N
NyayaAI

Information Technology & SaaS: statutory compliance in India

DPDP readiness, CERT-In incident reporting, intermediary safe harbour, SaaS contracting, cross-border data transfer, software export reporting and ESOPs.

What this covers

8 regulators, 11 key statutes and 15 compliance obligations, plus 10 common dispute types and 20 due-diligence checks. 7 entries are marked for verification because the rule is state-specific, recently amended, or commenced in stages — those say what to check rather than stating a date we cannot stand behind.

Who regulates this sector

RegulatorWhat it decides
Ministry of Electronics and Information Technology (MeitY)The IT Act rules, intermediary guidelines, and the DPDP Rules and notifications.
Indian Computer Emergency Response Team (CERT-In)Cyber incident reporting, log retention and KYC directions for VPN, cloud and VPS providers.
Data Protection Board of India (DPB)Adjudication of personal data breaches and complaints under the DPDP Act.
Software Technology Parks of India / SEZ Development Commissioner (STPI)Unit approvals, bonded operations and periodic performance reporting for export units.
Reserve Bank of India (RBI)Storage of payment system data in India, and outsourcing norms where the client is a regulated entity.
Registrar of Companies / Ministry of Corporate Affairs (RoC)ESOP resolutions, share allotments and annual filings.
Directorate General of Foreign Trade (DGFT)IEC, and export incentive schemes where services qualify.
Central Board of Direct Taxes (CBDT)Withholding on software and cross-border payments, transfer pricing and the significant economic presence rules.

Key statutes

StatuteYearWhy it matters
Information Technology Act2000Section 43A and section 72A for data, section 79 for intermediary safe harbour, section 69A for blocking and section 70B for CERT-In — the foundation of every digital compliance obligation.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules2021The due diligence an intermediary must do to keep safe harbour: publish policies, appoint a grievance officer, acknowledge within 24 hours, resolve within 15 days, act on court and government orders within 36 hours.
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules2011Still the operative data security standard for section 43A liability until the DPDP framework fully displaces it. — verify: The extent to which the 2011 Rules survive the DPDP Act depends on the notifications issued. Confirm the position before relying on either exclusively.
Digital Personal Data Protection Act2023Notice and consent, purpose limitation, data principal rights, obligations of Significant Data Fiduciaries, and penalties running to Rs 250 crore for a breach of security safeguards. — verify: Commencement is phased through the DPDP Rules. Check which sections and which timelines are actually in force.
Copyright Act1957Software is a literary work; ownership vests in the employer for work made in the course of employment but NOT automatically in a client for contractor-written code without an assignment.
Patents Act1970Section 3(k) excludes a computer programme per se, so software patent strategy in India turns on the technical effect and on the hardware limitation.
Trade Marks Act1999Brand, domain and app store enforcement; passing off remains the practical remedy for unregistered marks.
Companies Act2013Section 62(1)(b) and the share capital rules govern ESOPs in unlisted companies, including the special resolution and the filing that follows it.
Foreign Exchange Management Act1999Software export declarations, realisation of export proceeds, external commercial borrowing and the reporting of foreign investment.
Consumer Protection Act2019A B2C SaaS or app product is a 'service'; the e-commerce rules and the dark patterns guidelines apply to how it is sold.
Telecommunications Act2023Replaces the Telegraph Act framework; relevant where a product touches messaging, numbering or interception obligations. — verify: Commencement and the subordinate rules have been notified in stages. Confirm which provisions are in force for the client's product.

Compliance obligations

ObligationFormWhenIf missedAuthority
Report a cyber security incident to CERT-InOn the trigger event. Within six hours of noticing or being brought to notice of any incident in the specified list, including data breaches, ransomware and unauthorised access.Punishable under section 70B(7) of the IT Act; and a late report is the fact that colours every subsequent regulatory conversation.CERT-In Directions dated 28 April 2022 under section 70B(6), IT Act, 2000
Retain ICT system logs within IndiaMonthly. Maintain logs of all ICT systems for a rolling period of 180 days, within India, and produce them to CERT-In on direction.Same penal provision; and without logs an incident cannot be reconstructed, which shifts the factual burden onto the company.CERT-In Directions dated 28 April 2022
Publish and staff the grievance officer channelMonthly. Acknowledge every complaint within 24 hours and dispose of it within 15 days; act on court or authorised government orders within 36 hours.Loss of safe harbour under section 79 — the intermediary becomes liable for user content it did nothing to create.IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 Rule 3
Significant social media intermediary monthly compliance report (verify: Applies only above the notified user threshold. Confirm whether the client crosses it before diarising.)Monthly. Publish a monthly report of complaints received and action taken, and of proactive removals.Loss of safe harbour for a significant social media intermediary.IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 Rule 4
File the Letter of Undertaking for zero-rated export of servicesGST RFD-11Annual. Furnish a fresh LUT for each financial year before making zero-rated supplies without payment of IGST.Exports made without a valid LUT have to bear IGST and then be claimed back as a refund, which is a cash-flow event, not a formality.CGST Act, 2017 section 16 of the IGST Act read with Rule 96A
File SOFTEX for software exports and track realisation (verify: The realisation period and the SOFTEX filing mechanics have been amended more than once. Confirm the current period and the filing route (STPI or the designated authority).)SOFTEX (single consolidated form)Monthly. File for software exports through the designated authority and realise export proceeds within the period permitted under FEMA.Outstanding entries in EDPMS, which block further export benefits and become a FEMA contravention.FEMA, 1999; RBI Master Direction on Export of Goods and Services
Foreign Liabilities and Assets returnFLAAnnual. By 15 July each year, where the company has any foreign investment received or made.A FEMA contravention, compoundable with penalty.FEMA, 1999
Transfer pricing report for international transactionsForm 3CEBAnnual. By 31 October following the financial year, where there are international or specified domestic transactions with associated enterprises.Penalty of Rs 1 lakh for non-furnishing under section 271BA, plus adjustment exposure.Income-tax Act, 1961 section 92E
File the special resolution approving or varying an ESOP schemeMGT-14On the trigger event. Within 30 days of passing the special resolution under section 62(1)(b).The grant rests on an unfiled resolution, which becomes a diligence exception in every subsequent round.Companies Act, 2013 sections 62(1)(b) and 117
Return of allotment on ESOP exercise or a funding roundPAS-3On the trigger event. Within 30 days of allotment; for a private placement, within 15 days, and the money may not be used until it is filed.Penalty on the company and every officer in default, and the allotment is not reflected on the register.Companies Act, 2013 sections 39 and 42
Annual RoC filingsAOC-4 and MGT-7 / MGT-7AOn the trigger event. AOC-4 within 30 days of the AGM and MGT-7 within 60 days of the AGM.Rs 100 per day per form with no ceiling, and director disqualification on three consecutive defaults.Companies Act, 2013 sections 137 and 92
Director KYCDIR-3 KYC / web KYCAnnual. By 30 September each year for every person holding a DIN as on 31 March.The DIN is deactivated and a Rs 5,000 fee is payable to reactivate it — which stops every other filing.Companies (Appointment and Qualification of Directors) Rules, 2014 Rule 12A
Notify a personal data breach (verify: The notification format and timeline live in the DPDP Rules. Confirm the current text and commencement before committing to a number of hours in an incident response plan.)On the trigger event. Inform the Data Protection Board and each affected data principal in the form and within the time prescribed by the DPDP Rules.Penalty of up to Rs 250 crore for failure to take reasonable security safeguards.Digital Personal Data Protection Act, 2023 section 8(6)
Annual review of notices, consent flows and retention schedulesAnnual. Re-check that every purpose has a lawful basis, that notices are available in the Eighth Schedule languages and that data past its purpose is erased.Consent that does not match the actual processing is the finding that turns a complaint into an inquiry.Digital Personal Data Protection Act, 2023 sections 5, 6 and 8
STPI or SEZ periodic performance reports (verify: Applies only to STPI or SEZ units. Confirm the reporting calendar in the unit's letter of permission.)Monthly/quarterly performance reports and the Annual Performance ReportAnnual. As required by the unit's letter of permission and the applicable STPI or SEZ rules.Non-filing jeopardises the bonded status and the duty exemptions the unit was set up for.SEZ Act, 2005 and Rules; STPI scheme conditions

Where disputes in this sector are heard

DisputeForumNote
SaaS contract and payment disputesArbitration, or the Commercial Courts under the Commercial Courts Act, 2015Usually about service credits, data return on exit and disputed auto-renewals.
Data breach claimsData Protection Board of India, and contractual claims in arbitrationRegulatory penalty and contractual indemnity run on separate tracks and can both apply.
Software copyright infringementCommercial Court / High Court, with Anton Piller and John Doe reliefSource code comparison and preserved evidence decide these; interim relief is the whole game.
Employee IP and confidentiality claimsCivil court, injunction proceedingsSection 27 of the Contract Act voids restraint of trade, so confidentiality and IP ownership carry the case, not the non-compete.
Content takedown and blocking challengesHigh Court writ jurisdiction; Grievance Appellate Committee for user complaintsSafe harbour is lost if the intermediary does not act on a valid order within the prescribed window.
Consumer complaints about digital servicesDistrict, State and National Consumer CommissionsAuto-renewal, refusal to refund and dark pattern allegations.
Transfer pricing adjustmentsDispute Resolution Panel, then the Income Tax Appellate TribunalCaptive development centres remain the most litigated category.
Withholding tax on software paymentsIncome Tax Appellate Tribunal and the High CourtsThe Engineering Analysis line of authority on whether a payment for shrink-wrapped software is royalty.
Domain name and passing offCommercial Court; INDRP arbitration for .in domainsINDRP is faster and cheaper for a clear cybersquatting case.
Vendor and outsourcing failure claimsArbitrationFights are about acceptance, scope creep and whether the liability cap survives a fundamental breach.

Loading the full application…