India’s regulatory environment for technology companies is shifting faster than at any point in the past two decades. The Digital Personal Data Protection Act, 2023 (DPDP Act) entered enforcement in November 2025, MeitY released its AI Governance Guidelines the same month, and the Digital India Act is still in development. For CTOs, CPOs, legal heads, and founders of IT companies and AI startups, understanding the legal requirements for IT companies in India is now a core business function, not an afterthought. This guide maps the full compliance landscape across data protection, AI governance, intellectual property, employment law, and commercial contracts, giving you a structured starting point for building a defensible legal position in 2026.
Key Takeaways
- The DPDP Act’s three-phase rollout is live, with full enforcement expected by May 2027 and penalties reaching up to ₹250 crore per breach.
- MeitY published its AI Governance Guidelines in November 2025, introducing seven foundational principles that AI companies must now align with.
- Software is not directly patentable in India, but Computer-Related Inventions (CRI) with a technical effect can qualify under the revised CRI Guidelines.
- The Competition Commission of India’s 2023 amendments introduced a deal value threshold of ₹2,000 crore, directly affecting tech M&A and investment.
- IT company compliance India now spans data law, AI regulation, IP strategy, employment contracts, and commercial agreements simultaneously.
Key Laws Governing IT and AI Companies in India
IT company compliance India now requires navigating at least six major legal instruments, each governing a different aspect of technology business operations.
Information Technology Act, 2000 (IT Act)
The Information Technology Act, 2000 remains the foundational statute for tech company law India. It governs electronic contracts, digital signatures, cybersecurity obligations, and the liability of intermediaries. Sections 43A and 72A impose liability for data breaches involving sensitive personal data, and these provisions continue to operate alongside the DPDP Act until the Government transitions enforcement fully. IT companies processing payment data, health records, or financial information must maintain “reasonable security practices” as defined under the IT (Reasonable Security Practices and Procedures) Rules, 2011.
Digital Personal Data Protection Act, 2023 (DPDP Act)
The DPDP Act is the most consequential piece of tech company law India has introduced in a generation. Passed in August 2023 and brought into force through rules notified on November 13, 2025, the Act establishes obligations for any organization (a “Data Fiduciary”) that processes the personal data of Indian residents. Key obligations include obtaining valid consent, appointing a Data Protection Officer where required, honoring data principal rights (access, correction, erasure, and grievance redressal), and implementing technical and organizational safeguards. Non-compliance carries penalties of up to ₹250 crore per breach, calculated per incident rather than annually. For more details read our detailed guide on DPDP Act Compliance for IT Companies India 2026.
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
The 2021 Intermediary Rules impose due diligence obligations on social media platforms, online marketplaces, and digital media entities. Significant Social Media Intermediaries (SSMIs), defined as platforms with over five million registered users in India, must appoint a Chief Compliance Officer, a Nodal Contact Person, and a Grievance Officer, all physically located in India. AI platforms that host user-generated content need to assess whether they qualify as intermediaries and, if so, at what tier.
Patents Act, 1970: CRI Guidelines for Software and AI
India does not grant patents for software per se under Section 3(k) of the Patents Act, 1970. However, the Controller General of Patents, Designs and Trade Marks issued revised Computer-Related Inventions (CRI) Guidelines that permit patent protection for software-related inventions where the claimed invention demonstrates a “technical effect” or “technical advancement” beyond normal physical interactions. AI algorithms embedded in hardware systems, optimized semiconductor processes, and machine learning models with measurable industrial applications have a credible path to patent protection under the CRI framework. Altacit Global advises clients across Bangalore and Hyderabad on structuring patent claims to satisfy CRI requirements. For more details about patents read our comprehensive guide Software Patents in India: Can You Patent a Software or App? (2026).
Copyright Act, 1957: Software, Datasets, AI-Generated Content
Software is protected as a “literary work” under the Copyright Act, 1957. This protection arises automatically at creation without registration, though registration creates evidentiary advantages in disputes. Training datasets compiled with creative selection or arrangement can attract copyright protection as compilations. AI-generated content, however, presents an unresolved question: Indian copyright law requires a human author, meaning fully autonomous AI output currently lacks statutory protection. Companies relying on AI-generated assets should document the human creative contribution at each stage of the generative process.
Digital India Act (Upcoming)
The Digital India Act (DIA) is intended to replace the IT Act, 2000 and address the regulatory gaps exposed by AI, platform economies, and deepfakes. As of mid-2026, the DIA remains under consultation. When enacted, it is expected to introduce a tiered regulatory framework for intermediaries, specific obligations for AI systems, and revised cybercrime provisions. IT companies should monitor DIA developments closely, as transition obligations will require updates to privacy policies, Terms of Service, and backend data architecture.
DPDP Act Compliance Timeline: What IT Companies Must Do Now
The DPDP Act operates on a three-phase rollout. IT company compliance India teams should map internal readiness against each phase.
Phase | Deadline | Core Requirements |
Phase I | November 2025 (Active) | Consent frameworks, privacy notices, grievance redressal mechanisms |
Phase II | November 2026 | Data localization compliance, Data Protection Officer appointments, Significant Data Fiduciary obligations |
Phase III | May 2027 (Full Enforcement) | Complete audit rights, cross-border transfer mechanisms, penalty regime fully operative |
Phase I: November 2025 (Already Active)
Phase I obligations are enforceable now. IT companies must have a lawful basis for processing personal data, which in most commercial contexts means valid, informed, and specific consent. Consent notices must be in plain language, available in at least one scheduled Indian language, and clearly state the purpose of processing. Grievance mechanisms must be operational, with a named officer and a response timeline not exceeding 30 days.
Phase II: November 2026 (12 Months Away)
Phase II introduces Significant Data Fiduciary (SDF) designations (see Section on AI Governance below), mandatory Data Protection Impact Assessments (DPIAs), and stricter cross-border data transfer rules. Companies processing large volumes of sensitive data or operating critical digital infrastructure should begin SDF readiness assessments now. The Government has not yet published the positive list of countries to which cross-border transfer will be permitted, making contractual safeguards the interim risk management tool.
Phase III: May 2027 (Full Enforcement)
Full enforcement, including penalty proceedings by the Data Protection Board, commences in Phase III. The Board has the authority to levy penalties of up to ₹250 crore per breach. Repeated violations or breaches affecting children’s data attract the highest penalty bands. Companies that have not completed their compliance programs by this date face material financial exposure.
AI Governance in India: The Emerging Framework
AI company legal India obligations are forming rapidly, even without a comprehensive AI Act. Three parallel developments define the current landscape.
MeitY AI Governance Guidelines: November 2025
The Ministry of Electronics and Information Technology published its AI Governance Guidelines in November 2025. These guidelines are not yet legally binding, but they establish the Government’s expectations and are likely to inform binding rules under the Digital India Act. The guidelines articulate seven foundational principles, referred to as “sutras”:
- Safety and Reliability: AI systems must perform as intended across varied conditions and avoid causing harm.
- Equality: AI must not produce discriminatory outcomes across demographic groups.
- Inclusivity and Non-Discrimination: Design and deployment must account for India’s linguistic and socioeconomic diversity.
- Privacy and Security: AI systems handling personal data must align with DPDP Act obligations.
- Transparency: Decision-making processes of AI systems should be explainable to affected users.
- Accountability: Organizations deploying AI must be able to attribute outcomes and accept legal responsibility.
- Protection and Reinforcement: AI must support, not undermine, users’ fundamental rights.
MeitY also established the IndiaAI Safety Institute to evaluate high-risk AI systems and support voluntary compliance frameworks. Altacit Global recommends that AI companies begin internal audits against these seven sutras now, ahead of binding enforcement.
AI (Ethics and Accountability) Bill 2025
The AI (Ethics and Accountability) Bill 2025, introduced as a Private Member’s Bill in December 2025, proposes a structured liability regime for AI systems causing harm to individuals. While Private Member’s Bills rarely pass without Government support, this Bill signals legislative intent and is likely to influence the DIA’s AI-specific provisions. Key proposals include mandatory algorithmic audits for high-risk AI, a duty of care standard for AI deployers, and a right to explanation for automated decisions. Legal heads at AI companies should track this Bill’s progress closely.
Are You a Significant Data Fiduciary (SDF)?
The DPDP Act empowers the Government to designate certain Data Fiduciaries as Significant Data Fiduciaries, based on the volume and sensitivity of data processed, the risk to data principals, and the potential national security implications. SDFs carry additional obligations including mandatory DPIAs, algorithmic audits, and the appointment of an independent Data Auditor. AI companies processing large-scale user data, health information, or financial records are at elevated risk of SDF designation. The designation criteria will be clarified in Phase II rules expected before November 2026.
IP Protection for IT and AI Companies
A structured IP strategy is foundational to technology company compliance India and commercial value creation.
Software Patents: CRI Guidelines
Under the CRI Guidelines, patent claims for software inventions must demonstrate a technical effect (such as improved processing efficiency, reduced memory usage, or enhanced data security) that goes beyond the normal interaction of software with hardware. Claims framed purely as abstract methods or mathematical algorithms will be rejected under Section 3(k). Companies in Bangalore and Hyderabad developing AI models, embedded systems, or optimized network protocols should work with patent counsel to structure claims that satisfy the technical effect test. Altacit Global regularly assists clients in drafting patent applications that navigate the CRI Guidelines effectively.
Software Copyright
Source code and object code are protected under the Copyright Act, 1957 from the moment of creation. Employers own the copyright in software created by employees within the scope of their employment, but this default rule can be displaced by contract in the case of contractors and consultants. Every IT company should audit its contractor agreements to confirm proper IP assignment clauses are in place.
AI-Generated Content Copyright
As noted above, AI-generated content does not qualify for copyright protection under current Indian law without identifiable human authorship. Companies commercializing AI-generated text, images, or code should document the human editorial decisions that shape the final output. This documentation creates a factual record that supports copyright claims if the law is later clarified or if disputes arise in the interim.
Trade Secrets for Algorithms
Proprietary algorithms, training data pipelines, and model architectures that cannot be protected through patents or copyright can be protected as trade secrets under contract law and the Indian Penal Code. Trade secret protection requires the company to take active, documented steps to maintain confidentiality, including Non-Disclosure Agreements, access controls, and employee confidentiality obligations. Without these measures, courts will not recognize the information as legally protected.
Employment Law for IT Companies
ESOPs, RSUs, and SARs
The Corporate Laws Amendment Bill 2026 formally recognizes Restricted Stock Units (RSUs) and Stock Appreciation Rights (SARs) as distinct equity instruments under Indian company law, resolving longstanding ambiguity about their treatment. For IT companies in Bangalore, Hyderabad, and other tech hubs, this provides a clearer legal foundation for multi-instrument equity compensation plans. ESOP schemes must comply with the Companies Act, 2013 and, for listed companies, SEBI regulations. Altacit Global’s corporate team advises on structuring compliant equity plans for both early-stage startups and established IT companies.
Moonlighting Policy: Legal Position
The legal position on moonlighting (employees taking secondary employment or freelance work) depends on the terms of the employment contract. Indian law does not prohibit dual employment at the individual level, but most IT employment contracts include exclusivity clauses that make moonlighting a contractual breach. Companies that wish to enforce these clauses must ensure the restriction is clearly drafted, proportionate, and communicated to employees. A blanket prohibition without clear communication may be challenged as unenforceable.
Work-From-Home Contracts
Work-from-home arrangements require specific contractual adjustments, including clauses on data security obligations at remote locations, equipment ownership and return, jurisdiction for dispute resolution (particularly relevant where employees work from states different from the employer’s registered office), and overtime or working-hours compliance under applicable Shops and Establishments Acts.
Commercial Contracts for IT Companies
SaaS Agreements and Master Service Agreements (MSAs)
SaaS agreements and MSAs for IT companies must address liability caps, indemnification, service level commitments, data ownership, and termination rights. In cross-border agreements, governing law and dispute resolution clauses require careful drafting, particularly where the counterparty is a US or EU entity subject to its own data protection regime. For agreements with Indian government entities, specific public procurement rules and payment conditions apply.
Data Processing Agreements: Mandatory Under the DPDP Act
Where an IT company processes personal data on behalf of a Data Fiduciary (acting as a “Data Processor” under the DPDP Act), a written Data Processing Agreement (DPA) is mandatory. The DPA must specify the purposes of processing, the categories of data involved, security obligations, breach notification timelines, and the handling of data upon termination of the engagement. Altacit Global has developed standardized DPA templates that satisfy DPDP Act requirements and can be adapted for sector-specific engagements.
Competition Law and Big Tech in India
The Competition (Amendment) Act, 2023 introduced a deal value threshold: acquisitions where the transaction value exceeds ₹2,000 crore and the target has substantial Indian operations must now be notified to the Competition Commission of India (CCI), even if traditional turnover thresholds are not met. This change directly affects technology M&A, where high-value acquisitions of asset-light AI startups previously fell below notification thresholds.
The CCI has also demonstrated its willingness to act on platform-specific conduct. In 2023, the CCI imposed a fine of ₹1,338 crore on Google for anti-competitive conduct in the Android ecosystem. IT and AI companies building platform businesses, app marketplaces, or dominant digital services should ensure their product and commercial terms do not create tying, bundling, or self-preferencing arrangements that could attract CCI scrutiny.
The Compliance Imperative for IT and AI Companies in 2026
The legal requirements for IT companies in India now span data protection, AI governance, intellectual property, employment, and competition law simultaneously. Each of these frameworks is either newly enacted or actively evolving. Treating legal compliance as a standalone activity separate from product development, commercial contracting, and HR policy is no longer a viable approach.
The companies that manage this environment most effectively are those that build legal and compliance considerations into their product roadmaps and commercial strategies from the outset, rather than retrofitting legal fixes after the fact.
Altacit Global works with IT companies and AI startups across Bangalore, Hyderabad, Chennai, Kochi, and Coimbatore to design compliance programs that are proportionate, commercially aware, and built for the regulatory environment of 2026 and beyond. To discuss your company’s legal framework needs, contact us at info@altacit.com.
Frequently Asked Questions: Legal Requirements for IT Companies in India
Q1: What is the DPDP Act compliance deadline for IT companies?
The Digital Personal Data Protection Act, 2023 operates on a three-phase timeline. Phase I obligations (consent frameworks, grievance mechanisms, privacy notices) became enforceable in November 2025. Phase II obligations (Significant Data Fiduciary requirements, Data Protection Officers, cross-border transfer compliance) are due by November 2026. Full enforcement, including penalty proceedings by the Data Protection Board, begins in May 2027. Penalties for non-compliance reach up to ₹250 crore per breach.
Q2: Do AI companies in India need a licence to operate?
As of mid-2026, there is no general operating licence requirement specific to AI companies in India. However, AI companies processing personal data must comply with the DPDP Act, and those deploying AI in regulated sectors such as banking, insurance, or healthcare must comply with sector-specific rules issued by the RBI, IRDAI, or NHA. MeitY’s AI Governance Guidelines (November 2025) are currently advisory, not mandatory, but are expected to form the basis for binding rules under the Digital India Act.
Q3: Can Indian IT companies hold personal data overseas?
The DPDP Act does not impose a general data localization requirement. Cross-border transfer of personal data is permitted to countries included on a Government-approved “positive list.” This list has not yet been published, making the precise scope of permitted transfers uncertain. Until the list is notified, companies should rely on contractual safeguards in data processing agreements and monitor Government announcements ahead of the Phase II deadline of November 2026.
Q4: Is software patentable in India?
Software is not directly patentable as such under Section 3(k) of the Patents Act, 1970. However, software-related inventions that demonstrate a technical effect or technical advancement beyond normal hardware-software interaction can be protected as Computer-Related Inventions under the CRI Guidelines issued by the Controller General of Patents. Structuring a patent claim that satisfies this technical effect test requires experienced patent counsel. Altacit Global assists clients in Bangalore, Hyderabad, and other cities with CRI patent strategy.
Q5: What is the penalty for DPDP Act non-compliance?
The Data Protection Board of India can levy penalties of up to ₹250 crore per breach of the Digital Personal Data Protection Act, 2023. Penalty amounts are calculated per incident and take into account the nature of the breach, the volume of data principals affected, and whether the Data Fiduciary took reasonable security precautions. Breaches involving children’s data and repeat violations are subject to the highest penalty bands.



