Editor's Note
Technology law is no longer evolving only through legislation. It is evolving through adoption.
Artificial intelligence is now used in recruitment, contract review, software development, customer support, marketing, finance, cybersecurity and internal knowledge management. Personal data moves through more systems, vendors and jurisdictions than most businesses can map with confidence. A cyber incident can create legal, contractual, operational and reputational consequences at the same time.
The question is no longer: "Do we have a policy?" It is: "Can we show how this technology is governed in practice?"
- AI governance is becoming a business operating model, not an IT policy.
- India's DPDP Rules have moved privacy from a future concern to an implementation programme.
- Cyber incident response is now a legal and board-level capability.
- Vendor risk has become enterprise risk.
The purpose is not to make innovation slower. It is to help businesses adopt technology in a way that they can explain, defend and scale.
The strongest technology governance programmes do not slow innovation. They make innovation easier to trust.
Executive Summary: What Are the Most Important Data, AI and Cyber Law Developments in 2026?
1. India's data-protection transition is now operational
The Digital Personal Data Protection Rules, 2025 were notified in November 2025. The Rules provide the operational detail needed to implement the Digital Personal Data Protection Act, 2023.
- Provisions concerning the Data Protection Board took effect immediately.
- Consent Manager provisions take effect in November 2026.
- Most substantive operational obligations take effect in May 2027.
This gives businesses a transition period. It does not give them a reason to wait.
2. AI governance is now a procurement, people and product issue
Most businesses are not creating their own foundation models. They are buying, integrating, fine-tuning or using AI tools created by others. Their immediate legal exposure therefore lies in practical questions: what information can employees upload; can the vendor use prompts or data for training; who verifies AI-generated outputs; can the tool affect employees, candidates or customers; which uses need human review; and what does the business tell customers about AI use.
3. The EU AI Act has become an active compliance consideration
The EU AI Act's obligations for providers of general-purpose AI models have applied since 2 August 2025. The European Commission's enforcement powers for those obligations apply from 2 August 2026. Indian organisations should not assume the Act is irrelevant merely because they are based outside the EU. It can matter where a model or AI-enabled product is placed on the EU market, used in connection with people in the EU, or supported by an India-based GCC.
4. The first six hours after a cyber incident can determine the legal outcome
CERT-In directions require entities to report specified cyber incidents within six hours of noticing the incident or being brought to notice. Data breaches and data leaks are among the incidents covered by the reporting framework. The first report does not require every answer. It requires a disciplined process, timely escalation and accurate disclosure of the facts available at that time.
5. Third-party technology risk is now central to governance
Cloud services, AI platforms, payroll providers, identity-management tools, software-development partners, analytics vendors and managed-security providers all form part of the organisation's control environment. A vendor may process the data. It may not carry the full accountability.
How Should Businesses Govern AI Use in 2026?
The most common AI risk is not a futuristic autonomous system. It is ordinary work being done through an unapproved or poorly governed tool.
An employee uploads customer information into a public AI chatbot. A recruiter uses an AI-generated shortlist without understanding the criteria used. A developer deploys AI-generated code without checking security or licence implications. A marketing team publishes content that is inaccurate, misleading or too similar to protected material.
These are not merely technology questions. They can involve confidentiality, data protection, intellectual property, employment law, discrimination, consumer protection, professional responsibility, cybersecurity and contract liability.
A blanket ban on AI is rarely effective. It often drives use underground. A better approach is a clear operating model that enables lower-risk use, creates approval routes for higher-risk use, and makes accountability visible.
The four-tier AI use framework
Tier 1
Generally permitted
Low-risk productivity uses that do not involve personal, confidential, privileged or proprietary data.
Examples: Brainstorming; a first draft of generic content; translation of non-sensitive material; formatting internal meeting notes; preparing a generic agenda; researching a topic that will be independently verified.
Required controls
- Approved-tool list
- Employee guidance
- No sensitive inputs
- Human review before reliance
Tier 2
Permitted with safeguards
Uses involving internal material or outputs that could influence business decisions.
Examples: Code assistance; internal knowledge search; contract triage; first drafts of marketing copy; internal document summaries; customer-service drafting.
Required controls
- Approved enterprise account
- Data minimisation
- Review of vendor training and retention settings
- Output validation
- Restrictions on confidential and personal data
- A named business owner
Tier 3
Enhanced review required
Uses affecting people, money, access, legal rights or material business decisions.
Examples: Recruitment screening; employee performance analysis; customer eligibility; fraud detection; credit-related decision support; automated contract decisions; legal or compliance advice tools; AI tools generating external-facing recommendations.
Required controls
- Documented impact assessment
- Legal review
- Testing for accuracy and unfair outcomes
- Meaningful human intervention
- Monitoring and escalation
- Clear accountability
- Records of approval
Tier 4
Prohibited or board-approved only
Uses that create an unacceptable or disproportionate risk.
Examples: Entering privileged information into public AI tools; uploading customer confidential information to an unapproved service; fully automated high-impact decisions without meaningful human review; creating deceptive synthetic media; using AI to circumvent legal or contractual obligations; deployment where the business cannot explain or monitor the output.
Required controls
- Prohibition
- Technical restriction where possible
- Mandatory escalation
- Board approval for exceptional cases
If an AI tool can influence a person's employment, access, money, reputation or legal position, treat it as a governed decision system, not merely as software.
What does good AI governance look like?
Good AI governance is not a 30-page policy that employees never read. It is a practical system that answers five questions.
- Who can use which tools? Maintain a list of approved tools, approved business uses and prohibited uses, distinguishing public tools, enterprise tools and internally hosted tools.
- What data can enter the tool? Public information is generally permitted in approved tools; internal non-sensitive information only in enterprise-approved tools; personal data only after privacy review with appropriate safeguards; privileged or highly confidential information prohibited unless specifically approved.
- Who owns the output? The business using the tool must own the decision to rely on its output. AI can support work; it should not become an unaccountable decision-maker.
- What evidence exists? For material use cases, retain evidence of purpose, data involved, vendor and model, testing, approval, human oversight and escalation.
- What happens when something goes wrong? Every high-impact deployment needs a stop mechanism: suspend the tool, identify affected decisions, correct inaccurate output, notify those affected and investigate.
What Does the EU AI Act Mean for Indian Businesses?
The EU AI Act is often discussed as if it applies only to European technology companies. That is too narrow.
For providers of general-purpose AI models, the framework now includes obligations relating to technical documentation, information for downstream providers, copyright policy and public summaries of training content. For models presenting systemic risk, additional safety, security, evaluation and incident-related obligations apply.
The important issue for an Indian business is role. A company may be a provider, a deployer, a distributor, an importer, a downstream provider, a customer, a service provider, or a GCC supporting a global product team. Each role carries different responsibilities and commercial risks. A business that simply uses an established enterprise AI tool may not be a model provider. But it still needs to assess its contract, its data use, its customer commitments and the effect of the tool on people.
The AI contract checklist
- Can the vendor use our prompts, inputs or outputs to train its models?
- Where is our data processed and stored?
- Which sub-processors are involved?
- Can we turn off retention or training use?
- What security controls and audit logs are available?
- How quickly must the vendor notify us about an incident?
- Will the vendor provide evidence and cooperation during an investigation?
- Who is responsible for inaccurate, infringing or unlawful output?
- What happens if the vendor materially changes its model or terms?
- Can we export our data and exit the service?
What Must Businesses Do Before India's DPDP Rules Take Effect?
The Digital Personal Data Protection Rules, 2025 have changed the nature of the privacy conversation in India. The question is no longer whether India will have a comprehensive digital-personal-data framework. The question is whether organisations will be operationally ready. The Rules require organisations to move beyond generic privacy statements and build processes that work in practice.
What is the DPDP implementation timeline?
The Rules were notified on 13 November 2025. The phased commencement is significant: Rules 1, 2 and 17 to 21 took effect on notification; Rule 4, concerning Consent Managers, takes effect one year after notification; and Rules 3, 5 to 16, 22 and 23 take effect 18 months after notification, in May 2027.
For businesses, the practical deadline is May 2027. That may seem far away. It is not. A privacy implementation programme can require data discovery, system changes, redesign of digital journeys, contract remediation, vendor assessment, rights-management workflows, retention and deletion processes, security-control changes, breach-response testing and training across the organisation. For a large company or GCC, this work can involve multiple business units, jurisdictions and technology stacks.
What must a DPDP-compliant privacy notice include?
Rule 3 requires a notice to be understandable independently of other information and to give a clear and plain-language account of what the individual needs to provide specific and informed consent.
- An itemised description of the personal data being processed.
- The specified purpose or purposes for processing.
- The goods, services or uses enabled by the processing.
- Information on how rights can be exercised.
- Business contact details for relevant queries.
This has an important design implication. The privacy notice should be connected to the relevant moment in the customer, employee or user journey. A generic policy located in a website footer is not enough where the actual data collection experience is unclear.
How should businesses prepare for data-principal rights?
The Act provides rights relating to access, correction, completion, updating, erasure, grievance redressal and nomination. These rights require an operating model: how the requestor is authenticated, which team receives the request, which systems must be searched, who approves the response, the response timeline, how the response is recorded, how disputes are escalated, and whether the process can be completed across outsourced systems.
The Rules require Data Fiduciaries and Consent Managers to prominently publish the means by which individuals can make rights requests. The grievance-redressal system must respond within a reasonable period not exceeding 90 days. That means an email address alone is not enough. The business needs a workflow.
What are the breach-notification obligations under the DPDP Rules?
The Rules require a Data Fiduciary, upon becoming aware of a personal-data breach, to inform affected Data Principals without delay. The notification should include the nature, extent and timing of the breach; likely consequences relevant to the individual; mitigation measures taken or being taken; safety steps the individual can take; and contact information for queries.
The Data Protection Board must also be informed without delay. A more detailed report is due within 72 hours of becoming aware of the breach, unless the Board allows more time. That report includes updated breach information, broad facts, mitigation measures, findings on the person who caused the breach, remedial measures and a report on notifications to affected Data Principals.
This matters because businesses may face multiple reporting clocks after a single incident: CERT-In reporting, Data Protection Board notification, sector-regulator reporting, contractual notice obligations, insurer notification and customer communication obligations. The response process must bring these together.
What do the Rules say about retention?
Rule 8 includes specific retention and erasure requirements. For certain large e-commerce entities, online gaming intermediaries and social-media intermediaries, personal data must be erased after a specified period if the individual has not approached the entity for the relevant purpose or exercised rights, unless retention is required by law. The Rules also require Data Fiduciaries to retain personal data, associated traffic data and other processing logs for at least one year for specified purposes, subject to other applicable legal requirements.
The practical message is not simply "retain less." It is: retain intentionally.
Every organisation should be able to explain what data it holds, why it holds it, where it holds it, how long it holds it, what legal or operational reason supports that period, and how it deletes it securely.
What should companies do about children's data?
Businesses processing children's data should identify the relevant journeys now: education platforms, gaming, family accounts, children's content, parental controls, health services, travel and transport services, and targeted marketing. The Rules require appropriate technical and organisational measures to ensure verifiable parental consent before processing a child's personal data. This is not a task that can be left only to legal or compliance teams. It requires product, engineering, operations and customer-support input.
A 120-day DPDP readiness programme
Phase 1 · Days 1-30
Establish the facts
- Create a cross-functional DPDP steering group.
- Identify key data systems, business owners and vendors.
- Map high-volume and high-risk personal-data flows.
- Identify transfers between group companies and vendors.
- Review current notices and consent journeys.
- Identify children's-data and high-risk processing journeys.
- Create a gap assessment against the Act and Rules.
Phase 2 · Days 31-60
Build the controls
- Redraft privacy notices in clear, specific language.
- Design data-principal request workflows.
- Update vendor and processor agreements.
- Define retention and deletion schedules.
- Establish breach-response roles and reporting routes.
- Review AI tools processing personal data.
- Create a process for identifying and managing significant risks.
Phase 3 · Days 61-90
Test and train
- Run a data-subject request exercise.
- Run a breach-notification tabletop exercise.
- Test vendor escalation paths.
- Train HR, product, engineering, sales, customer support and procurement.
- Establish management reporting.
- Create a funded remediation plan.
Phase 4 · Days 91-120
Prepare for evidence
- Maintain records of data flows, notices, contracts and approvals.
- Confirm that key vendors can support rights requests and incidents.
- Document unresolved gaps and accountable owners.
- Present progress, risk and resource requirements to leadership.
- Test whether the programme works under time pressure.
The transition period is a build period, not a waiting period.
How Should a Business Respond to a Cyber Incident in India?
A cyber incident is not solely a technical event. It is a legal event from the first hour. CERT-In handled 29.44 lakh (approximately 2.94 million) cyber security incidents in 2025 alone. At that volume, the question for any business is not whether an incident will occur, but whether the organisation can execute its legal and regulatory obligations in the hours immediately after it does.
It can affect regulators, customers, employees, business partners, insurers, lenders, investors and the board. The first question should not be: "Who caused this?" The first question should be: "What must we do now to contain the incident, preserve evidence and meet our legal obligations?"
What should happen in the first six hours?
CERT-In directions require reporting of specified cyber incidents within six hours of noticing the incident or being brought to notice. The right response is not to wait until every fact is known. The right response is to establish a disciplined process.
First six hours
Stabilise and notify
- Activate the incident-response team.
- Confirm who has authority to make urgent decisions.
- Preserve legal privilege where appropriate.
- Contain the threat without unnecessarily destroying evidence.
- Preserve logs, access records and system images.
- Identify whether CERT-In reporting is triggered.
- Notify insurers where policy terms require it.
- Notify critical vendors where cooperation is needed.
- Start a time-stamped decision log.
First 24 hours
Determine exposure
- Identify affected systems, accounts and geographies.
- Determine whether personal, customer, regulated or confidential data is involved.
- Assess the impact on business continuity.
- Review contractual notification obligations.
- Prepare a controlled update for senior management and the board.
- Maintain a single communications process.
First 72 hours
Communicate and remediate
- Refine the regulatory notification analysis.
- Determine whether affected individuals or customers need to be informed.
- Provide accurate and proportionate stakeholder communications.
- Implement immediate remediation.
- Begin the root-cause review.
- Assign owners and deadlines for corrective actions.
What should every incident-response plan contain?
- Current contact details and clear authority levels.
- A legal escalation route and CERT-In reporting templates.
- Customer and vendor notification templates.
- Insurer contact details and outside forensic and legal support contacts.
- Evidence-preservation instructions and a decision-log format.
- A communications approval process and pre-planned tabletop exercises.
A plan says who should do what. A capability has current contact details, delegated authority, tested vendor access and a team that has practised together.
The incident contract checklist
For material vendors, contracts should address notification timing, cooperation obligations, evidence preservation, access to logs and relevant records, incident updates, sub-processor obligations, audit rights, recovery support, cost allocation, liability limits, and termination or exit rights after a serious incident. "Prompt notification" is often too vague. A contract should establish when the vendor must notify, what an initial notification must contain and how updates will be provided.
Why Is Third-Party Technology Risk Now a Board-Level Issue?
Modern organisations depend on vendors for critical functions: cloud infrastructure, AI tools, identity management, payroll, customer relationship management, payment systems, analytics, security monitoring, software development and data hosting. This means a vendor's failure can quickly become the company's failure.
The relevant question is not "Is this vendor secure?" It is "Is this vendor, service configuration and contract appropriate for the data, risk and business use involved?"
Five questions before onboarding an AI, cloud or data vendor
- What data will enter the service? Classify the data before the tool is adopted - public, internal, confidential, personal, sensitive, regulated, privileged or customer-owned - and let the answer determine the review level.
- What will the provider do with the data? Ask whether it may retain inputs, use inputs to train models, share information with sub-processors, process data outside India, use data for analytics or service improvement, or keep data after the contract ends.
- Can the business control access and deletion? Look for enterprise access controls, role-based permissions, audit logs, administrative controls, retention settings, deletion tools, deletion certification and export capability.
- What happens during an incident? The contract should cover notification, support, logs, evidence, remediation, customer communications and allocation of cost.
- Can the business exit? Understand how data will be returned and deleted, whether systems can be migrated, whether transition support is available, and what happens if the vendor changes terms or suffers a prolonged outage.
How Should GCCs Approach AI, Privacy and Cyber Governance?
India now hosts 2,117 GCCs across 3,728 units, generating $98.4 billion in revenue and employing 2.36 million professionals - up 32% since FY2021, according to the Zinnov-Nasscom India GCC Landscape Report 2026. India has also become the #1 AI hiring market globally, with over 506,000 AI/ML roles. But the same report flags an operating-model gap: AI hiring is outpacing the governance structures needed to manage it. That gap is precisely where legal exposure concentrates.
GCCs are increasingly strategic control centres. They may build products, process global data, operate security functions, develop AI solutions, support regulated group entities and manage vendors across jurisdictions. This creates an opportunity. A GCC that can provide reliable AI-use inventories, privacy operations, incident coordination and evidence-ready controls becomes a source of confidence for the global group.
AI
Own approved-tool controls, use-case inventories, testing records and employee training. Escalate high-impact use cases and material risk decisions to global business and legal leadership.
Privacy
Maintain data maps, support rights requests, maintain notices and keep vendor-processing records current. Escalate cross-border processing, high-risk data uses and material interpretation issues.
Cybersecurity
Support monitoring, incident playbooks, evidence preservation and tabletop exercises. Escalate major incident decisions and regulatory notifications through the agreed global crisis process.
Contracts & Assurance
Support standard technology clauses, vendor due diligence and tracking of material deviations; maintain metrics, audit evidence and remediation tracking, reporting persistent control failures to the board.
The key is not centralisation for its own sake. It is clarity of responsibility.
Ten Questions Every Board Should Be Able to Answer
- 01Do we have a current inventory of material AI uses and AI vendors?
- 02Which AI-enabled decisions affect employees, customers or other individuals?
- 03Do we know where personal data is stored, shared and retained?
- 04Are our DPDP readiness milestones owned, funded and reported?
- 05Have we tested a cyber incident involving personal-data compromise?
- 06Can we meet the CERT-In reporting timeline in practice?
- 07Are material vendor contracts aligned with our privacy and security risk?
- 08Does management report meaningful AI, privacy and cyber metrics?
- 09Are staff trained on approved AI use and data-handling boundaries?
- 10If challenged by a regulator, customer or board member, can we show evidence of our decisions and controls?
Good governance is not a collection of policies. It is a record of informed choices, clear ownership, tested controls and timely escalation.
Frequently Asked Questions
What are the most important data, AI and cyber law developments in 2026?
Four: India's DPDP Rules, 2025 have moved privacy from policy to an implementation programme with a May 2027 operational deadline; AI governance has become a procurement, people and product issue rather than an IT policy; CERT-In's six-hour reporting window makes cyber incident response a board-level capability; and third-party risk across cloud, AI and data services has become enterprise risk.
What is the DPDP Rules, 2025 implementation timeline?
The Rules were notified on 13 November 2025. Rules 1, 2 and 17 to 21 took effect on notification. Rule 4, concerning Consent Managers, takes effect one year after notification in November 2026. Rules 3, 5 to 16, 22 and 23 take effect 18 months after notification, in May 2027. For most businesses, the practical operational deadline is May 2027.
How should businesses govern AI use in 2026?
Use a four-tier operating model rather than a blanket ban. Tier 1 covers generally permitted low-risk productivity uses with no sensitive inputs. Tier 2 covers internal uses permitted with safeguards such as enterprise accounts, data minimisation and output validation. Tier 3 covers uses affecting people, money, access or legal rights and requires an impact assessment, legal review, testing and meaningful human intervention. Tier 4 covers prohibited or board-approved-only uses.
Does the EU AI Act apply to Indian businesses?
It can. Obligations for providers of general-purpose AI models have applied since 2 August 2025, and the European Commission's enforcement powers for those obligations apply from 2 August 2026. The Act can matter where a model or AI-enabled product is placed on the EU market, used in connection with people in the EU, or supported by an India-based GCC. The decisive question is the organisation's role: provider, deployer, distributor, importer, downstream provider or service provider.
How quickly must a cyber incident be reported in India?
CERT-In directions require entities to report specified cyber incidents within six hours of noticing the incident or being brought to notice. Data breaches and data leaks are among the incidents covered. The first report does not require every answer; it requires a disciplined process, timely escalation and accurate disclosure of the facts available at that time.
What are the breach-notification obligations under the DPDP Rules?
A Data Fiduciary must inform affected Data Principals without delay of the nature, extent and timing of the breach, likely consequences, mitigation measures, safety steps and contact information. The Data Protection Board must also be informed without delay, with a more detailed report due within 72 hours of becoming aware of the breach unless the Board allows more time.
Why is third-party technology risk now a board-level issue?
Cloud infrastructure, AI platforms, identity management, payroll, analytics, managed security and development partners all form part of the organisation's control environment. A vendor may process the data, but it may not carry the full accountability. The right question is not whether a vendor is secure, but whether the vendor, service configuration and contract are appropriate for the data, risk and business use involved.
How should GCCs approach AI, privacy and cyber governance?
A GCC should own approved-tool controls, use-case inventories, data maps, rights-request support, incident playbooks, evidence preservation, standard technology clauses and assurance metrics, while escalating high-impact AI use cases, cross-border processing decisions, major incident decisions and material liability allocation to global business and legal leadership.
Closing Note
The organisations that will lead in 2026 will not be those that adopt every new tool first. They will be the ones that can adopt the right tools with confidence.
They will know what data is involved, who is accountable, what controls apply, where the risk sits and how they will respond if something goes wrong.
That is the shift underway in data, AI and cyber law. Not compliance after innovation. Governance as part of innovation.
Official Sources
- Digital Personal Data Protection Rules, 2025 - Ministry of Electronics and Information Technology
- Digital Personal Data Protection Act, 2023 - India Code
- CERT-In Directions under section 70B of the Information Technology Act
- CERT-In FAQ on Cyber Security Directions
- European Commission guidance on obligations for general-purpose AI providers
- European Commission guidance on the GPAI compliance and enforcement timeline
- Zinnov-Nasscom India GCC Landscape Report 2026
- CERT-In / PIB - Cyber incidents handled in 2025
This newsletter is for general information only and does not constitute legal advice. Specific facts, sector rules, jurisdictions and contractual obligations can materially change the analysis.
Authored by
Zuber Syed
Founder & Managing Partner · Advocate · Data, AI & Technology Law
Zuber Syed advises General Counsel, founders, boards and GCC leaders on AI governance, data protection and cyber incident readiness across India and global delivery models. This edition is part of the Zuber & Partners quarterly technology-law series.
