India’s corporate law landscape is in the midst of a complex and layered transition. New rules are arriving in waves and overlapping older frameworks. Recent trends in corporate law are already reshaping policy and practice as we head into 2026.
DPDP Act (Digital Personal Data Protection Act, 2023) rules have been notified, with phased operationalisation stretching into 2026 and 2027, tightening consent, breach notification, and transparency obligations.
After its December 2024 board meeting, SEBI (Securities and Exchange Board of India) standardised BRSR Core (Business Responsibility & Sustainability Reporting) to industry standards. It also eased some assurance burdens while staggering value‑chain disclosures, which will affect listed companies’ reporting calendars in FY 2025‑26.
Meanwhile, MCA21 V3 of the Ministry of Corporate Affairs has become the default filing spine with web‑based forms, e‑adjudication, and real‑time validation. This shows the state’s push for digital compliance at scale.
Add to that mandatory dematerialisation for private companies via Rule 9B, with timelines extended into 2025 for non‑small entities. In fact, the arc of India’s corporate regulations is clearly bending toward data‑rich and machine‑verifiable governance.
Hence, it is important to anticipate regulatory shifts and prioritise defensible compliance so legal and business risks do not compound in 2026.
What Legal Services Does Every Business Need? Explore the essential corporate legal services for long-term growth.
Impact of Artificial Intelligence on Legal Workflows
The way businesses actually used AI was initially complex. Later on, with more subsequent legal regulations, drafting is faster, clause comparisons are more consistent, diligence turns searchable, and litigation analytics move probabilities to dashboards. What matters now is embedding AI in the compliance stack where filings are present.
Note the government’s own signals: MCA21 V3**(1) is already deploying AI and ML for helpdesk workflows, feedback analysis, and name approvals. This quietly normalises AI in public‑facing compliance processes.
For company law updates and transaction work, the lift is in model‑assisted redlining and real-time risk flags that map to statutory prerequisites.
Hence, it is important to keep human oversight and use audit logs, where corporate lawyers in India can help you. Also, integrate model outputs with matter management, and treat AI outputs as working papers. The following are some practical guardrails:
- Human‑in‑the‑loop approvals
- Training sets curated for Indian statutes
- Clear version control to protect privilege and accuracy.
First, align AI use policies with DPDP expectations**(2) on data minimisation and verifiable consent when models touch personal data. Second, connect AI tools to MCA21 timelines to reduce filing defects and resubmission churn, which remains a cost centre.
Is Your Startup DPDP Act Compliant Yet? Understand the crucial compliance steps under India’s DPDP Act.
Reorienting Compliance Teams with AI‑Driven Tools
Self‑service policies and chat‑assist bots are turning compliance into a frontline function rather than back-office work.
In fact, teams that used to rely on manual trackers now draft notices, reconcile registers, and pre‑validate board‑report disclosures with embedded prompts. As a result, the work feels lighter yet more watchful.
For legal issues on DPDP and CERT‑In (Computer Emergency Response Team) timing requirements**(3), automated breach playbooks help hit the six‑hour reporting clock. This helps to avoid penalties and reputation risk.
Hence, businesses must focus on:
- Automating the repetitive.
- Log the exceptions.
- Make sure audit files capture model prompts and responses to preserve defensibility.
ESG (Environmental, Social, and Governance) Regulation Intensification
The following are the major trends related to ESG for business regulations:
1. SEBI’s Mandatory Business Responsibility and Sustainability Reporting (BRSR)
The top 1,000 listed entities already file BRSR. Now the “Core” layer has industry standards as of December 20, 2024, and the assurance load was recalibrated after the December 18, 2024, meeting.
Moreover, value‑chain disclosures have been eased and, in parts, deferred to FY 2025‑26 to reduce the immediate burden while still pushing standardisation.
The 2026 view is that ESG reporting will sit closer to financial reporting in terms of cadence and scrutiny. This means board oversight cannot be performative.
The following shows the timeline and impact of BRSR Core:
|
Element |
Status/Timeline |
Practical Impact |
|
Industry Standards for BRSR Core |
SEBI circular issued Dec 20, 2024 |
Harmonised templates reduce interpretation disputes; internal data dictionaries are now essential. |
|
Value‑Chain Disclosures |
Compliance staggered; deferrals into FY 2025‑26 |
More time to set supplier/customer data rails without immediate penalty exposure. |
|
Assurance vs Assessment |
Ease‑of‑Business committee recommendations adopted |
Flexibility in choosing assessments reduces costs; boards must still ensure credibility. |
2. Organisational Response to ESG Demands
Now, carbon, labour metrics, and board‑level responsibility will not remain in the voluntary zone.
The operating model response looks like this:
Central sustainability data warehouse → mapped to BRSR indicators → cross‑checked by finance.
The governance response is sharper:
ESG risk is integrated into enterprise risk registers → with committee charters reflecting oversight duties.
So, prepare for tighter links between social metrics and board‑report disclosures as regulators align ESG and workplace practices.
Data Privacy and Cybersecurity Governance
The following are the major regulations related to data privacy and cybersecurity governance:
1. Implementing the Digital Personal Data Protection (DPDP) Act
The DPDP Act is no longer abstract. Rules notified in November 2025 lay down enforcement timelines, consent mechanics, and obligations for significant data fiduciaries, with phased sections entering into force through late 2026 and March 2027.
Also, stronger notice language, withdrawal symmetry, and breach reporting to the Data Protection Board tighten accountability. Moreover, they increase the risk of penalties for sloppy controls.
How Exposed Is Your Company Under the 2024 Data Law? Understand corporate liability and compliance risks.
Hence, for teams building internal roadmaps, the anchor points are straightforward:
- Lawful grounds of processing
- Retention boundaries
- Consent manager obligations
- Localisation of notices into the Eighth Schedule languages when required.
In short, these are no longer optional. They define legal compliance trends in Indian businesses going into 2026.
The table below shows the difference between DPRP and CERT-In rules:
|
Aspect |
DPDP Act + Rules (2025) |
CERT‑In Directions (2022) |
|
Breach Notification |
Report to the Data Protection Board; notify affected individuals per the Rules |
Mandatory reporting within 6 hours of awareness to CERT‑In |
|
Scope |
Digital personal data, onshore and certain offshore processing tied to India |
All entities operating in India across services and infrastructure |
|
Penalties |
Up to INR 250 crore for specified contraventions |
Penal consequences under the IT Act; enforcement via MeitY |
|
Operational Demands |
Clear notices, verifiable consent, rights handling, and significant fiduciary controls |
Clock sync, log retention, incident taxonomy, designated point of contact. |
2. Growing Importance of Cybersecurity in Compliance
The six‑hour breach reporting rule remains the tightest in the region. Hence, companies must balance CERT‑In clocks with DPDP transparency duties and sector‑specific rules, including SEBI guidance for regulated entities.
This is a hard coordination problem that is better solved by rehearsed runbooks rather than ad hoc command centres. So, build triage, legal notice templates, and data maps now.
Corporate Governance Reforms
The following are the major corporate governance reforms businesses must know about:
1. Strengthening Board Independence and Diversity
The 2024–2025 amendments under SEBI’s LODR framework**(4), and the FAQs updated April 23, 2025, signal more structured disclosure discipline and tighter process hygiene.
Moreover, secretarial auditor tenure rules have clarified application dynamics effective April 1, 2025. Also, integrated filing protocols have nudged issuers toward more complete and machine‑readable submissions.
As diversity and competence matrices mature, independence will be judged by information symmetry and committee effectiveness, rather than mere compliance checklists.
2. Enhanced Disclosure Norms for Board Reporting
The Ministry of Corporate Affairs’ 2025 amendments require the inclusion of POSH (Prevention of Sexual Harassment) and workforce metrics in the Board’s Report for all companies required to file it. This includes counts of complaints, resolution status, gender composition, and confirmations of complaint committees.
Also, expect maternity benefit compliance statements to come with these disclosures in standardised e‑forms. This will align governance tone with workplace realities.
Insolvency and Bankruptcy Code (IBC) Developments
The following are the recent developments that took place in the Insolvency and Bankruptcy Code:
1. Adoption of Pre‑Pack Insolvency and Cross‑Border Resolution
Pre‑pack for MSMEs has been on the books since 2021 under Chapter III‑A**(5).This offers a faster, debtor‑in‑possession alternative that can close in roughly 120 days.
In this case, uptake remains uneven due to admission bottlenecks and creditor coordination. However, for viable promoters with clean books, it can preserve value better than a full CIRP.
Cross‑border alignment continues to be discussed through the lens of the UNCITRAL**(6) (United Nations Commission on International Trade Law). While wholesale adoption is still evolving, the trend line points to more predictable frameworks for foreign asset recognition in the coming cycles.
The table below shows the difference between PPIRP and CIRP:
|
Feature |
Pre-Packaged Insolvency Resolution Process (MSMEs) |
Corporate Insolvency Resolution Process (All corporates) |
|
Control |
Debtor‑in‑possession unless fraud is found |
RP takes over management |
|
Timeline |
Target closure around 120 days |
Statutory window 180–330 days |
|
Cost/Process |
Pre‑negotiated plan, limited litigation |
Public bidding is a more complex process |
|
Eligibility |
MSMEs only, thresholds apply |
All corporates under IBC |
2. Strengthening Creditor‑Led Processes
At the outset, creditor rights remain central to IBC’s credibility. Interim representatives and committee protocols are now tested against practical challenges such as valuation gaps and late‑stage disputes.
The counsel takeaway is pragmatic:
- Build early alignment with financial creditors.
- Keep operational creditors informed to avoid avoidable litigation.
- Treat pre‑pack admissions as a structured negotiation, not a formality.
Statutory Compliance & Digitalisation Efforts
The following are the major corporate law trends in statutory compliance and digitalisation:
1. Digital MCA21 V3 Portal & Penalty Rationalisation
MCA21 V3 shows a steady march toward web‑native filings, real‑time validation, and dashboard visibility. In fact, form volumes and adoption climbed through 2024–25, supported by new helpdesk features and multi‑factor authentication standards.
Meanwhile, public notes highlight e‑adjudication and AI‑enabled name approvals. This further signals automation roots in the registry backbone. The decriminalisation drift under broader reform efforts keeps minor lapses in the civil penalty lane. This reduces procedural criminal exposure for technical defaults.
2. Labour, PF/ESI and e‑Invoicing Compliance
Finance teams should look beyond HR and payroll system hygiene and clock GST e‑invoicing changes. Effective April 1, 2025, businesses with an annual aggregate turnover of INR 10 crore or more must report e‑invoices within 30 days of invoice date on the IRP.
However, expect thresholds to continue tightening from the current INR 5 crore applicability baseline for e‑invoicing. Actually, multiple advisories indicate a downward trend and stricter validations.
The impact is that you can cache invoice data in near real time. Also, you can train teams on two‑factor authentication and build alerts for the 30‑day clock.
Foreign Legal Entry & Securities Digitisation
The following are the major trends in foreign legal entry and security digitisation:
1. Relaxed Regulations for Foreign Lawyers and Firms
The Bar Council’s 2025 amendments**(7) permit foreign lawyers and firms to practice foreign and international law in India on a reciprocal basis. It is largely in non‑litigious domains and international arbitration, without touching Indian law or courts.
The 2023 rules laid the base, and later clarifications kept Indian law as a domestic counsel terrain while opening structured collaboration channels for cross‑border matters. This shift will influence mandates where corporate lawyers in India collaborate with foreign counsel on complex M&A and arbitration seated in India but governed by foreign law.
2. Mandatory Dematerialisation of Securities
Rule 9B extends demat obligations to private companies other than small and government companies, requiring issuance only in dematerialised form and facilitation of dematerialisation of all outstanding securities.
Also, compliance timelines have been extended into 2025 for qualifying entities. Moreover, promoters, directors, and executives must be in demat before certain corporate actions. This must be your immediate call to keep company law updates clean and audit‑ready:
- Secure ISINs
- Align RTA processes
- File PAS‑6 on schedule
Decriminalisation and Ease‑of‑Business Measures
The following are the decriminalisation and Ease-of-business measures in India:
1. Jan Vishwas Bill 2.0 and Minor Offence De‑Criminalisation
Introduced in August 2025, Jan Vishwas 2.0 expands on the 2023 decriminalisation push, proposing to decriminalise 288 provisions across 16 central laws and to rationalise penalties, with advisory or warning notices for first‑time contraventions in many cases.
The policy aim is consistent: trust‑based governance and unclogged judicial pipelines. So, expect graduated penalties, administrative adjudication, and automatic fine increases every three years to keep deterrence without constant legislative change.
B. Simplified M&A and Quick‑Fix Merger Frameworks
The movement toward fewer procedural bottlenecks is visible across filings and clearances. In practice, streamlining works best when data hygiene meets timeline discipline.
Hence, counsels need to codify closing checklists that tie directly to MCA21 V3 validations and demat preconditions. Moreover, it is important to keep the transaction engine aligned with the registry’s digital rails.
Are Directors Personally Liable for Board Decisions? Understand the legal risks and protections.
Comparison of the Regulations
The following table compares the major regulations for corporate businesses:
|
Regulation |
Key Timer |
Who’s Affected |
Action Now |
|
DPDP Act + Rules (2025–2027 rollout) |
Staggered enforcement through 2026–2027 |
Data fiduciaries, significant data fiduciaries |
Build notices, consent flows, breach protocols |
|
CERT‑In Directions |
6‑hour breach reporting |
Most entities operating in India |
Rehearse runbooks; clock sync and logging |
|
SEBI BRSR Core |
FY 2025–26 value‑chain staging |
Top 1,000 listed |
Supplier/customer data standards |
|
MCA21 V3 |
Real‑time validation |
All companies/LLPs |
Pre‑validate filings. Use dashboards |
|
Rule 9B Demat |
Extended deadlines into 2025 |
Private companies, not small/government |
ISINs, PAS‑6, demat preconditions |
|
GST E‑Invoice |
30‑day IRP reporting for ≥ INR 10 crore turnover |
Mid‑sized to large taxpayers |
Configure ERP alerts and perform 2FA setup |
Keep Up with Trends!
Put simply, 2026 will reward legal teams that think in systems. The recent trends in corporate law do not wait for stragglers and slow-movers. Hence, map each obligation to a single owner, a single dashboard, and a single audit trail.
Also, work with specialised corporate lawyers in India who can translate regulations into processes, not memos. This way, legal compliance trends will become a competitive advantage. Hence, corporate regulations wil become less of a burden and more of a backbone for resilient growth.
**Source:
**(1)MCA21 V3
**(2) DPDP expectations
**(3) CERT‑In (Computer Emergency Response Team) timing requirements
**(4) SEBI’s LODR framework
**(5) Chapter III‑A
**(6) UNCITRAL
Share on
×