DPDP readiness, CERT-In incident reporting, intermediary safe harbour, SaaS contracting, cross-border data transfer, software export reporting and ESOPs.
8 regulators, 11 key statutes and 15 compliance obligations, plus 10 common dispute types and 20 due-diligence checks. 7 entries are marked for verification because the rule is state-specific, recently amended, or commenced in stages — those say what to check rather than stating a date we cannot stand behind.
| Regulator | What it decides |
|---|---|
| Ministry of Electronics and Information Technology (MeitY) | The IT Act rules, intermediary guidelines, and the DPDP Rules and notifications. |
| Indian Computer Emergency Response Team (CERT-In) | Cyber incident reporting, log retention and KYC directions for VPN, cloud and VPS providers. |
| Data Protection Board of India (DPB) | Adjudication of personal data breaches and complaints under the DPDP Act. |
| Software Technology Parks of India / SEZ Development Commissioner (STPI) | Unit approvals, bonded operations and periodic performance reporting for export units. |
| Reserve Bank of India (RBI) | Storage of payment system data in India, and outsourcing norms where the client is a regulated entity. |
| Registrar of Companies / Ministry of Corporate Affairs (RoC) | ESOP resolutions, share allotments and annual filings. |
| Directorate General of Foreign Trade (DGFT) | IEC, and export incentive schemes where services qualify. |
| Central Board of Direct Taxes (CBDT) | Withholding on software and cross-border payments, transfer pricing and the significant economic presence rules. |
| Statute | Year | Why it matters |
|---|---|---|
| Information Technology Act | 2000 | Section 43A and section 72A for data, section 79 for intermediary safe harbour, section 69A for blocking and section 70B for CERT-In — the foundation of every digital compliance obligation. |
| Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules | 2021 | The due diligence an intermediary must do to keep safe harbour: publish policies, appoint a grievance officer, acknowledge within 24 hours, resolve within 15 days, act on court and government orders within 36 hours. |
| Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules | 2011 | Still the operative data security standard for section 43A liability until the DPDP framework fully displaces it. — verify: The extent to which the 2011 Rules survive the DPDP Act depends on the notifications issued. Confirm the position before relying on either exclusively. |
| Digital Personal Data Protection Act | 2023 | Notice and consent, purpose limitation, data principal rights, obligations of Significant Data Fiduciaries, and penalties running to Rs 250 crore for a breach of security safeguards. — verify: Commencement is phased through the DPDP Rules. Check which sections and which timelines are actually in force. |
| Copyright Act | 1957 | Software is a literary work; ownership vests in the employer for work made in the course of employment but NOT automatically in a client for contractor-written code without an assignment. |
| Patents Act | 1970 | Section 3(k) excludes a computer programme per se, so software patent strategy in India turns on the technical effect and on the hardware limitation. |
| Trade Marks Act | 1999 | Brand, domain and app store enforcement; passing off remains the practical remedy for unregistered marks. |
| Companies Act | 2013 | Section 62(1)(b) and the share capital rules govern ESOPs in unlisted companies, including the special resolution and the filing that follows it. |
| Foreign Exchange Management Act | 1999 | Software export declarations, realisation of export proceeds, external commercial borrowing and the reporting of foreign investment. |
| Consumer Protection Act | 2019 | A B2C SaaS or app product is a 'service'; the e-commerce rules and the dark patterns guidelines apply to how it is sold. |
| Telecommunications Act | 2023 | Replaces the Telegraph Act framework; relevant where a product touches messaging, numbering or interception obligations. — verify: Commencement and the subordinate rules have been notified in stages. Confirm which provisions are in force for the client's product. |
| Obligation | Form | When | If missed | Authority |
|---|---|---|---|---|
| Report a cyber security incident to CERT-In | — | On the trigger event. Within six hours of noticing or being brought to notice of any incident in the specified list, including data breaches, ransomware and unauthorised access. | Punishable under section 70B(7) of the IT Act; and a late report is the fact that colours every subsequent regulatory conversation. | CERT-In Directions dated 28 April 2022 under section 70B(6), IT Act, 2000 |
| Retain ICT system logs within India | — | Monthly. Maintain logs of all ICT systems for a rolling period of 180 days, within India, and produce them to CERT-In on direction. | Same penal provision; and without logs an incident cannot be reconstructed, which shifts the factual burden onto the company. | CERT-In Directions dated 28 April 2022 |
| Publish and staff the grievance officer channel | — | Monthly. Acknowledge every complaint within 24 hours and dispose of it within 15 days; act on court or authorised government orders within 36 hours. | Loss of safe harbour under section 79 — the intermediary becomes liable for user content it did nothing to create. | IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 Rule 3 |
| Significant social media intermediary monthly compliance report (verify: Applies only above the notified user threshold. Confirm whether the client crosses it before diarising.) | — | Monthly. Publish a monthly report of complaints received and action taken, and of proactive removals. | Loss of safe harbour for a significant social media intermediary. | IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 Rule 4 |
| File the Letter of Undertaking for zero-rated export of services | GST RFD-11 | Annual. Furnish a fresh LUT for each financial year before making zero-rated supplies without payment of IGST. | Exports made without a valid LUT have to bear IGST and then be claimed back as a refund, which is a cash-flow event, not a formality. | CGST Act, 2017 section 16 of the IGST Act read with Rule 96A |
| File SOFTEX for software exports and track realisation (verify: The realisation period and the SOFTEX filing mechanics have been amended more than once. Confirm the current period and the filing route (STPI or the designated authority).) | SOFTEX (single consolidated form) | Monthly. File for software exports through the designated authority and realise export proceeds within the period permitted under FEMA. | Outstanding entries in EDPMS, which block further export benefits and become a FEMA contravention. | FEMA, 1999; RBI Master Direction on Export of Goods and Services |
| Foreign Liabilities and Assets return | FLA | Annual. By 15 July each year, where the company has any foreign investment received or made. | A FEMA contravention, compoundable with penalty. | FEMA, 1999 |
| Transfer pricing report for international transactions | Form 3CEB | Annual. By 31 October following the financial year, where there are international or specified domestic transactions with associated enterprises. | Penalty of Rs 1 lakh for non-furnishing under section 271BA, plus adjustment exposure. | Income-tax Act, 1961 section 92E |
| File the special resolution approving or varying an ESOP scheme | MGT-14 | On the trigger event. Within 30 days of passing the special resolution under section 62(1)(b). | The grant rests on an unfiled resolution, which becomes a diligence exception in every subsequent round. | Companies Act, 2013 sections 62(1)(b) and 117 |
| Return of allotment on ESOP exercise or a funding round | PAS-3 | On the trigger event. Within 30 days of allotment; for a private placement, within 15 days, and the money may not be used until it is filed. | Penalty on the company and every officer in default, and the allotment is not reflected on the register. | Companies Act, 2013 sections 39 and 42 |
| Annual RoC filings | AOC-4 and MGT-7 / MGT-7A | On the trigger event. AOC-4 within 30 days of the AGM and MGT-7 within 60 days of the AGM. | Rs 100 per day per form with no ceiling, and director disqualification on three consecutive defaults. | Companies Act, 2013 sections 137 and 92 |
| Director KYC | DIR-3 KYC / web KYC | Annual. By 30 September each year for every person holding a DIN as on 31 March. | The DIN is deactivated and a Rs 5,000 fee is payable to reactivate it — which stops every other filing. | Companies (Appointment and Qualification of Directors) Rules, 2014 Rule 12A |
| Notify a personal data breach (verify: The notification format and timeline live in the DPDP Rules. Confirm the current text and commencement before committing to a number of hours in an incident response plan.) | — | On the trigger event. Inform the Data Protection Board and each affected data principal in the form and within the time prescribed by the DPDP Rules. | Penalty of up to Rs 250 crore for failure to take reasonable security safeguards. | Digital Personal Data Protection Act, 2023 section 8(6) |
| Annual review of notices, consent flows and retention schedules | — | Annual. Re-check that every purpose has a lawful basis, that notices are available in the Eighth Schedule languages and that data past its purpose is erased. | Consent that does not match the actual processing is the finding that turns a complaint into an inquiry. | Digital Personal Data Protection Act, 2023 sections 5, 6 and 8 |
| STPI or SEZ periodic performance reports (verify: Applies only to STPI or SEZ units. Confirm the reporting calendar in the unit's letter of permission.) | Monthly/quarterly performance reports and the Annual Performance Report | Annual. As required by the unit's letter of permission and the applicable STPI or SEZ rules. | Non-filing jeopardises the bonded status and the duty exemptions the unit was set up for. | SEZ Act, 2005 and Rules; STPI scheme conditions |
| Dispute | Forum | Note |
|---|---|---|
| SaaS contract and payment disputes | Arbitration, or the Commercial Courts under the Commercial Courts Act, 2015 | Usually about service credits, data return on exit and disputed auto-renewals. |
| Data breach claims | Data Protection Board of India, and contractual claims in arbitration | Regulatory penalty and contractual indemnity run on separate tracks and can both apply. |
| Software copyright infringement | Commercial Court / High Court, with Anton Piller and John Doe relief | Source code comparison and preserved evidence decide these; interim relief is the whole game. |
| Employee IP and confidentiality claims | Civil court, injunction proceedings | Section 27 of the Contract Act voids restraint of trade, so confidentiality and IP ownership carry the case, not the non-compete. |
| Content takedown and blocking challenges | High Court writ jurisdiction; Grievance Appellate Committee for user complaints | Safe harbour is lost if the intermediary does not act on a valid order within the prescribed window. |
| Consumer complaints about digital services | District, State and National Consumer Commissions | Auto-renewal, refusal to refund and dark pattern allegations. |
| Transfer pricing adjustments | Dispute Resolution Panel, then the Income Tax Appellate Tribunal | Captive development centres remain the most litigated category. |
| Withholding tax on software payments | Income Tax Appellate Tribunal and the High Courts | The Engineering Analysis line of authority on whether a payment for shrink-wrapped software is royalty. |
| Domain name and passing off | Commercial Court; INDRP arbitration for .in domains | INDRP is faster and cheaper for a clear cybersquatting case. |
| Vendor and outsourcing failure claims | Arbitration | Fights are about acceptance, scope creep and whether the liability cap survives a fundamental breach. |
Loading the full application…