Our Services

Data Protection, Cyber-Security and AI Governance

Introduction

Privacy obligations attach to how a product is built, not only to what a business says about it. A consent flow, a retention period, a vendor integration, and a decision about where data sits are all determined during development, and each is expensive to revisit once a product is live and carrying users. Our Data Privacy & Protection practice advises on the Digital Personal Data Protection Act and the sectoral regimes that sit alongside it, on the foreign frameworks that apply to Indian businesses serving users abroad, and on the operational architecture — notices, consent, records, contracts, and escalation — through which those obligations are actually met. We act across consumer internet, SaaS, fintech, media and ad-tech, gaming, healthcare technology, and enterprise businesses processing employee and customer data at scale.

Our Experience

We advise on the DPDP Act framework as it applies to a specific business: whether a client is a data fiduciary or a data processor and what follows from that characterisation, the form and timing of notice, the consent architecture a product requires and treatment of children's data and the verifiable parental consent obligation. We advise on data principal rights and the mechanics of servicing them at volume, on grievance redressal and consent manager arrangements, and on breach notification.

Indian privacy obligations rarely arrive alone. We advise on the sectoral requirements that layer over the general framework, including the Reserve Bank of India's payment data storage directive and the storage and access conditions attaching to regulated financial entities, CERT-In's incident reporting and log retention directions, the cyber security obligations applicable to telecom licensees, and the health, insurance, and securities regimes where a client is subject to them. On cross-border movement of data we advise on the restriction-by-notification structure the DPDP Act adopts, on sectoral localisation requirements that operate independently of it, on contractual transfer mechanisms under the GDPR and transfer impact assessments, and on the practical question of where a global architecture must be re-engineered and where contractual and governance measures will suffice.

We advise Indian businesses on the privacy laws that apply to them from abroad. This includes the GDPR, the UK regime, CCPA/CPRA, APPI, LGPD, and the PDPA regimes across Singapore and the rest of Asia, along with PIPL. We also advise on the EU's Digital Services Act and Digital Markets Act. These aren't privacy statutes, but they usually sit with the same team and shape the same product decisions. Our work spans privacy-by-design and impact assessments for new features, AI and machine-learning governance (including training data provenance, transparency, and automated decision-making), consent and signal management in programmatic advertising, records of processing and data mapping, vendor and processor contracting, and employee and candidate data. We also advise on privacy diligence in technology acquisitions, where the lawfulness of a target's data often decides whether the deal is worth its price.

Artificial intelligence governance sits alongside privacy rather than within it, and increasingly arrives as a distinct client instruction. Where a system processes personal data, we advise on the lawful basis for training and fine-tuning, and on purpose limitation where an existing dataset is repurposed for model development. We further advise on whether anonymisation or synthetic data claims will withstand regulatory scrutiny, and on how data principal rights are to be serviced against a model that has already been trained. Beyond this privacy overlay, we assist clients in building the governance apparatus that regulators and enterprise customers now expect to see: an inventory of the AI systems in current use, risk classification proportionate to the consequence of each system's outputs, documentation of model provenance, training data, and known limitations, human oversight at the points where an output affects a person, evaluation and red-teaming prior to deployment, and an incident response process for model failure, distinct from a security breach.

As most of our clients deploy models they have not themselves built, a significant part of this practice is contractual in nature. This includes allocating responsibility between developer, deployer, and integrator for output accuracy, infringement, and misuse, and securing the information a deployer requires to discharge obligations it cannot otherwise satisfy independently. We also advise on transparency and disclosure requirements, including the labelling of synthetic and AI-generated content, and on the risks arising from unaddressed employee use of generative AI tools. On the regulatory front, we advise with reference to the EU AI Act, emerging US state legislation, and voluntary standards such as ISO/IEC 42001 and the NIST AI Risk Management Framework, where clients elect to adopt these as evidence of diligence. In India, the regulatory position is developing rapidly; we advise on current ministerial and sectoral regulator expectations while structuring frameworks capable of accommodating a binding regime once one is introduced.

When something goes wrong, we act quickly. We advise on breach containment, forensic and regulatory sequencing, notification to CERT-In and the sectoral regulator, communications to affected individuals, and the downstream contractual and litigation exposure. Our lawyers are frequently seconded into client privacy, product, and security teams, which is where most of this work is best done — close enough to the build to influence it, rather than reviewing it afterwards.resilient, future-ready frameworks.

Select Mandates

Supported a sports news and content platform in achieving U.S. privacy compliance, including alignment with CCPA/CPRA and VPPA requirements, implementing consent frameworks and secure data-handling practices.

Advised a fast-moving consumer electronics company with IoT product functionality, ensuring privacy compliance across multiple jurisdictions including the U.S., EU, India, Bahrain, and UAE.

Acted as product counsel to a global CRM service provider, advising executives and product teams on SaaS product lifecycle issues and global data protection compliance.

Supported a sports analytics solutions company in designing offerings aligned with privacy frameworks in India and the EU.

Provided end-to-end privacy and compliance support to a leading real money gaming company in India and its expansion into Brazil and the U.S.

Prepared suite of consumer-facing documentation for a leading apparel brand, including Terms of Use, Privacy Policies, and refund and return policies, drafted in alignment with applicable consumer-protection legislation, data protection framework and industry best practices.

Follow on LinkedIn