Need A Consultation? Make An Appointment

Technology, Media and Telecommunications

Contracting for a regime still being written

Practice Area: Technology, Media and Telecommunications

Technology law in India changed regime rather than changed rules. The Digital Personal Data Protection Act and the rules made under it replace a consent notice with an architecture: notice in the form prescribed, consent that is specific and withdrawable and capable of being routed through a consent manager, purpose limitation and erasure that actually deletes, obligations that must flow down to processors by contract, breach intimation, and a heavier set of duties where a company is notified as a significant data fiduciary. Around it sit the CERT-In directions with their reporting window and log retention requirements, safe harbour under IT Act and the due diligence, grievance and traceability obligations that condition it under the Intermediary Guidelines and Digital Media Ethics Code Rules, the Telecommunications Act and the authorisation framework built under it, the statutory line now drawn between e-sports and social games on one side and online money games on the other, and the CCPA's guidelines on misleading advertisements, endorsements by influencers and dark patterns.

Be it launching a product that collects personal data and needing a consent architecture that will survive a regulator reading it, negotiating an enterprise SaaS or outsourcing agreement where the customer is a regulated entity and the directions travel down the contract chain, papering a creator and influencer programme against the endorsement guidelines, licensing content or building a marketplace against the e-commerce rules, or selling a technology business where the IP chain of title is the diligence, the recurring failure is the same: a document written for one regime, or one jurisdiction, carried unexamined into another. Imported templates arrive carrying foreign law assumptions and constructs that do not survive contact with an Indian counterparty or an Indian court, and we rebuild them on Indian statutory footing rather than annotating them.

We treat data protection as engineering rather than as a policy annexure. Consent that is granular in the notice and not in the product is a finding waiting to be made, so we work from the actual data flows, the actual retention behaviour and the actual sub-processor chain, and draft to those. The same applies to intellectual property: employee and contractor assignments, founder-era code, open-source obligations and the terms on which a third-party model or dataset was used are the issues that surface in diligence, and it is cheaper to fix them while the company is small than to price them at exit. Because our technology and transactional lawyers are the same lawyers, they usually are fixed early.

Services and Expertise

This page contains general information regarding Bombay Juris Law Offices and is not intended as a solicitation or an advertisement of its services or any invitation or inducement of any sort. Nothing contained in this website constitutes legal advice or creation of a lawyer-client relationship. If you have any issues, you must seek legal advice.

Disclaimer

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.