Introduction India’s real-time digital payments architecture, spearheaded by the Unified Payments Interface, has achieved unprecedented operational scale, handling over 750 million daily transactions with a strategic target of exceeding one billion daily transactions. However, this explosive growth in transaction volume has coincided with an increasingly sophisticated landscape of financial cybercrime, forcing regulatory authorities and infrastructure…

Introduction Online Information and Database Access or Retrieval services, hereinafter referred to as “OIDAR services”, have been taxed in India when supplied by overseas providers since 01.12.2026.  The tax was first levied as service tax under the Finance Act, 1994 and the Service Tax Rules, 1994. From 01.07.2017, it has been levied as integrated tax…

Introduction India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) represents a monumental statutory assertion of digital sovereignty for 1.4 billion citizens. However, the simultaneous emergence of Generative AI (“GenAI”), trained on vast, opaque datasets and deployed over borderless global cloud infrastructure, creates a profound operational collision. Where the DPDP Act establishes a territorially rooted,…

Introduction Eporters who supply goods without payment of tax frequently find that the credit they have accumulated on inputs cannot be used against any output liability, and must instead be recovered through a refund claim. How the amount of that refund is computed is therefore a question of considerable commercial importance. In its recent order…

Introduction India’s card payments ecosystem has recently seen two fee-related issues come to a head in quick succession. On one hand, the National Payments Corporation of India has issued detailed FAQs clarifying the Merchant Discount Rate, the fee a merchant pays for accepting a digital payment, applicable to UPI transactions, providing much-needed certainty to industry…

Introduction The European Commission issued preliminary findings indicating that TikTok may have breached the Digital Services Act (“DSA”) in relation to the protection of minors. The Commission’s concerns include the accessibility of public account content, the ease with which younger users can change their account settings, and the recommendation of minors’ content through the platform’s…

€403M Fine on Google: What Global Enforcement Means for India’s DPDPA Landscape? When a legacy UX decision costs €403 million, “industry standard” is no longer a defense. India is sitting on a time bomb of legacy data only. Ireland’s Data Protection Commission (DPC) has penalized Google €403 million over historical location-tracking practices across Web &…

Introduction Global Capability Centres (‘GCCs’) have moved well beyond their origins as cost-efficient offshore delivery units. Across technology, financial services, pharmaceuticals, retail, manufacturing and consulting, India-based GCCs now anchor product engineering, analytics, cybersecurity, finance and AI-led work for global enterprises. For foreign businesses, general counsel and investors evaluating or scaling a GCC, this shift carries…

Introduction The Department of Consumer Affairs, Ministry of Consumer Affairs, Food and Public Distribution, notified the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 on 9 September 2026, amending the Consumer Protection (E-Commerce) Rules, 2020 framed under the Consumer Protection Act, 2019. The amendment, which comes into force on 1 January 2027, is the most significant recalibration…

Introduction The National Payments Corporation of India (“NPCI”) launched Agentic Orchestration & Messaging (“AtOM”), an open-source platform designed to manage the full lifecycle of a specification change across India’s payments ecosystem. AtOM takes a change from an initial idea through research, design documents and schemas, out to partner banks and payment service providers over an…

Introduction Modern businesses increasingly rely on third-party infrastructure to operate: cloud storage providers, artificial intelligence platforms, payment processors and HR systems now hold, transmit or process significant volumes of personal and business data on behalf of the organisations that engage them. This arrangement is efficient, but it does not change where legal responsibility for that…

Introduction The question of whether a delayed remittance of statutory tax collected by an entity can be treated as absolute non-payment to trigger harsh penal provisions has long created friction between taxpayers and revenue authorities. This issue becomes particularly crucial when fiscal statutes prescribe strict penalties for failure to pay taxes, leading authorities to routinely…

Introduction The Employee’s Provident Fund Scheme, 2026 (‘2026 Scheme’) came into effect from July 2026, introduced as delegated legislation under the Code on Social Security, 2020 (‘SS Code’). Its arrival has raised a question that is more consequential in principle than in practice: whether the 2026 Scheme has actually displaced the Employee’s Provident Fund Scheme,…

Introduction The Unified Payments Interface (“UPI”) has transformed India’s digital payments ecosystem by enabling instant payments without a direct transaction charge for consumers and merchants. However, its unprecedented growth has raised a fundamental question: if UPI transactions remain free for users, who should ultimately bear the cost of maintaining the infrastructure? The question has gained…

Introduction As India’s data protection regime moves from legislation to enforcement, businesses are increasingly treating cyber insurance as a ready answer to their compliance worries. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) became operational once the DPDP Rules were notified in November 2025, with phased implementation expected through 2027, and insurers are already…

Introduction The Hon’ble Supreme Court has recently clarified that Section 74 of the CGST Act cannot be invoked merely by reproducing the expressions “fraud”, “wilful misstatement” or “suppression of facts”. Where the Department seeks to invoke the extended period of limitation, the show-cause notice (“SCN”) must disclose the material facts and circumstances which form the…

Introduction On 13 May 2026, RBI introduced a new framework for facilitating outward remittances through non-bank entities in partnership with Authorised Dealer (AD) Category-I banks. The significant change was simple: non-bank entities no longer need prior RBI approval for such tie-ups. Instead, banks can enter into these arrangements within a prescribed regulatory framework. This could…

Introduction The internet has made Child Sexual Abuse Material (hereinafter referred to as “CSAM”) a profoundly transnational crime. A child may be located in India, the offender may operate from another jurisdiction, the platform may be incorporated in the United States, and the relevant electronic evidence may be stored across multiple servers. Yet, investigations continue…

Introduction The question of whether the Government can retain an amount collected as tax despite the absence of a lawful statutory liability has repeatedly arisen under the erstwhile service tax regime. The issue becomes particularly significant where tax has been paid under an erroneous classification and the assessee subsequently establishes that the underlying activity was…

Introduction India’s digital payments revolution is often defined by one word, UPI. The Unified Payments Interface has transformed the manner in which money moves, making transactions instant, interoperable and accessible. However, the next phase of India’s digital financial journey may not be about making payments faster. It may be about making financial opportunity easier to…

Introduction The Digital Personal Data Protection Act, 2023 (“DPDP Act”) borrows some of the European Union (“EU”)’s General Data Protection Regulation (“GDPR”)’s vocabulary a Data Fiduciary echoes a “controller,” a Data Principal echoes a “data subject” and the legal architecture behind those words is roughly the same. In several places the DPDP Act gives a…

Introduction The rapid expansion of digital payments, online banking and fintech platforms has transformed India’s financial ecosystem. However, the same infrastructure has also enabled cyber fraudsters to transfer illicit funds rapidly across multiple bank accounts and payment channels. In response, law-enforcement authorities and financial institutions increasingly rely upon account freezes, debit restrictions and lien markings…

Introduction In August, Meta’s technical team and the Ministry of Electronics and Information Technology (MeitY) lead to the government clarifying that Meta’s platforms in India must be governed by Indian law, not merely by the company’s global policies. The discussion focused on content moderation, deepfakes, child sexual abuse material (CSAM), and the opacity of Meta’s…

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.