Intellectual property, technology
and data protection.
Intellectual property, technology and data protection counsel, from filing and portfolio strategy through to enforcement, compliance and incident response.
IP Rights, Technology & Data Protection
Ownership of created work is frequently less complete than assumed.
Filing and prosecution under the Trade Marks Act, 1999, and the drafting of patent specifications, are within the practice. Copyright is the quieter problem: first ownership generally vests in the author, subject to the exceptions in Section 17 of the Copyright Act, 1957, and agencies and contractors are authors too.
Data sits in the same practice because the Digital Personal Data Protection Act, 2023 turns on a question that ownership work already asks, which is what the organisation actually holds and where it came from.
Procedural steps are as capable of defeating a right as a substantive dispute. A renewal missed, a design disclosed at a trade fair before filing, an assignment left unsigned through a funding round.
Ownership, data and technology contracting sit in one practice because the same question runs under all three: what the business holds, where it came from, and who else has a claim on it.
Our intellectual property work covers patents, trademarks, copyright, designs and trade secrets, across registration, enforcement and litigation, and it includes managing the portfolio as an asset rather than as a filing habit. Trademarks are the right most businesses register first. We advise on adoption and clearance before money goes into a brand, handle filing and prosecution under the Trade Marks Act, 1999, reply to examination reports, and manage oppositions, renewals and the structure of a portfolio across classes. Enforcement is a separate exercise with its own economics. We act in infringement and passing-off proceedings, and parallel channels are also available: platform takedowns, domain name complaints under the UDRP and INDRP, and customs recordal against infringing imports. Which of those to reach for is a commercial decision before it is a legal one, because the question is often which remedy is proportionate to the harm and how quickly it can be obtained. A hard first letter can also turn a contained problem into a public one.
On patents we advise on patentability and on the exclusions in Section 3 of the Patents Act, 1970, including the computer programme and business method exclusion in Section 3(k), which frequently shapes how a specification is drafted. We run prosecution, work with technical teams on specifications, and look at freedom to operate before a product launches. Copyright work covers subsistence and ownership, assignment and licensing under Sections 18 and 19 of the Copyright Act, 1957, where Section 19 sets form requirements and statutory defaults on duration and territory, and the moral rights that generally survive an assignment under Section 57.
India has no standalone trade secrets statute at present. Protection comes from contract, from equitable obligations of confidence, and from how carefully an organisation controls access, which makes the ordinary housekeeping the protection rather than an addition to it.
Design registration is frequently overlooked. Registration under the Designs Act, 2000 protects the visual features of shape, configuration, pattern and ornamentation applied to an article, and novelty is assessed against what has already been published or used, subject to the limited protections for disclosure in Sections 16 and 21 of that Act, so disclosure before filing can defeat the right you were about to register. Product teams show a design at a trade fair or put it on a launch page long before anyone has thought about protection, and by then the question is no longer what to file but whether anything can still be filed at all.
Owning intellectual property and managing it are different jobs. Management starts with knowing what the company actually owns rather than what it assumes it owns, which is a live question wherever work has been done by contractors, by founders before incorporation, by agencies, or by employees whose contracts never assigned anything. Licensing then follows the commercial deal: field and territory limits, sublicensing, who owns improvements, and what happens to the licence on insolvency or a change of control. Assignment chain gaps are commonly identified during diligence on a fundraise.
India’s data protection regime moved from principle to practice with the Digital Personal Data Protection Act, 2023, and with the Digital Personal Data Protection Rules made under it, whose provisions commence in stages. The work this creates is concrete. Map what personal data the organisation actually holds and why. Establish a lawful basis for each processing activity. Rebuild consent notices to the standard of specificity the Act requires, appoint and properly empower the accountability function, and put in place a process that answers data principal requests rather than leaving them until somebody gets to them. Section 10 imposes additional obligations on data fiduciaries notified as significant data fiduciaries. None of that is a drafting exercise, which is why programmes that begin with a policy document tend to stall: the policy describes an organisation that has not been built yet, and the systems it describes carry on behaving the way they always did.
Order matters more than enthusiasm. Inventory comes first: systems, data elements, purposes, retention, recipients. Then lawful basis, then notice and consent design, then the rights process, then contracts. Retention is where the surprises are, because data is rarely deleted and nobody in the organisation owns deletion. Part of the early work is also forming a defensible view of where the organisation is likely to sit on the significant data fiduciary question and what that classification would demand of it. That view fits in a paragraph and changes what the programme has to build.
Vendor and group data flows are where compliance most often fails, because the obligation does not stop where your systems stop. We paper the processing arrangements, deal with cross-border transfer, and write breach response into the contract rather than improvising it afterwards. On incidents, the CERT-In directions require the cyber security incidents they specify to be reported to CERT-In by the entities they cover, and evidence handling in the first hours affects what can be shown if the matter later turns into litigation.
AI governance is a growing part of this practice: policy frameworks, model risk assessment, and the questions with money attached, which are who owns model output, what the training data licence actually permitted, what a vendor’s indemnity covers when a model produces infringing or defamatory output, and what has to be disclosed about an automated decision. India has no dedicated AI statute at the date of this page, rulemaking in the area is active, and what exists has been assembled out of law written for other purposes: the Information Technology Act, 2000 and the IT Rules, 2021 where an intermediary is involved, the Digital Personal Data Protection Act, 2023 where personal data is used in training or inference, copyright for training inputs and generated outputs, and guidance issued by sector regulators. Advice built to survive change therefore rests on the risk allocated in your contracts and the governance you can evidence internally.
Technology contracting is more ordinary and no less consequential. Data and exit clauses are frequently decisive in SaaS disputes, and renewal pricing repays a look before signature, because bargaining power drains away once the data is inside the system.
These areas converge in transactions. IP diligence asks whether the registered portfolio is in the company’s name and the assignments on record; data diligence asks what the target holds, on what basis, and whether the consent record supports the use the buyer has planned.
The statutes that apply
- Digital Personal Data Protection Act, 2023
- Consent, purpose limitation, data principal rights and obligations of data fiduciaries.
- DPDP Rules, 2025
- Operational detail under the Act, with provisions commencing in stages.
- Trade Marks Act, 1999
- Registration, opposition, rectification, infringement and passing off.
- Patents Act, 1970
- Patentability, the Section 3 exclusions including Section 3(k), prosecution and revocation.
- Copyright Act, 1957
- Subsistence, ownership, assignment and licensing, moral rights under Section 57.
- Designs Act, 2000
- Registration and protection of the visual features applied to an article.
- IT Act, 2000 and IT Rules, 2021
- Intermediary obligations, due diligence and safe harbour.
- CERT-In Directions, 2022
- Reporting of the cyber security incidents specified in the directions, by the entities they cover.
What we do
- Trademark clearance, filing & prosecution
- Oppositions, rectification & renewals
- Patent drafting & prosecution
- Copyright, assignment & licensing
- Design registration
- Trade secret & confidentiality architecture
- IP enforcement, takedowns & customs recordal
- DPDP Act compliance programmes
- Breach & incident response
- AI governance frameworks
- Technology, SaaS & licensing contracts
Common questions
No. India recognises rights in an unregistered mark through use, enforceable in a passing-off action. Registration provides a statutory infringement remedy in addition to that action, and it puts later applicants on notice. Clearance searching before adoption is one way the conflict question is commonly addressed, and the sequencing matters, because a conflicting prior mark identified after a launch reaches packaging, signage and the recognition already built rather than the choice of name alone.
The Act applies to the processing of digital personal data, and employee data is personal data. The basis on which it is processed differs, and so do the notices and the rights process that follow. Employee data is sometimes overlooked in compliance work focused on customers, though the HR side often holds the larger volume. The Act does not use a sensitive personal data category, so recruitment records, monitoring, biometric attendance and retention after exit are each analysed on the same footing, and each needs its own treatment rather than one blanket position.
Yes, but through contract and confidence rather than a dedicated statute. That makes the practical controls decisive: who has access, what the employment and contractor terms actually say, whether confidentiality survives termination, and whether exit processes recover materials. Courts look at whether the information was genuinely treated as confidential, so protection turns on how the material was handled in practice, and good drafting on its own will not carry it. Where the code is also a product, copyright subsists in it independently, and the two protections are usually run together.
Not a dedicated one at the date of this page. AI is governed by the law that already applies to whatever the system does: the Information Technology Act, 2000 and the IT Rules, 2021 where a platform is involved, the Digital Personal Data Protection Act, 2023 where personal data is processed, copyright for training material and outputs, and consumer law for how capabilities are described to buyers. Sector regulators have begun issuing their own guidance and the framework is still developing. So sound advice leans on contractual risk allocation and documented governance rather than on rules that may change.
Usually more than one applies. The CERT-In directions require the cyber security incidents they specify to be reported to CERT-In by the entities they cover. Separately, the Digital Personal Data Protection Act, 2023 requires a data fiduciary to intimate a personal data breach to the Data Protection Board and to affected data principals, on the terms set out in the Rules made under the Act. Regulated sectors add their own reporting lines on top. Each obligation has its own trigger, and the practical difficulty is often the internal authority to decide that an incident has occurred.
Absent a written assignment, generally they do. Under the Copyright Act, 1957 first ownership vests in the author, subject to the exceptions in Section 17, which include work made in the course of employment under a contract of service and certain commissioned works. An independent contractor is not an employee, so copyright in what they wrote will usually stay with them unless it has been assigned in writing and signed, as Section 19 requires. A purchase order describing an engagement as work for hire will not usually satisfy those requirements. A confirmatory assignment is one way this is commonly addressed, and it is easier to obtain while the relationship is still a good one.
In this practice
Facing something in
ip, tech & data?
Every enquiry is confidential. Tell us what you’re facing and our team will come back to you.
Get in Touch