Technology, data and product
Advisory on data protection, technology contracting and product compliance obligations for technology-driven businesses.
Technology-driven businesses carry a category of legal obligation that did not exist for most Indian companies a decade ago: obligations tied specifically to the personal data they collect, the platforms they operate, and the software they license to or from others.
Data protection
The Digital Personal Data Protection Act, 2023 sets out how a data fiduciary must obtain consent, provide notice, and handle the personal data of individuals, with distinct obligations depending on the nature and scale of processing involved. Advisory under this framework covers how consent mechanisms are designed, what a privacy notice must disclose, and what obligations apply when data is transferred to a processor or, in defined circumstances, outside India. A security incident involving personal data can trigger its own reporting obligations, separate from the underlying data protection compliance.
Platforms and intermediaries
Businesses that operate an online platform, marketplace or other intermediary carry obligations under the Information Technology Act framework concerning the content they host, the grievance mechanisms they must provide, and the due diligence expected of them to retain the protections available to intermediaries. How a platform is designed and operated has a direct bearing on whether it can actually rely on those protections if a dispute arises.
Contracting for technology
Software licensing, SaaS agreements, cloud services arrangements and data processing agreements each require terms specific to how the technology is delivered and how data moves through it: service levels, data ownership, security obligations and termination or transition provisions. Technology outsourcing and managed services agreements raise a further layer of questions about liability allocation and continuity if the arrangement ends.
What a technology business has to decide
The pace at which a product or platform evolves means its data practices and its contracts rarely stay still for long. A business has to decide how frequently its consent flows, privacy notices and technology contracts are revisited against a regulatory framework that is itself still being built out through rules and guidance, rather than assuming a compliance position taken at launch remains accurate indefinitely.
What this covers
- Data protection compliance
- Advisory on obligations under the Digital Personal Data Protection Act, including consent, notice and data fiduciary obligations.
- Technology contracting
- Drafting of software licensing, SaaS, cloud services and data processing agreements.
- Product and platform compliance
- Advisory on obligations applicable to online platforms and intermediaries under the Information Technology Act framework.
- Cybersecurity incident advisory
- Advisory on reporting obligations following a data breach or security incident.
- Cross-border data transfer
- Advisory on the conditions applicable to transfer of personal data outside India.
- IT and outsourcing agreements
- Drafting and negotiation of technology outsourcing and managed services agreements.
Statutes and instruments
Forums
Sectors this practice works in
Counsel
- Adv. Harsha Swaroop P
Corporate, Projects & Regulatory
- Adv. Dr. Vijay Mishra
Technology, Semiconductors & Intellectual Property
