Founding Partner
20 November 2025
15 minutes
For over two decades, India’s data privacy regime was governed by the Information Technology Act, 2000, mainly Section 43A and its rules. This framework was narrow, focusing on compensation for negligent data security by “body corporates” rather than ensuring proactive protection. It offered a reactive, liability-based model with vague definitions of “personal data” limited consent mechanisms, and little emphasis on individual rights. With growing data volumes, cross-border transfers, and rising cyber risks, this compensatory approach became inadequate. The Digital Personal Data Protection Act, 2023 (“The Act”) shifts to an accountability-based model, requiring Data Fiduciaries to adopt strong security measures, ensure transparent consent, and report breaches. The law emphasizes proactive governance and risk mitigation, marking a fundamental shift in India’s privacy framework.
The Statement of Objects and Reasons behind the Bill highlights its dual purpose i.e. promoting responsible growth of online gaming while curbing the harms of money-based games.
The Act introduces a new definition for the key entities involved in data processing.
1.
Data Principal: The individual to whom the personal data This term, in contrast to “data subject” in other legal frameworks like the General Data Protection Regulation (“GDPR”), emphasizes the individual’s role as the principal owner of their data.
2.
Data Fiduciary: Any person who, alone or in conjunction with others, determines the purpose and means of processing personal This is the equivalent of a “data controller” under the GDPR.
3.
Data Processor: Any person who processes personal data on behalf of a Data
4.
Significant Data Fiduciary (“SDF”): A class of Data Fiduciaries notified by the Central Government based on factors such as the volume and sensitivity of personal data processed, risk to the rights of the Data Principal, and potential impact on India’s sovereignty and integrity, electoral democracy, and state security.
5.
Consent Manager: A person registered with the Data Protection Board who acts as a single point of contact, enabling a Data Principal to give, manage, review, and withdraw her consent through an “accessible, transparent and interoperable platform”.
The Act’s reach is both domestic and extraterritorial. It applies to the processing of all digital personal data within India, including data initially collected in non-digital form and subsequently digitized. Furthermore, it has a crucial extraterritorial application, extending to the processing of digital personal data outside of India if such processing is in connection with offering goods or services to Data Principals within India. This broad scope ensures that foreign entities targeting the Indian market are subject to the same legal obligations as domestic ones.
The legislation provides specific exemptions under Section 3 of the Act, including:
1.
Processing of data by an individual for any “personal or domestic purpose”.
2.
Data that has been made or caused to be made “publicly available” by the Data Principal or by any person who is legally obligated to do so.
The Act provides two primary grounds for lawful processing of personal data: consent and certain legitimate uses.
1.
Consent is the cornerstone, requiring it to be free, specific, informed, unconditional, and unambiguous through clear affirmative action. The term “unconditional” prevents organizations from tying access to services with consent for non-essential Data Fiduciaries must provide a plain-language notice, in English or any Eighth Schedule language, before or along with a consent request. Data Principals also have the right to withdraw consent anytime, with withdrawal as simple as giving it.
2.
Additionally, the Act permits processing without consent for certain legitimate uses, such as when data is voluntarily shared, to perform state functions, comply with legal obligations, or address emergencies and This balance protecting individual rights with enabling essential state and economic functions.
The draft Digital Personal Data Protection Rules, 2025 (“The Rules”), released on January 3, 2025, aim to operationalize the Act by translating its principles into a detailed compliance framework. A central theme is the “digital-by-design” philosophy, ensuring that processes such as consent management and grievance redressal are structured for efficiency, accessibility, and transparency in the digital ecosystem.
The Rules provide clarity on the consent process. Notices must be concise, itemized, and easy to understand, specifying the exact personal data to be collected and its purpose. This strengthens informed consent. They also establish the role of Consent Managers, requiring their registration with the Data Protection Board and mandating obligations such as retaining records of consents for seven years and acting in a fiduciary capacity toward Data Principals.
The Rules convert broad obligations into concrete safeguards, mandating encryption, access controls, monitoring logs, and data backups. In case of a breach, Data Fiduciaries must notify both the Board and affected Data Principals “without delay,” and submit a detailed breach report within seventy- two (72) hours.
Additionally, the Rules fix data retention timelines. Entities like e-commerce, social media, and gaming platforms must erase personal data within three (3) years of the last user interaction, unless retention is legally required.
| Obligation | Provisions | Key Actionable Items |
|---|---|---|
| Lawful Processing | Section 4, 5, 6, 7 | Obtain free, specific, informed, unconditional consent for processing; use a clear and itemized notice; ensure processing is for a lawful purpose. |
| Data Security Safeguards | Section 8(5), Rule 6 | Implement reasonable security safeguards, including encryption, access controls, and data backups, to prevent personal data breaches. |
| Breach Intimation | Section 8(5), Rule | Immediately notify the Data Protection Board and affected Data Principals of a personal data breach; submit a detailed report to the Board within 72 hours. |
| Data Retention and Erasure | Section 8(7), Rule 8 | Erase personal data when the specified purpose is no longer served or after the prescribed time period (e.g., three years for large platforms), unless retention is legally required. |
| Obligations for Children's Data | Section 9 | Obtain verifiable parental consent before processing a child's data; prohibit tracking, behavioral monitoring, and targeted advertising directed at children. |
| Additional Obligations for SDFs | Section 10, Rule 12 | Appoint a Data Protection Officer (“DPO”) in India; appoint an independent data auditor; conduct periodic Data Protection Impact Assessments (“DPIA”) and audits; review algorithmic software for potential risks to Data Principals' rights. |
The draft Rules impose additional obligations on SDFs, designated by the Central Government based on factors like data volume, sensitivity, and risks to electoral democracy. This tiered model ensures stricter compliance for entities handling high-risk data.
Under Section 10(2) of the Act and Rule 12 of the Rules, SDFs must appoint a Data Protection Officer (based in India) as a grievance redressal contact and an independent data auditor to conduct regular audits and report to the Data Protection Board of India (“DPBI”). They are also required to conduct annual DPIA to evaluate risks to Data Principals. Another unique obligation is algorithmic software verification, ensuring deployed systems do not harm Data Principals’ rights, especially in automated decision-making.
The Act grants Data Principals significant control over their personal data. They can access summaries of processed data, understand processing activities, and identify entities with whom their data is shared. They may request correction, completion, updating, or erasure of their data. Further, they have a right to grievance redressal via Data Fiduciaries or Consent Managers, with escalation to the Data Protection Board if unresolved. A distinctive right allows them to nominate another person to exercise these rights in the event of death or incapacity, addressing digital legacies.
The Act also imposes reciprocal duties on Data Principals such as exercising rights lawfully, avoiding impersonation or suppression of material information, and refraining from filing false or frivolous grievances. This balanced approach ensures efficient grievance redressal and reinforces the law’s digital-first framework.
The Act establishes the DPBI as a body corporate with the power to investigate and enforce the Act’s provisions. The Chairperson and Members of the Board will be appointed by the Central Government for a two-year term, with eligibility for re-appointment. This short term and the potential for re-appointment have been noted as a potential point of contention regarding the Board’s long-term independence.
The DPBI has the powers of a civil court to summon and enforce the attendance of any person, and it can inquire into personal data breaches and breaches of obligations by Data Fiduciaries or Consent Managers. The Act empowers the Board to impose significant monetary penalties for non-compliance, as specified in the Schedule.
| Type Of Breach | Provisions | Monetary Penalty |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach. | Section 8(5) | May extend to Indian Rupee Two Hundred and Fifty (250) Crore. |
| Failure to give intimation of a personal data breach to the Board and affected Data Principal. | Section 8(6) | May extend to Indian Rupee Two Hundred (200) Crore |
| Failure to observe additional obligations in relation to children. | Section 9 | May extend to Indian Rupee Two Hundred (200) Crore |
| Failure to observe additional obligations of a SDF. | Section 10 | May extend to Indian Rupee One Hundred and Fifty (150) Crore. |
| Breach in observance of Data Principal duties. | Section 15 | May extend to Indian Rupee Ten (10) Thousand. |
| Breach of any other provision of the Act or Rules. | Section 33 | May extend to Indian Rupee Fifty (50) Crore. |
The Act adopts a less prescriptive approach to cross-border data transfers than many other global frameworks. Instead of creating a whitelist of “safe” countries, it grants the Central Government the power to, by notification, restrict the transfer of personal data to any country or territory outside India. This approach allows the government the flexibility to manage data flows based on evolving geopolitical and security considerations. The draft Rules further specify that a Data Fiduciary must meet certain requirements when making data available to a foreign state or entity, subject to a general or special order from the Central Government.
Beyond territorial scope, the Act provides significant exemptions under Section 17. These include enforcing legal rights, processing by courts or regulatory bodies for their functions, crime prevention and prosecution, processing foreign data principals under a contract, processing for corporate mergers or restructuring approved by a competent authority, and ascertaining the financial details of loan defaulters for financial institutions, in accordance with other laws.
The Act marks a transformative shift in India’s data governance, replacing a reactive, liability- based model with a proactive, rights-focused framework. By establishing clear roles, stringent obligations for Data Fiduciaries, and robust rights for Data Principals, the Act aims to balance individual privacy with legitimate state and business interests. Its extraterritorial applicability and flexible cross- border data transfer rules reflect a modern, adaptable approach. While the success of this new regime will depend on effective enforcement by the DPBI and conscientious compliance by organizations, the Act undoubtedly lays a strong foundation for a secure and accountable digital ecosystem in India.
Our firm advises clients on direct, indirect, and international taxation matters, including tax structuring, compliance, assessments, and litigation. We have experience across income tax, goods and services tax, cross border taxation, and transfer pricing issues. Our team assists businesses and individuals in planning transactions, evaluating tax exposure, and meeting statutory obligations while aligning tax strategy with commercial objectives.
We provide practical, risk conscious tax advice and represent clients before tax authorities, appellate tribunals, and courts. Our services include assessment support, audit assistance, dispute resolution, advance rulings, and advisory on domestic and cross border transactions. By combining technical expertise with regulatory insight, we help clients manage tax risk, resolve controversies, and maintain compliant, sustainable tax positions across sectors while navigating evolving tax laws, enforcement practices, and international reporting requirements efficiently. Our approach supports informed decision making, transaction certainty, and long term value creation for businesses operating in complex domestic and international tax environments across industries and regulatory frameworks worldwide today globally.
Our firm provides strategic legal advisory on human resource and employment matters across sectors and organisational structures. We advise employers on labour law compliance, workforce structuring, HR policies, employee handbooks, hiring practices, employment contracts, disciplinary actions, and termination processes. Our team also supports internal investigations, grievance management, and representation in employment disputes before courts, tribunals, and authorities throughout jurisdictions.
We adopt a practical and business oriented approach to help organisations manage people related risk across the employment lifecycle. Our advice balances statutory compliance with operational efficiency, workplace culture, and human considerations. By combining regulatory insight with sector experience, we assist clients in navigating evolving labour laws, managing workforce transitions, and responding to sensitive employee issues. We deliver clear, implementable solutions that support effective employee management, mitigate legal exposure, and align human resource strategies with organisational objectives, governance standards, and long term business sustainability in dynamic and regulated work environments nationwide for employers facing compliance complexity and evolving workforce expectations today.
Our firm assists clients in protecting, managing, and enforcing intellectual property rights across diverse industries and business models. We advise on trademarks, copyrights, patents, designs, licensing, and commercialisation of intellectual assets. Our team supports clients through IP registrations, portfolio management, audits, and due diligence in transactions, ensuring rights are properly identified, secured, and aligned with commercial objectives across domestic and international jurisdictions.
We also represent clients in enforcement actions, opposition proceedings, and infringement disputes before courts and authorities. We adopt a strategic and commercially driven approach to help clients leverage intellectual property as a business asset while mitigating legal and reputational risk. By combining technical expertise with sector awareness, we enable effective brand protection, encourage innovation, and support long term competitive advantage. Our advice focuses on enforceability, scalability, and value creation, helping businesses strengthen market position, protect goodwill, and navigate evolving IP laws in technology driven and competitive global markets with practical solutions tailored to growth, enforcement, and commercial sustainability.
Our firm advises lenders, borrowers, and financial institutions on banking, finance, and structured transactions across sectors. We assist with loan structuring, financing documentation, security creation, perfection, and regulatory compliance, supporting transactions from origination to disbursement. Our team has experience in corporate lending, project finance, refinancing, and restructuring, and regularly advises on facility agreements, security packages, intercreditor arrangements, and related commercial negotiations.
We provide commercially sound and risk conscious advice focused on enforceability, regulatory alignment, and efficient execution. Our services include compliance advisory, monitoring covenant obligations, and representing clients in enforcement, recovery, and restructuring proceedings. By aligning financial objectives with evolving banking regulations, we help clients navigate complex domestic and cross border transactions with strategic precision, clarity, and certainty while managing credit, regulatory, and operational risk in dynamic financial markets. Our approach balances lender protection and borrower flexibility, ensuring documentation strength, commercial viability, and compliance consistency throughout transaction lifecycles and regulatory interactions across varied industries and financing structures globally and markets.
Our firm advises organisations on data privacy, protection, and cybersecurity compliance under Indian and global data protection frameworks. We assist businesses in designing privacy policies, data governance structures, consent mechanisms, vendor management protocols, and cross border data transfer strategies. Our team supports clients in aligning technology practices with legal requirements while integrating privacy by design into products, platforms, and internal operations across sectors.
We also advise on regulatory exposure management, incident response planning, and breach notifications, and represent clients before regulators and enforcement authorities. Our approach focuses on building compliant, secure, and trust driven data ecosystems that balance risk mitigation with business efficiency. By delivering practical, scalable, and forward looking advice, we help organisations navigate evolving digital risks, regulatory scrutiny, and cross jurisdictional obligations while supporting innovation, customer confidence, and sustainable global operations. Our services remain adaptable to changing technologies, sector specific regulations, and international compliance expectations, ensuring long term resilience, accountability, and operational continuity for data driven enterprises globally.
Our firm partners with startups and emerging businesses throughout their growth journey, providing focused legal and strategic support from inception onwards. We advise founders on incorporation, founder arrangements, equity structuring, employee incentives, shareholder documentation, and regulatory compliance. Our team regularly supports startups during seed, angel, venture capital, and growth stage funding rounds, including due diligence, term sheets, and transaction documentation, while ensuring alignment between commercial goals, governance frameworks, and long term scalability.
With experience representing both founders and investors, we understand startup realities, timelines, and evolving risk appetites. We deliver agile, cost conscious, and business friendly legal solutions that support innovation, protect founder interests, and enhance investor readiness. Our advice emphasises compliance, risk mitigation, and strategic clarity, enabling startups to scale responsibly while navigating regulatory complexity, competitive markets, and operational challenges across diverse sectors and evolving legal landscapes nationwide. We remain closely involved as long term advisors supporting sustainable growth, governance discipline, and successful transitions through expansion, exits, or restructuring.
Our firm provides comprehensive general corporate and legal advisory services to promoters, boards, and senior management across the business lifecycle. We advise on corporate governance, regulatory compliance, mergers and acquisitions, joint ventures, restructuring, and routine corporate matters. From entity incorporation and ongoing statutory compliances to complex corporate actions and strategic transactions, we work closely with clients to ensure advice remains practical, timely, and aligned with commercial objectives and operational realities.
We adopt a transaction focused and solution oriented approach that supports informed decision making, regulatory certainty, and effective risk management. Our team assists in structuring transactions, negotiating commercial arrangements, managing stakeholder expectations, and navigating evolving regulatory frameworks across industries. By combining technical precision with strategic insight, we help businesses address legal challenges efficiently while enabling sustainable growth, operational stability, and long term value creation in dynamic and competitive market conditions nationwide. Our advice remains commercially grounded, risk conscious, and responsive to changing legal, economic, and regulatory developments across business environments.
Our firm provides comprehensive legal support under the Insolvency and Bankruptcy Code, advising corporate debtors, financial and operational creditors, resolution professionals, and investors at all stages of the insolvency process. We have strong experience in corporate insolvency resolution processes, liquidation, restructuring, and distressed asset transactions, and regularly represent clients before the NCLT, NCLAT, and other connected forums across India.
We adopt a commercially driven and solution oriented approach, with a focus on value maximisation, timely resolution, and effective risk management. Our team assists in claim verification, resolution plan evaluation, stakeholder negotiations, and litigation arising during insolvency proceedings. By aligning legal strategy with business and financial objectives, we deliver practical and sustainable insolvency solutions in complex, multi stakeholder matters, helping clients navigate regulatory challenges while protecting commercial interests and ensuring procedural efficiency across diverse industry sectors. Our practice effectively navigates complex, multi-stakeholder scenarios across diverse sectors, ensuring outcomes that are both legally sound and strategically advantageous for our clients.
Our firm provides comprehensive counsel and defense in white collar crime, regulatory investigations, and complex economic offenses. We represent both individuals and corporations at every stage, from initial enforcement agency inquiries through trial and appellate proceedings. Our team delivers end-to-end support, including proactive investigation management, compliance advisory services, and the development of robust, strategic defenses tailored to each client’s unique situation.
We develop carefully calibrated defence strategies tailored to the factual, regulatory, and commercial context of each matter. Our focus remains on safeguarding individual rights, ensuring procedural fairness, and mitigating legal, regulatory, and reputational exposure. With a discreet and structured approach, we guide clients through complex criminal and quasi-criminal proceedings involving financial misconduct, corporate fraud, and regulatory non-compliance. By combining technical expertise with strategic insight, we provide practical, informed advice aimed at achieving effective outcomes while maintaining confidentiality and business continuity throughout the enforcement and adjudicatory process. Our approach is characterized by discretion, precision, and strategic insight, ensuring clients are protected throughout even the most complex and high-stakes proceedings.
Our firm advises and represents clients in complex commercial disputes before courts, tribunals, and arbitral forums in India and internationally. We have strong experience in litigation and domestic and international arbitration, including ad hoc and institutional proceedings. Our team assists clients through every stage of a dispute, from pre litigation risk assessment and negotiations to interim relief, hearings, enforcement of awards and judgments, ensuring strategies remain aligned with commercial realities.
We regularly act in high value, high stakes disputes across industries involving commercial contracts, shareholder arrangements, infrastructure projects, and financial transactions. Our approach is business focused and outcome oriented, aimed at protecting client interests while managing legal, financial, and reputational risk. Through pragmatic advice, robust advocacy, and tailored dispute resolution strategies, we strive to achieve timely, cost effective, and enforceable outcomes that support commercial certainty and long term business objectives. These efforts ensure consistent execution, procedural efficiency, and commercially sensible resolutions in contentious matters across jurisdictions and evolving regulatory environments.