CorpConnect Corporate Law News July 2026

July 28, 2026
Corp Connect July Edition

We are pleased to present the July 2026 edition of Corp Connect, SS Rana & Co.’s monthly Corporate Law Newsletter, bringing together key legal and regulatory developments that are shaping businesses across sectors. This edition focuses on practical compliance issues arising from rapidly evolving technology, data protection, intellectual property, food regulation, and workplace governance.

Some of the highlights from this month’s edition include:

  • WhatsApp’s proposed shift to usernames and the legal implications surrounding impersonation, personality rights and compliance with the Digital Personal Data Protection Act, 2023.
  • CERT-In’s new AI Vulnerability Guidelines and the significant compliance obligations now imposed directly on OEMs, software vendors, cloud service providers and technology companies.
  • A practical guide to IPRS licensing for mobile applications, OTT platforms, gaming platforms and other digital businesses, together with an analysis of when businesses should opt for direct licensing as opposed to licensing through a copyright society.
  • FSSAI’s advisory against the use of “100%” claims on food labels and the broader implications for advertising, labelling and consumer protection compliance.
  • The Bengaluru crèche abuse case and what it reveals about India’s regulatory framework governing childcare facilities, employer obligations and data protection.
  • The compliance obligations of schools, coaching centres, edtech platforms and other organisations processing children’s personal data under the DPDP Act.

As the regulatory landscape continues to evolve, organisations must increasingly navigate overlapping obligations across technology, privacy, intellectual property and sector-specific laws. We hope this edition offers practical insights that assist businesses, in-house legal teams and compliance professionals in staying informed and prepared.

WhatsApp's Shift to Usernames

Whatsapp’s Shift to Usernames: Impersonation Risk, Regulatory Pushback and the Dpdp Compliance Test

WhatsApp’s proposed move away from phone-number-based identification towards a username-based system has, within days of being reported, triggered two distinct but connected reactions in India: public concern voiced by industry founders and privacy experts over impersonation and data-sharing risk, and a reported regulatory direction to Meta to pause the feature’s India rollout pending consultations. Read together, these developments sit squarely at the intersection of intellectual property law, personality rights and the Digital Personal Data Protection Act, 2023 (“DPDP Act”), and merit close attention from brand owners, public figures and ordinary users alike.

Continue Reading →

New AI-Vulnerability Guidelines

Cert-In’s New Al-Vulnerability Guidelines: a Quick-Reference for Oems, Tech Vendors and In-House Counsel

Cybersecurity regulation in India has, until now, largely spoken to the entity that suffers the breach. The 2022 CERT-In Directions issued under Section 70B of the Information Technology Act, 2000 fixed a six-hour reporting clock on the organisation that detects an incident. The new Guidelines flip the lens onto the entity upstream of that breach, the OEM or technology provider that built the product in the first place. For the first time, vendors supplying software, firmware, cloud platforms, or APIs into India carry direct, time-bound, and independently verifiable obligations of their own and not obligations that are merely passed through a customer contract, but obligations CERT-In itself may enforce.
The trigger is squarely artificial intelligence. Al has made vulnerability discovery, exploit generation, and attack execution dramatically faster on both sides of the fight, that is, for defenders and attackers alike. CERT-In has responded by building a regulatory framework where compliance timelines compress sharply the moment a vulnerability is assessed as Al-exploitable, rather than waiting for a fixed, one-size-fits-all patch cycle.

Continue Reading →

IPRS Licence

Do You Need an Iprs Licence for Your App or Digital Platform?

The Indian Performing Right Society Limited (IPRS) is a copyright society registered under Section 33 of the Copyright Act, 1957. It administers and collects royalties on behalf of authors, composers, and music publishers for the public communication of musical and literary works. Under Section 2(ff) of the Copyright Act, 1957, ‘communication to the public’ includes any transmission of a work, by wire or wireless diffusion, broadcast, cable, satellite, or any other means, that makes the work accessible to the public. Digital platforms, apps, and online services that incorporate music into their product therefore fall squarely within this definition. For any business operating a mobile application, gaming platform, OTT service, or other digital product that uses music accessible to users in India, the question of whether an IPRS licence is required is not theoretical. It is a live compliance question with real commercial and legal consequences.

Continue Reading →

Two Routes to Music Licensing

Direct Licensing Vs. Copyright Society Licensing in India: Which Protects You Better?

Any business that uses copyrighted music in India, whether in a mobile application, digital platform, live event, broadcast, or commercial production, must obtain authorisation from the relevant copyright holders. In India, there are two primary routes through which this authorisation can be obtained: (i) a direct licence negotiated with and granted by the rights holder (or its authorised representative), or (ii) a licence obtained through a registered copyright society that administers the rights of multiple owners on a collective basis. Both routes are legally valid. Neither is inherently superior in all circumstances. The right choice for a specific business depends on the nature of the music usage, the identity of the rights holder, the territory of operation and the degree of legal certainty required. This article examines both routes, identifies the factors that inform the choice, and explains how Indian courts have approached disputes arising at the intersection of the two.

Continue Reading →

100% Labelling Crackdown

Fssai Vs. Misleading Claims: the Legal Story Behind the “100%” Labelling Crackdown

The Food Safety and Standards Authority of India (“FSSAI”) has, over the course of late May 2025, taken two connected regulatory steps aimed at curbing misleading claims on packaged food labels. First, FSSAI issued a formal advisory to all Food Business Operators (“FBOs”) directing them to discontinue the use of the term “100%” on food labels, packaging. and promotional material. Second, and consistent with the concerns underlying that advisory, FSSAI issued a detailed notice to a confectionery company in India, flagging specific instances of non-compliant labelling and misleading claims across several of its product lines.This alert summarises both developments and their implications for FBOs operating in the Indian packaged food and confectionery sector.

Continue Reading →

Bengaluru Crèche Abuse Case

Bengaluru Creche Abuse Case: Examining India’s Regulatory Gaps in Childcare Oversight and Data Protection

The registration of a criminal case against five daycare workers at a crèche operating within Capgemini Technology Services India Limited’s Brookefield campus in Bengaluru has brought renewed attention to a persistent gap in Indian law: the absence of a uniform, enforceable regulatory framework for workplace and standalone childcare facilities. The allegations – involving toddlers left in the care of employer-provided crèche staff – raise questions spanning criminal law, child protection legislation, employer obligations under labour law, and, increasingly, data protection law given the role that recorded video evidence played in bringing the matter to light. This alert summarises the reported facts, the applicable legal provisions, and the structural regulatory gaps that the case has surfaced, drawing on expert commentary from the early childhood education sector alongside contemporaneous news reporting.

Continue Reading →

performance data with third parties

Schools, Coaching Centres & Platforms Processing Children’s Data: Are You Compliant?

Across India, educational institutions and businesses that deal with minors have made it a routine practice to photograph children celebrating achievements, post their names and images on social media, websites, and marketing material, share performance data with third parties, and collect biometric or health-related data – all without obtaining verifiable parental consent. These photographs and videos are posted without the child or parent having any meaningful opportunity to review, restrict, or object.

Continue Reading →

For more information please contact us at : info@ssrana.com