CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
UPDATES
PRACTICE AREAS
PEOPLE
News and Articles
business privacy requirements
How Businesses Can Comply with India's Data Protection Laws?
Businesses in India now need to treat privacy as an operational and governance issue, not simply a matter of publishing a privacy policy. Business privacy requirements increasingly affect how organisations collect customer information, manage employee records, use software vendors, respond to data requests and handle security incidents. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 form the central framework, while sector specific regulations and cyber security requirements can also apply. Since implementation is phased, businesses have an important opportunity to build their compliance framework before the main substantive obligations take effect. Top Four Search Results Reviewed for “Business Privacy Requirements” Search results for this topic vary considerably because the exact phrase “business privacy requirements” is not a standard Indian statutory term. Current results and closely related Indian privacy searches largely focus on DPDP compliance checklists, business readiness, consent, privacy notices, security, Data Principal rights and implementation timelines. The common search intent is practical. Businesses want to know whether the law applies to them, what they need to change, how consent should work, what documents are required, how data breaches should be handled and how much time they have to prepare. A stronger compliance guide also needs to distinguish statutory obligations from recommended governance measures and explain the phased commencement of the framework. What Are India's Data Protection Laws? India's principal general law for digital personal data is the Digital Personal Data Protection Act, 2023, commonly called the DPDP Act. Parliament enacted it on 11 August 2023. Its purpose is to regulate the processing of digital personal data while recognising an individual's right to protect personal data and the legitimate need for lawful processing. The Act uses three central concepts. A Data Principal is the individual to whom personal data relates. A Data Fiduciary is the person or organisation deciding the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary. For most businesses, the practical question is simple: if the organisation decides why customer, employee or user information is collected and how it will be used, it is likely to have Data Fiduciary responsibilities. The DPDP Rules, 2025 provide detailed operational requirements under the Act. MeitY notified the Rules on 14 November 2025. Who Needs to Comply? The DPDP Act can apply to organisations processing digital personal data in India. It can also apply to processing outside India where the processing is connected with offering goods or services to individuals in India. This makes the framework relevant to more than Indian incorporated companies. An overseas SaaS provider serving Indian customers may need to consider the Act. An Indian ecommerce platform will need to examine its customer data practices. A company employing staff in India must consider how it handles employee information. A startup using cloud applications can also have privacy obligations even if it has a small team. The scale of the organisation does not, by itself, determine whether privacy law is relevant. The nature of the processing matters. Start With a Personal Data Inventory The first practical step towards compliance is understanding what personal data the organisation actually handles. A business should identify the information collected through websites, mobile applications, customer forms, payment systems, recruitment portals, email campaigns, support desks and internal systems. The exercise should go beyond listing databases. The business should understand why information is collected, who can access it, where it is stored, which vendors receive it and when it is deleted. A data inventory often reveals unexpected processing. Marketing teams may use analytics tools. Human resources may upload employee information to cloud platforms. Sales teams may maintain contact databases in spreadsheets. Customer support teams may store conversation records. Each activity should be examined rather than assuming the company's main database represents the entire privacy landscape. Identify the Purpose of Each Processing Activity Purpose is central to effective privacy governance. Businesses should be able to explain why they need each category of personal data. A company collecting a telephone number for account verification should not automatically assume it can use the same information for every future marketing purpose. The purpose should be specific enough to guide employees and systems. This also helps businesses avoid excessive collection. If a service can operate without collecting a particular piece of information, the organisation should consider whether collecting it creates unnecessary legal and security exposure. Review the Legal Basis for Processing The DPDP Act provides for processing based on consent as well as certain legitimate uses specified under Section 7. This distinction is important. Businesses should not assume consent is required for every processing activity. Equally, they should not treat the existence of a business purpose as a substitute for the requirements imposed by the Act. Where consent is used, the organisation should ensure it meets the statutory requirements. Consent should be capable of being demonstrated. Businesses should therefore maintain appropriate records showing when consent was obtained and for which purpose. The consent mechanism should also allow withdrawal in accordance with the Act and Rules. Build a Clear Privacy Notice A privacy notice should explain what personal data is being processed and why. It should be written in language users can understand. It should not be buried behind complicated legal terminology. The DPDP Rules, 2025 provide specific requirements concerning notices. The framework expects notices to provide clear information concerning the personal data involved and the purpose for processing. Businesses should compare their privacy notice with their actual technology environment. If a website uses advertising technology, analytics tools, customer relationship management software or third party forms, the notice should reflect the actual processing arrangements. An outdated notice can create risk because it gives individuals an inaccurate picture of how their information is handled. Make Consent Practical and Auditable A consent mechanism should be designed as part of the user journey. Businesses should avoid relying on vague statements such as consent to “all business purposes”. The purpose should be sufficiently clear for the individual to understand what is being authorised. Consent records should also be retained in a form capable of demonstrating what happened. For example, a business may need to establish which version of its notice was presented, when consent was provided and whether the individual subsequently withdrew it. This becomes particularly important when organisations use multiple websites, applications or customer databases. Establish a Process for Data Principal Rights The DPDP Act gives Data Principals several rights, including rights concerning access to information, correction and erasure in specified circumstances, grievance redressal and nomination. Businesses need an operational mechanism for handling these rights. A customer should not have to contact five different departments to correct inaccurate information. The organisation should establish an internal route for receiving requests, verifying the requester, locating relevant data, determining the response and maintaining appropriate records. Customer support teams should understand when a routine customer complaint may actually involve a statutory privacy request. Strengthen Data Security Privacy compliance cannot be separated from information security. Section 8 of the DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The appropriate safeguards will depend on the organisation's size, systems, data and risk profile. Businesses should consider access controls, authentication, encryption where appropriate, system monitoring, secure backups, vulnerability management and appropriate incident response procedures. The goal is not simply to have a security policy. The organisation should be able to demonstrate reasonable security measures through actual technical and organisational controls. Prepare for Data Breaches A breach response plan should exist before an incident occurs. Businesses should know who receives an internal incident report, who assesses the scope of the incident and who decides whether regulatory or individual notifications are required. The DPDP Rules establish requirements concerning breach intimation to affected Data Principals and the Data Protection Board. Businesses should also consider separate cyber security obligations. CERT In's directions under Section 70B of the Information Technology Act require specified cyber security incidents to be reported within six hours of noticing the incident or being informed about it. This is a useful reminder that Indian privacy compliance cannot be assessed by looking at the DPDP Act alone. Review Contracts With Data Processors Modern businesses rarely process all personal data internally. Cloud providers, payroll companies, CRM platforms, payment providers, marketing tools and customer support vendors can all process personal information. Businesses should therefore review contracts with such providers. The agreement should address the permitted processing, confidentiality, security, incident reporting, cooperation and appropriate handling of personal data when the relationship ends. Vendor selection should also involve privacy considerations. A business should know what data a vendor receives and whether the vendor's systems create unnecessary exposure. This is especially important when several SaaS applications are connected to the same customer database. Control Internal Access to Personal Data Not every employee needs access to every customer record. Businesses should adopt role based access wherever practical. Employees should receive access appropriate to their responsibilities. Access should also be reviewed when employees change roles or leave the organisation. Shared passwords, uncontrolled spreadsheets and unrestricted administrator accounts can create avoidable privacy risks. Privacy governance is therefore closely linked with basic information security discipline. Establish Retention and Deletion Practices Keeping personal data indefinitely increases exposure. Businesses should identify how long different categories of information need to be retained for business, contractual, statutory or regulatory reasons. The DPDP Rules contain specific provisions concerning retention and erasure in certain circumstances and also provide special retention periods for specified classes of Data Fiduciaries. A sensible retention programme should therefore connect legal requirements with actual system functionality. If information is no longer needed, the business should have a controlled process for deletion or appropriate anonymisation where legally suitable. Pay Special Attention to Children's Data Children receive enhanced protection under the DPDP Act. A child is defined as an individual who has not completed eighteen years of age. Section 9 requires verifiable parental consent before processing children's personal data, subject to applicable provisions and exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being and places restrictions concerning tracking, behavioural monitoring and targeted advertising. The Rules provide additional requirements concerning verification of parental consent and identify specified exemptions for certain classes of organisations and purposes. Educational platforms, gaming services, healthcare providers and children's applications should therefore assess these requirements during product design. Determine Whether You Could Become a Significant Data Fiduciary The DPDP Act creates additional obligations for Significant Data Fiduciaries. Designation can take into account factors including the volume and sensitivity of personal data processed, risks to Data Principals and potential impacts involving national interests and public order. Significant Data Fiduciaries have additional responsibilities, including appointing a Data Protection Officer based in India, appointing an independent data auditor and undertaking specified impact assessments and audits. A business should monitor its processing profile as it grows. A company which begins as a small consumer application may eventually process enough information to require a substantially stronger governance structure. Examine Cross Border Data Flows Businesses with international operations should map cross border data movement. The DPDP Act permits the Central Government to restrict transfers of personal data to specified countries or territories through notification. This does not create a blanket requirement for all personal data to remain physically in India. Instead, organisations should understand where data is stored, who can access it and whether overseas group companies or technology vendors are involved. Cloud architecture should therefore be considered during privacy assessments. Consider Sector Specific Regulations The DPDP framework does not operate in isolation. Banks and financial institutions may have additional RBI requirements. Securities market entities may have SEBI obligations. Insurance businesses may need to consider IRDAI requirements. Telecommunications, healthcare, education and other regulated sectors can also involve additional privacy, security and record keeping obligations. A business should therefore identify its sector before preparing a generic compliance programme. Build Privacy Into Business Operations Privacy should not remain the responsibility of one legal or technology employee. Marketing teams decide how customer information is collected. Human resources manages employee information. Procurement selects vendors. Technology teams control access and security. Customer support handles individual requests. Each function therefore has a role. For businesses planning data protection legal services, the most useful approach is often to integrate legal analysis with technology and operational processes rather than treating privacy as a document exercise. Understand the Implementation Timeline The DPDP Act and Rules use phased commencement. The Act was enacted in 2023, but Section 1 itself provides for different commencement dates for different provisions. The Government's November 2025 notification brought several institutional provisions into force while scheduling the major substantive provisions for eighteen months after 13 November 2025. The Rules also follow a phased structure. Some provisions commenced upon publication, while other requirements have commencement dates one year or eighteen months after notification. MeitY provides the official Rules and enforcement timeline on its website. For businesses, the practical message is clear: the compliance programme should begin before the main obligations become operational. Common Mistakes Businesses Should Avoid A common mistake is assuming a privacy policy equals compliance. It does not. Another mistake is collecting excessive personal information without clearly defined purposes. Businesses also overlook personal data stored in spreadsheets, emails, messaging systems and third party applications. Some organisations rely on vendor contracts without checking whether vendors actually maintain appropriate security controls. Another weakness is the absence of evidence. A company may have a policy requiring deletion but no system capable of demonstrating whether deletion occurs. A mature programme therefore connects legal requirements with people, processes, contracts and technology. What Should a Business Do First? A practical starting point is a privacy gap assessment. The organisation should identify its data flows, processing purposes, legal bases, vendors, security controls, retention practices and user rights processes. It can then prioritise high risk areas. For example, a company processing children's data or financial information may need more immediate attention than a business processing limited contact information. The organisation should document the findings and assign responsibility for remediation. This creates an evidence trail and gives management a clearer view of privacy risk. Why Privacy Compliance Matters Beyond Legal Risk Privacy governance can influence more than regulatory exposure. Customers increasingly ask how their information is handled. Enterprise clients may require privacy representations during procurement. Investors may examine privacy controls during due diligence. Poor data governance can also make business expansion harder because new markets, new technology systems and new vendors create additional data flows. For businesses undertaking corporate legal compliance services, privacy should therefore sit alongside contracts, employment law, corporate governance and sector specific obligations. Conclusion Complying with India's data protection framework requires more than adding a privacy policy to a website. Businesses need to understand what personal data they collect, why they collect it, where it goes, who can access it and how long it should remain in their systems. They also need practical processes for consent, individual rights, vendor management, security, breach response and deletion. The DPDP Act, 2023 and DPDP Rules, 2025 provide the central framework, but sector specific regulations and cyber security requirements can create additional obligations. The phased implementation gives businesses time to prepare. The strongest approach is to use this period to conduct a data inventory, review processing purposes, update notices, assess vendors, strengthen security controls and establish an internal privacy governance process. Businesses should also monitor official Government notifications because commencement dates and regulatory guidance can affect the practical compliance position. The official Digital Personal Data Protection Act on India Code and Digital Personal Data Protection Rules, 2025 published by MeitY should remain the primary sources for determining the current statutory position. For businesses, privacy compliance is ultimately part of sound corporate governance. When personal data is handled responsibly from the beginning, organisations are better placed to manage regulatory change, protect customer trust and scale their operations with greater confidence. Frequently Asked Questions (FAQs)   Q1. What are the main business privacy requirements in India? The core requirements arise from the DPDP Act and Rules and can include lawful processing, appropriate notice, valid consent where relied upon, security safeguards, breach response, Data Principal rights, children's data protection, vendor governance and appropriate retention practices. Q2.Does the DPDP Act apply to small businesses? Potentially, yes. Applicability depends on the nature of processing and the statutory scope rather than simply the number of employees. Q3.Is a privacy policy mandatory for every business? Businesses should assess their specific statutory obligations and processing activities. More importantly, a privacy notice should accurately explain relevant processing where the framework requires notice. Publishing a generic privacy policy does not by itself establish compliance. Q4.Does every processing activity require consent? No. The Act provides for consent as well as certain legitimate uses under Section 7. Businesses should identify the appropriate statutory basis for each processing activity. Q5.What is a Data Fiduciary? A Data Fiduciary is the person or organisation deciding the purpose and means of processing personal data. Q6.What is a Data Processor? A Data Processor processes personal data on behalf of a Data Fiduciary. Q7.What rights do Data Principals have? The Act provides rights including access to information concerning personal data, correction and erasure in specified circumstances, grievance redressal and nomination. Q8.How should businesses prepare for a data breach? Businesses should establish an incident response process, identify responsible personnel, maintain appropriate security controls and understand both DPDP notification requirements and other cyber incident reporting obligations. Q9.Does the DPDP Act apply to foreign companies? It can apply to processing outside India where the processing is connected with offering goods or services to Data Principals in India. Q10.Are children's data subject to additional requirements? Yes. The DPDP Act provides enhanced protection for children's personal data, including verifiable parental consent and restrictions on certain forms of processing. Q11.What is a Significant Data Fiduciary? It is a Data Fiduciary designated by the Central Government based on factors specified in the Act. Such entities have additional governance, audit and impact assessment obligations. Q12.What are the maximum penalties under the DPDP Act? The Schedule provides penalties of up to ₹250 crore for specified failures concerning reasonable security safeguards. Other contraventions can attract penalties of up to ₹200 crore or ₹50 crore depending on the provision involved.
Digital Personal Data Protection Act,
The Digital Personal Data Protection Act, 2023 Explained in Simple Terms
The Digital Personal Data Protection Act is India's principal legislation governing the processing of digital personal data. For businesses, the law changes how customer, employee, user and other personal information must be collected, used, stored and shared. The framework is built around a balance between individual privacy and lawful use of data. The Act was enacted in 2023, while the Digital Personal Data Protection Rules, 2025 provide the operational framework for several obligations. Importantly, implementation is phased, so businesses need to distinguish between provisions already in force and provisions scheduled to commence later.This guide explains the law in practical language, with particular attention to what businesses need to understand before reviewing their privacy policies, contracts, technology systems and internal processes. What Is the Digital Personal Data Protection Act, 2023? The Digital Personal Data Protection Act, 2023, commonly called the DPDP Act, is India's dedicated statutory framework for digital personal data protection. Parliament enacted the legislation on 11 August 2023. Its stated purpose is to regulate the processing of digital personal data while recognising both an individual's right to protect personal data and the need for organisations to process information for lawful purposes. In practical terms, the law asks businesses to answer several basic questions. Why are you collecting someone's personal data? Have you provided an appropriate notice? Do you have a lawful basis for processing it? Are you collecting more information than necessary? Is the information secure? Can the individual exercise their statutory rights? What happens when the purpose for collection ends? These questions sit at the centre of the new compliance framework. When Does the DPDP Act Apply? The Act primarily concerns digital personal data. It applies to processing within India where personal data is collected in digital form. It also covers information collected in non digital form and subsequently digitised. The law can also apply outside India where processing is connected with offering goods or services to Data Principals in India. This means a foreign company serving Indian customers may need to consider the Indian framework even if its headquarters, servers or parent company are located overseas. There are exclusions. Personal data processed by an individual for a personal or domestic purpose falls outside the Act. Certain publicly available personal data is also excluded in circumstances specified by Section 3. The important point for businesses is scope. A company should assess its actual processing activities rather than assuming the law applies only to technology companies. A manufacturer with an employee database, an online retailer with customer accounts and a professional services firm managing client contacts can all have relevant processing activities. The Three Main Players Under the DPDP Act The Act uses terminology which businesses need to understand. A Data Principal is the individual to whom personal data relates. For a child, the statutory framework also recognises the parent or lawful guardian in the relevant context. A Data Fiduciary is the organisation or person deciding the purpose and means of processing personal data. This is broadly comparable to the concept of a data controller under some international privacy regimes, although the legal frameworks are not identical. A Data Processor processes personal data on behalf of a Data Fiduciary. For example, an online retailer may determine why customer information is collected and how it is used. The retailer may engage a cloud provider or software company to process the information. The retailer can therefore be the Data Fiduciary while the external service provider acts as a Data Processor. The distinction matters because responsibility does not disappear simply because processing is outsourced. What Does “Processing” Mean? Processing is broader than simply collecting information. The Act covers operations such as collection, recording, organisation, storage, adaptation, retrieval, use, sharing, disclosure, transmission, dissemination, restriction, erasure and destruction of digital personal data. This broad definition has practical consequences. A business processes personal data when a customer creates an account. It also processes data when the information is stored in a cloud platform, shared with a payment provider, accessed by customer support staff or deleted after the account is closed. Businesses therefore need to examine the complete data lifecycle. Consent Under the DPDP Act Consent is one of the most important concepts in the Act. Where consent is relied upon, it must be free, specific, informed, unconditional and unambiguous. It must involve a clear affirmative action and relate to the specified purpose for which the information is being processed. This means businesses should reconsider vague consent mechanisms. A pre selected box or a general statement hidden within lengthy terms may not provide the same level of clarity as an appropriately designed consent process. The Rules add further requirements around notices and consent mechanisms. Businesses should also remember one important point: consent is not necessarily required for every processing activity. The Act recognises specified legitimate uses and other statutory grounds. The correct approach is to identify the legal basis for each significant processing activity. What Is a Privacy Notice? A privacy notice tells the Data Principal how their information will be handled. The DPDP framework requires businesses to provide relevant information concerning processing. The 2025 Rules add detail regarding the manner in which notices should be presented. A good notice should be clear enough for an ordinary user to understand. It should not merely reproduce technical or legal terminology. It should explain the purpose of processing, the information involved and how the individual can exercise relevant rights. More importantly, the notice should accurately reflect the organisation's actual practices. If a company says information is used only to provide a service but its marketing team later uses the same information for unrelated advertising, the organisation may create a significant compliance gap. Rights of Data Principals The DPDP Act gives individuals specific rights concerning their personal data. These include rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination. For businesses, these rights require operational processes. An organisation should know who receives a request, how the identity of the requester is verified, which department investigates it, how the response is prepared and how the action is recorded. This becomes particularly important for businesses handling large customer databases. A privacy policy may provide a contact address, but the organisation still needs an internal workflow capable of responding to legitimate requests.  What Happens When a Person Withdraws Consent? The Act provides individuals with the ability to withdraw consent. The withdrawal mechanism should be as easy as the mechanism through which consent was given. The consequences of withdrawal also need to be understood. If an individual withdraws consent, the business must assess whether another lawful basis permits continued processing. If not, relevant processing should cease and applicable erasure requirements should be considered. This is one reason consent management should be integrated with business systems rather than treated as a standalone legal document. Special Rules for Children's Data The DPDP Act gives children additional protection. A child is generally an individual who has not completed eighteen years of age. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian, subject to prescribed exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being. It further restricts tracking and behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. For educational technology companies, gaming platforms, children's applications and other services likely to be used by minors, these provisions require specific attention. Security Obligations Under the Act A business cannot comply merely by obtaining consent. The Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The 2025 Rules provide additional detail regarding security safeguards, including measures relating to organisational and technical controls. Businesses should therefore examine access controls, authentication, encryption where appropriate, monitoring, security testing, incident management and vendor security. Security should be proportionate to the nature and volume of personal data involved. A company holding millions of customer records will generally require a more mature security programme than a small business maintaining a limited customer database.  What Is a Personal Data Breach? The Act defines a personal data breach broadly. It includes unauthorised processing and accidental or unlawful disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data which compromises its confidentiality, integrity or availability. This means a breach is not necessarily a dramatic cyberattack. An employee sending a customer database to the wrong recipient, unauthorised access to an internal system or accidental disclosure of information can potentially create a data protection incident. Businesses therefore need an internal reporting and response mechanism. Legal, security and management teams should know how an incident is escalated and what information needs to be preserved. Data Retention and Erasure The DPDP framework also addresses what happens when personal data is no longer required. Businesses should not treat every piece of information as an asset which must be stored indefinitely. Retention should be linked to the purpose for which the information was collected and any other legal requirement requiring continued retention. For example, a customer database may contain inactive accounts, old marketing records and information retained purely because no one has reviewed it. A proper retention schedule helps businesses identify information which should be removed. Deletion should also be considered across relevant systems, including third party platforms where applicable. Significant Data Fiduciaries The Act creates a special category known as a Significant Data Fiduciary. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as significant based on factors including the volume and sensitivity of personal data, risks to India's sovereignty and integrity, electoral democracy, security of the State, public order and other relevant considerations. Significant Data Fiduciaries have additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor and conducting specified assessments and audits. Large digital platforms and organisations processing significant volumes of sensitive information should therefore monitor whether this category becomes relevant to them. What Is the Data Protection Board of India? The DPDP Act establishes the Data Protection Board of India. The Board is intended to serve as the principal enforcement and adjudicatory body under the framework. The Government established the Board as a body corporate under Section 18. The Board's role includes dealing with contraventions and matters connected with enforcement of the Act. The framework also provides an appeal mechanism. The Telecom Disputes Settlement and Appellate Tribunal is identified as the Appellate Tribunal under the Act. For businesses, this means data protection is no longer simply a matter of internal corporate policy. There is a statutory enforcement structure behind the obligations. Penalties Under the DPDP Framework The financial consequences can be substantial. The Schedule to the Act provides for penalties of up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Certain breaches concerning notification of personal data breaches and children's data can attract penalties of up to ₹200 crore. Other specified breaches can attract penalties of up to ₹50 crore. These figures represent statutory maximums. They do not mean every breach results in the maximum penalty. The enforcement framework considers relevant circumstances when determining an appropriate penalty. Still, the potential exposure makes privacy governance a board level business concern for organisations handling substantial volumes of personal data. How the DPDP Rules, 2025 Fit Into the Framework? The Act establishes the legal framework. The Rules provide practical detail. The Government notified the Digital Personal Data Protection Rules, 2025 in November 2025. The Rules cover areas such as notice requirements, consent mechanisms, security safeguards, breach notifications, rights management, registration of Consent Managers and obligations relevant to Significant Data Fiduciaries. The Rules also provide a phased implementation period. This gives organisations time to adapt their systems. It does not mean businesses should wait until the final commencement date before starting their compliance work. Technology changes can take months. Contract revisions can take longer where multiple vendors or international group entities are involved. Understanding the Phased Commencement The DPDP Act does not become fully operational through a single commencement date. The Government's notification provides different commencement dates for different provisions. Sections 2, 18 to 26, 35 to 43 and specified parts of Section 44 commenced on 13 November 2025. Other provisions are scheduled to commence one year later, while the main operational provisions, including Sections 3 to 5 and Sections 7 to 17, are scheduled to commence eighteen months after 13 November 2025. This phased structure is important when writing internal compliance plans. A business should identify whether a requirement is currently operational, scheduled for commencement or already applicable through another existing law or sectoral regulation. Does the DPDP Act Replace Every Other Privacy Requirement? No. The DPDP framework needs to be read alongside applicable sectoral laws and regulations. Financial institutions, insurers, telecommunications companies, healthcare businesses and other regulated entities may have additional requirements concerning information security, outsourcing, technology systems and data management. The constitutional right to privacy also remains relevant. In Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the Supreme Court recognised privacy as a constitutionally protected right. The judgment remains an important part of India's broader privacy jurisprudence. Businesses should therefore avoid treating the DPDP Act as an isolated compliance exercise. What Should Businesses Do Now? The most useful starting point is a data inventory. A business should identify the personal data it collects, the purpose of collection, the systems in which it is stored, the people who can access it and the third parties who receive it. The organisation should then review its privacy notices and consent mechanisms. The next stage should involve vendor contracts. Cloud service providers, payroll companies, analytics platforms, customer relationship management systems and marketing providers can all form part of the data processing chain. Businesses should also establish a breach response procedure, a retention framework and a process for handling Data Principal requests. Finally, legal requirements should be mapped against actual technology. A privacy policy cannot protect a business if the application's underlying architecture collects or shares information in a different manner. Organisations handling substantial or complex data flows may also benefit from advice from top-rated data privacy lawyers, particularly where international transfers, children's data, technology vendors or regulatory investigations are involved.  Why DPDP Compliance Is Also a Commercial Issue Data protection affects more than regulatory risk. Investors may examine how a business acquired its customer database. Enterprise clients may ask for privacy warranties before signing a contract. Buyers conducting due diligence may review consent records, security incidents and vendor agreements before acquiring a company. A weak privacy framework can therefore create commercial friction. A mature data governance programme can make transactions easier because the business can demonstrate how personal information is collected, used, protected and deleted. This is especially relevant for companies planning international expansion. Businesses should also consider privacy when drafting technology contracts, employment documents and commercial agreements. A best corporate law firm can help integrate privacy obligations into wider corporate and contractual structures. Conclusion The Digital Personal Data Protection Act represents a significant development in India's privacy framework. It places greater responsibility on organisations which decide why and how digital personal data is processed. For businesses, the most important lesson is simple: privacy compliance should be built into operations rather than added after a problem occurs. Organisations should understand their data flows, establish appropriate legal bases for processing, provide meaningful notices, maintain suitable consent mechanisms, protect personal data, respect individual rights and establish procedures for breaches and deletion. The DPDP Rules, 2025 now provide much of the operational detail required to translate the Act into business practice. However, implementation is phased, so organisations should verify the commencement status of individual provisions before setting compliance deadlines. The official Digital Personal Data Protection Act, 2023 on India Code and DPDP Rules and official MeitY publications should remain the primary sources for checking the statutory text and current implementation position. Frequently Asked Questions (FAQs) Q1. What is the Digital Personal Data Protection Act, 2023? The Digital Personal Data Protection Act, 2023 is India's principal statutory framework for regulating the processing of digital personal data. It establishes obligations for Data Fiduciaries and rights for Data Principals, together with an enforcement mechanism and financial penalties. Q2. Who needs to comply with the DPDP Act? The Act can apply to organisations processing digital personal data in India and, in certain circumstances, organisations outside India offering goods or services to individuals in India. Q3. Is consent always required under the DPDP Act? No. Consent is one lawful basis for processing. The Act also recognises specified legitimate uses and other statutory circumstances. Businesses should assess the appropriate legal basis for each processing activity. Q4. What is a Data Fiduciary? A Data Fiduciary is an entity or person which determines the purpose and means of processing personal data. Q5. What rights do individuals have under the DPDP Act? Data Principals have rights relating to access to information, correction and erasure, grievance redressal and nomination, subject to the Act and applicable Rules. Q6. Does the DPDP Act protect children's data? Yes. Section 9 provides additional protection for children's personal data, including requirements concerning verifiable parental consent and restrictions on certain tracking, behavioural monitoring and targeted advertising activities. Q7. What is the maximum penalty under the DPDP Act? The highest scheduled penalty is up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches. Other contraventions have separate statutory maximums. Q8. Does the DPDP Act apply to foreign companies? It can apply where processing outside India is connected with offering goods or services to Data Principals in India. Q9. What is a Significant Data Fiduciary? It is a Data Fiduciary or class of Data Fiduciaries notified by the Central Government based on specified factors. Such entities face additional governance, audit and accountability obligations. Q10. When should businesses begin preparing for DPDP compliance? Businesses should begin preparation before the relevant provisions become operational. Data mapping, contract reviews, system changes and consent mechanisms can require considerable time.
Data Protection Laws,
Data Protection Laws in India: A Complete Guide for Businesses
Businesses operating in India increasingly depend on personal data for customer acquisition, employee management, payments, marketing, analytics and digital services. As a result, Data Protection Laws have become an important part of corporate compliance rather than a matter limited to the information technology department. India now has a dedicated statutory framework through the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The framework is being introduced through a phased commencement structure, making it important for businesses to understand both the law and its implementation timeline. This guide explains the present Indian data protection framework, the obligations businesses need to prepare for, the continuing relevance of the earlier legal regime, sector specific requirements, penalties, children's data, cross border processing and practical steps for compliance. Top Four Ranking Resources for “Data Protection Laws” Search results for this subject are changing quickly because India's new privacy regime is moving from legislation towards implementation. The following resources provide useful coverage of the current framework: Data Protection Laws and Regulations 2026: India Data Protected: India Data protection and cybersecurity laws in India Data Protection Laws in India: Complete Guide for Businesses The leading material generally covers the DPDP Act, scope, consent, individual rights, security, breach notification, children's data, cross border transfers and enforcement. A stronger business focused approach also needs to explain the phased commencement of the new regime and how organisations should manage the transition from the older framework. How India's Data Protection Framework Has Evolved India's privacy framework did not begin with the DPDP Act. For many years, protection of personal information was spread across the Information Technology Act, 2000, the Information Technology Rules, contractual principles, sectoral regulations and constitutional jurisprudence. Section 43A of the Information Technology Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 were particularly relevant to businesses handling sensitive personal data. The framework required reasonable security practices and addressed matters such as privacy policies, consent and disclosure of sensitive information. The constitutional position also changed significantly with the Supreme Court's decision in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. A nine Judge Bench recognised privacy as a constitutionally protected right linked to liberty, dignity and autonomy. The Court also held privacy is not absolute and restrictions must satisfy constitutional requirements including legality, legitimate need and proportionality. The DPDP Act represents a major shift because it establishes a dedicated statutory framework for digital personal data. What Are the Main Data Protection Laws in India? The principal modern framework is the Digital Personal Data Protection Act, 2023, read with the Digital Personal Data Protection Rules, 2025. The DPDP Act received Presidential assent on 11 August 2023. It establishes the concepts of Data Fiduciaries and Data Principals and regulates the processing of digital personal data. Its provisions address lawful processing, notice, consent, legitimate uses, security safeguards, children's data, Significant Data Fiduciaries, individual rights, cross border processing and enforcement. The Government notified the DPDP Rules, 2025 in November 2025. The Rules provide operational detail for several obligations under the Act. They also introduce a phased implementation timetable rather than making every obligation effective on the same day. This distinction is important. A business should not describe the entire DPDP framework as immediately enforceable in the same way across all provisions. Understanding the DPDP Act's Phased Implementation The commencement notification dated 13 November 2025 divides the Act into different implementation stages. Several institutional provisions, including provisions relating to the Data Protection Board, commenced on 13 November 2025. Certain other provisions are scheduled to commence one year later. The core provisions dealing with processing, notice, consent, general obligations, children's data, Significant Data Fiduciaries, individual rights, exemptions and penalties are scheduled to commence eighteen months after 13 November 2025, which falls on 13 May 2027. The Rules follow a similar phased structure. Rules 1, 2 and 17 to 21 commenced upon publication. Rule 4 is scheduled one year after publication, while Rules 3, 5 to 16, 22 and 23 are scheduled eighteen months after publication. For businesses, the practical lesson is simple. Preparation should begin before the compliance deadline. Privacy notices, contracts, consent architecture, data inventories and technical controls cannot always be redesigned immediately. Who Is Covered by the DPDP Act? The Act applies to the processing of digital personal data within India where the data is collected in digital form or is digitised subsequently. It can also apply to processing outside India where such processing is connected with offering goods or services to Data Principals in India. This makes the law relevant to foreign businesses serving Indian customers, even where the technical infrastructure or parent organisation is located overseas. The key regulated entity is the Data Fiduciary. In simple terms, this is the person or organisation which determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary. Businesses therefore need to consider their own processing activities as well as the external vendors handling data on their behalf. What Counts as Personal Data? The DPDP Act adopts a broad concept of personal data. It concerns data about an individual who is identifiable by or in relation to such data. Examples can include a person's name, telephone number, email address, identification information, account details, employment information, customer records and other information connected with an identifiable individual. Importantly, the Act focuses on digital personal data. A business should therefore examine how paper records become digitised and subsequently enter its information systems. Businesses should not limit their assessment to customer databases. Employee records, recruitment platforms, vendor contacts, marketing databases, website enquiries and customer support systems can also contain personal data. Consent and Lawful Processing Consent is a central part of the DPDP framework. Where consent is relied upon, the Act requires it to be free, specific, informed and unambiguous, with a clear affirmative action. A Data Principal must also be able to withdraw consent. The processing undertaken following consent must remain connected with the purpose for which consent was obtained. This has practical consequences for website forms and applications. A statement buried in lengthy terms and conditions may not provide a sound basis for a consent based processing activity. Businesses should instead consider whether their notice clearly explains the relevant purpose and whether the user can understand what they are agreeing to. The Act also recognises certain legitimate uses. Therefore, consent is not the only possible ground for every processing activity. Businesses should identify the appropriate legal basis rather than automatically seeking consent for everything. Notice Requirements for Businesses Transparency is a fundamental part of the framework. The DPDP Act requires notice to be given in connection with the processing of personal data. The Rules provide further detail concerning the form and content of notices. A good privacy notice should be understandable to its intended audience. It should explain what personal data is being processed, the purpose of processing and the relevant rights and mechanisms available to the Data Principal. The notice should also match reality. If a privacy policy says information is collected only for account administration but the business subsequently uses the same information for targeted marketing, the organisation may create a mismatch between its published position and actual processing. Rights of Data Principals Individuals are referred to as Data Principals under the DPDP Act. The framework provides rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination. Businesses therefore need operational processes for responding to rights requests. It is not enough to place an email address in a privacy policy. The organisation should determine who receives requests, how identity is verified, how requests are logged, which internal teams respond and how deadlines are monitored. A central register of privacy requests can help create an audit trail. Children's Data Receives Additional Protection The DPDP Act imposes additional obligations concerning children's personal data. A child is generally defined as an individual who has not completed eighteen years of age. The Data Fiduciary must obtain verifiable consent from a parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions. The Act also restricts processing likely to cause a detrimental effect on a child's well being. It prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. Businesses operating educational platforms, gaming services, children's applications and other products likely to be used by minors therefore require specific compliance controls rather than relying solely on a general privacy policy. Security Safeguards and Data Breaches Security is not merely a technical consideration under the DPDP framework. Section 8 requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. The Rules provide further requirements concerning security safeguards and breach response. A mature compliance programme should therefore connect legal requirements with actual security controls. Access management, encryption where appropriate, authentication, monitoring, vulnerability management, incident response and vendor security should be assessed according to the nature and volume of data processed. The organisation should also have a documented breach response procedure. A legal team should not discover the incident for the first time after a technical team has already taken external action. Data Retention and Erasure Data protection is not only about how information is collected. It also concerns how long information remains in an organisation's systems. The DPDP framework places importance on erasure once the purpose for which personal data was processed is fulfilled, unless retention is necessary for a legal purpose. Businesses should therefore create retention schedules. For example, information collected for a temporary marketing campaign should not necessarily remain indefinitely in a CRM system. Former employee information, customer accounts and inactive user profiles may also require separate retention assessments. Data deletion should extend beyond the main production database where appropriate. Backups, archives and third party systems should also be considered. Significant Data Fiduciaries The DPDP Act creates a separate category known as a Significant Data Fiduciary. The Government may notify an organisation or class of organisations as Significant Data Fiduciaries based on factors specified in the Act, including the volume and sensitivity of personal data processed, risk to the sovereignty and integrity of India, risk to electoral democracy, security of the State, public order and other relevant factors. Significant Data Fiduciaries face additional obligations. These include appointing a Data Protection Officer based in India, appointing an independent data auditor and undertaking specified assessments and audits. Businesses likely to fall within this category should not wait for notification before building suitable governance structures. Cross Border Data Processing International businesses should pay particular attention to Section 16 of the DPDP Act and the Rules concerning transfers and availability of personal data outside India. The Act permits the Central Government to restrict transfers of personal data outside India to notified countries or territories. The Rules also contemplate restrictions concerning making personal data available to foreign States or entities under their control. This does not mean every business must automatically store all personal data exclusively in India. Instead, organisations should understand the applicable restrictions, their infrastructure arrangements, group data flows and vendor locations. Cloud hosting agreements and intra group data sharing arrangements deserve particular attention where personal data moves across jurisdictions. Sector Specific Regulations Still Matter The DPDP Act does not eliminate every other regulatory obligation affecting personal information. Businesses in financial services, insurance, securities, healthcare, telecommunications and other regulated sectors may remain subject to sector specific requirements. For example, regulatory directions issued by authorities such as the Reserve Bank of India, Securities and Exchange Board of India and Insurance Regulatory and Development Authority of India can impose additional requirements concerning data security, outsourcing, technology governance and information handling. This creates a layered compliance environment. A fintech business should therefore assess both the DPDP framework and applicable financial sector requirements rather than treating the DPDP Act as its only privacy obligation. What Happens to the Earlier IT Act Framework? The transition from the older framework needs careful attention. Section 44(2) of the DPDP Act provides for omission of Section 43A of the Information Technology Act. However, this particular amendment has a later commencement date under the phased notification. It is scheduled to take effect on 13 May 2027. This is an important distinction for businesses preparing compliance policies in 2026. The older provisions should not simply be treated as having disappeared immediately after enactment of the DPDP Act. Organisations should assess the framework applicable to their activities during the transition period. Penalties for Non Compliance The DPDP Act provides for substantial financial penalties. The Schedule permits penalties of up to ₹250 crore for failure to take reasonable security safeguards, up to ₹200 crore for certain breach notification failures, and up to ₹200 crore for breaches concerning children's data. Significant Data Fiduciary failures can attract penalties of up to ₹150 crore. Other breaches can attract penalties of up to ₹50 crore. These figures represent statutory maximums rather than automatic fines. Section 33 requires the Board to consider factors including the nature, gravity and duration of the breach, the type of data affected, whether the breach is repetitive, any gain or loss involved, mitigation measures, proportionality and the likely impact of the penalty. The financial exposure is therefore significant, but the broader commercial consequences can also include customer disputes, contractual claims, investor concerns and reputational damage. How Businesses Can Prepare for Data Protection Compliance The first practical step is a data mapping exercise. A business should identify what personal data it collects, where it comes from, why it is processed, where it is stored, who can access it and which third parties receive it. The next step is to compare actual practices with privacy notices and contractual documents.Businesses should then review their consent mechanisms, retention practices, security controls, vendor agreements and incident response procedures. Contracts with Data Processors deserve particular attention. Organisations should establish clear responsibilities concerning security, confidentiality, breach reporting, assistance with rights requests and deletion or return of information.Businesses should also establish internal ownership. Privacy compliance usually involves legal, information technology, cybersecurity, human resources, marketing, product and procurement teams. Without defined responsibility, compliance gaps can remain unnoticed. For organisations requiring specialist advice, engaging best data privacy law firms may be appropriate where processing involves sensitive commercial operations, large datasets, international transfers or significant regulatory exposure. Why Data Protection Should Be Treated as a Business Function Privacy compliance can influence more than regulatory risk. A company preparing for investment may face questions concerning its customer database, employee information, technology vendors and international data flows. A company entering an enterprise contract may be required to provide detailed privacy assurances. A business preparing for an acquisition may need to demonstrate how its data was collected and whether its processing practices comply with applicable law. Privacy therefore has a direct connection with corporate value. A well organised data governance programme can make due diligence easier, reduce operational uncertainty and give management a clearer understanding of one of its most important business assets. A passionate corporate lawyer can also help connect privacy requirements with corporate contracts, employment documentation, technology agreements, intellectual property arrangements and broader governance requirements. Conclusion India's data protection framework has moved from a fragmented model towards a dedicated statutory regime. The DPDP Act, 2023 and DPDP Rules, 2025 provide the foundation for regulating digital personal data while recognising individual rights and placing accountability on organisations processing personal information.For businesses, compliance should not begin with rewriting a privacy policy. It should begin with understanding the data itself. Organisations should know what information they hold, why they collect it, how they use it, where it travels, which vendors process it and when it should be removed. They should also understand how the rules apply to children, international operations, security incidents and Significant Data Fiduciaries. The phased implementation of the DPDP framework gives businesses time to prepare. It does not remove the need for preparation. A sound privacy programme should ultimately connect legal requirements with actual business operations. When privacy notices, contracts, technology systems and internal processes all tell the same story, compliance becomes considerably more defensible. Frequently Asked Questions Q1. What are the main Data Protection Laws in India? The principal statutory framework for digital personal data is the Digital Personal Data Protection Act, 2023, together with the Digital Personal Data Protection Rules, 2025. The constitutional right to privacy and sector specific regulatory requirements also form part of India's wider privacy landscape. Q2. Is the DPDP Act currently applicable to all businesses? The Act has commenced in phases. Several institutional provisions came into force on 13 November 2025, while the principal operational provisions concerning processing and many business obligations are scheduled for 13 May 2027. Businesses should therefore distinguish between enacted provisions and provisions currently in force. Q3. What is a Data Fiduciary? A Data Fiduciary is an individual or organisation which determines the purpose and means of processing personal data under the DPDP framework. Q4. Is consent mandatory for every type of personal data processing? No. Consent is an important legal basis, but the DPDP Act also recognises specified legitimate uses. Businesses should determine the appropriate legal basis for each processing activity rather than assuming consent is always required. Q5. Does the DPDP Act apply to foreign companies? It can. The Act applies to processing outside India where the processing is connected with offering goods or services to Data Principals in India. Q6. What rights do individuals have under the DPDP Act? Data Principals have rights including access to information about their personal data, correction and erasure, grievance redressal and nomination, subject to the statutory framework. Q7. What is the maximum penalty under the DPDP Act? The highest scheduled penalty can extend to ₹250 crore for failure to take reasonable security safeguards. Other specified contraventions carry separate maximum penalties. The actual amount is determined following the statutory process and relevant factors. Q8. Does India have a separate law for children's personal data? The DPDP Act provides specific protections for children's personal data under Section 9. These include parental consent requirements and restrictions concerning detrimental processing, tracking, behavioural monitoring and targeted advertising, subject to prescribed exemptions. Q9. Do businesses need a Data Protection Officer? Not every organisation automatically needs a Data Protection Officer under the same requirements. Additional obligations apply to Significant Data Fiduciaries, including the appointment of a Data Protection Officer based in India. Businesses should assess whether they fall within the relevant category. Q10. What should a business do before the main DPDP obligations become effective? Businesses should map personal data, review notices and consent mechanisms, assess vendor contracts, establish retention policies, strengthen security controls, prepare breach response procedures and create processes for handling Data Principal rights.  
Children's Data Consent,
Legal Risks for Businesses Processing Children's Data Without Proper Consent
Businesses increasingly collect information from children through educational platforms, gaming applications, social networks, healthcare services, e commerce platforms and other digital products. As this activity grows, Children's Data Consent has become a significant legal and compliance issue in India. Under the Digital Personal Data Protection Act, 2023, businesses processing a child's personal data must obtain verifiable consent from a parent or lawful guardian before processing, subject to prescribed exemptions. The law also imposes separate restrictions on tracking, behavioural monitoring and targeted advertising directed at children.For businesses, the issue is not simply whether a consent box exists. The real question is whether consent was obtained from the right person, in a verifiable manner, before processing began, and whether the organisation's subsequent activities remain within the permitted legal framework. Top Four Search Results for “Children's Data Consent” Search results for this emerging legal topic vary considerably because the Indian DPDP framework is still being implemented. The most relevant results identified during the research include specialist explanations of Section 9 and the parental consent mechanism, alongside academic and professional commentary. DPDP Act India: Section 9, Processing of Children's Data DPDP Reference Hub: Children's Data and Verifiable Consent NMIMS Law Review: Parental Consent and the DPDP Rules CheckDPDP: Verifiable Parental Consent under the DPDP Act The stronger content opportunity lies in moving beyond a simple explanation of parental consent. Businesses also need to understand the consequences of invalid consent, the distinction between consent and permission for specific processing activities, vendor exposure, security obligations, retention issues and the interaction between the Act and the notified Rules. What the DPDP Act Requires When Businesses Process Children's Data? Section 9 of the DPDP Act creates a special framework for processing personal data belonging to children. The Act defines a child as an individual who has not completed eighteen years of age. This threshold is important for Indian businesses because it is broader than the age threshold used in some other major privacy regimes. Before processing a child's personal data, the Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. The requirement is not limited to particularly sensitive information. It applies to personal data of a child, subject to the exemptions created under the statutory framework. Section 9 also contains two important restrictions beyond consent. A Data Fiduciary must not process children's personal data in a manner likely to cause a detrimental effect on the child's well being. It must also not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, subject to prescribed exemptions. This means parental consent should never be treated as a universal permission slip. A parent providing consent does not automatically authorise every form of data use. Why Invalid Children's Data Consent Creates Legal Exposure? The first risk arises when a business processes children's personal data without obtaining the required parental consent. Consider a learning application which allows a child to create an account independently. If the application begins collecting identifiable information before the required consent process is completed, the business may have difficulty demonstrating compliance with Section 9. The problem can become more serious where the business has no reliable record of how consent was obtained. A database entry stating "parent consent received" may not be sufficient if the organisation cannot demonstrate the verification process, date, relevant account and scope of the consent. A defensible consent system therefore requires more than an affirmative action by a user. It requires an auditable process. Verifiable Parental Consent Is Different from Ordinary Consent The DPDP Rules, 2025 provide the mechanism for verifiable parental consent. Rule 10 requires a Data Fiduciary to adopt appropriate technical and organisational measures to obtain verifiable consent from the parent before processing a child's personal data. The business must also exercise due diligence to establish whether the person identifying themselves as the parent is an identifiable adult. Rule 10 permits verification by reference to reliable identity and age information already available with the Data Fiduciary, or information voluntarily provided by the individual, including information made available through a virtual token issued by an authorised entity. This approach creates an important compliance distinction. A business cannot simply assume a person is a parent because the person has clicked "I am the parent". The organisation needs a reasonable and documented method for satisfying the statutory verification requirement. At the same time, the Rules do not require businesses to collect every conceivable identity document. A proportionate system should be designed around the statutory requirements, the nature of the service and the information already available to the organisation. Consent Does Not Permit Behavioural Tracking of Children One of the most important legal risks arises when businesses assume parental consent permits behavioural monitoring. Section 9 separately restricts tracking and behavioural monitoring of children. This means a business cannot necessarily justify behavioural profiling merely because a parent has approved the child's account. For example, an application might collect information about how long a child watches particular videos, which games they play, what educational content they select and how frequently they return. If this information is used to construct behavioural profiles, the business needs to assess whether the activity falls within the statutory prohibition or an applicable exemption. This is particularly relevant for advertising technology and recommendation systems. Product teams should therefore review analytics software, cookies, software development kits, pixels and similar technologies rather than focusing only on information deliberately collected through registration forms. Targeted Advertising Creates a Separate Compliance Risk Section 9 also restricts targeted advertising directed at children. The restriction matters because many digital businesses depend upon advertising systems operated by third party platforms. A business may not directly select an advertisement for a particular child. Its application may instead send user information to an advertising network which determines the advertisements displayed. From a compliance perspective, the technical architecture still needs careful examination. Businesses should understand what information is transferred to advertising providers, whether a child can be identified, whether the system creates profiles and whether advertising technology can distinguish children from adult users. The commercial arrangement with the advertising provider should also be reviewed alongside the technical configuration. Processing Without Consent Can Create Contractual and Commercial Problems Privacy non compliance is not confined to regulatory exposure. Businesses increasingly make representations about data protection in investment documents, customer contracts, vendor agreements and enterprise procurement questionnaires. A material privacy failure may therefore create contractual concerns if the organisation has represented compliance with applicable law. Investor due diligence can also expose weaknesses in children's data practices. An investor examining an education technology company, gaming platform or children's application may ask how age verification works, whether parental consent is documented, which vendors process children's data and whether the organisation has experienced privacy incidents. Poor documentation can therefore affect the commercial value of a business even before a regulatory authority becomes involved. Third Party Vendors Can Multiply the Risk Many businesses do not process children's data entirely within their own systems. Cloud infrastructure providers, analytics companies, customer relationship management platforms, messaging providers, advertising networks and outsourced support teams may all receive personal information. A business remains responsible for understanding these data flows.Suppose an application has a compliant parental consent mechanism but an analytics tool begins collecting information before consent is recorded. The organisation may still face a compliance problem. This is why vendor due diligence should form part of children's privacy governance. Contracts should address permitted processing, security safeguards, confidentiality, incident reporting, assistance with regulatory obligations and deletion or return of information where appropriate. Businesses reviewing their broader privacy and data protection laws framework should also map every third party receiving children's personal data. Excessive Data Collection Can Create an Additional Risk Consent does not make unnecessary collection appropriate. Businesses sometimes collect extensive information because it may become useful later. For children's services, this approach creates unnecessary privacy exposure. A business should consider whether each data field is genuinely required for the stated service.An educational platform may need a student's age group to provide appropriate learning material. It may not need precise location information. A gaming application may require an account identifier but have no genuine need for access to a child's contact list. Data minimisation reduces the consequences of a security incident and makes the organisation's compliance position easier to demonstrate. Security Failures Can Compound Consent Problems A business can obtain valid parental consent and still face legal exposure if children's personal data is inadequately protected. The DPDP Act imposes obligations on Data Fiduciaries concerning reasonable security safeguards. The Act also provides significant financial penalties for specified contraventions. A consent process therefore needs to sit alongside appropriate access controls, authentication, monitoring, secure storage and incident response procedures. Internal access should also be limited. Employees should receive access based on their actual responsibilities rather than unrestricted access to children's information. Security testing should cover both the application and the systems supporting the consent process. Poor Consent Records Can Become a Serious Evidentiary Problem One of the most overlooked risks is the inability to prove compliance. A business should be able to establish when consent was obtained, who provided it, how the person was verified and what processing was covered. The organisation should also understand how consent withdrawal is handled. If a parent withdraws consent, the business needs a process for responding appropriately and updating relevant systems. Simply changing a status field in one database may not be sufficient if children's information remains accessible through other systems or third party platforms. Good record keeping therefore has both legal and operational value. Businesses Need to Consider the DPDP Implementation Timeline The DPDP Act and Rules are being brought into force in stages. The Central Government notified the DPDP Rules, 2025 on 13 November 2025. The Rules provide different commencement periods for different provisions. Rules 3, 5 to 16, 22 and 23 are scheduled to commence eighteen months after publication. The corresponding commencement notification under the Act similarly places Sections 3 to 5, Sections 6 to 17 and several related provisions eighteen months after 13 November 2025. Section 9 therefore falls within the later commencement group. Businesses should not interpret the phased timeline as a reason to delay preparation. Rebuilding account registration, age assurance, parental verification, analytics and advertising architecture can take considerable time. Early preparation is particularly important for platforms with a large existing child user base. What Businesses Should Do Before Processing Children's Data? The starting point should be a detailed data mapping exercise. The business should identify where children's personal data enters the organisation, where it is stored, who can access it, which vendors receive it and how long it is retained. The next step should be an assessment of the registration and consent journey. The organisation should determine whether it can identify child users appropriately, whether parental verification works reliably and whether processing begins only after the required consent has been obtained.Technology should then be reviewed. Analytics, advertising, recommendation engines, cookies and software development kits should all be assessed. The objective is to ensure the actual technology reflects the organisation's legal position. Businesses should also review contracts with processors and vendors. Finally, the organisation should establish internal responsibility. Legal, product, engineering, marketing, security and compliance teams should understand their respective responsibilities. For organisations dealing with complex privacy questions, obtaining advice from a best corporate lawyer can help integrate data protection requirements with commercial contracts, technology arrangements and broader corporate governance. Exemptions Need Careful Legal Assessment The DPDP framework does provide exemptions for specified classes of Data Fiduciaries and purposes. The final Rules contain a Fourth Schedule setting out certain classes and purposes for which specified child related obligations do not apply, subject to conditions. Examples include certain healthcare activities, educational activities and child safety functions. Businesses should not assume an exemption applies simply because their service falls within a broad industry category. The conditions attached to an exemption matter. An educational institution, for example, may have a prescribed basis for tracking or behavioural monitoring when the activity is restricted to educational activities or the safety of enrolled children. The same principle cannot automatically be extended to commercial profiling for unrelated purposes. The safest approach is to document the precise statutory basis for any exemption relied upon. Common Mistakes Businesses Should Avoid A business may believe it is compliant because its privacy policy refers to children. This is insufficient if the underlying consent mechanism does not meet the statutory requirements. Another common mistake is relying entirely on self declared age information. Businesses also overlook third party analytics and advertising tools. A platform may appear compliant at the user interface level while collecting information through embedded technologies in the background. Another problem is treating parental consent as permission for all subsequent processing. Section 9 contains separate restrictions, including restrictions on tracking, behavioural monitoring and targeted advertising. Finally, businesses sometimes wait until enforcement becomes imminent before reviewing their systems. Privacy compliance is considerably easier when considered during product development rather than retrofitted into an established platform. Conclusion Processing children's personal data without proper consent is not simply a privacy policy issue. It can create regulatory, contractual, operational, security and commercial risks for businesses operating in India.The DPDP framework places children in a specially protected category. Businesses need verifiable parental consent before processing children's personal data where Section 9 applies. They must also consider separate restrictions concerning detrimental effects on well being, tracking, behavioural monitoring and targeted advertising. The strongest compliance approach begins with understanding the data flow. Businesses should know what they collect, why they collect it, how parental consent is verified, where the information goes, who can access it and when it should be deleted. Most importantly, legal compliance should match the technology in use. A carefully drafted policy cannot protect a business if its application behaves differently from the policy. The official Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 should remain the primary references when assessing current obligations and commencement dates. Frequently Asked Questions (FAQs) Q1. What is Children's Data Consent under Indian law? It refers to the verifiable consent of a parent or lawful guardian required before a Data Fiduciary processes personal data belonging to a child, subject to applicable exemptions under the DPDP framework. Q2. Who is considered a child under the DPDP Act? The DPDP Act defines a child as an individual who has not completed eighteen years of age. The Central Government may notify a lower age for specified circumstances where the statutory conditions are satisfied. Q3. Is a child's own consent sufficient? No. Where Section 9 applies, the Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing the child's personal data. Q4. What does verifiable parental consent mean? Rule 10 requires appropriate technical and organisational measures and due diligence to establish whether the individual identifying themselves as the parent is an identifiable adult. Verification may rely on reliable information already held by the Data Fiduciary or information voluntarily provided through specified mechanisms. Q5. Does parental consent allow targeted advertising to children? No. Section 9 separately prohibits targeted advertising directed at children, subject to prescribed exemptions. Parental consent should not be treated as permission to disregard this restriction. Q6. Can businesses track children if parents have given consent? Businesses must separately examine the prohibition on tracking and behavioural monitoring under Section 9. Consent does not automatically override this statutory restriction. Prescribed exemptions may apply in limited circumstances. Q7. What happens if a business processes children's data without proper consent? The business may face regulatory consequences under the DPDP framework, alongside contractual, commercial, reputational and investor due diligence risks. The applicable consequences depend on the nature and circumstances of the contravention. Q8. Can schools and healthcare providers rely on exemptions? Certain exemptions exist under the Fourth Schedule, but they are limited and conditional. A business or institution should establish the exact statutory basis and conditions before relying upon an exemption. Q9. When should businesses begin preparing for children's data compliance? Businesses should begin preparation before the relevant provisions become operational. Consent architecture, age assurance, vendor arrangements and technology controls can require substantial redesign, particularly for platforms with a large existing user base.  
MHCO Updates
SEBI Update
REGULATORY UPDATE | SEBI ORDERS VARANIUM CLOUD TO RESTORE & DISGORGE FUNDS OVER IPO & RIGHT ISSUE FRAUD
The Securities and Exchange Board of India (“SEBI”) on 25 August 2025 passed a Final Order against Varanium Cloud Limited (“VCL”) and its key management for alleged fraudulent and misleading activities in connection with its Initial Public Offer (IPO), Rights Issue and subsequent disclosures. BACKGROUND The proceedings stemmed from SEBI’s preliminary examination pursuant to media reports and complaints regarding VCL’s financial statements and corporate announcements, which led to an Interim Order dated 10 May 2024 against VCL and its MD/Chairman, Harshwardhan Hanmant Sabale (Mr Sabale). VCL raised approximately Rs 40.39 crore through its IPO in September 2022 (primarily for Edge Data Centres and Edmission Digital Learning Centres) and proposed a further Rs. 48.45 crore through a Rights Issue in September 2023. SEBI examined the utilisation of issue proceeds, financial statements, Prospectus disclosures, corporate announcements, related-party transactions, and the role of directors, the CFO, the merchant banker and other intermediaries. SEBI’S FINDINGS SEBI found that VCL misrepresented its financial statements and prospectus by showing fictitious sales and purchases, and that its disclosures on utilisation of IPO proceeds (including the Statement of Deviation dated 17 November 2023) were incorrect and misleading. SEBI found that IPO and Rights Issue proceeds of Rs. 62.51 crore were diverted to related parties and other entities, including Rs. 32.73 crore transferred directly to Mr Sabale’s personal account. BM Traders (operated by Mr Raj Jagtani) received Rs. 19.66 crore in aggregate from the issue proceeds, of which Rs. 15.60 crore was transferred onwards; and that no adequate evidence of genuine business purpose was produced. SEBI found several business announcements by VCL to be false and unsubstantiated. SEBI also found that the Company also failed to support the substantial increase in reported revenues (including those of its US subsidiary) with invoices, contracts or employee details. Pending litigation was omitted from the Letter of Offer, and the Prospectus contained material omissions and misstatements. Liability was fastened on the Company, its MD, Executive Directors and CFO. SEBI found that the lead manager, First Overseas Capital Limited (FOCL), failed to exercise independent due diligence and did not disclose pending litigation. SEBI rejected FOCL’s defence that  it  could  rely  on  the  Company’s  representations  and  third-party  reports. Athos Capital Advisors Private Limited (ACAPL) and Mr Jinesh Mehta were held to have aided and abetted the misrepresentations; ACAPL received approximately Rs. 2.50 crore from VCL, and Mr Mehta admitted drafting portions of the Prospectus and assisting with fundraising. SEBI’S DIRECTIONS VCL was directed to bring back Rs. 62.51 crore (with 12% p.a. interest) within three months. Mr Sabale was directed to disgorge unlawful gains of Rs. 128.77 crore (with 12% p.a. simple interest) to the Investor Protection and Education Fund. VCL and Mr Sabale were debarred from the securities market for 7 years. ACAPL and Mr Jinesh Mehta were debarred for 2 years; Mr Raj Jagtani/BM Traders for 4 years; the Executive Directors and CFO (Mr Vinayak Jadhav, Mr Mukundan Raghavan and Mr Fahim Shaikh) for 1 year; and FOCL for 2 years (to run consecutively with an earlier debarment). Monetary penalties were also imposed, including Rs. 20.40 crore on Mr Sabale, Rs. 13 crore on VCL and Rs. 10.10 crore on Mr Raj Jagtani. Proceedings against the Company Secretary (Ms Hetal Somani) and a Non-Executive Director (Mr Kalpesh Acharekar) were disposed of without directions or penalty, the allegations against them being found unsustainable. MHCO COMMENT The order is significant for its treatment of misrepresentation in financial statements and public-issue disclosures, diversion of IPO and Rights Issue proceeds, and the accountability of directors, KMPs and intermediaries. It reiterates that a lead manager must conduct independent due diligence and cannot merely rely on the issuer’s representations or third-party reports. SEBI did not fasten liability on every director or officer; allegations against the Company Secretary and non-executive director were dropped for want of material. Overall, SEBI characterised the matter as a fraudulent scheme of raising public funds on misleading disclosures, followed by diversion of proceeds and creation of a false picture of the Company’s performance. The restoration, disgorgement, debarment and penalty directions reflect the seriousness with which the conduct was viewed. By: Mr. Bhushan Shah, Partner Mr. Abhishek Nair, Associate Ms. Sayali Kshirsagar, Associate
Rea Estate
BOMBAY HIGH COURT ALLOWS REFUND OF STAMP DUTY PAID ON CANCELLED DEVELOPMENT AGREEMENT
The Bombay High Court, vide judgment dated 20 August 2026 in Sai Innovation v. Joint District Registrar and Collector of Stamps, Pune City & Ors. (Writ Petition No. 7566 of 2016), has held that a Development Agreement which fails to achieve its intended purpose and is subsequently cancelled can qualify for refund of stamp duty under Section 47(c)(5) of the Maharashtra Stamp Act, 1958 (“the Stamp Act”), and that such an agreement can avail the extended limitation period under the proviso to Section 48(1) where stamp duty has been calculated with reference to Article 25 of Schedule I. Background: Sai Innovation had entered into a Development Agreement (“said Agreement”) dated 15 April 2013 with the owners of land at Village Mauje Balewadi, Pune, for development of approximately 8,000 sq. metres of land and paid stamp duty under Article 25 read with Article 5 of Schedule I to the Stamp Act. The owners were unable to obtain sanction of the building plans within a reasonable time, and disputes subsequently arose between the parties. The said Agreement was therefore cancelled by a registered Deed of Cancellation (“said Deed”) dated 18 February 2014, registered on 24 February 2014, and the consideration received was returned. Sai Innovation thereafter applied on 7 April 2014 for refund of the stamp duty. The Respondent Nos 1&2 vide their orders dated 11 August 2014 and 6 December 2014 (“Impugned Orders”) respectively, rejected the refund application of the Petitioner, principally on the ground that the said Agreement was not a “conveyance” and therefore did not fall within the proviso to Section 48(1) of the Stamp Act. Issue: The Court dealt with the following issues: Whether the said Agreement had failed to achieve its intended purpose to attract Section 47(c)(5) of the Stamp Act; Whether a Development Agreement could avail the benefit of the proviso to Section 48(1), particularly where stamp duty was calculated as per Article 25 of Schedule I; Whether the reference to “actual, open possession” in Clause 13 of said Agreement be interpreted as transfer of possession to the developer, notwithstanding Clause 11 of the said Agreement which described the developer as a licensee; and Whether the Respondents could subsequently rely upon the alleged transfer of possession as a ground for rejecting the refund claim, when the refund claim had initially been rejected by the Impugned Orders on other grounds, and the issue of possession did not form part of the reasons recorded in those orders. Key Findings The Court, while differentiating between Section 47 and Section 48 of the Stamp Act, held that while Section 47 is the main provision that gives the right to a refund of stamp duty, Section 48 only deals with the time limit. In the present case, the proposed development under the said Agreement was never acted upon, and the parties later cancelled the said Agreement by the said Deed. As a result, the transaction had clearly failed to achieve its intended purpose under Section 47(c)(5) of the Stamp Act. The Court therefore said the refund claim had to be examined first under Section 47 and could not be turned down simply by pointing to the limitation period. On the question of possession, the Court held that Clause 13 of the said Agreement could not be read in isolation from Clause 11. Although Clause 13 referred to “actual, open possession”, Clause 11 expressly described the developer’s rights as those of “a licensee for development”. Reading the Agreement as a whole, the Court concluded that the developer was granted only a limited contractual licence to enter the property and undertake development activities, and that there was no transfer of legal or exclusive possession. The Court also noted that the absence of a separate possession receipt, by itself, did not establish that possession had been transferred. Held In light of the above reasoning, the Court allowed the writ petition and quashed the Impugned Orders passed by the Respondents. The Court held that the refund application was filed within the extended period prescribed under the proviso to Section 48(1) of the Stamp Act and, accordingly, rejected the Respondents’ objection that the claim was barred by the ordinary six-month limitation period. MHCO Comment Parties seeking refund of stamp duty on a cancelled Development Agreement should note that Section 47 governs the substantive entitlement to refund, while the proviso to Section 48(1) determines the applicable limitation period. Further, the legal character of a Development Agreement should be assessed by reading the same meaningfully and not in isolation from other clauses provided therein. By: Mr. Bhushan Shah, Partner Ms. Meeta Kadhi, Associate Partner Mr. Saptadip Nandi Chowdhury, Associate
SEBI Update
REGULATORY UPDATE | SEBI IMPOUNDS ₹ 3.67 CR FROM TWO ENTITIES FOR ALLEGED MANIPULATIVE TRADES DURING CLOSING AUCTION SESSION
BACKGROUND The Securities and Exchange Board of India (“SEBI”) passed an Ex-Parte Interim Order dated 19 August 2026 against Copthall Mauritius Investment Limited (“Copthall”) and Mansi Share and Stock Broking Private Limited (“Mansi”) in relation to alleged manipulative trading during the Closing Auction Session (“CAS”) on the BSE SENSEX expiry day. SEBI's CAS framework, introduced vide Circular dated 16 January 2026 and made effective from 3 August 2026, provides for determination of the closing price through a dedicated auction mechanism based on the interaction of buy and sell orders. The framework replaced the earlier methodology based on the volume-weighted average price (“VWAP”) for securities covered under the CAS framework, which determined the price of securities based on the closing price of the security or focused on the weight of trades executed in the last 30 minutes of the trading session. Now, under the CAS framework, the price of securities is determined based on buy and sell orders in a single pool, executed at a single equilibrium price in a dedicated 20-minute daily auction timeline. SEBI’S FINDING SEBI prima facie found that the trading activity of Copthall and Mansi was linked to their outstanding SENSEX option positions and was undertaken to influence the Indicative Equilibrium Price (“IEP”) and closing price of the SENSEX so as to obtain a favourable payoff from their expiry-day F&O positions. On 13 August 2026, SEBI's surveillance observed three sharp movements in the SENSEX during the CAS. Upon examination of the trade and order logs, SEBI observed that these movements coincided with large and aggressive buy orders placed by Copthall and sell orders placed by Mansi in SENSEX constituent securities, which were subsequently cancelled. SEBI accordingly examined the trading activity of the two entities and its linkage with their outstanding SENSEX option positions. SEBI noted that the material on record did not prima facie indicate that the two Noticees acted in concert. Rather, each appeared to have adopted a separate strategy to move the SENSEX in a direction favourable to its respective F&O positions. SEBI'S DIRECTIONS SEBI directed that the bank accounts of Copthall and Mansi be impounded to the extent of ₹2,96,16,000 and ₹71,64,773 respectively, aggregating a total of ₹3,67,80,773. SEBI also debarred the noticees from accessing the securities markets and prohibited them from participating in the CAS, including placing, modifying or cancelling orders. Restrictions were also imposed on their bank and demat accounts, transfer/redemption of securities and disposal of assets without SEBI's permission. They were further directed to cooperate with SEBI's ongoing examination/investigation. MHCO COMMENT The order is significant in the context of the newly introduced CAS framework and SEBI's surveillance of potential attempts to influence the closing price through order placement and cancellation. The order demonstrates that SEBI is examining the nature, timing and price of orders, their impact on the IEP, subsequent cancellation of orders and the corresponding F&O positions of the concerned entities. The directions are interim in nature and are based on prima facie findings pending further investigation. SEBI has expressly clarified that the detailed investigation is to proceed independently of the prima facie observations contained in the interim order. Notably, SEBI has not alleged that Copthall and Mansi acted in concert. The findings against the two entities are based on their respective trading patterns and F&O positions. Since the order is ex-parte and interim in nature, the findings remain subject to SEBI's further examination, as well as the Noticees' replies and opportunity of hearing. By: Mr. Bhushan Shah, Partner Ms. Sayali Kshirsagar, Associate
IBC Update
IBC UPDATE - REMOVAL OF INTERIM MORATORIUM FOR PERSONAL GUARANTORS APPLIES TO PENDING PROCEEDINGS
Recently, the Bombay High Court in the case of Tata Capital Financial Services Limited v. Neel Motors LLP & Ors., held that the amendment introducing Section 96(4) of the Insolvency and Bankruptcy Code, 2016 (“IBC”) applies to insolvency applications filed before that date which remain pending. The Court consequently held that the interim moratorium under Section 96 ceased to operate against the personal guarantors from 26 May 2026, enabling Tata Capital to pursue limited interim relief under Section 9 of the Arbitration and Conciliation Act, 1996 (“Arbitration Act”). FACTS: The Petitioner, Tata Capital Financial Services Limited (“Tata Capital”) extended financial assistance to Respondent No. 1, Neel Motors LLP, under a Channel Finance Agreement. Respondent Nos. 2 to 4 were individual guarantors and partners of Neel Motors LLP, while Respondent No. 5 was a separate LLP acting as guarantor. The Letters of Guarantee contained arbitration clauses with Mumbai as the seat. In 2021, Tata Capital filed a petition under Section 9 of the Arbitration Act seeking interim protection. Approximately one month prior to filing the Section 9 petition, Tata Capital had initiated Corporate Insolvency Resolution Process (“CIRP”) against Neel Motors under the IBC. The CIRP ultimately failed and Neel Motors was ordered to be liquidated by the NCLT, Mumbai, on 1 April 2022. Thereafter, in June 2022, Tata Capital initiated insolvency proceedings under Section 95 of the IBC against Respondent Nos. 2, 3 and 4, who were the individual guarantors (“Guarantors”). The filing of the Section 95 applications triggered the interim moratorium under Section 96, stalling the Section 9 petition. The legal position changed with the insertion of Section 96(4) into the IBC which came into force on 26 May 2026. The amendment provided that Section 96 would not apply where an application was filed for initiating an insolvency resolution process in respect of a personal guarantor to a corporate debtor. Relying upon the amendment, Tata Capital sought consideration of its pending Section 9 petition. The principal issue before the Court was whether Section 96(4) could apply to Section 95 applications which had been filed before 26 May 2026 but continued to remain pending on the date of the amendment. Tata Capital’s Case Tata Capital contended that, in view of the newly inserted Section 96(4), the moratorium under   Section 96 no longer operated against the individual guarantors and the expression “where an application is filed” was sufficiently broad to include pending applications. It further relied upon the legislative purpose behind the amendment, that it was intended to “remove any perverse incentives” associated with the initiation of individual insolvency proceedings. Considering the considerable delay since filing of the Section 9 petition, Tata Capital only sought disclosure of the guarantors’ assets and an injunction restraining them from selling, transferring, alienating, encumbering or otherwise dealing with such assets pending arbitration. Guarantor’s Case The guarantors opposed the application, contending that such an interpretation would give the amendment retrospective effect. They submitted that the expression “where an application is filed” covers only applications filed after 26 May 2026 and could not extend to applications which had already been filed. Any other interpretation, according to the guarantors, would retrospectively alter the legal consequences attached to the pending proceedings. They further argued that although insolvency proceedings are not strictly recovery proceedings, both the insolvency and arbitration proceedings were directed towards recovery of the same debt and Tata Capital should therefore not be permitted to pursue both simultaneously Court’s Finding The Hon’ble Court held that the expression “where an application is filed” in Section 96(4) encompasses applications which had already been filed and continued to remain pending before the adjudicating authority. Had the legislature intended to restrict the provision only to applications filed after 26 May 2026, it could have expressly used language to that effect. The Court distinguished between retrospective and retroactive operation, relying upon the Supreme Court’s decision in Securities and Exchange Board of India v. Rajkumar Nagpal, the Court observed that a provision is retrospective when it operates backwards and impairs vested rights, whereas a retroactive provision operates prospectively on a character or status originating in the past. The existence of antecedent facts does not, by itself, make its application retrospective. Accordingly, the moratorium under Section 96 operated against Respondent Nos. 2 to 4 until 25 May 2026 but ceased from 26 May 2026 when Section 96(4) came into force. The pending Section 9 petition was therefore no longer barred by the IBC moratorium. The Court further acknowledged the possibility of a conflict of interest where the creditor initiating insolvency proceedings may also be pursuing claims against the individual guarantor. However, it held that such considerations could not override the express statutory language, particularly when Section 96(4) was agnostic as to the identity of the person who initiated the Section 95 proceedings. MHCO Comment Pending proceedings can be affected by a new provision without the provision necessarily being retrospective. The decisive factor is whether the provision changes completed past rights or operates prospectively upon an existing/pending legal status. Section 96(4) therefore lifted the Section 96 moratorium prospectively from 26 May 2026 even in respect of Section 95 applications filed prior to the amendment coming into force. By: Mr. Bhushan Shah, Partner Ms. Neha Lakshman, Associate Partner
LIFE AT MHCO
Need Help? Chat with us