. These include parental consent requirements and restrictions concerning detrimental processing, tracking, behavioural monitoring and targeted advertising, subject to prescribed exemptions. Q9. Do businesses need a Data Protection Officer? Not every organisation automatically needs a Data Protection Officer under the same requirements. Additional obligations apply to Significant Data Fiduciaries, including the appointment of a Data Protection Officer based in India. Businesses should assess whether they fall within the relevant category. Q10. What should a business do before the main DPDP obligations become effective? Businesses should map personal data, review notices and consent mechanisms, assess vendor contracts, establish retention policies, strengthen security controls, prepare breach response procedures and create processes for handling Data Principal rights.  
MHCO Updates
SEBI Update
REGULATORY UPDATE | SEBI ORDERS VARANIUM CLOUD TO RESTORE & DISGORGE FUNDS OVER IPO & RIGHT ISSUE FRAUD
The Securities and Exchange Board of India (“SEBI”) on 25 August 2025 passed a Final Order against Varanium Cloud Limited (“VCL”) and its key management for alleged fraudulent and misleading activities in connection with its Initial Public Offer (IPO), Rights Issue and subsequent disclosures. BACKGROUND The proceedings stemmed from SEBI’s preliminary examination pursuant to media reports and complaints regarding VCL’s financial statements and corporate announcements, which led to an Interim Order dated 10 May 2024 against VCL and its MD/Chairman, Harshwardhan Hanmant Sabale (Mr Sabale). VCL raised approximately Rs 40.39 crore through its IPO in September 2022 (primarily for Edge Data Centres and Edmission Digital Learning Centres) and proposed a further Rs. 48.45 crore through a Rights Issue in September 2023. SEBI examined the utilisation of issue proceeds, financial statements, Prospectus disclosures, corporate announcements, related-party transactions, and the role of directors, the CFO, the merchant banker and other intermediaries. SEBI’S FINDINGS SEBI found that VCL misrepresented its financial statements and prospectus by showing fictitious sales and purchases, and that its disclosures on utilisation of IPO proceeds (including the Statement of Deviation dated 17 November 2023) were incorrect and misleading. SEBI found that IPO and Rights Issue proceeds of Rs. 62.51 crore were diverted to related parties and other entities, including Rs. 32.73 crore transferred directly to Mr Sabale’s personal account. BM Traders (operated by Mr Raj Jagtani) received Rs. 19.66 crore in aggregate from the issue proceeds, of which Rs. 15.60 crore was transferred onwards; and that no adequate evidence of genuine business purpose was produced. SEBI found several business announcements by VCL to be false and unsubstantiated. SEBI also found that the Company also failed to support the substantial increase in reported revenues (including those of its US subsidiary) with invoices, contracts or employee details. Pending litigation was omitted from the Letter of Offer, and the Prospectus contained material omissions and misstatements. Liability was fastened on the Company, its MD, Executive Directors and CFO. SEBI found that the lead manager, First Overseas Capital Limited (FOCL), failed to exercise independent due diligence and did not disclose pending litigation. SEBI rejected FOCL’s defence that  it  could  rely  on  the  Company’s  representations  and  third-party  reports. Athos Capital Advisors Private Limited (ACAPL) and Mr Jinesh Mehta were held to have aided and abetted the misrepresentations; ACAPL received approximately Rs. 2.50 crore from VCL, and Mr Mehta admitted drafting portions of the Prospectus and assisting with fundraising. SEBI’S DIRECTIONS VCL was directed to bring back Rs. 62.51 crore (with 12% p.a. interest) within three months. Mr Sabale was directed to disgorge unlawful gains of Rs. 128.77 crore (with 12% p.a. simple interest) to the Investor Protection and Education Fund. VCL and Mr Sabale were debarred from the securities market for 7 years. ACAPL and Mr Jinesh Mehta were debarred for 2 years; Mr Raj Jagtani/BM Traders for 4 years; the Executive Directors and CFO (Mr Vinayak Jadhav, Mr Mukundan Raghavan and Mr Fahim Shaikh) for 1 year; and FOCL for 2 years (to run consecutively with an earlier debarment). Monetary penalties were also imposed, including Rs. 20.40 crore on Mr Sabale, Rs. 13 crore on VCL and Rs. 10.10 crore on Mr Raj Jagtani. Proceedings against the Company Secretary (Ms Hetal Somani) and a Non-Executive Director (Mr Kalpesh Acharekar) were disposed of without directions or penalty, the allegations against them being found unsustainable. MHCO COMMENT The order is significant for its treatment of misrepresentation in financial statements and public-issue disclosures, diversion of IPO and Rights Issue proceeds, and the accountability of directors, KMPs and intermediaries. It reiterates that a lead manager must conduct independent due diligence and cannot merely rely on the issuer’s representations or third-party reports. SEBI did not fasten liability on every director or officer; allegations against the Company Secretary and non-executive director were dropped for want of material. Overall, SEBI characterised the matter as a fraudulent scheme of raising public funds on misleading disclosures, followed by diversion of proceeds and creation of a false picture of the Company’s performance. The restoration, disgorgement, debarment and penalty directions reflect the seriousness with which the conduct was viewed. By: Mr. Bhushan Shah, Partner Mr. Abhishek Nair, Associate Ms. Sayali Kshirsagar, Associate
Rea Estate
BOMBAY HIGH COURT ALLOWS REFUND OF STAMP DUTY PAID ON CANCELLED DEVELOPMENT AGREEMENT
The Bombay High Court, vide judgment dated 20 August 2026 in Sai Innovation v. Joint District Registrar and Collector of Stamps, Pune City & Ors. (Writ Petition No. 7566 of 2016), has held that a Development Agreement which fails to achieve its intended purpose and is subsequently cancelled can qualify for refund of stamp duty under Section 47(c)(5) of the Maharashtra Stamp Act, 1958 (“the Stamp Act”), and that such an agreement can avail the extended limitation period under the proviso to Section 48(1) where stamp duty has been calculated with reference to Article 25 of Schedule I. Background: Sai Innovation had entered into a Development Agreement (“said Agreement”) dated 15 April 2013 with the owners of land at Village Mauje Balewadi, Pune, for development of approximately 8,000 sq. metres of land and paid stamp duty under Article 25 read with Article 5 of Schedule I to the Stamp Act. The owners were unable to obtain sanction of the building plans within a reasonable time, and disputes subsequently arose between the parties. The said Agreement was therefore cancelled by a registered Deed of Cancellation (“said Deed”) dated 18 February 2014, registered on 24 February 2014, and the consideration received was returned. Sai Innovation thereafter applied on 7 April 2014 for refund of the stamp duty. The Respondent Nos 1&2 vide their orders dated 11 August 2014 and 6 December 2014 (“Impugned Orders”) respectively, rejected the refund application of the Petitioner, principally on the ground that the said Agreement was not a “conveyance” and therefore did not fall within the proviso to Section 48(1) of the Stamp Act. Issue: The Court dealt with the following issues: Whether the said Agreement had failed to achieve its intended purpose to attract Section 47(c)(5) of the Stamp Act; Whether a Development Agreement could avail the benefit of the proviso to Section 48(1), particularly where stamp duty was calculated as per Article 25 of Schedule I; Whether the reference to “actual, open possession” in Clause 13 of said Agreement be interpreted as transfer of possession to the developer, notwithstanding Clause 11 of the said Agreement which described the developer as a licensee; and Whether the Respondents could subsequently rely upon the alleged transfer of possession as a ground for rejecting the refund claim, when the refund claim had initially been rejected by the Impugned Orders on other grounds, and the issue of possession did not form part of the reasons recorded in those orders. Key Findings The Court, while differentiating between Section 47 and Section 48 of the Stamp Act, held that while Section 47 is the main provision that gives the right to a refund of stamp duty, Section 48 only deals with the time limit. In the present case, the proposed development under the said Agreement was never acted upon, and the parties later cancelled the said Agreement by the said Deed. As a result, the transaction had clearly failed to achieve its intended purpose under Section 47(c)(5) of the Stamp Act. The Court therefore said the refund claim had to be examined first under Section 47 and could not be turned down simply by pointing to the limitation period. On the question of possession, the Court held that Clause 13 of the said Agreement could not be read in isolation from Clause 11. Although Clause 13 referred to “actual, open possession”, Clause 11 expressly described the developer’s rights as those of “a licensee for development”. Reading the Agreement as a whole, the Court concluded that the developer was granted only a limited contractual licence to enter the property and undertake development activities, and that there was no transfer of legal or exclusive possession. The Court also noted that the absence of a separate possession receipt, by itself, did not establish that possession had been transferred. Held In light of the above reasoning, the Court allowed the writ petition and quashed the Impugned Orders passed by the Respondents. The Court held that the refund application was filed within the extended period prescribed under the proviso to Section 48(1) of the Stamp Act and, accordingly, rejected the Respondents’ objection that the claim was barred by the ordinary six-month limitation period. MHCO Comment Parties seeking refund of stamp duty on a cancelled Development Agreement should note that Section 47 governs the substantive entitlement to refund, while the proviso to Section 48(1) determines the applicable limitation period. Further, the legal character of a Development Agreement should be assessed by reading the same meaningfully and not in isolation from other clauses provided therein. By: Mr. Bhushan Shah, Partner Ms. Meeta Kadhi, Associate Partner Mr. Saptadip Nandi Chowdhury, Associate
SEBI Update
REGULATORY UPDATE | SEBI IMPOUNDS ₹ 3.67 CR FROM TWO ENTITIES FOR ALLEGED MANIPULATIVE TRADES DURING CLOSING AUCTION SESSION
BACKGROUND The Securities and Exchange Board of India (“SEBI”) passed an Ex-Parte Interim Order dated 19 August 2026 against Copthall Mauritius Investment Limited (“Copthall”) and Mansi Share and Stock Broking Private Limited (“Mansi”) in relation to alleged manipulative trading during the Closing Auction Session (“CAS”) on the BSE SENSEX expiry day. SEBI's CAS framework, introduced vide Circular dated 16 January 2026 and made effective from 3 August 2026, provides for determination of the closing price through a dedicated auction mechanism based on the interaction of buy and sell orders. The framework replaced the earlier methodology based on the volume-weighted average price (“VWAP”) for securities covered under the CAS framework, which determined the price of securities based on the closing price of the security or focused on the weight of trades executed in the last 30 minutes of the trading session. Now, under the CAS framework, the price of securities is determined based on buy and sell orders in a single pool, executed at a single equilibrium price in a dedicated 20-minute daily auction timeline. SEBI’S FINDING SEBI prima facie found that the trading activity of Copthall and Mansi was linked to their outstanding SENSEX option positions and was undertaken to influence the Indicative Equilibrium Price (“IEP”) and closing price of the SENSEX so as to obtain a favourable payoff from their expiry-day F&O positions. On 13 August 2026, SEBI's surveillance observed three sharp movements in the SENSEX during the CAS. Upon examination of the trade and order logs, SEBI observed that these movements coincided with large and aggressive buy orders placed by Copthall and sell orders placed by Mansi in SENSEX constituent securities, which were subsequently cancelled. SEBI accordingly examined the trading activity of the two entities and its linkage with their outstanding SENSEX option positions. SEBI noted that the material on record did not prima facie indicate that the two Noticees acted in concert. Rather, each appeared to have adopted a separate strategy to move the SENSEX in a direction favourable to its respective F&O positions. SEBI'S DIRECTIONS SEBI directed that the bank accounts of Copthall and Mansi be impounded to the extent of ₹2,96,16,000 and ₹71,64,773 respectively, aggregating a total of ₹3,67,80,773. SEBI also debarred the noticees from accessing the securities markets and prohibited them from participating in the CAS, including placing, modifying or cancelling orders. Restrictions were also imposed on their bank and demat accounts, transfer/redemption of securities and disposal of assets without SEBI's permission. They were further directed to cooperate with SEBI's ongoing examination/investigation. MHCO COMMENT The order is significant in the context of the newly introduced CAS framework and SEBI's surveillance of potential attempts to influence the closing price through order placement and cancellation. The order demonstrates that SEBI is examining the nature, timing and price of orders, their impact on the IEP, subsequent cancellation of orders and the corresponding F&O positions of the concerned entities. The directions are interim in nature and are based on prima facie findings pending further investigation. SEBI has expressly clarified that the detailed investigation is to proceed independently of the prima facie observations contained in the interim order. Notably, SEBI has not alleged that Copthall and Mansi acted in concert. The findings against the two entities are based on their respective trading patterns and F&O positions. Since the order is ex-parte and interim in nature, the findings remain subject to SEBI's further examination, as well as the Noticees' replies and opportunity of hearing. By: Mr. Bhushan Shah, Partner Ms. Sayali Kshirsagar, Associate
IBC Update
IBC UPDATE - REMOVAL OF INTERIM MORATORIUM FOR PERSONAL GUARANTORS APPLIES TO PENDING PROCEEDINGS
Recently, the Bombay High Court in the case of Tata Capital Financial Services Limited v. Neel Motors LLP & Ors., held that the amendment introducing Section 96(4) of the Insolvency and Bankruptcy Code, 2016 (“IBC”) applies to insolvency applications filed before that date which remain pending. The Court consequently held that the interim moratorium under Section 96 ceased to operate against the personal guarantors from 26 May 2026, enabling Tata Capital to pursue limited interim relief under Section 9 of the Arbitration and Conciliation Act, 1996 (“Arbitration Act”). FACTS: The Petitioner, Tata Capital Financial Services Limited (“Tata Capital”) extended financial assistance to Respondent No. 1, Neel Motors LLP, under a Channel Finance Agreement. Respondent Nos. 2 to 4 were individual guarantors and partners of Neel Motors LLP, while Respondent No. 5 was a separate LLP acting as guarantor. The Letters of Guarantee contained arbitration clauses with Mumbai as the seat. In 2021, Tata Capital filed a petition under Section 9 of the Arbitration Act seeking interim protection. Approximately one month prior to filing the Section 9 petition, Tata Capital had initiated Corporate Insolvency Resolution Process (“CIRP”) against Neel Motors under the IBC. The CIRP ultimately failed and Neel Motors was ordered to be liquidated by the NCLT, Mumbai, on 1 April 2022. Thereafter, in June 2022, Tata Capital initiated insolvency proceedings under Section 95 of the IBC against Respondent Nos. 2, 3 and 4, who were the individual guarantors (“Guarantors”). The filing of the Section 95 applications triggered the interim moratorium under Section 96, stalling the Section 9 petition. The legal position changed with the insertion of Section 96(4) into the IBC which came into force on 26 May 2026. The amendment provided that Section 96 would not apply where an application was filed for initiating an insolvency resolution process in respect of a personal guarantor to a corporate debtor. Relying upon the amendment, Tata Capital sought consideration of its pending Section 9 petition. The principal issue before the Court was whether Section 96(4) could apply to Section 95 applications which had been filed before 26 May 2026 but continued to remain pending on the date of the amendment. Tata Capital’s Case Tata Capital contended that, in view of the newly inserted Section 96(4), the moratorium under   Section 96 no longer operated against the individual guarantors and the expression “where an application is filed” was sufficiently broad to include pending applications. It further relied upon the legislative purpose behind the amendment, that it was intended to “remove any perverse incentives” associated with the initiation of individual insolvency proceedings. Considering the considerable delay since filing of the Section 9 petition, Tata Capital only sought disclosure of the guarantors’ assets and an injunction restraining them from selling, transferring, alienating, encumbering or otherwise dealing with such assets pending arbitration. Guarantor’s Case The guarantors opposed the application, contending that such an interpretation would give the amendment retrospective effect. They submitted that the expression “where an application is filed” covers only applications filed after 26 May 2026 and could not extend to applications which had already been filed. Any other interpretation, according to the guarantors, would retrospectively alter the legal consequences attached to the pending proceedings. They further argued that although insolvency proceedings are not strictly recovery proceedings, both the insolvency and arbitration proceedings were directed towards recovery of the same debt and Tata Capital should therefore not be permitted to pursue both simultaneously Court’s Finding The Hon’ble Court held that the expression “where an application is filed” in Section 96(4) encompasses applications which had already been filed and continued to remain pending before the adjudicating authority. Had the legislature intended to restrict the provision only to applications filed after 26 May 2026, it could have expressly used language to that effect. The Court distinguished between retrospective and retroactive operation, relying upon the Supreme Court’s decision in Securities and Exchange Board of India v. Rajkumar Nagpal, the Court observed that a provision is retrospective when it operates backwards and impairs vested rights, whereas a retroactive provision operates prospectively on a character or status originating in the past. The existence of antecedent facts does not, by itself, make its application retrospective. Accordingly, the moratorium under Section 96 operated against Respondent Nos. 2 to 4 until 25 May 2026 but ceased from 26 May 2026 when Section 96(4) came into force. The pending Section 9 petition was therefore no longer barred by the IBC moratorium. The Court further acknowledged the possibility of a conflict of interest where the creditor initiating insolvency proceedings may also be pursuing claims against the individual guarantor. However, it held that such considerations could not override the express statutory language, particularly when Section 96(4) was agnostic as to the identity of the person who initiated the Section 95 proceedings. MHCO Comment Pending proceedings can be affected by a new provision without the provision necessarily being retrospective. The decisive factor is whether the provision changes completed past rights or operates prospectively upon an existing/pending legal status. Section 96(4) therefore lifted the Section 96 moratorium prospectively from 26 May 2026 even in respect of Section 95 applications filed prior to the amendment coming into force. By: Mr. Bhushan Shah, Partner Ms. Neha Lakshman, Associate Partner
LIFE AT MHCO
Need Help? Chat with us