Data Protection, Cybersecurity and Technology Contracts Under Indian Law
India’s technology law landscape has shifted significantly with the Digital Personal Data Protection Act, 2023 (DPDPA), which functions as India’s central data protection act and sets out obligations for entities that process personal data, alongside existing frameworks such as the Information Technology Act, 2000 and sector-specific rules for finance, telecom and e-commerce. The DPDP Act is now supported by the Digital Personal Data Protection Rules, 2025, notified on 14 November 2025, which operationalise it on a staggered timeline; the Data Protection Board of India oversees compliance and adjudicates certain data protection complaints under this framework, and the team acts as lawyer to businesses navigating this data protection regulation.
Most businesses that collect or process personal data are expected to maintain a clear privacy policy i.e. setting out what data is collected, how it is used, and the consent basis on which it is obtained supported by appropriate terms of use and cookie notices. Higher-risk processing may also require a data protection impact assessment before it begins.
The practice covers the commercial contracts that underpin technology businesses, including SaaS agreements, software licences and cloud-services arrangements, together with the data protection considerations that arise when data is stored or processed by a third party.
As artificial intelligence tools become embedded in more products, the team advises on AI deployment and the related intellectual property questions, applying existing data protection, IP and consumer protection law while dedicated AI legislation continues to develop.
The practice also advises on cybersecurity compliance and incident response, including the mandatory reporting obligations under CERT-In directions, which require certain categories of cyber incidents to be reported within six hours of detection, alongside coordination with regulators and affected parties.
The DPDPA also addresses cross-border data transfers, restricting transfers of personal data to countries notified by the Central Government; businesses with global operations should review their data flows and, where required, put in place appropriate contractual mechanisms and compliance documentation.
For digital platforms and e-commerce businesses, the team advises on compliance with the Consumer Protection (E-Commerce) Rules, 2020 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, including intermediary safe harbour conditions, grievance redressal mechanisms and compliance officer requirements.
Sector-specific advice is provided to businesses in fintech (including digital lending and payment aggregator regulations), health tech (telemedicine guidelines and health data sensitivity) and edtech (processing of children’s data under the DPDPA), where technology law intersects with industry-specific regulatory frameworks.
The technology practice also covers issues arising in the digital context, including open source software licensing and compliance, copyright protection for software and databases, trade secret protection for proprietary algorithms and business logic, and technology-focused mergers and acquisitions.