Veritect Legal Intelligence · Regulatory desk

India's digital stack, tracked weekly.

DPDP Rules 2025, CERT-In Directions, IT Rules amendments, RBI & SEBI cyber frameworks, the Telecommunications Act 2023, and AI governance — each anchored to the Tier 1 gazette, circular or order that actually moves. Written for counsel and founders who need to act, not skim.

Everygazette read Everycircular tracked Everyrule sourced
Full library

115 articles across 7 pillars.

Updated as new rules land
Showing 12 of 115 articles
01
Weekly Trackercross-pillar31 Aug 2026

Digital Law Weekly Tracker: W36 2026 — RBI Fines Three of India's Four Credit Bureaus Rs 34.91 Lakh for Failing to Pay the Rs 100-a-Day Credit-Correction Compensation, Hits the Other End of the Same Data Pipe With a CRILC Reporting Penalty, and CERT-In Logs Twelve Vulnerability Notes in Five Working Days With Six CRITICAL and Two Under Active Exploitation

India's digital-law week of 31 August to 6 September 2026 produced its most consequential development in data-rights enforcement rather than in data-protection law. On 4 September 2026 the Reserve Bank of India announced penalties totalling Rs 34,91,800 against three of India's four credit information companies — Rs 26,82,800 on TransUnion CIBIL Limited, Rs 6,89,600 on CRIF High Mark Credit Information Services Private Limited and Rs 1,19,400 on Equifax Credit Information Services Private Limited — on orders all dated 31 August 2026, in each case for the identical sustained charge that the company failed to credit the compensation amount to the bank accounts of certain eligible complainants within the prescribed period. The power exercised is Section 25(1)(iii) read with Section 23(4) of the Credit Information Companies (Regulation) Act, 2005; the substantive duty is Section 17 of the Master Direction — Reserve Bank of India (Credit Information Reporting) Directions, 2025 (RBI/DoR/2024-25/125, 6 January 2025), which fixes compensation at Rs 100 per calendar day where a credit-information complaint is not resolved within 30 calendar days, gives the credit institution 21 calendar days to send corrected data to the bureau, and requires the compensation to be credited within 5 working days. In the same batch RBI penalised Sammaan Finserve Limited Rs 4.20 lakh for failing to report a borrower's credit information to the Central Repository of Information on Large Credits, and Hinduja Leyland Finance Limited Rs 6.20 lakh. Separately, CERT-In issued twelve vulnerability notes between 31 August and 4 September 2026 (CIVN-2026-0429 to CIVN-2026-0440), of which six are rated CRITICAL and two record active exploitation in the wild — SonicWall SMA1000 (CVE-2026-83548 and CVE-2026-83549) and Zimbra Collaboration Suite (CVE-2026-73570), both on 3 September.

Veritect Legal Intelligence·30 min read
Read
02
Weekly Trackercross-pillar24 Aug 2026

Digital Law Weekly Tracker: W35 2026 — SEBI Aligns Its Cyber Incident Reporting Portal With the FSB FIRE Format, Puts a 100-Point IT Resilience Index on Market Infrastructure Institutions, Launches the Cyber Suraksha Portal, and Signs a Tripartite Cyber-Capacity MoU, While CERT-In Records Five CRITICAL Notes Inside the Security Stack Itself

India's digital-law week of 24 to 30 August 2026 belongs almost entirely to one regulator and one day. On 24 August 2026 SEBI issued four cyber instruments. Circular HO/(449)2026-ITD-5_DIV1/I/19448/2026 aligns SEBI's Cyber Incident Reporting Portal at siportal.sebi.gov.in with the Financial Stability Board's Format for Incident Reporting Exchange (FIRE), finalised on 15 April 2025 with 87 information items of which 39 are optional, and introduces staged reporting across the incident life cycle from initial report through intermediate updates to final closure; the existing CSCRF Annexure-O(B) clocks of six hours by email to mkt_incidents@sebi.gov.in and twenty-four hours to the portal are unchanged. Circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026 creates an IT Resilience Index for Market Infrastructure Institutions scored out of 100 across nine parameters, with Availability and Security weighted 20 each, computed system-driven without manual intervention, half-yearly within 60 days of each half-year end, first submission for the half-year ending 31 March 2027. SEBI also launched the Cyber Suraksha Portal (Press Release No. 51/2026) and announced a tripartite MoU with Rashtriya Raksha University and NISM signed on 17 August 2026 (Press Release No. 52/2026), including a Technical Innovation Unit envisioned as a command centre for the securities market. CERT-In recorded five CRITICAL vulnerability notes in the window, in Splunk, Cisco Secure Workload, Zoom, NetScaler ADC and Gateway, and Gitea, plus a HIGH note on hardcoded credentials in an Indian-brand CP Plus 4G LTE router (CVE-2026-19412).

Veritect Legal Intelligence·34 min read
Read
03
Weekly Trackercross-pillar17 Aug 2026

Digital Law Weekly Tracker: W34 2026 — Zero-MDR Moves to Executive Notification as the Taxation and Other Laws (Amendment) Act Receives Assent, CERT-In Records a Critical Unauthenticated SSRF in MLflow, SEBI Cautions on Live Trading Strategies and Accepts Digitally Signed FPI Powers of Attorney

India's digital-law week of 17 to 23 August 2026 is anchored by the Taxation and Other Laws (Amendment) Act, 2026, which received Presidential assent on 17 August 2026 and rewrites Section 10A of the Payment and Settlement Systems Act, 2007 — the zero-MDR mandate no longer runs through Section 269SU of the repealed Income-tax Act, 1961 but through electronic payment modes the Central Government may specify by notification, taking effect from the date of publication in the Official Gazette. CERT-In recorded Vulnerability Note CIVN-2026-0416 on 20 August, a CRITICAL unauthenticated server-side request forgery flaw in MLflow versions before 3.15.0 (CVE-2026-64849) sitting in the ML experiment-tracking and model-registry layer, alongside a critical arbitrary-file-upload flaw in the WordPress Forminator Forms plugin (CIVN-2026-0414, 19 August) and advisories CIAD-2026-0040 to 0042. SEBI issued Press Release No. 48/2026 on 17 August cautioning investors on live trading strategies on social media, and on 20 August issued two circulars accepting digitally signed Powers of Attorney from Foreign Portfolio Investors and enabling KYC Registration Agencies to share information with IFSCA-regulated entities. The RBI data-governance consultation closed on 17 August 2026.

Veritect Legal Intelligence·27 min read
Read
04
Weekly Trackercross-pillar10 Aug 2026

Digital Law Weekly Tracker: W33 2026 — TRAI Extends the Verified Calling Regime Beyond BFSI with the 1601 Numbering Series, DoT Warns Handset Sellers on IMEI Registration and Tampering, CERT-In Issues Apple Threat Notifications Advisory

India's digital-law week of 10 to 16 August 2026 is anchored by TRAI's Direction of 10 August 2026 on allocation and operationalisation of the 1601 numbering series for service and transactional voice calls by entities in sectors other than BFSI and Government, issued under the Telecom Commercial Communications Customer Preference Regulations, 2018 — extending India's verified-calling architecture beyond the 1600-series BFSI cohort to utilities, courier and logistics entities on a phase-wise basis (Press Release No. 113). On 12 August the Department of Telecommunications cautioned manufacturers, importers and resellers on mandatory IMEI registration and the consequences of IMEI tampering under the Telecommunications Act, 2023. CERT-In issued advisory CIAD-2026-0039 on Apple Threat Notifications on 14 August and CIAD-2026-0038 on Microsoft product vulnerabilities on 12 August, alongside thirteen vulnerability notes including a remote-code-execution flaw in the Langflow open-source AI orchestration framework. SEBI modified the Online Bond Platform Provider framework on 14 August. The RBI data-governance consultation closes 17 August 2026.

Veritect Legal Intelligence·21 min read
Read
05
Weekly Trackercross-pillar3 Aug 2026

Digital Law Weekly Tracker: W32 2026 — RBI Regulates Remote Device-Locking in Digital Lending with Rs 250-Per-Hour Compensation, TRAI Opens Quality-of-Service Consultation and Publishes Quarterly Anti-Spam Enforcement Data, DoT Opens Radio Equipment Authorisation Portal

India's digital-law week of 3 to 9 August 2026 is anchored by the Reserve Bank of India's Responsible Business Conduct Fourth Amendment Directions, 2026 of 6 August (RBI/2026-27/223, DOR.MCS.REC.No.193/01-01-032/2026-27, effective 1 January 2027) — the first Indian instrument to regulate remote device-locking of financed mobile handsets as a recovery tool. Lenders may deploy a locking mechanism only where the loan agreement expressly permits it, may not restrict functionality before 30 days past due, must preserve essential functions including incoming calls and emergency SOS, and owe compensation of Rs 250 per hour for wrongful restriction, capped at the loan amount. Parallel amendments issued the same day across nine regulated-entity classes. TRAI released a consultation paper on draft amendments to the Quality of Service Regulations, 2024 on 5 August and quarterly anti-spam enforcement data on 4 August. CERT-In issued advisory CIAD-2026-0037 on emerging threats targeting Microsoft 365 on 7 August.

Veritect Legal Intelligence·20 min read
Read
06
Compliance PlaybookCybersecurity28 Jul 2026

Cybercrime Response Playbook: NCRP, FIR and BSA Section 63 Evidence

After an Indian cyber incident, the CERT-In six-hour report is only the regulatory leg. The prosecution leg runs on three intake routes — the National Cyber Crime Reporting Portal at cybercrime.gov.in, the 1930 financial-fraud helpline, and a direct FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 — and on a Section 63(4) certificate under the Bharatiya Sakshya Adhiniyam, 2023 for every log, export or screenshot tendered as secondary electronic evidence. Intermediaries must preserve requested data for at least 180 days under Rule 3(1)(j) of the IT Rules, 2021. Since 1 July 2024 all three criminal codes are the 2023 Sanhitas.

Veritect Legal Intelligence·8 min read
Read
07
Compliance PlaybookAI Governance28 Jul 2026

Enterprise AI Deployment Playbook: Clearing an AI Feature for India

India has no AI statute. An enterprise deploying an AI feature clears it against existing law plus the India AI Governance Guidelines issued by MeitY and the IndiaAI Mission on 5 November 2025, which set seven guiding principles, a six-category risk taxonomy and a voluntary compliance pathway rather than a mandatory risk-tier system like the EU AI Act. The binding obligations come from elsewhere: the Digital Personal Data Protection Act, 2023 for training and inference data, with penalties up to Rs 250 crore under the Schedule; the IT Rules 2021 synthetic-media labelling amendment of February 2026; Section 79 of the IT Act, 2000 where content is generated rather than hosted; and sectoral frameworks from the RBI, SEBI, ICMR, TEC, CERT-In and NCIIPC.

Veritect Legal Intelligence·7 min read
Read
08
Regulatory ExplainerPlatforms & Intermediaries28 Jul 2026

IT Rules 2021 Part III: Digital Media Ethics Code for Publishers and OTT

Part III of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, notified vide G.S.R. 139(E) dated 25 February 2021, binds publishers of news and current affairs content and publishers of online curated content — not intermediaries, except for the blocking provisions in Rules 15 and 16. It is administered by the Ministry of Information and Broadcasting, not MeitY. Compliance runs on a three-tier structure: Level I self-regulation by the publisher, Level II a registered self-regulating body headed by a retired Supreme Court or High Court judge with no more than six other members, and Level III an oversight mechanism with an Inter-Departmental Committee drawn from seven ministries. Grievances are acknowledged in 24 hours and decided in 15 days at each tier.

Veritect Legal Intelligence·7 min read
Read
09
Regulatory ExplainerCybersecurity28 Jul 2026

SPDI, Blocking and Interception Rules: What Still Binds You in 2026

Three sets of rules made under the Information Technology Act, 2000 remain operative in 2026 alongside the DPDP Rules 2025 and the IT Rules 2021. The SPDI Rules 2011 (G.S.R. 313(E), 11 April 2011) carry the Section 43A reasonable-security duty and lose their parent section on 13 May 2027 when Section 44(2)(a) of the DPDP Act 2023 commences. The Blocking Rules 2009 (G.S.R. 781(E)) have never been amended and were upheld in Shreya Singhal v. Union of India, (2015) 5 SCC 1. The Interception Rules 2009 (G.S.R. 780(E)) remain in force for non-telecom computer resources but were displaced for telecom service providers by the Telecom lawful-interception rules notified on 6 December 2024.

Veritect Legal Intelligence·8 min read
Read
10
Regulatory ExplainerPlatforms & Intermediaries28 Jul 2026

TDSAT as India's Cyber and Data Appellate Tribunal: DPDP Appeals Route

The Telecom Disputes Settlement and Appellate Tribunal (TDSAT), constituted under Section 14 of the TRAI Act, 1997, became the appellate tribunal for the Information Technology Act, 2000 on 26 May 2017 when Section 169 of the Finance Act, 2017 substituted Section 48 of the IT Act and absorbed the dormant Cyber Appellate Tribunal. From 13 November 2025, Rule 22 of the DPDP Rules, 2025 designates TDSAT as the appellate forum from Data Protection Board of India orders, with a 60-day limitation extendable by 60 days, mandatory digital filing and UPI-based fees. Appeals from IT Act matters go to the High Court under Section 62 on fact and law; DPDP appeals go to the Supreme Court on questions of law only.

Veritect Legal Intelligence·7 min read
Read
11
Compliance PlaybookTelecom & Emerging Tech28 Jul 2026

Telecom Cyber Security Rules 2024 Playbook: CTSO, 6-Hour Clock, MNV

The Telecommunications (Telecom Cyber Security) Rules, 2024, notified by the Department of Telecommunications on 21 November 2024 under Section 22 read with Section 56 of the Telecommunications Act, 2023, require every telecommunication entity to appoint a Chief Telecommunication Security Officer who is an Indian citizen and resident answerable to the board, run a Security Operations Centre with periodic VAPT, and report any security incident within 6 hours of detection with a detailed report within 24 hours. The Amendment Rules of 22 October 2025 (G.S.R. 771(E)) added the Telecommunication Identifier User Entity category and the Mobile Number Validation platform, pulling banks, fintechs, e-commerce and OTT services that use mobile numbers to identify customers into the regime.

Veritect Legal Intelligence·8 min read
Read
12
Weekly Trackercross-pillar27 Jul 2026

Digital Law Weekly Tracker: W31 2026 — RBI Repeals 628 Circulars and Issues 64 Consolidated Supervisory Directions, Including Entity-Wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions 2026 with Six-Hour DAKSH Incident Reporting

India's digital-law week of 27 July to 2 August 2026 was dominated by a single event on 31 July: the Reserve Bank of India's Department of Supervision released 64 consolidated Directions and repealed 628 circulars in one exercise (RBI/DoS/2026-27/221, DoS.CO.PPG.66/11.01.005/2026-27). Inside that package sit entity-wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 — for Commercial Banks (RBI/DoS/2026-27/410), NBFCs (RBI/DoS/2026-27/461), Payments Banks (RBI/DoS/2026-27/428) and All India Financial Institutions — each in force with immediate effect and each requiring cyber-incident reporting to the DAKSH platform within six hours of detection, a 24x7 Security Operations Centre, multi-factor authentication for privileged users and half-yearly disaster-recovery drills. Companion Digital Payment Security Controls and Fraud Risk Management Directions, 2026 issued the same day. The OGAI Rule 10 determination deadline of 30 July for 1-May filers passed with no determination order published on a Tier 1 source as at 2 August 2026.

Veritect Legal Intelligence·20 min read
Read
Showing 12 of 115
For counsel & founders

Act on the rule, not the headline.

Three days, full access, no credit card. 115 gazette notification, CERT-In direction, RBI circular and AI advisory that moves India's digital stack — with the primary source attached.

No credit card · 3 days full access · Tier 1 sources only