CELEBRATING MORE THAN YEARS
AWARDS & RECOGNITION
PRACTICE AREAS
Dispute Resolution
Insolvency & Restructuring
General Corporate & Corporate Advisory
Real Estate & Property Laws
Employment & Labour Law
Regulatory Practice
Family Constitution, Succession, Estate Planning, Trust & Private Clients
Intellectual Property Rights
Mergers / Amalgamations / Business Transfer
Foreign Investments
Tax
Banking & Finance
Cyber Law, Privacy, Data Protection & Information Technology
Startups
PEOPLE

RA ShahManaging Partner

Niranjan parekhSenior Partner

Bhushan ShahPartner

Purvi AsherPartner

Meeta kadhiAssociate Partner

Akash JainAssociate Partner

Sanjana SaddyOf-Counsel

Bhavin shahOf-Counsel

Neha LakshmanAssociate partner
News and Articles
Children’s Data Protection,
Children’s Data Protection Under India’s DPDP Act: What Businesses Need to Know
The rapid growth of digital services for children has made Children's Data Protection an important legal issue for businesses operating in India. Educational platforms, gaming companies, healthcare providers, social platforms, e commerce businesses and family focused applications may collect information from users below eighteen years of age. India’s Digital Personal Data Protection Act, 2023 introduces specific safeguards for such processing, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. The Digital Personal Data Protection Rules, 2025 now provide greater operational clarity, although the substantive children’s data provisions are subject to the Act’s phased commencement framework.
For businesses, the issue extends well beyond publishing a privacy policy. Organisations need to examine their products, consent mechanisms, technology infrastructure, advertising practices, contracts and internal governance before the relevant provisions become operational.
What Does Children’s Data Protection Mean Under the DPDP Act?
The DPDP Act takes a broad approach to the protection of children’s personal data. Section 2(g) defines a child as an individual who has not completed eighteen years of age. This age threshold is important because businesses cannot simply adopt the age threshold used under another country's privacy regime and assume it will satisfy Indian requirements. Section 9 of the Act specifically deals with processing personal data of children. Before processing such data, a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian in the prescribed manner. The provision also requires businesses to ensure their processing does not cause a detrimental effect on the well being of a child. Further, subject to prescribed exemptions, the Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. This creates a higher compliance threshold than ordinary personal data processing. A business must therefore understand not only what information it collects, but also how its product uses information after collection. A child’s name, age, photograph, account details, location, educational information or online activity may all form part of a wider data processing ecosystem.
Why the DPDP Act Matters to Businesses?
The DPDP Act establishes a framework for digital personal data processing in India. It places obligations on Data Fiduciaries, meaning organisations which determine the purpose and means of processing personal data. The distinction is commercially significant. A company does not avoid responsibility simply because another company provides the technical infrastructure used for processing. Cloud providers, analytics vendors, software providers and other processors may support the service, but the business still needs to understand its own statutory responsibilities. The Act also creates rights for Data Principals and establishes an enforcement structure through the Data Protection Board of India. The statutory framework therefore moves privacy away from being purely an internal policy issue and towards formal organisational accountability. For businesses dealing with children, this accountability becomes particularly important because the law treats children's data as requiring additional safeguards.
The Current Legal Position and Commencement Timeline
One of the most important points for businesses is the phased implementation of the DPDP framework. The Central Government notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. The Rules provide for different commencement dates. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4 is scheduled to commence one year after publication, while Rules 3 and 5 to 16, along with Rules 22 and 23, are scheduled to commence eighteen months after publication. The Act follows a similar phased approach. India Code records Sections 2, 18 to 26, 35 to 43 and specified provisions of Section 44 as commencing on 13 November 2025. Substantive provisions including Sections 3 to 5, Sections 7 to 17 and other specified provisions are scheduled to commence eighteen months from that date. Section 9 falls within this later group. Accordingly, as of August 2026, businesses should distinguish between provisions already operational and provisions scheduled to commence later. This distinction is important for legal accuracy. Businesses should not describe every DPDP obligation as fully enforceable today. At the same time, waiting until the final commencement date would be commercially unwise. Product changes, vendor negotiations, consent architecture and internal governance can take months to implement.
Verifiable Parental Consent Is Central to Compliance
The most visible obligation concerning children's data is parental consent. Section 9 requires verifiable consent from the parent or lawful guardian before processing a child's personal data. The final Rules provide greater detail on how verification is expected to work. Rule 10 requires a Data Fiduciary to adopt appropriate technical and organisational measures and conduct due diligence to establish whether the person presenting themselves as a parent is an identifiable adult. Verification may rely on reliable identity and age information already available to the Data Fiduciary or information voluntarily provided by the individual or through a virtual token issued by an authorised entity. This creates an important design challenge. A business must verify parental authority without creating an unnecessarily intrusive identity collection process. Collecting excessive information from parents can create additional privacy and security risks. The consent mechanism should therefore be designed around necessity, proportionality and security. A simple declaration such as “I am the parent” may not be sufficient where the law requires verifiable consent. Businesses should document the verification methodology and retain appropriate evidence of consent.
The Restrictions on Tracking and Behavioural Monitoring
The DPDP Act takes a particularly cautious approach to children's behavioural data. Section 9 restricts tracking and behavioural monitoring of children, along with targeted advertising directed at children, subject to prescribed exemptions. This can affect technologies businesses commonly use for analytics and personalisation. For example, a platform may use cookies, device identifiers, engagement data, location information or interaction histories to understand user behaviour. For an adult audience, these practices may form part of ordinary analytics. A child focused service requires a much more careful assessment. Businesses should therefore review software development kits, analytics tools, advertising pixels, recommendation systems and third party tracking technologies before deployment. The question should not simply be whether the technology collects personal data. The business should ask whether it tracks or monitors the behaviour of children and whether the proposed activity falls within a permitted exemption.
Targeted Advertising to Children Requires Particular Caution
Advertising models based on user profiling can create significant legal concerns. A business may collect information about content preferences, browsing behaviour, purchasing patterns or engagement levels and use it to deliver personalised advertisements. Section 9 places a specific restriction on targeted advertising directed at children, subject to prescribed exemptions. This means marketing teams should not treat children's advertising as merely another segmentation exercise. Businesses need to understand how their advertising systems identify audiences and whether child users can enter those audiences. This becomes more complicated for platforms serving both adults and children. Age assurance, account design and advertising controls may therefore need to work together. A company should also examine whether external advertising partners receive information about child users and what contractual restrictions apply to such processing.
Exemptions Under the DPDP Rules
The Rules recognise certain exemptions from specific children's data obligations. The explanatory note published by the Ministry of Electronics and Information Technology identifies specific classes of organisations, including certain healthcare professionals, educational institutions and childcare providers, which may benefit from exemptions for defined purposes. The exemptions are subject to conditions and are not a blanket permission to process children's personal data without safeguards. For example, processing may be permitted for activities connected with healthcare, education, child safety or transportation, depending on the applicable category and conditions. This purpose based approach matters. An educational institution should not assume its entire database is exempt merely because it is an educational institution. The organisation should identify the precise processing activity and establish whether it falls within the relevant statutory exemption. A written exemption assessment can be valuable during internal compliance reviews.
Data Minimisation Should Start at Product Design
Children's privacy cannot be managed effectively if a business collects excessive information from the outset. A useful question is simple: does the service genuinely need every piece of information being collected? An educational application may need a child's name, class and learning records to provide its service. It may not need precise location data, extensive behavioural profiles or unrelated demographic information. Data minimisation reduces both compliance exposure and cybersecurity risk. Product teams should therefore involve privacy considerations before new features are released. A feature which creates a new category of children's data should trigger a review before development is completed. Privacy by design is considerably easier than restructuring a mature product after launch.
Privacy Notices and Consent Records
Businesses should ensure their privacy notices accurately describe their processing activities. The DPDP Rules introduce specific notice requirements, including clear information about the personal data being processed and the purpose for processing. The Government's explanatory note emphasises accessible information and transparency for Data Principals. For children's services, the privacy notice should align with the parental consent process. A common compliance weakness occurs when the privacy notice describes one processing purpose while the product performs additional analytics or marketing activities. The legal document, application interface and internal data practices should therefore remain consistent. Businesses should also maintain reliable records showing how and when consent was obtained. Consent records may become important when responding to complaints, regulatory enquiries or internal audits.
Children's Data and Third Party Vendors
Modern businesses rarely operate entirely within their own technology environment. An application may use external cloud hosting, analytics, customer support software, communication services, payment platforms and advertising networks. Every such relationship should be examined where children's personal data is involved. The business should know what information is shared, why it is shared, where it is stored, how long it is retained and what happens when the relationship ends. Vendor contracts should contain appropriate provisions dealing with confidentiality, security, permitted processing, breach reporting, deletion, subcontracting and assistance with legal obligations. A business should also maintain an up to date inventory of relevant vendors. It is difficult to demonstrate effective privacy governance when the organisation does not know who has access to its data.
Security Obligations Cannot Be Separated From Children's Privacy
Consent alone does not protect children's information. A business can have a perfectly designed consent mechanism and still face serious exposure if its databases, applications or vendor systems are insecure. The DPDP framework requires Data Fiduciaries to adopt reasonable security safeguards. The statutory penalty framework provides significant financial exposure for specified breaches, including penalties of up to ₹250 crore for failure to take reasonable security safeguards and up to ₹200 crore for breach of obligations relating to children. Security controls should therefore be proportionate to the nature and volume of data handled. Access restrictions, authentication, encryption where appropriate, secure software development, monitoring, vulnerability management and incident response should form part of the wider governance framework. Employee awareness is also important. A child’s information may be exposed through simple operational mistakes such as incorrect email distribution, insecure file sharing or excessive employee access.
What Happens After a Data Breach?
Businesses should have an incident response procedure before an incident occurs. The response should establish who investigates the breach, who makes legal decisions, who communicates with affected parties and who manages regulatory engagement where required. Children's information can present distinctive risks. A breach involving a child's location, photograph, school details or behavioural information may create consequences beyond ordinary commercial inconvenience. Incident response should therefore consider the nature of the affected information and the potential impact on children. The DPDP framework contains specific requirements concerning personal data breaches, while the Rules provide operational detail for breach intimation. Businesses should ensure their technical and legal teams understand the applicable requirements before an incident occurs.
Artificial Intelligence Creates New Children's Data Questions
AI based products create another layer of complexity. A business may use children's data to personalise educational content, generate recommendations, analyse performance or develop machine learning systems. Before using information for a new purpose, the organisation should examine whether the proposed processing is consistent with the original purpose, notice and applicable consent framework. A company should not assume data collected for one service can automatically be reused to train a commercial AI system. AI governance should therefore be integrated into children's data governance. Product teams should identify whether AI tools receive personal data, whether external providers process it and whether the proposed use is necessary for the service.
What Businesses Should Do Before Section 9 Becomes Operational?
Businesses handling children's data should use the transition period to conduct a detailed privacy readiness assessment. The first stage should be data mapping. Identify where children's information enters the organisation, what categories are collected, where the information is stored and which internal teams and external vendors can access it. The second stage should involve an age and consent assessment. Determine how the business will identify child users and how it will obtain and verify parental consent where required. The third stage should focus on product design. Review analytics, behavioural monitoring, recommendation engines, advertising systems and location features. The fourth stage should involve contractual review. Vendor and partner agreements should reflect the organisation's actual data processing arrangements. The final stage should involve governance. Assign responsibility for privacy compliance, consent records, data inventories, incident response and regulatory developments. Businesses can consult the official Digital Personal Data Protection Rules, 2025 published by MeitY for the notified regulatory text and commencement information.
Why Businesses Should Prepare Before the Legal Deadline?
The transition period should not be viewed as a reason to postpone compliance. A privacy programme may require changes to software architecture, account creation, consent flows, databases, advertising technology and contracts. These changes cannot always be completed immediately. Early preparation also gives businesses an opportunity to identify commercially unnecessary data collection. For example, a company may discover it has been collecting precise location information simply because an analytics tool automatically captures it. Removing unnecessary collection may be easier than creating a complex legal justification for retaining it. The objective should be to build a product where privacy safeguards support the business model rather than obstruct it.
The Role of Legal Advisers in Children's Data Compliance
Children's data compliance involves several disciplines. Technology teams understand the systems. Product teams understand the user journey. Marketing teams understand advertising practices. Security teams understand infrastructure. Legal professionals connect these activities with statutory requirements. Businesses may therefore benefit from involving data privacy law firms when reviewing complex children's data processing arrangements, particularly where the service involves large scale processing, behavioural technology, international vendors or sensitive categories of information. A legal review should examine the actual product rather than only the privacy policy.
The right questions include whether parental consent is genuinely verifiable, whether the business collects more information than necessary, whether tracking technologies operate on child accounts, whether vendors receive children's data and whether the business can demonstrate compliance through reliable records. The objective is practical risk management, not paperwork for its own sake. Where the organisation has wider corporate governance or commercial contracting concerns, a corporate lawyer can also help connect privacy requirements with shareholder arrangements, technology contracts, vendor agreements and business operations.
Conclusion
India's DPDP framework represents a significant shift in how businesses must approach children's personal data. Section 9 places specific emphasis on verifiable parental consent, child well being and restrictions on behavioural monitoring, tracking and targeted advertising. The DPDP Rules, 2025 provide additional operational detail and introduce specified exemptions for certain organisations and purposes. For businesses, the strongest response is early preparation. Children's privacy should be considered during product development, vendor selection, marketing planning and technology design rather than being addressed only when a regulatory deadline approaches. A defensible compliance framework should allow the organisation to answer five basic questions clearly: What children's data do we collect? Why do we need it? Who can access it? How do we obtain and record consent? When do we delete it? Businesses able to answer these questions with evidence will be better placed to manage the legal, operational and reputational risks associated with children's personal data.
Frequently Asked Questions (FAQs)
Q1. What is Children's Data Protection under the DPDP Act?
It refers to the additional legal safeguards applicable to processing personal data belonging to individuals who have not completed eighteen years of age. Section 9 of the DPDP Act specifically addresses children's personal data.
Q2. What age is considered a child under India's DPDP Act?
A child is an individual who has not completed eighteen years of age.
Q3. Is parental consent mandatory for children's data?
Section 9 requires verifiable consent from the parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions.
Q4. Can businesses track children online?
Section 9 restricts tracking and behavioural monitoring of children, subject to prescribed exemptions. Businesses should therefore review analytics, advertising and profiling technologies used on child facing services.
Q5. Can businesses show targeted advertisements to children?
Targeted advertising directed at children is restricted under Section 9, subject to prescribed exemptions.
Q6. Does the DPDP Act apply only to children's apps?
No. The relevant obligations can affect any Data Fiduciary processing personal data of children. This can include education, healthcare, gaming, retail, entertainment and other digital services.
Q7. Are schools exempt from children's data requirements?
The Rules provide specific exemptions for certain educational institutions and specified purposes. These exemptions are conditional and should not be interpreted as a general exemption from all DPDP obligations.
Q8. When will Section 9 become applicable?
Section 9 is scheduled to commence eighteen months after 13 November 2025, alongside other substantive provisions listed in the commencement notification. This places the scheduled commencement date at 13 May 2027, subject to any subsequent notification or amendment.
Q9. What penalties can apply for children's data violations?
The DPDP Act's Schedule provides for a penalty of up to ₹200 crore for breach of the additional obligations relating to children. Other contraventions carry different maximum penalties.
Q10. Is a privacy policy enough for compliance?
No. Businesses need a broader framework covering data mapping, consent management, security safeguards, vendor governance, retention, rights management, incident response and internal accountability.
Children's Data Privacy,
Data Privacy Laws for Businesses Handling Children's Personal Data in India
Children increasingly interact with digital platforms for education, entertainment, gaming, communication and financial services. As businesses collect names, photographs, contact details, location information, account credentials, academic records and behavioural information from young users, Children's Data Privacy has become a significant legal and governance issue in India. The Digital Personal Data Protection Act, 2023 introduces specific obligations for organisations processing children's personal data, including verifiable parental consent and restrictions on tracking, behavioural monitoring and targeted advertising. The Digital Personal Data Protection Rules, 2025 provide further operational detail.
For businesses, the issue is no longer limited to having a privacy policy. It involves understanding what data is collected, why it is collected, how parental consent is established, who receives the information, how long it is retained and how the organisation responds when something goes wrong.
What Is Children's Data Privacy Under Indian Law?
The Digital Personal Data Protection Act, 2023 defines a child as an individual who has not completed eighteen years of age. This is a considerably broader age threshold than some international privacy regimes. Section 9 of the Act creates additional safeguards specifically for processing personal data belonging to children. The Act applies to digital personal data. This includes information collected in digital form as well as personal data collected in non digital form and subsequently digitised, subject to the Act's scope and exclusions. For a business, this means a child's data should not be treated as an ordinary customer dataset. The organisation needs to determine whether the user is a child, whether parental consent is required, whether an exemption applies and whether the proposed processing could adversely affect the child's well being. The Supreme Court's privacy jurisprudence also provides an important constitutional backdrop. In Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the Supreme Court recognised privacy as a fundamental right. The later judgment specifically discussed the importance of protecting children's digital footprints and recognised the need for special protection for children's privacy.
India's Current Legal Framework for Children's Data Privacy
India's principal statutory framework is the Digital Personal Data Protection Act, 2023, supported by the Digital Personal Data Protection Rules, 2025. The Act establishes the concepts of Data Fiduciaries and Data Principals. A business deciding the purpose and means of processing personal data generally falls within the role of a Data Fiduciary. A child whose personal data is processed is a Data Principal. Section 9 is the central provision for children's data. It requires the Data Fiduciary to obtain verifiable consent from the parent or lawful guardian before processing a child's personal data. The provision also prohibits processing likely to cause a detrimental effect on the well being of a child. In addition, it prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This framework is important for more than children's apps. EdTech platforms, healthcare providers, gaming businesses, e commerce platforms, social platforms, educational institutions, childcare providers and businesses offering services to families may all need to examine whether their activities involve children's personal data.
When Do the Children's Data Provisions Take Effect?
This point requires particular care because the DPDP Act and Rules have a phased commencement structure. The Central Government issued the commencement notification on 13 November 2025. Several institutional provisions came into force immediately. However, Sections 3 to 5, most of Section 6, Sections 7 to 17 and several other substantive provisions, including Section 9 dealing specifically with children's personal data, are scheduled to come into force eighteen months after 13 November 2025. This places the scheduled commencement of Section 9 on 13 May 2027. The same phased approach applies to the relevant provisions of the DPDP Rules, 2025. Rule 10, which deals with verifiable consent for processing children's personal data, falls within the provisions scheduled to commence eighteen months after publication. As of August 2026, businesses therefore have an important preparation window. The fact that the principal children's data obligations are not yet fully operational does not make preparation unnecessary. Organisations handling children's information should use the transition period to redesign their systems, contracts, consent mechanisms and governance arrangements.
What Does Verifiable Parental Consent Mean?
Parental consent under the DPDP framework is more demanding than simply displaying a checkbox stating, "I am the parent". The 2025 Rules provide an operational mechanism for verifying the person providing consent. Rule 10 requires a Data Fiduciary to adopt appropriate measures to verify whether the person giving consent is the parent or lawful guardian and whether the person is an identifiable adult. The Ministry's explanatory note refers to reliable identity details and virtual tokens mapped to such details. The Rules also contemplate situations where a parent is already registered with the service and circumstances where identity details may need to be provided through mechanisms such as Digital Locker. For businesses, the practical challenge is significant. The consent journey must be reliable without collecting excessive information from parents merely to establish their authority. An organisation should therefore consider data minimisation while designing parental verification. Collecting more identity information than necessary may create a second privacy problem while attempting to solve the first.
Restrictions on Tracking and Behavioural Monitoring
One of the most significant aspects of India's children's privacy regime is the restriction on tracking and behavioural monitoring. Businesses often rely on analytics tools to understand how users interact with their websites or applications. They may use cookies, device identifiers, location signals, engagement histories or other technical information to understand user behaviour. Where a user is a child, these practices require careful examination.
Section 9(3) expressly prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, subject to prescribed exemptions. This creates an important distinction between providing a service and profiling its users. An educational platform may need certain information to provide lessons, assess performance or maintain account security. It does not automatically follow that the same platform can use the child's behavioural information to build advertising profiles. Businesses should map every category of analytics and advertising technology used on a child facing service. Third party SDKs and advertising technologies deserve particular attention because a company may remain responsible for how personal data is processed even where technical processing is performed through external vendors.
Can Schools, Healthcare Providers and Childcare Businesses Rely on Exemptions?
The DPDP Rules recognise certain exemptions from some of the obligations under Section 9.
The Fourth Schedule contains specific classes of Data Fiduciaries and prescribed conditions. These include certain healthcare establishments and professionals, educational institutions and childcare providers. The exemptions are purpose specific and subject to conditions. This distinction is important. An educational institution cannot assume every form of data processing is automatically exempt simply because it is a school. The relevant processing must fall within the prescribed class and purpose. For example, processing necessary for educational activities may be treated differently from using children's information for unrelated commercial profiling or promotional activities. Businesses should therefore document the precise statutory basis for relying on an exemption rather than treating an exemption as a blanket permission.
Privacy Notices Must Be Designed for the Actual Processing
A privacy notice should tell users what information is being collected and why it is needed. Under the 2025 Rules, the notice requirements include clear and understandable information about the personal data being processed and the specific purpose for processing. The notice also needs to provide a means through which the Data Principal can access relevant information and exercise applicable rights. For children's services, the consent experience should be designed around the parent or lawful guardian where parental consent is required. A lengthy privacy policy hidden behind multiple links is unlikely to provide a strong operational solution. The business should separate the legal document from the actual user journey. The consent interface, privacy notice, account creation process and internal records should tell the same story.
Data Minimisation Becomes Especially Important
Children's privacy compliance is not simply about obtaining consent. Businesses should ask whether each item of information is genuinely necessary for the service. If a platform needs an email address to create an account, collecting detailed location information may require separate justification. If a learning service needs assessment results, collecting unrelated behavioural information may increase legal and security exposure. Data minimisation also reduces the consequences of a breach. A business cannot lose information it never collected. This principle should be reflected in product design, database architecture, analytics configuration and vendor contracts.
Security Safeguards and Children's Personal Data
The sensitivity of children's information makes information security a central compliance concern. The DPDP Act requires Data Fiduciaries to take reasonable security safeguards to prevent personal data breaches. The statutory schedule allows a penalty of up to ₹250 crore for breach of the obligation concerning reasonable security safeguards. A breach of the additional obligations relating to children can attract a penalty of up to ₹200 crore. These figures demonstrate why cybersecurity cannot be treated solely as an IT issue. A business handling children's information should consider access controls, encryption where appropriate, authentication, secure development practices, logging, vulnerability management, backup security and incident response procedures. Employees should also understand how children's information is handled. Human error remains a significant source of privacy incidents.
Vendor and Third Party Risk
Many businesses do not process all personal data internally. Cloud service providers, analytics companies, customer relationship platforms, communication tools, payment providers and software developers may process information on behalf of the business. This creates contractual and operational risk. A company should know which vendors receive children's personal data, what information they receive, why they receive it, where it is processed and how it is deleted. Vendor agreements should address confidentiality, security obligations, permitted processing, incident reporting, subcontracting, deletion and assistance with regulatory requirements. A privacy programme is only as strong as its weakest significant data processor.
What Happens When a Data Breach Occurs?
A business should have an incident response plan before a breach occurs.
The response should identify who investigates the incident, who decides whether notification is required, who communicates with affected individuals and who liaises with regulators or authorities where necessary. The DPDP Act contains specific obligations concerning personal data breaches and provides penalties for failure to comply with applicable notification requirements. For businesses serving children, incident response should also consider the potential real world consequences of disclosure. A leaked email address is one concern. Exposure of a child's location, school information, photographs or behavioural profile can create substantially different risks. The response should therefore be proportionate to the nature of the information involved.
Children's Data and Artificial Intelligence
The growth of artificial intelligence creates another layer of complexity. Businesses may use children's information to train models, personalise educational content, generate recommendations or analyse performance. Before doing so, the business should identify the purpose of processing and determine whether the proposed use is permitted under the applicable legal framework. Using data collected for education to train a commercial model may raise questions about purpose, notice, consent and fairness. The business should not assume the original consent automatically covers every later use. Data governance should therefore extend to AI systems, analytics tools and automated decision making processes.
How Businesses Should Prepare Before the Rules Fully Apply?
Businesses handling children's personal data should begin with a data mapping exercise. The organisation should identify where children's data enters its systems, what categories are collected, which teams access it, which vendors receive it, where it is stored and when it is deleted. The next step should be an assessment of the user journey. If parental consent will be required, the organisation should determine how it will identify children, verify parents and maintain evidence of consent without collecting unnecessary information. The organisation should then review its advertising and analytics architecture. Tracking technologies directed at children's activity require particular scrutiny because Section 9 specifically addresses behavioural monitoring and targeted advertising. Contracts should also be reviewed. Vendor agreements, data processing arrangements, confidentiality clauses and security obligations should reflect the organisation's actual data practices. Finally, internal accountability should be established. Someone should be responsible for maintaining the data inventory, reviewing privacy controls, managing incidents and keeping the business informed about regulatory developments.
Why Businesses Should Not Wait Until May 2027?
The eighteen month transition period may appear generous, but privacy compliance is rarely solved by changing a single document. A business may need to modify its application, database, consent architecture, vendor arrangements, marketing technology, privacy notices and internal procedures. Technology changes take time. Vendor negotiations take time. Product teams need time to test new consent flows. Early preparation also allows businesses to identify practices which may be commercially attractive but legally difficult to defend. India's data protection regime is moving towards a more structured accountability model. Businesses should therefore treat children's privacy as a product governance issue rather than a compliance formality. Organisations looking for guidance on India's evolving data protection laws should rely primarily on the legislation, notified Rules, government notifications and authoritative regulatory material.
The Role of Legal and Compliance Teams
Legal review should not begin only after a privacy incident. Where a business regularly handles children's information, legal advisers should work with product, technology, security and marketing teams from an early stage. The role of commercial lawyers can extend beyond drafting privacy notices. They can help assess contractual arrangements, advertising models, vendor obligations, consent mechanisms, regulatory exposure and commercial implications of data processing practices.
A good legal review asks practical questions.
What is the business trying to achieve?
What information does it actually need?
What legal basis supports the processing?
Is parental consent required?
Can the same objective be achieved with less information?
Who else receives the data?
What happens if the user withdraws consent?
How will the company respond to a breach?
These questions connect legal compliance with actual business operations.
Key Takeaway
India's approach to children's personal data is moving towards stronger accountability and more active protection. The DPDP Act, 2023 places particular emphasis on verifiable parental consent, child wellbeing and restrictions on tracking, behavioural monitoring and targeted advertising. The DPDP Rules, 2025 add practical mechanisms for implementing these requirements. For businesses, compliance should begin with understanding the data lifecycle. The organisation needs to know what information it collects, why it needs it, who can access it, which third parties receive it and when it should be deleted. Product design, cybersecurity, contracts and legal governance should then work together. The strongest approach is not to treat children's privacy as a document prepared shortly before a regulatory deadline. It is to build privacy safeguards into the way the business collects and uses information from the outset.
Frequently Asked Questions (FAQs)
Q1. What is Children's Data Privacy in India?
Children's Data Privacy refers to the legal and organisational safeguards applicable when businesses process personal data relating to individuals below eighteen years of age. The DPDP Act, 2023 contains specific protections for children's personal data.
Q2. What age is considered a child under the DPDP Act?
Under the DPDP Act, a child is an individual who has not completed eighteen years of age.
Q3. Is parental consent required to process children's personal data?
Section 9 requires verifiable consent from a parent or lawful guardian before processing a child's personal data, subject to prescribed exemptions.
Q4. Can businesses use targeted advertising for children?
Section 9 prohibits targeted advertising directed at children, subject to the exemptions prescribed under the law. Businesses should therefore review advertising technology carefully before using it in services accessed by children.
Q5. Is behavioural tracking of children allowed in India?
Section 9 of the DPDP Act prohibits tracking or behavioural monitoring of children, subject to prescribed exemptions.
Q6. When will Section 9 of the DPDP Act become effective?
Section 9 is scheduled to come into force eighteen months after 13 November 2025, meaning the scheduled commencement date is 13 May 2027, subject to any subsequent government notification or change.
Q7. Do educational institutions have any exemptions?
The DPDP Rules provide specified exemptions for certain classes of Data Fiduciaries, including educational institutions, subject to prescribed conditions and purposes. The exemption should not be treated as a blanket exemption from all privacy obligations.
Q8. What penalties can apply for violating children's data obligations?
The Schedule to the DPDP Act provides for a penalty of up to ₹200 crore for breach of the additional obligations relating to children under Section 9. Other breaches can attract different maximum penalties.
Q9. Does a privacy policy alone make a business compliant?
No. A privacy policy is only one component of a wider privacy framework. Businesses also need appropriate consent mechanisms, data governance, security controls, contractual safeguards, retention practices and processes for handling rights requests and incidents.
Q10 Should startups prepare for children's data obligations before they become effective?
Yes. Businesses handling children's personal data should use the transition period to review their products, consent mechanisms, technology, contracts and internal controls. Waiting until the statutory provisions become operational may leave insufficient time for meaningful implementation.
Contract Management,
Why Many New Businesses Overlook Contract Management in the Early Stage?
A new business usually begins with a simple priority: win customers, deliver the product and keep cash moving. Legal paperwork often comes later. This is why Contract Management is frequently overlooked during the early stage. Founders may sign agreements through email, save documents in different folders and rely on memory for renewal dates or commercial commitments. The problem becomes visible only when a customer disputes an obligation, a supplier changes its terms, confidential information is misused or an important contract expires without anyone noticing. For an early stage business, contract management is not merely an administrative function. It is a practical system for controlling legal obligations, commercial relationships and avoidable risk.
What Contract Management Really Means
Contract management is the process of managing an agreement from the moment a business identifies the need for it until the agreement is completed, renewed, amended or terminated. Modern contract lifecycle frameworks generally cover initiation, drafting, negotiation, approval, execution, performance monitoring and closure. This distinction matters for new businesses. A signed contract is not the end of the process. It is the point at which the parties begin performing their obligations. Consider a technology startup which signs a one year software services agreement. The founder may focus on the negotiated fee and scope of work. Six months later, the business may discover an automatic renewal clause, a minimum purchase commitment or a liability cap it no longer considers commercially suitable. If nobody was responsible for monitoring the agreement, the opportunity to renegotiate may already have passed. Effective contract management keeps such obligations visible.
Why Founders Often Ignore Contracts in the Early Stage?
The reason is rarely deliberate neglect. It is usually a consequence of limited resources. Founders often perform several roles simultaneously. They manage sales, finance, recruitment, product development and investor discussions. Legal administration competes with activities perceived as more urgent. There is also a misconception about contract volume. A business may have only ten or fifteen agreements during its first year. Founders therefore assume a formal system is unnecessary. Yet a small contract portfolio can contain significant exposure. A single customer agreement may govern a large portion of revenue. A supplier agreement may affect business continuity. An employment agreement may deal with confidential information and intellectual property. A lease can create a substantial financial commitment. Contract value is therefore more important than contract count.
The Difference Between Drafting and Managing a Contract
Drafting determines what the parties agree. Management determines whether the agreement continues to work as intended. A carefully drafted agreement can still cause problems if the business does not monitor it. Suppose a services contract requires delivery within defined timelines. The legal document may contain an escalation mechanism, service levels and payment consequences. If the operational team never receives the relevant deadlines, the business may breach its own obligations despite having negotiated a strong agreement. Contract management creates the connection between legal terms and daily business activity. This is one of the most important gaps in early stage businesses. Founders may involve lawyers before signing but fail to involve the legal or operations function after execution.
The Legal Framework Governing Contracts in India
The primary legislation governing contracts in India is the Indian Contract Act, 1872. It deals with matters including proposal and acceptance, competency, free consent, lawful consideration and object, performance, breach, indemnity, guarantee and agency. Section 10 sets out the basic requirements for agreements to become contracts, subject to the other provisions of the Act. Contractual arrangements may also be affected by sector specific legislation, company law, tax law, intellectual property legislation, data protection requirements and state specific stamp laws. Founders should therefore avoid treating every agreement as a generic commercial document. The legal requirements can vary depending on the nature of the transaction, parties involved, subject matter, governing law and place of execution.
Why Informal Agreements Create Problems?
Early stage businesses frequently rely on emails, WhatsApp messages, purchase orders and verbal commitments. Electronic communications can have legal significance. The Information Technology Act, 2000 recognises electronic records and electronic signatures and contains Section 10A concerning contracts formed through electronic means. This does not mean every informal conversation is a suitable substitute for a carefully drafted commercial agreement. The central problem is uncertainty. If the parties disagree later, they may have different understandings about price, scope, delivery, intellectual property ownership, confidentiality, termination or liability. A fragmented email trail can make the dispute harder to resolve. A written agreement should therefore record material commercial terms clearly rather than leaving important matters to assumptions.
Contract Risks New Businesses Commonly Miss
One recurring problem is unclear scope. If a customer and service provider understand the deliverables differently, a dispute can arise even when both believe they acted reasonably. Payment terms can create another problem. Businesses sometimes focus on the headline price while overlooking advance payments, taxes, credit periods, late payment provisions, set offs and milestone conditions. Termination clauses also deserve close attention. A business should understand how an agreement can end, how much notice is required and what happens to outstanding obligations after termination. Liability provisions are equally important. Indemnities, exclusions, limitation of liability clauses and warranties can materially change the financial consequences of a dispute. Intellectual property provisions are particularly important for technology businesses. The contract should make it clear who owns pre existing material, newly created work product, source code, designs, documentation and improvements. Confidentiality provisions should also reflect the nature of information being exchanged.
Contract Management and Corporate Authority
A new company should also consider who has authority to enter into agreements on its behalf. This becomes particularly important when founders, employees or business development personnel negotiate contracts with customers and suppliers. The company should have an internal approval structure appropriate to its size and risk profile. High value transactions, long term commitments, related party arrangements and unusual liability provisions may require higher level review. The Companies Act, 2013 also contains specific requirements concerning interested directors and certain contracts or arrangements involving companies. Section 184 requires disclosure of a director's interest in specified contracts or arrangements and restricts participation in the relevant Board discussion in the circumstances prescribed by law. Contract management should therefore connect commercial decision making with corporate governance.
Stamp Duty Should Not Be an Afterthought
Stamp duty is another area often missed when businesses focus only on commercial terms. The Indian Stamp Act, 1899 contains provisions concerning instruments chargeable with stamp duty. State amendments and state specific stamp legislation can also be relevant, depending on the document and place of execution. A contract should therefore be reviewed for applicable stamping requirements before execution or within the legally prescribed framework. The consequences of inadequate stamping can depend on the applicable law and circumstances. Businesses should obtain advice where the agreement involves significant commercial value or a complex transaction.
Why Contract Storage Matters?
Finding the latest signed version of an agreement should not require a search through an employee's inbox. A basic contract repository should contain the executed agreement, amendments, schedules, supporting documents and relevant correspondence. Access should be controlled according to the sensitivity of the information. The repository should also capture practical information such as the parties, effective date, expiry date, renewal provisions, notice period, payment obligations and responsible business owner. The aim is simple: someone should be able to understand the status of an agreement without reading every email exchanged during negotiation.
Managing Renewals and Expiry Dates
Automatic renewal clauses deserve particular attention. A contract may renew automatically unless notice is given within a specific period. Missing the notice window can lock the business into another contractual period. The same problem can arise with leases, software subscriptions, insurance arrangements, maintenance contracts and vendor agreements. A simple reminder system can prevent avoidable costs. The responsible person should receive notice sufficiently early to allow commercial review and renegotiation. The key point is not merely recording the expiry date. The business should record the date by which action must be taken.
Contract Management During Business Expansion
Contract complexity usually increases as a business grows. A company entering new markets may work with distributors, channel partners, consultants, logistics providers, technology vendors and overseas customers. Different jurisdictions may introduce additional considerations concerning governing law, dispute resolution, taxation, foreign exchange, data transfers and regulatory compliance. For businesses considering business setup in india, contract management should be considered alongside corporate structuring rather than after commercial operations begin. Early discipline makes expansion easier because the business already has approved processes, contract records and defined authority levels.
Contract Management and Business Expansion in India
Expansion often creates a second challenge: contracts start being negotiated by different teams using different terms. One sales employee may offer a generous liability position. Another may use a different payment structure. A third may promise intellectual property rights without internal approval. This inconsistency creates legal and commercial exposure. Businesses planning Business Expansion in India should therefore establish core contract principles before transaction volume becomes difficult to control. Standard templates can be used for recurring arrangements, while material deviations can be escalated for legal review. The objective is not to make every agreement identical. It is to ensure deviations are deliberate.
A Practical Contract Management Process for a New Business
A young company does not necessarily need sophisticated contract management software. It first needs a disciplined process. Every new agreement should begin with a clear business purpose. The parties and commercial objectives should be identified before drafting. The agreement should then undergo an appropriate legal and commercial review. Once the parties agree, the person authorised to sign should execute the final version. The signed document should be stored centrally. After signing, responsibility should move to the person responsible for performance. Important obligations, payment dates, milestones, renewal periods and notice requirements should be recorded. Before expiry or renewal, the business should assess performance and commercial value. This process is simple enough for a small company and can become more sophisticated as the business grows.
When Should a Startup Introduce Formal Contract Management?
The answer is earlier than many founders expect. A startup does not need dozens of agreements before establishing basic controls. Once it starts entering recurring customer, supplier, employment, consultant, technology or partnership arrangements, it has enough contractual exposure to justify a structured process. The system can initially be a well maintained central repository combined with a contract register and clear approval responsibilities. As contract volume increases, specialised contract lifecycle management technology may become useful. Current industry guidance increasingly emphasises centralised repositories, standard templates, approval workflows and obligation tracking. Technology should support a sound process rather than substitute for one.
What Good Contract Management Looks Like
Good contract management does not mean involving lawyers in every email. It means knowing which agreements require detailed legal review and which routine documents can follow an approved process. It means knowing who can approve a contract, who can sign it, where the final version is stored and who owns the obligations afterwards. It also means reviewing contracts when circumstances change. A supplier may become strategically important. A customer may request new services. A regulatory change may affect the relationship. A business may enter a new jurisdiction. The contract should not remain static while the commercial relationship changes around it.
Why Early Contract Discipline Pays Off Later
Contract problems often remain invisible until a business is under pressure. A funding round may trigger legal due diligence. A large customer may request warranties and indemnities. An acquisition may require a review of change of control provisions. A dispute may require the business to locate historic agreements quickly. If contracts have been managed properly from the beginning, these exercises become easier. The company can demonstrate its contractual relationships, identify material obligations and explain how agreements are approved and maintained. This strengthens legal readiness without turning contract management into unnecessary bureaucracy.
Frequently Asked Questions (FAQs)
Q1. What is Contract Management?
Contract Management is the systematic process of creating, reviewing, negotiating, approving, executing, monitoring, renewing and terminating business agreements. It covers both the legal document and the obligations arising from it.
Q2. Why is contract management important for startups?
Startups often have limited resources and significant dependence on a small number of customers, suppliers and employees. A single poorly managed agreement can therefore have a disproportionate financial or operational impact.
Q3. Is contract management necessary for a small business?
Yes. The process does not need to be complex. A central repository, contract register, approval process and renewal calendar can provide meaningful protection even for a small company.
Q4. What contracts should a new business manage?
Common categories include customer agreements, supplier contracts, employment agreements, consultancy agreements, non disclosure agreements, technology licences, leases, distribution agreements, partnership arrangements and investment documents.
Q5. Is an email agreement legally valid in India?
Electronic contracts can be legally recognised in India. Section 10A of the Information Technology Act, 2000 addresses the validity of contracts formed through electronic means. However, the enforceability of a particular arrangement depends on its facts and applicable law.
Q6. Who should manage contracts in a startup?
Responsibility can be divided between founders, finance, operations, sales and legal advisers depending on the size of the business. One person should nevertheless have clear ownership of the contract register and compliance calendar.
Q7. What happens after a contract is signed?
The business should store the executed version, record important obligations, monitor performance, track payment and delivery milestones, monitor renewal or termination dates and retain amendments with the original agreement.
Q8. Should every startup use contract management software?
Not necessarily. A small business can begin with a structured manual process. Software becomes more useful when contract volume, teams, jurisdictions or compliance requirements make manual tracking difficult.
Q9. Why should contracts be reviewed before renewal?
Renewal provides an opportunity to assess performance, pricing, service levels, liability exposure and changing business needs. Automatic renewal provisions can also create obligations if the required notice is missed.
Q10. What is the contract lifecycle?
The contract lifecycle generally begins with identifying the need for an agreement and continues through drafting, negotiation, approval, execution, performance monitoring, amendment, renewal or termination and retention. Different frameworks divide these stages differently, but the underlying principle remains the same.
ROC Filings
Understanding ROC Filings for Newly Incorporated Companies in India
For a newly incorporated company, ROC Filings are among the first statutory responsibilities management needs to understand. Incorporation does not mark the end of compliance. It marks the beginning of an ongoing relationship with the Registrar of Companies under the Companies Act, 2013. Depending on the company's structure and activities, filings may relate to commencement of business, registered office details, directors, share capital, financial statements, annual returns and other corporate events. Missing a filing can lead to additional fees, penalties and, in serious cases, broader compliance consequences. A clear filing calendar helps founders avoid treating ROC compliance as an issue to be addressed only when the first annual return becomes due.
Top Four Relevant Resources for “ROC Filings”
The current search landscape for the keyword ROC Filings is dominated by practical compliance guides explaining annual filings, statutory forms, due dates and penalties. Four relevant resources identified during the research are:
IndiaFilings: ROC Filing Responsibility and Procedure in India
LegalClarity: ROC Forms Explained, including AOC 4 and MGT 7
Tax Garden: ROC Annual Compliance for Private Limited Companies
Vakilsearch: ROC Compliance for Private Limited Companies
These pages largely focus on the practical question of which forms must be filed and when. A stronger approach for newly incorporated companies is to explain the compliance journey from incorporation onwards, distinguish annual filings from event based filings, and clarify why the underlying corporate records matter as much as the electronic forms.
What Are ROC Filings?
ROC filings are statutory documents and forms submitted to the Registrar of Companies through the Ministry of Corporate Affairs. The Registrar maintains records relating to companies registered under the Companies Act, 2013. These filings provide the government with information about the company's financial position, ownership, directors, registered office and significant corporate events. They also create a public regulatory record of important aspects of the company's affairs.The expression "ROC filing" is therefore broader than annual return filing. A newly incorporated company may have several compliance obligations during its first year, depending on its circumstances. The exact forms applicable to a company depend upon factors such as its legal structure, share capital, size, transactions, sector and corporate events.
Why ROC Compliance Starts Immediately After Incorporation?
A common misconception among new founders is that ROC compliance begins with the first annual filing. In reality, certain obligations can arise soon after incorporation. For example, a company having share capital is required to file a declaration relating to commencement of business under Section 10A of the Companies Act, 2013, subject to the statutory conditions. The MCA's official instruction kit for Form INC 20A states that the declaration is filed within 180 days from incorporation. This is important because a company may be legally incorporated but still unable to commence certain business activities until the relevant statutory requirement has been satisfied. The first months of operation should therefore be treated as a compliance period rather than a grace period.
INC 20A and Commencement of Business
For a company to which Section 10A applies, Form INC 20A is an important post incorporation filing. The declaration confirms compliance with the requirement concerning subscription money and commencement of business. The MCA instruction kit identifies Section 10A(1)(a) of the Companies Act, 2013 and Rule 23A of the Companies (Incorporation) Rules, 2014 as the governing provisions. Founders should not treat this filing as a routine formality. The company should first verify whether the statutory conditions have been fulfilled and whether the supporting records are in order. This is also one reason why proper company incorporation records should be maintained from the beginning. The documents created during incorporation form the foundation for later compliance.
Registered Office Compliance
A company must maintain a registered office capable of receiving official communications. The address should remain properly documented and supported by appropriate evidence. Changes in the registered office can trigger filing requirements. The relevant MCA form and supporting documentation depend upon the nature of the change and the applicable provisions of the Companies Act. The registered office should therefore not be treated simply as an address used for incorporation. It has continuing legal significance. Companies should maintain ownership or occupancy documents, utility records and other relevant evidence in an organised manner. These records may also become relevant during banking, taxation, investment or due diligence exercises.
Director and Key Managerial Personnel Filings
Changes in directors and key managerial personnel are another important area of ROC compliance. The MCA's official instruction kit for Form DIR 12 states that companies must file particulars relating to appointment, cessation and changes in designation of directors and KMP with the Registrar within 30 days of the relevant event. This means a company should not wait until its annual filing to update the MCA record. If a director resigns, a new director is appointed or there is a relevant change in designation, the corporate records and MCA filings should be updated within the prescribed period. Keeping board resolutions, consent documents and filing acknowledgements together makes future compliance checks considerably easier.
Share Capital and Allotment Related Filings
New companies often issue additional shares during their first year. This can happen when founders inject additional capital or when an angel investor or other investor enters the company. An allotment of shares is not simply an accounting transaction. It can involve board approval, shareholder approval where required, valuation considerations, issue documentation, share certificates and filing obligations. The company must ensure its statutory registers, cap table, share certificates and MCA filings remain consistent. A mismatch between the company's internal cap table and its statutory records can create serious problems during future investment or legal due diligence.
Annual ROC Filings
Annual compliance forms the core of recurring ROC obligations. For most companies, two major annual filings are Form AOC 4 and Form MGT 7 or the applicable simplified form. Form AOC 4 relates to filing the company's financial statements with the Registrar. The MCA has prescribed the form under Section 137 of the Companies Act, 2013 and Rule 12 of the Companies (Accounts) Rules, 2014. Form MGT 7 relates to the company's annual return under Section 92. MCA documentation identifies MGT 7 as the annual return form for companies other than OPCs and small companies covered by the applicable simplified filing framework. The filing process therefore involves more than uploading documents. The accounts, annual return, board records and underlying statutory information must tell a consistent story.
AOC 4 and Financial Statement Filing
AOC 4 provides the Registrar with information relating to the company's financial statements. Before filing, the company should ensure its financial statements have been properly prepared, approved and audited where applicable. Supporting documents and reports should also be reviewed for consistency. The filing should correspond with the financial records maintained by the company. Differences between the accounts filed with the ROC and information reported elsewhere can create unnecessary questions. Financial statement filing is therefore closely connected with accounting, audit and corporate governance rather than being an isolated secretarial task.
MGT 7 and Annual Return Filing
The annual return provides a broader picture of the company's corporate affairs. It can contain information relating to the company's registered office, principal business activities, shareholding, members, directors and other prescribed matters. Because the annual return deals with corporate information beyond financial figures, founders should ensure its contents correspond with statutory registers and other company records. A company experiencing changes in shareholding or directorship during the year should pay particular attention to the accuracy of the annual return.
AGM and Board Meetings
ROC compliance cannot be separated from the company's governance process. The annual general meeting is an important event in the annual compliance cycle. The financial statements and other matters are placed before members in accordance with the Companies Act and the company's constitutional documents. Board meetings are also important. Section 173 of the Companies Act contains requirements concerning meetings of the Board, subject to applicable exemptions and modifications. Minutes should be prepared and maintained properly. Decisions involving investments, borrowings, share issues, related party matters and significant contracts should be supported by appropriate corporate approvals. Good minutes provide evidence of how important decisions were taken.
Event Based ROC Filings
Not every ROC filing occurs once a year. Certain corporate events trigger separate filing obligations. These can include changes in directors, changes in registered office, alteration of share capital, allotment of shares, creation or modification of charges, changes in certain company particulars and other prescribed events. This distinction is important for founders. A company can complete its annual filings correctly and still become non compliant because an event based filing was missed during the year. The compliance system should therefore include an internal process for identifying events which may trigger MCA filing requirements.
What Happens If ROC Filings Are Delayed?
Delayed ROC filings can lead to additional filing fees and statutory penalties. The financial impact depends on the particular form, provision and duration of the default. The consequences may extend beyond the immediate financial cost. Persistent non compliance can affect the company's ability to demonstrate good standing during funding, acquisition, lending or other transactions. Directors and officers may also face consequences where the Companies Act places responsibility upon them. The precise consequence should always be assessed against the provision governing the particular default rather than relying upon a general penalty assumption.
Why Newly Incorporated Companies Commonly Miss ROC Compliance?
The first year of business is usually dominated by sales, recruitment, product development and cash flow management. Compliance can easily become secondary. Another problem is fragmented record keeping. Incorporation documents may be with the legal adviser, accounting records with the finance team and shareholder information with the founders. When responsibilities are unclear, deadlines can be missed. A simple compliance calendar with clearly assigned responsibility can prevent many of these problems.
How Founders Can Build a Reliable ROC Filing System?
A newly incorporated company should maintain a central statutory compliance file from the beginning. This should include the certificate of incorporation, constitutional documents, director records, shareholding information, statutory registers, board minutes, shareholder resolutions, filing challans and copies of forms submitted to the MCA. The company should also reconcile its internal records with MCA records periodically. When a funding round, director change or share allotment occurs, the compliance review should happen immediately rather than at the end of the financial year. For founders considering Pvt ltd company registration cost, it is equally important to recognise the continuing compliance expenditure associated with maintaining a company. Incorporation is an initial cost. Statutory accounting, audit, governance and ROC compliance continue throughout the company's existence.
ROC Compliance and Future Fundraising
Good ROC records can materially improve transaction readiness. Investors and their legal advisers may examine incorporation documents, shareholding records, board minutes, statutory registers and MCA filings during due diligence. If the company's records contain unexplained inconsistencies, the investor may request clarification or remediation before proceeding. A clean compliance history does not guarantee funding. It does, however, reduce avoidable legal uncertainty.
The Role of the Ministry of Corporate Affairs
The Ministry of Corporate Affairs is the primary government authority through which companies interact with the corporate registry. Founders should use the official Ministry of Corporate Affairs portal for current forms, filing instructions, notifications and statutory information. This is particularly important because forms, filing mechanisms, fees and compliance requirements can change through amendments and notifications. Secondary articles can become outdated even when the underlying topic remains relevant.
A Practical Approach for Newly Incorporated Companies
The most effective approach is to treat ROC compliance as a continuing governance function. Immediately after incorporation, the company should identify all applicable post incorporation filings. It should then establish a calendar covering board meetings, financial reporting, audit, AGM requirements and annual filings. Every significant corporate event should trigger a compliance review. Before each filing, the company should verify the information against its statutory registers, accounting records and previous filings. After submission, the company should retain the filed form, acknowledgement and payment record in its permanent compliance file. This process creates an audit trail and reduces the possibility of repeated errors.
Frequently Asked Questions (FAQs)
Q1. What are ROC Filings in India?
ROC Filings are statutory forms and documents submitted by companies to the Registrar of Companies under the Companies Act, 2013. They cover annual compliance as well as specific corporate events.
Q2. Are ROC filings mandatory for newly incorporated companies?
Yes. Incorporation creates continuing statutory obligations. The precise requirements depend on the company's type, capital structure, activities and corporate events.
Q3. What is the first ROC filing after incorporation?
For a company having share capital to which Section 10A applies, Form INC 20A is an important post incorporation filing. The MCA states it is to be filed within 180 days from incorporation, subject to the statutory conditions.
Q4. What are the main annual ROC forms?
For many companies, AOC 4 relates to financial statements and MGT 7 relates to the annual return. OPCs and qualifying small companies may have different filing requirements, including the applicable simplified annual return form.
Q5. Is ROC filing required if a company has no business activity?
A company should not assume inactivity removes its statutory obligations. Annual filing and other compliance requirements may continue even when the company has little or no business activity. The exact obligations should be checked against the company's status and applicable law.
Q6. What is the difference between annual and event based ROC filings?
Annual filings recur as part of the company's yearly compliance cycle. Event based filings arise when a specific corporate event occurs, such as a director appointment, resignation, share allotment or other prescribed change.
Q7. Who is responsible for ROC compliance?
The company and its responsible officers have statutory duties under the Companies Act. Directors should therefore maintain oversight even where accountants, company secretaries or external professionals assist with preparation and filing.
Q8. What happens if a company misses an ROC filing deadline?
A delayed filing can result in additional fees and, depending upon the applicable provision, penalties or other consequences. Persistent defaults can create wider corporate and regulatory problems.
Q9. Can ROC filings affect startup fundraising?
Yes. Investors often review statutory records and MCA filings during legal due diligence. Inconsistent or incomplete records can lead to additional questions and remediation requirements.
Q10. Where can companies verify ROC filing requirements?
Companies should refer primarily to the official Ministry of Corporate Affairs portal, applicable provisions of the Companies Act, rules, notifications and relevant MCA filing instructions. MCA official website
Q11. Should a newly incorporated company maintain a compliance calendar?
Yes. A compliance calendar helps founders track post incorporation filings, board meetings, annual accounts, annual returns and event based obligations. It also clarifies who is responsible for each task.
Q12. Why are accurate statutory records important?
Statutory records support the company's legal history. They provide evidence of ownership, governance decisions, share issuances and other corporate matters. Accurate records also make audits, fundraising, acquisitions and regulatory reviews easier to manage.
MHCO Updates
Litigation
SUPREME COURT CLARIFIES INHERITANCE RIGHTS WHERE PROPERTY IS JOINTLY HELD IN THE NAMES OF TWO WIDOWS UNDER THE INDIAN SUCCESSION ACT, 1925
The Supreme Court, in Shakuntala & Ors. v. Robert Anthony & Ors. (Civil Appeal arising out of SLP(C) No. 9449 of 2020, judgment dated 30 July 2026), has held that where immovable property is purchased and registered in the joint names of two wives of a common husband, the property vests in the two wives themselves, and Section 33 of the Indian Succession Act, 1925 (“the Act”) which governs succession to the estate of a male intestate survived by a widow and lineal descendants cannot be applied to the entirety of such property merely because the husband had provided the purchase consideration. The Court set aside the concurrent (and mutually inconsistent) findings of the Trial Court, First Appellate Court and the High Court of Chhattisgarh, and worked out the succession afresh by applying Sections 33, 35 and 38 of the Act separately to each wife's share.
Background:
One Mattus Anthony (“MA”) had two wives, Filomina and Shyam Bai. In 1959, MA purchased a parcel of land for a consideration of INR 300 in the joint names of his two wives. Filomina had three children (the plaintiffs), while Shyam Bai had one son, John Anthony, who predeceased her in 1985 leaving behind his widow and four children (defendant Nos. 1 to 5). Filomina died in 1985, MA died intestate in 1991, and Shyam Bai died in 2000. In 2002, defendant Nos. 1 to 5 (the widow and children of John Anthony) sold half of the property, i.e., their understood share, to defendant No. 6. The plaintiffs, contending that the property was joint ancestral property in which they too had a share, challenged the sale as void.
Figure: Family Tree of Mattus Anthony and the parties to the litigation
Family Tree:
The Trial Court decreed the suit, holding the sale deed invalid for want of consent of all co-owners and granting the plaintiffs a one-fourth share. The First Appellate Court reversed this, holding that each wife independently held a half share in the property (since it was purchased in their joint names), that the defendants, as legal heirs of John Anthony, were entitled to Shyam Bai's half, and that the 2002 sale deed was accordingly valid. The High Court, in second appeal, took yet another view: applying Section 33 of the Act on the footing that MA had died intestate leaving behind two widows and lineal descendants, it held that both widows, together, were entitled to one-third of the property, while the plaintiffs – treated as MA's only “lineal descendants” because John Anthony was held not to qualify as such – were entitled to the remaining two-thirds.
Issue Before the Court:
The principal question before the Supreme Court was whether Section 33 of the Act, which applies to the estate of a male who dies intestate, could be applied to property that was purchased in the joint names of MA's two wives, or whether the property had to be treated as belonging to the two wives themselves, with succession to each wife's share being worked out independently.
Key Findings of the Court:
The Court held that Section 33 of the Act, on its plain text, applies only to the property of a deceased male intestate. Since the property in question was purchased and registered in the names of MA's two wives, it was, in law, their property and not MA's, notwithstanding that MA had provided the consideration. The High Court's application of Section 33 to the entire property was accordingly held to be misconceived, since it proceeded on the incorrect premise that the property vested in MA and passed on his death to his widows and lineal descendants.
Having held that the property vested independently in the two wives, the Court worked out succession separately to each half. As Filomina predeceased MA, the Court applied Section 35 of the Act (which gives a surviving husband the same rights over his intestate wife's property as a widow would have over her intestate husband's property). Applying Section 33 through the mechanism of Section 35, MA became entitled to one-third of Filomina's half share, with the remaining two-thirds devolving directly upon her children (the plaintiffs). On MA's own death intestate in 1991, the one-third share he had inherited from Filomina devolved equally upon all four of his children through both wives the three plaintiffs and John Anthony as tenants-in-common, there being no concept of joint family property, as under Hindu law, applicable to succession under the Indian Succession Act.
As regards Shyam Bai's half share (together with the portion she in turn received through MA), the Court held that since Shyam Bai's own son, John Anthony, had predeceased her, the property devolved on her surviving grandchildren (defendant Nos. 2 to 5) under Section 38 of the Act, which governs the case of an intestate survived by grandchildren but no surviving child. On this basis, the defendants' entitlement was confined to Shyam Bai's share (as enlarged by the portion received through MA), and did not extend to any part of Filomina's share, contrary to the High Court's view that the two widows' shares should be pooled together and treated as a single one-third block.
Treatment of Ancillary Contentions:
The Court noted two further contentions that were not seriously pressed by the parties and did not call for detailed adjudication. First, on the question of benami, reliance was placed on Valliammal v. Subramaniam (2004) 7 SCC 233, for the proposition that intention and source of funds are relevant to a benami transaction; however, since it was undisputed that MA had purchased the property in the names of his two wives out of love and affection, no case of benami arose. Second, the validity of MA's second marriage to Shyam Bai was not in dispute between the parties, who were agreed that the controversy was confined to the extent of inheritance rights and not the existence of Shyam Bai's status as MA's widow.
MHCO Comment:
This decision offers useful guidance on succession disputes arising out of property held in the names of multiple wives of a common husband under the Indian Succession Act, 1925. The Court's central holding that property registered in the name of a person is that person's property in the eyes of the law, irrespective of who funded the purchase (absent a proven case of benami) reaffirms settled principles of ownership and cautions against conflating source-of-funds with title. Equally significant is the Court's demonstration of how Sections 33, 35 and 38 of the ISA interact and must be applied sequentially, and separately, wherever succession opens up more than once within the same family (here, on the deaths of Filomina, MA and Shyam Bai in turn), rather than being collapsed into a single, composite application of Section 33 to the family's property as a whole. The decision will be of particular relevance in estate planning and succession litigation involving Christian families with blended households, where property is often held jointly in the names of multiple spouses, and underscores the importance of tracing title and the chain of succession event-by-event rather than treating the ultimate distribution as a single-step exercise.
By:
Ms. Purvi Asher, Partner
Ms. Ananya Sakpal, Associate
Disclaimer: This legal update is intended for general information purposes only and does not constitute legal advice. Readers are advised to seek specific legal advice before acting upon any information contained herein.
Litigation
LITIGATION UPDATE | BOMBAY HC | PROSPECTIVE FSI CANNOT DELAY DEEMED CONVEYANCE
Recently, the Bombay High Court in the case of Ariisto Realtors Private Limited v. District Deputy Registrar, Co-operative Societies, reaffirmed the position that deemed conveyance cannot be withheld indefinitely by the builder, to exploit additional FSI made available by a change in the FSI Regime.
FACTS:
The Petitioner, Aristo Realtor Private Limited (“Developer”) was granted the right to construct a building, "Ariisto Cloud”, under a Development Agreement dated 3 March 2010. Another building had been constructed on the same plot by a different developer, Kum Kum Apartments Co-Operative Housing Society Limited (“Kum Kum CHSL”).
Pursuant to disputes between the Developer, landowners and Kum Kum CHSL, a Tripartite Deed of Irrevocable Perpetual Lease dated 9 September 2011, was entered into by which all FSI over and above 2674.13 square meters, was to be utilised solely by the Developer. Though the future additional FSI and TDR was to exclusively belong to the landowners, the Developer was given the right to utilise the same by paying additional consideration of Rs.51,000/- per square meter to the landowners.
The Developer claimed that additional FSI of 841.16 square meters was made available in terms of Development Control and Promotion Regulations, 2034 (“DCPR, 2034”) on 8 May 2018 and filed an application dated 23 October 2024 with the Municipal Corporation for utilisation of additional FSI.
Meanwhile, the flat purchasers of Ariisto Cloud formed a Society in June 2016 and demanded conveyance of the land vide a letter dated 16 August 2024. Upon the Petitioner’s failure to convey the land om their favour, the Society filed a deemed conveyance application. The Society's first deemed-conveyance application (No. 179 of 2024) was rejected as premature by the Competent Authority on 10 March 2025, on the following grounds and the Society was given the liberty to reapply:
The construction of the building was incomplete;
The Petitioner was yet to consume unutilised FSI admeasuring 81.03 sq.m; and
The Petitioner was entitled to utilize additional FSI by paying the landowners additional consideration at Rs.51,000/- per sq meter.
Following consent terms between the Society and the landowners on 16 June 2025, under which the landowners expressed willingness to convey the land to the Society, the Society filed a fresh Application (No. 56 of 2025), now asserting that construction was complete and only 3.25 square meters of FSI remained unconsumed. The Competent Authority allowed this application on 14 July 2025, granting a certificate of unilateral deemed conveyance in the Society's favour.
The developer challenged this order before the Bombay High Court by way of a writ petition.
Developer’s Case
The Developer contended that the Development Agreement granted them the right to exercise an option to purchase any future FSI from the landowners by paying the additional consideration of Rs.51,000/- (Rupees Fifty-one thousand only) per square meter of such additional FSI/TDR to the Owners. Owing to DPCR 2034, the Developer was now entitled to a substantial FSI of 841.16 sq.mts. The Developer argued that the land could be conveyed to the Society only after such additional FSI had been exploited by it.
Court’s Findings
The Hon’ble Court held once a society has been formed, the Developer must convey the land to the Society within a period of 4 months, as prescribed by Rule 9 of the Maharashtra Ownership of Flats (Regulation of the Promotion of Construction, Sale, Management and Transfer) Rules, 1964 (“MOFA Rules”). Relying on its earlier decision in Flagship Infrastructure Ltd. vs. The Competent Authority, the Court reaffirmed that the word period in Rule 9 denotes a fixed, definite block of time running from registration of the society and cannot be contractually extended by clauses permitting the promoter to retain title pending further construction or future FSI exploitation; such clauses are void to that extent. The Society was formed on 28 June 2016 and the Developer was under the statutory obligation to convey the land and building to the society within 4 months of 28 June 2016.
The Court relied on its decision in Lakeview Developers vs. Eternia Co-operative Housing Society Limited, which held that once a developer has exhausted the sanctioned development potential and the obligation to convey has crystallised, any subsequent benefit accruing from an increase in FSI cannot be availed of by a developer who has failed to convey the property despite being under a legal obligation to do so. Any increase in FSI, that is available subsequent to the date on which conveyance ought to have taken place, belongs to the Society, and a defaulting developer cannot retrospectively claim a right to exploit it.
MHCO Comment
Builders must note that they cannot rely on a prospective increase in FSI, even where purportedly reserved by contract to defer or resist deemed conveyance once the society has been registered and the statutory period to initiate deemed conveyance has begun.
By:
Mr. Bhushan Shah, Partner
Ms. Neha Lakshman, Associate Partner
Disclaimer: This legal update is intended for general information purposes only and does not constitute legal advice. Readers are advised to seek specific legal advice before acting upon any information contained herein.
SEBI Update
SEBI BANS ZEE PROMOTERS FROM ACCESSING THE SECURITIES MARKET
The Securities and Exchange Board of India (SEBI) has recently passed a final Order on the matter of the unauthorised pledging of the immovable property of Zee Entertainment Enterprises Limited (ZEEL). The update briefly analyses the final order passed by SEBI.
Background
The proceedings against Zee Promoters (i.e. Mr Subhash Chandra and Mr Punit Goenka) arose out of SEBI’s investigation into the unauthorised use of an immovable property owned by ZEEL as collateral for loans aggregating to ₹ 726 crores availed by four Essel Group entities from Indiabulls Housing Finance Limited (IHFL). The investigation was initiated after ZEEL's statutory auditors, in their audit report for FY 2018–19, observed that the original title deeds of the
Hyderabad property were not available with the Company.
SEBI alleged that on 27 December 2018, Mr Subhash Chandra, acting as an authorised signatory of ZEEL, executed a Declaration and Acknowledgement and deposited the original title deeds with IHFL to create security over the Hyderabad property for the benefit of the borrowing entities. According to SEBI, the transaction was undertaken without obtaining approval from ZEEL's Board of Directors, Audit Committee, or shareholders.
SEBI further alleged that the borrowing entities were promoter-related, thereby making the transaction a related-party transaction requiring prior Audit Committee approval under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 (LODR Regulations). It was also alleged that ZEEL failed to disclose the transaction, the related party relationship, the contingent liability arising from the pledge, the subsequent litigation before the Delhi High Court initiated by IHFL concerning the said loan, and other material developments to the stock exchanges and in its financial statements.
SEBI Analysis
After considering the replies and submissions of ZEEL, Mr Subhash Chandra and Mr Punit Goenka, SEBI concluded that ZEEL's Hyderabad property had been deployed as security for loans availed by promoter-related entities without the requisite corporate approvals and disclosures. SEBI held that the transaction constituted a related party transaction and that the failure to obtain prior Audit Committee approval amounted to a violation of the LODR Regulations.
SEBI further held that ZEEL failed to make material disclosures regarding the unauthorised pledge, related party transaction, litigation concerning the property, and release of the title deeds. According to SEBI, these omissions resulted in inaccurate financial reporting and deprived shareholders and investors of material information.
SEBI also concluded that Mr Subhash Chandra, by executing the Declaration and Acknowledgement without corporate authorisation, breached his fiduciary duties and facilitated the unauthorised deployment of ZEEL's assets. While Mr Punit Goenka did not execute the mortgage documents, SEBI held that, after becoming aware of the transaction, he failed to ensure appropriate disclosures, accurate financial reporting and corrective action. SEBI therefore held both individuals liable for violations of the PFUTP Regulations and various provisions of the LODR Regulations.
SEBI’s Directions
SEBI has restrained ZEEL from accessing the securities market and from buying, selling or otherwise dealing in securities, directly or indirectly, for a period of two months and restrained Mr Punit Goenka and Mr Subhash Chandra from accessing the securities market and from buying, selling or otherwise dealing in securities for a period of twelve months each. Additionally, SEBI imposed monetary penalties of ₹ 30 lakh on ZEEL, ₹ 58 lakh on Mr Punit Goenka and ₹60 lakh on Mr Subhash Chandra.
MHCO Comment
This order pertains to disclosure obligations on the listed companies. In the present matter, the unauthorised pledge of ZEEL’s Hyderabad property was not disclosed. Although SEBI acknowledged that the pledge of ZEEL's Hyderabad property was undertaken without the requisite board, audit and shareholders approvals and was therefore unauthorised, it nevertheless held that the actual deposit of the title deeds and the subsequent exposure of the company’s asset to third parties create liability on the company to duly disclose as per the LODR Regulation. In doing so, SEBI distinguished the question of the legal validity of the said pledge from the regulatory consequences arising from the transaction, emphasising that an unauthorised transaction may still attract liability for disclosure requirements, where it materially affects a listed company and its investors. The order therefore highlights that all listed companies must ensure the disclosure of all material events under the LODR Regulation and accurate financial reporting in accordance with the accounting standards.
By:
- Mr. Bhushan Shah, Partner
- Mr. Abhishek Nair, Associate
- Ms. Sayali Kshirsagar, Associate
Disclaimer: This legal update is intended for general information purposes only and does not constitute legal advice. Readers are advised to seek specific legal advice before acting upon any information contained herein.
Employees' Provident Funds Scheme 2026,
LABOUR LAW UPDATE | Employees' Provident Funds Scheme, 2026 - Key Changes under the Code on Social Security, 2020
Contributors
Mr. Bhushan Shah, Partner
Ms. Neha Lakshman, Associate Partner
On 29 June 2026, the Ministry of labour and Employment unveiled the new Employees’ Provident Funds Scheme, 2026, (“Scheme”) which was followed by Notification SO 3582(E) (“Notification”) on 1 July 2026, under the Code on Social Security, 2020 (“Code”). Together, these notifications operationalise the provident fund framework under the Code by replacing the long-standing Employees’ Provident Funds Scheme, 1952 with a modernised statutory scheme.
Employer and Employee Contributions
The contributions payable by the employer and the employee under the Scheme, shall be 12% (twelve percent). However the Notification mandates that the statutory rate of 10% shall continue to prevail in the following establishments:
Establishments where a resolution plan or repayment plan has been approved by the Adjudicating Authority under the Insolvency and Bankruptcy Code, 2016; and
Establishments engaged in the jute industry, beedi industry, brick industry, coir industry (other than the spinning sector); and guar gum factories.
The contributions shall be calculated on the basis of wages actually drawn or payable during the month, irrespective of the payment schedule.
The employee may make voluntary contributions exceeding the wage ceiling, and the employer can match such voluntary contributions if they so choose. However the employer is under no obligation to do so. The employee or employer may at any time, opt to reduce or stop making such additional voluntary contributions.
The Scheme clearly mandates that the employer shall not be entitled to deduct the employer's contribution from the wages of an employee or otherwise to recover it from him.
Continuity
Existing employees covered by the 1952 Scheme, continue to be covered and the wage ceiling remains constant at Rs. 15,000/- (Rupees Fifteen Thousand Only). The contribution payable in respect of a member is subject to the wage ceiling limit.
Reporting Responsibilities
The new Scheme mandates several reporting requirements, that employers must comply with.
Employers are required to file a detailed return, within 15 days of the end of each month inter alia detailing the employees who are part of the Provident fund scheme, employees whose provident fund accounts have migrated to the employer as a result of them joining the establishment, employees who have left the service, etc. The employer must upload details relating to the contributions payable against each employee on the designated portal within 15 days of the close of each month.
Every employer in relation to an establishment to which the Code applies must file an ownership return after registration of the establishment in the prescribed form, containing details of occupiers, directors, partners, manager or any other person, who has the ultimate control over the administration of the establishment along with documentary proof for authenticating identity on the specified portal. The extract of the ownership return must be displayed at the entrance of the establishment and on its website.
The principal employer shall ensure registration of the establishment and declare all contractors engaged by him. Contractors and employers shall be jointly and severally liable for payment of contributions and charges in respect of contractual employees.
Every contractor shall within ten days of the close of each month, inform the principal employer electronically of the, Universal Account Number, wages and contributions payable in respect of such contractual employees
Digital Transformation of the Provident Fund Administration
The Scheme places significant emphasis on technology-driven compliance by strengthening electronic governance across provident fund administration. Through provisions relating to electronic maintenance of records, online filing of returns and claims, digital access to member accounts and electronic reporting by employers and exempted establishments, the Scheme seeks to modernise compliance processes, improve administrative efficiency and enhance transparency in the management of provident fund obligations.
MHCO Comment:
Employers should view these notifications not merely as a continuation of the existing regime, but as the formal migration to a new statutory architecture. Organisations should undertake a review of payroll systems, digital compliance processes and historical provident fund practices to ensure full alignment with the new Scheme and minimise regulatory exposure.
2025 - MANSUKHLAL HIRALAL & CO.
Need Help? Chat with us







