DPDP Act, 2023: From Legal Obligation to Operational Readiness

DPDP Act, 2023: From Legal Obligation to Operational Readiness

Author by: Rashi Anand Suri

A post-webinar legal and implementation perspective from Upscale Legal and G-Info Technology Solutions Pvt. Ltd. (GISPL)

Webinar: “DPDP Act Compliance: End-to-End Readiness & Implementation” | 14 August 2026

 

Introduction

For most organisations, DPDP compliance will not fail because the organisation has never heard of the Digital Personal Data Protection Act, 2023 (“DPDP Act”). The harder problem is more ordinary: the organisation may not know, with sufficient confidence, where personal data is collected, which systems hold it, who can access it, which vendors receive it, how consent is recorded, or whether a request from a Data Principal can actually be fulfilled.

That is where the discussion around the Digital Personal Data Protection Act, 2023 has moved. The statute establishes the legal framework; the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) add operational detail; and organisations now have to work out what those requirements mean for their own data, contracts, systems and people.

This was the focus of the webinar “DPDP Act Compliance: End-to-End Readiness & Implementation”, conducted by Upscale Legal and G-Info Technology Solutions Pvt. Ltd. (GISPL) on 14 August 2026. The discussion brought together two perspectives that are closely connected in practice: Upscale Legal’s legal and regulatory perspective, and GISPL’s information-security and implementation perspective. The distinction is important. Legal advice may identify an obligation, but the organisation still has to translate that obligation into a process, a contractual arrangement, a system control or an internal responsibility. Equally, a technical control does not, by itself, establish that every legal requirement has been addressed.

 

A note on the current regulatory position

The DPDP Act received Presidential assent on 11 August 2023. The Central Government’s commencement notification was issued on 13 November 2025 and published in the Gazette on 14 November 2025. It adopts a phased commencement structure. Certain provisions came into force on publication; specified provisions are to commence one year after publication; and the larger substantive set of provisions is to commence eighteen months after publication.

The DPDP Rules, 2025 follow the same broad approach. Rules 1, 2 and 17 to 21 came into force on publication; Rule 4 is to come into force one year after publication; and Rules 3, 5 to 16, 22 and 23 are to come into force eighteen months after publication.

That distinction should be kept clear when discussing compliance. The fact that the Rules have been notified does not mean that every substantive provision is already operative. At the same time, organisations should not treat the phased commencement period as a reason to defer preparation. A meaningful compliance exercise may require data mapping, contractual review, policy changes, system configuration, rights-management processes, security controls and employee training.

 

1. The first question is applicability

A DPDP exercise should begin with the organisation’s facts, not with a template privacy policy.

Section 3 of the DPDP Act sets out the territorial application of the legislation. In broad terms, the Act applies to the processing of digital personal data within India in the circumstances specified by the statute and may also apply to certain processing outside India where such processing is connected with offering goods or services to Data Principals in India.

The organisation’s role also matters. A Data Fiduciary is the person who determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of a Data Fiduciary.

That distinction becomes important when reviewing technology providers, outsourcing arrangements and other third-party relationships. The applicability assessment should also consider whether specific provisions may apply to the organisation—for example, provisions concerning children’s personal data or the additional obligations applicable to a Significant Data Fiduciary.

This is fundamentally a legal assessment. The organisation should understand its processing activities and then determine which statutory obligations attach to them.

 

2. Before reviewing the privacy policy, understand the data

One of the practical difficulties in data protection work is that organisations often know their systems individually but do not have a sufficiently complete picture of how personal data moves between them.

Consider a relatively ordinary customer journey. A person provides information through a website. The information enters a CRM. A marketing platform may receive part of it. A third-party service provider may process another element. Records may subsequently be archived.

The same problem appears in employee data, recruitment, customer support, finance and other business functions.

For legal counsel, this matters because questions about purpose, notice, consent, retention, disclosure and Data Principal rights cannot be answered properly without understanding the underlying processing activity.

Data mapping is therefore not simply an IT exercise. The implementation framework discussed during the webinar included data discovery, mapping and classification to establish visibility into the organisation’s data environment.

This implementation perspective also aligns with GISPL’s information-security background. GISPL describes its services around information-security audits, cybersecurity assessments and protection of information assets, networks and applications, and identifies itself as a CERT-In empanelled security auditor.

 

3. Notice and consent require more than revised wording

The DPDP Act places specific requirements around notice and consent. Section 5 addresses notice, while Section 6 addresses consent. Where consent is relied upon, the statutory framework requires consent to satisfy specified conditions, including that it be free, specific, informed and unambiguous and involve a clear affirmative action.

The DPDP Rules provide further detail. Rule 3 requires the notice to be presented independently and in clear and plain language. It must include, at a minimum, an itemised description of the personal data and the specified purpose or purposes of processing. It must also provide the means through which the Data Principal may withdraw consent, exercise rights and make a complaint to the Board.

For organisations, this raises a more practical question: Does the actual data-collection process correspond with the notice?

That requires examining the point at which information is collected—not merely the privacy policy page. A legal review should consider what information is being collected, for what purpose, what is communicated to the Data Principal, how consent is captured and evidenced, and how withdrawal operates.

A carefully drafted notice cannot, by itself, correct a process that operates differently from the notice.

 

4. A privacy policy is one document, not the compliance programme

A privacy policy may be an important part of DPDP compliance. It is not, however, a substitute for the broader governance framework.

Depending on the organisation’s activities, the compliance framework may need to address data protection responsibilities; consent management; retention and deletion; Data Principal rights; grievance handling; vendor and processor arrangements; breach response; and internal escalation and accountability.

The important issue is whether these documents correspond with the organisation’s actual practices.

For example, if an organisation’s policy states that information will be deleted after a specified period, it should be possible to identify the systems in which that information is held and the process through which deletion is effected. Similarly, if a contract requires a processor to report a security incident, there should be an internal mechanism through which that notification is received, assessed and escalated.

 

5. Data Principal rights have to work in practice

The DPDP Act provides Data Principals with specified rights, including rights relating to access to information about personal data, correction and erasure, grievance redressal and nomination.

For organisations, the practical difficulty begins when a right is actually exercised.

Suppose a Data Principal requests correction of information. Who receives the request? How is the request verified? Which system contains the authoritative record? Does a processor hold the same information? Who confirms that the correction has been completed? What evidence is retained?

These are operational questions, but they have a direct legal consequence.

A compliance review should therefore examine the entire rights-management process rather than simply checking whether the organisation’s privacy policy mentions Data Principal rights. One useful way to test readiness is to take a hypothetical rights request and follow it through the organisation.

 

6. Children’s personal data requires specific attention

Section 9 of the DPDP Act establishes specific requirements concerning the processing of children’s personal data, including requirements relating to verifiable parental consent and restrictions on certain processing activities.

The Rules provide additional detail concerning verification mechanisms.

Organisations whose products or services are likely to be used by children should therefore consider more than the wording of a privacy notice. Age-related processes, parental consent, product design, communications and the systems used to implement those processes may all require examination.

 

7. Significant Data Fiduciaries: an assessment, not an assumption

The DPDP Act provides a separate framework for Significant Data Fiduciaries (“SDFs”). Section 10 sets out additional obligations for entities notified as SDFs, including requirements relating to a Data Protection Officer, an independent data auditor and specified assessments and audits.

An organisation should not assume that it is an SDF merely because it maintains a large database or processes information that it considers sensitive. The statutory framework contemplates consideration of factors including the volume and nature of personal data processed, the risk to the rights of Data Principals and other specified factors.

SDF status therefore requires a proper legal assessment against the applicable framework.

 

8. Vendor contracts are part of the data-protection picture

Most organisations do not process personal data entirely within their own infrastructure. Cloud providers, SaaS platforms, HR technology providers, CRM vendors, outsourcing partners and other service providers may process information on behalf of a Data Fiduciary.

The contractual review should therefore go beyond a generic confidentiality clause.

Depending on the relationship, it may be appropriate to consider provisions concerning the purpose and scope of processing; confidentiality; security safeguards; incident reporting; sub-processing; assistance with Data Principal rights; retention and deletion; and other responsibilities between the parties.

The legal character of the third party should also be examined carefully. Simply calling an organisation a “vendor” or “processor” in a contract does not, without more, resolve the legal analysis.

 

9. Security safeguards and breach response must be connected

Section 8 of the DPDP Act addresses obligations of Data Fiduciaries concerning reasonable security safeguards and personal-data breaches. The DPDP Rules provide additional detail concerning security safeguards and breach-related requirements.

The practical lesson is straightforward: breach response should be designed before an incident occurs.

An organisation should have clarity about how an incident is detected; who receives the initial escalation; how it is assessed; when Legal is involved; how technical containment is coordinated; what regulatory notifications may be required; how affected individuals are addressed where applicable; and what documentation is retained.

The Rules prescribe specific notification requirements, including requirements concerning notification to the Board and communication to affected Data Principals in the circumstances specified by the Rules.

This is an area where the respective roles of Legal and information security are particularly clear. GISPL’s published work includes cybersecurity testing, security assessments and information-security auditing. Upscale Legal’s role in the joint framework is to address the legal and regulatory implications of incidents and the organisation’s response.

 

10. Training should reflect the work people actually do

Employees are often directly involved in collecting, accessing, sharing or deleting personal data. Training therefore needs to be relevant to the role.

A marketing team may need to understand consent and communications. HR may need to understand employee and recruitment data. Procurement may need to identify data-processing issues in vendor arrangements. IT and security teams may require more detailed guidance on access controls, incident escalation and technical safeguards. Senior management, meanwhile, needs visibility into accountability, risk and organisational readiness.

The webinar framework contemplated organisation-wide awareness, role-based training and management-level briefings. The objective should be to build understanding into everyday processes rather than treat data protection as an annual compliance module.

 

11. Readiness should be demonstrated, not assumed

A compliance programme should ultimately be capable of being tested.

That does not necessarily mean conducting an exhaustive audit of every system. It means selecting the areas that matter and checking whether the documented position corresponds with actual practice.

Examples include checking whether the privacy notice matches information collected through the website; whether a Data Principal request can be routed to the appropriate team; whether consent and its withdrawal can be evidenced; whether relevant vendor agreements contain appropriate provisions; whether an incident can be escalated through a defined process; and whether employees understand their responsibilities.

The webinar’s final stage was framed as compliance validation and readiness assessment, including review of policies, controls and processes. That is a more meaningful measure of readiness than the number of documents sitting in a compliance folder.

 

A practical starting point for organisations

There is no single DPDP implementation sequence that will suit every organisation. A hospital, an e-commerce business, a financial institution, an educational institution and a technology company may all process personal data, but their processing activities, systems and risk profiles will differ.

A useful starting assessment can nevertheless ask six basic questions:

  • What personal data does the organisation process, and for what purposes?
  • Which systems, business functions and third parties handle that data?
  • What notices and consent mechanisms are currently used?
  • Can applicable Data Principal requests be received and fulfilled through a documented process?
  • What would happen if a personal-data incident were detected today?
  • Who is responsible for bringing the legal, operational and technical aspects together?

The answers provide a more useful starting point than simply asking whether an organisation is “DPDP compliant”. They show where legal interpretation is required, where existing processes may need to change and where technology or security controls need to be examined.

 

The Upscale Legal–GISPL approach

The joint approach presented by Upscale Legal and GISPL during the 14 August 2026 webinar was based on the intersection of law, technology and operations.

Upscale Legal addresses the legal and regulatory layer: applicability, interpretation of the DPDP framework, privacy and consent documentation, contractual and Data Processing Agreement review, SDF/DPO/DPIA considerations where applicable, and breach and regulatory readiness.

GISPL brings an information-security and implementation perspective. Its published services include cybersecurity compliance, information-security audits, vulnerability and security testing, and other measures aimed at protecting information assets, networks and applications. GISPL also identifies itself as a CERT-In empanelled security auditor.

The value of bringing these perspectives together is practical. A legal team may identify a requirement relating to security safeguards. The organisation then has to determine what safeguards are appropriate, where they need to be implemented and how their operation can be evidenced. Similarly, a security team may identify a vulnerability. The organisation may then need to determine whether the vulnerability has legal or regulatory consequences and what response is required.

DPDP compliance therefore sits neither exclusively with Legal nor exclusively with IT. It sits within the organisation’s wider governance of personal data.

 

Conclusion

The Digital Personal Data Protection Act, 2023 has established the statutory foundation for India’s digital personal-data protection framework. The notification of the DPDP Rules, 2025 has added significant operational detail, while the phased commencement structure provides organisations with time to prepare.

That preparation should begin with the organisation’s actual processing environment. Where is personal data collected? Why is it collected? Who receives it? How is consent managed? How are Data Principal rights handled? Which vendors process the information? What safeguards protect it? What happens when something goes wrong?

Those questions lead to the legal analysis that matters.

The 14 August 2026 webinar conducted by Upscale Legal and GISPL reinforced the importance of bringing legal, information-security and operational perspectives together. The objective is not simply to produce a set of documents. It is to establish a defensible understanding of the organisation’s obligations and a practical means of meeting them.

For organisations beginning their DPDP journey—or reassessing work already undertaken—the appropriate first step is therefore a structured assessment of applicability, data processing, governance, contractual arrangements, Data Principal rights, security safeguards and incident readiness. The resulting gaps can then be prioritised according to the organisation’s legal obligations, risk profile and operational realities.

 

Frequently Asked Questions

What is the Digital Personal Data Protection Act, 2023?

The Digital Personal Data Protection Act, 2023 is India’s statutory framework governing the processing of digital personal data and establishing rights, duties and obligations for Data Principals and Data Fiduciaries.

Are the DPDP Rules, 2025 currently in force?

The Rules were notified on 13 November 2025 and published on 14 November 2025, but their provisions have phased commencement dates. Rules 1, 2 and 17–21 came into force upon publication; Rule 4 is scheduled to commence one year later; and Rules 3, 5–16, 22 and 23 are scheduled to commence eighteen months after publication.

Is consent required for every processing activity under the DPDP Act?

No. Section 4 provides for processing for a lawful purpose where the Data Principal has given consent or where the processing falls within the statutory framework of certain legitimate uses. The appropriate legal basis should be assessed for the particular processing activity.

Is a privacy policy sufficient for DPDP compliance?

No. A privacy policy is one component of a broader compliance framework. Depending on the organisation and its processing activities, compliance may also involve data mapping, notice and consent, Data Principal rights, governance, processor arrangements, security safeguards, breach response and validation.

What is a Data Fiduciary?

A Data Fiduciary is a person who, alone or together with others, determines the purpose and means of processing personal data.

What is a Data Processor?

A Data Processor processes personal data on behalf of a Data Fiduciary. Whether a particular third party falls within this role should be assessed from the actual relationship and processing activities.

What should an organisation do before the substantive DPDP provisions commence?

The appropriate starting point is an applicability and gap assessment. Depending on the organisation, this may involve data mapping, review of notices and consent mechanisms, vendor-contract review, rights-management processes, breach preparedness, security assessment, training and remediation planning.

What role does GISPL play in DPDP compliance?

GISPL brings an information-security and implementation perspective, including cybersecurity assessment, information-security auditing, testing and security controls. GISPL states on its website that it is a CERT-In empanelled security auditor.

What role does Upscale Legal play?

Upscale Legal provides the legal and regulatory advisory perspective, including applicability assessment, privacy and consent review, contractual and DPA review, SDF/DPO/DPIA considerations where applicable, and legal and regulatory readiness in relation to personal-data incidents.

 

About the Webinar

DPDP Act Compliance: End-to-End Readiness & Implementation – 14 August 2026

The webinar brought together Upscale Legal and G-Info Technology Solutions Pvt. Ltd. (GISPL) to examine DPDP compliance from both legal/regulatory and implementation/information-security perspectives. The webinar framework covered applicability, data mapping, governance, privacy and consent, Data Principal rights, vendor management, breach response, training, technical safeguards and compliance validation.

 

Legal Disclaimer

This article is intended for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. The Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 and related notifications, directions and regulatory developments should be read in their current form. The application of the law may vary depending upon the nature of the organisation, its processing activities, contractual arrangements and other applicable legal or regulatory requirements. Organisations should obtain legal advice based on their particular facts and circumstances before taking compliance decisions.

Need Legal Guidance?

Schedule a Consultation

UPSCALE LEGALAbout
Upscale Legal is a multi-service law firm catering to the needs and interests of various Corporate houses, Financial institutions, Government agencies & departments, along with assisting in supplementary business & legal issues of our individual clients.
AWARDSOur Presence
https://upscalelegal.com/wp-content/uploads/2022/09/iblj.jpg
The 10 Highly Recommend
Untitled design (1)
Legal era
Insight
image 6
image 5
Untitled design (2)
Legal Era awards
certificate-of-Indian-business-law-journal-new
GET IN TOUCHUpscale Social links
UPSCALE LEGALHeadquarters
Upscale Legal is a multi-service law firm catering to the needs and interests of various Corporate houses, Financial institutions, Government agencies & departments, along with assisting in supplementary business & legal issues of our individual clients.
OUR LOCATIONSWhere to find us
https://upscalelegal.com/wp-content/uploads/2019/04/img-footer-map.png
AWARDSOur Presence
https://upscalelegal.com/wp-content/uploads/2022/08/Awards.png
GET IN TOUCHSocial links

Copyright by Upscale Legal. All rights reserved.

Copyright by Upscale Legal. All rights reserved.

Devraj Singh

Devraj Singh is a law graduate from Christ (Deemed to be University), Pune, with a specialization in business and corporate law. His professional experience spans Corporate Advisory, Regulatory Compliance, Technology Law, Data Privacy, Cyber Law, and Commercial Dispute Resolution, enabling him to provide comprehensive legal solutions that balance business objectives with regulatory requirements.

Through his experience with law firms and compliance organizations, Devraj has gained substantial experience in drafting, reviewing, and negotiating commercial, technology, and employment-related agreements, including Software Development Agreements, MSAs, NDAs, Employment Agreements, Terms of Service, and other commercial contracts. He has advised on contract management, regulatory compliance, legal due diligence, corporate governance, tender compliance, and risk assessment, while assisting businesses in navigating complex legal and operational challenges across technology, financial, and regulated sectors. He regularly advises clients on tender compliance, procurement processes, corporate governance, regulatory approvals, legal due diligence, vendor management, and risk mitigation strategies.

His practice extends to day-to-day corporate compliance management, regulatory audits, compliance monitoring frameworks, policy drafting, internal governance mechanisms, enterprise risk assessment, and business process compliance. He has assisted companies in evaluating legal and regulatory obligations across sectors including technology, telecommunications, healthcare, financial services, infrastructure, and emerging digital businesses. His work also includes advising on labour and employment compliance, corporate structuring, regulatory registrations, and operational legal risk management.

In the field of Technology, Data Privacy, and Artificial Intelligence Law, Devraj has advised on the Digital Personal Data Protection Act, 2023, GDPR compliance, Data Protection Impact Assessments (DPIAs), consent management frameworks, CERT-In reporting obligations, cybersecurity governance, platform regulations, intermediary liability, and emerging AI regulatory frameworks. He has prepared legal opinions and compliance memoranda on the EU AI Act, Digital Services Act, online gaming regulations, data protection requirements, and technology-driven business models. His academic and professional interests further extend to AI governance, cybersecurity regulation, digital platforms, and the legal implications of emerging technologies.

Devraj has also been actively involved in complex legal due diligence exercises, including high-value investment transactions, reviewing commercial contracts, intellectual property arrangements, confidentiality frameworks, and regulatory exposures. His experience includes advising on anti-bribery and anti-corruption laws, cross-border compliance obligations, sanctions regimes, accessibility regulations, and corporate compliance standards across multiple jurisdictions.

On the disputes side, Devraj has assisted in commercial litigation, debt recovery proceedings, cyber fraud investigations, contractual disputes, and regulatory proceedings. His experience includes drafting pleadings, legal notices, complaints, recovery strategies, arbitration-related research, and litigation support before courts, tribunals, and regulatory authorities. He has also worked on matters involving insolvency law, infrastructure disputes, property-related claims, cybercrime investigations, and complex commercial recoveries.

Devraj’s practice is driven by a strong focus on regulatory compliance, risk management, corporate governance, technology law, and strategic legal advisory. He regularly assists businesses in identifying legal risks, strengthening compliance frameworks, managing contractual relationships, ensuring regulatory adherence, and supporting management in making legally sound and commercially viable decisions.

Kshitij Suri

Kshitij Suri is a practicing advocate, having completed his B.A.LLB from the University School of Law and Legal Studies, with focused experience in civil and criminal litigation. He has trained and practiced in a rigorous chamber environment prior to joining the Firm, where his work was primarily rooted in trial-level advocacy across a range of forums.

His practice includes handling civil disputes, consumer litigation, and select criminal matters, with substantial involvement in drafting pleadings, applications, written arguments and legal notices.

He is also adept in conducting in-depth and exhaustive legal research, providing comprehensive legal answers.

Aditya Chopra

Aditya is a professionally qualified Advocate with over 8 years of post-qualification experience, specializing in diverse domains including Commercial Law, Dispute Resolution, Contract Management, Corporate Advisory, Tender Management, Labor & Employment, Intellectual Property Rights, Document Processing, Business Set-up & Management Services, and Start-Up Advisory.

His expertise lies in contract management, due diligence, corporate advisory, and litigation, where he has successfully drafted, negotiated, and reviewed complex agreements, conducted risk assessments, ensured regulatory compliance, and represented clients before various judicial and quasi-judicial forums. Aditya has actively handled high-stakes disputes and achieved tangible results through negotiations, settlements, and arbitration.

With a strong foundation in legal drafting and research, Aditya is adept at providing strategic solutions to clients across industries. I take pride in building and maintaining trusted professional relationships with clients, colleagues, and law enforcement authorities, thereby ensuring effective outcomes and long-term success.

Vagisha Gupta

Vagisha is a highly skilled legal professional with extensive experience as an advocate, legal advisor, and consultant, specializing in litigation, arbitration, and corporate advisory. I have successfully represented clients before labour courts, sessions courts, trial courts, and the High Court of Delhi, handling diverse legal disputes with strategic precision and professionalism. Her expertise spans drafting and reviewing a wide range of legal documents, including commercial suits etc.

In the corporate sphere, Vagisha has conducted comprehensive due diligence in transactions, evaluated risks, and ensured adherence to regulatory frameworks across HR policies and governance structures. Ms. Gupta has advised clients extensively on employment agreements, labour law compliance, and POSH policies, contributing to legally sound and ethically compliant workplaces. Vagisha’s work reflects a blend of technical legal expertise and practical business insight, ensuring effective solutions for complex challenges.

With strong analytical, drafting, and negotiation skills, she remains committed to safeguarding client interests, upholding the highest standards of ethics and confidentiality, and fostering enduring professional relationships.

Shreya Shrivastav

Shreya Shrivastav is a strategic outreach and coordination professional with over three years of cross-functional experience spanning HR operations, stakeholder management, and growth-oriented communication. At Upscale Legal, she operates at the intersection of leadership coordination and external engagement, working closely with founders, HR heads, and institutional partners.

Her expertise lies in people management, structured planning, negotiation, and disciplined execution. She plays a key role in managing professional relationships, coordinating internal teams, and ensuring seamless communication across operational and growth initiatives. Her ability to balance strategy with execution allows her to contribute meaningfully to both organizational development and market positioning.

Shreya brings a strong foundation in digital marketing and operational structuring, enabling her to align outreach efforts with long-term business objectives. She is known for her clarity in communication, composure in professional interactions, and ability to build trust-driven relationships.

Her approach is deliberate and growth-focused — combining strategic thinking with reliable execution.

Saurabh Dikshit

Saurabh is a corporate law professional holding a B.A., LL.B. (H) (Batch 2016–2021) and a Master’s degree in Corporate Law from Amity University (Batch 2023–24), with over two years of focused experience in corporate advisory and real estate transactions. He currently serves as a Legal Associate at Upscale Legal, advising clients on a wide spectrum of commercial, transactional, and regulatory matters.

His core expertise lies in transaction structuring, drafting, and documentation, including Lease Deeds, Sale Deeds, MOUs, MSAs, Trust Deeds, Undertakings, NDAs, Settlement Deeds, and Statutory Legal Notices, including Notices under Section 138 of the Negotiable Instruments Act, 1881. He has substantial experience in conducting legal Due Diligence, Share Transfer Transactions, Labour Law Advisory, Licensing and Regulatory Registrations, and Comprehensive Document Vetting across complex commercial arrangements.

He has actively handled corporate leasing transactions and conducted extensive real estate and corporate due diligence for a leading edutech enterprise undertaking pan-India expansion, supporting multi-city commercial leasing, title verification, regulatory compliance, and transaction risk assessment across jurisdictions.

His practice reflects strong proficiency in contract management, risk assessment, corporate governance advisory, and dispute pre-litigation strategy. He brings a commercially driven approach to legal structuring, ensuring enforceability, compliance, and long-term risk mitigation for his clients.

Samriddhi Goswami

Samriddhi Goswami is a law graduate from the Faculty of Law, University of Delhi (Batch 2021–2024). Her professional journey has provided her with substantial exposure to both Corporate Advisory and Litigation, enabling her to address legal issues from preventive as well as remedial perspectives.

With approximately one year of post-qualification experience in Corporate Advisory, she has developed proficiency in drafting and reviewing a wide range of complex agreements, including Service Agreements, Memorandum of Understanding (MoUs), Lease Deeds, and Non-Disclosure Agreements (NDAs). Her practice further extends to Intellectual Property advisory, Labour and Employment law matters, Real Estate transactions, Tender management, Due Diligence, Mergers and Acquisitions (M&A) support, RERA compliance, and regulatory registrations, including TRAI compliance and Start-up advisory.

On the litigation front, she has represented clients before various judicial forums, including District Courts, the High Court of Delhi, and several Tribunals. Her litigation experience encompasses civil disputes, criminal matters, labour and employment disputes, and proceedings under Section 138 of the Negotiable Instruments Act.

Anushrut Rajawat

A versatile legal professional with a strong foundation in both corporate law and litigation. Anushrut holds a B.A.LL. B from the School of Law, University of Petroleum and Energy Studies, Dehradun. His journey in the legal field began early, as he gained invaluable experience as a legal advisor during my 5th year of law school.

With over one year of post-qualification experience at Upscale Legal, He has developed a robust skill set. Anushrut’s corporate experience includes drafting and reviewing a wide range of agreements (including SHA’s, NDAs, and Service Agreements), conducting due diligence for real estate and company acquisitions, and managing regulatory tasks such as GST registrations. He has also gained unique insight into corporate legal departments through a client secondment.

On the litigation front also, he has a proven track record of representing clients in civil and criminal matters before the District Courts and High Court of Delhi. Anushrut has specific expertise in recovery and labour matters, providing effective legal counsel and representation in court. This dual expertise allows him to offer comprehensive legal solutions, blending proactive corporate advice with assertive dispute resolution.

Jasleen Kaur

Jasleen Kaur is an Advocate providing comprehensive legal solutions across a broad spectrum of practice areas. She has developed a dynamic and well-rounded practice that seamlessly combines effective courtroom advocacy with strategic legal advisory services for individuals, corporates, and institutions. She holds a Bachelor of Laws (LL.B.) degree and commenced her professional journey in 2017 through extensive internships and rigorous practical training. This early exposure afforded her substantial hands-on experience in both litigation and corporate law even prior to her formal enrolment as an Advocate, enabling her to cultivate a mature, practical, and in-depth understanding of the legal profession from an early stage.

Jasleen is recognised for her strong command over litigation and dispute resolution, having successfully represented clients before District Courts, High Courts, arbitral tribunals, and statutory forums. Her practice spans civil litigation, criminal defence, arbitration proceedings, labour and employment disputes, matrimonial and family law matters, consumer complaints, corporate and commercial disputes, and cases under Section 138 of the Negotiable Instruments Act (cheque dishonour matters). She has developed a particularly robust practice in criminal law, handling complex trials, sensitive matters, and bail applications with precision and diligence. She is also actively involved in critical stages of criminal proceedings, including police station proceedings, interactions with investigating officers, and safeguarding clients’ procedural and constitutional rights at every stage.

In the field of arbitration, Jasleen possesses a strong working knowledge of the Arbitration and Conciliation Act, 1996, and regularly appears in arbitral proceedings, including matters before institutional arbitration forums. She is experienced in drafting pleadings, applications, and written submissions, managing procedural aspects of arbitration, and advising clients on strategy and enforcement.

She also commands significant expertise in labour and employment laws, representing clients in disputes relating to illegal termination, non-payment of dues, disciplinary proceedings, industrial disputes, and service-related matters before Labour Courts, Industrial Tribunals, and other appropriate forums. Her approach in labour matters is both legally sound and commercially pragmatic, balancing employer compliance with employee rights.

In addition to domestic corporate advisory, Jasleen advises clients on international incorporation and cross-border business structuring, assisting startups and businesses with company incorporation in foreign jurisdictions, regulatory compliance, shareholder structuring, and coordination with overseas professionals, ensuring legally sound and commercially viable expansion beyond India.

Jasleen has actively participated in court-referred mediations, facilitating amicable and commercially viable settlements in civil and matrimonial disputes. She has further handled accident claims, sensitive criminal cases, and disputes arising out of altercations, equipping her with a comprehensive and practical understanding of civil, criminal, and quasi-criminal proceedings.

While litigation remains her core strength, she also efficiently manages complex corporate and commercial assignments, including drafting, vetting, and negotiating high-value contracts, agreements, and legal documentation. Her drafting and advocacy are marked by clarity, precision, and persuasive articulation, and she is particularly known for identifying weaknesses in the opposing party’s case and presenting focused, effective submissions before judicial and arbitral forums.

Disclaimer

Welcome to the website of Upscale Legal. As per the rules of the Bar Council of India, lawyers and law firms are not permitted to solicit work or advertise. By clicking on the “AGREE” button below, the website visitor agrees and acknowledges that:-

* There has been no advertisement, personal communication, solicitation, invitation or any other inducement of any sort whatsoever by or on behalf of Upscale Legal or any of its members to solicit any work through this website.
* The user wishes to gain more information about Upscale Legal for his/her/their own information and use.
* All information about Upscale Legal on this website is being provided to the user only on his/her/their specific request and any information obtained or materials downloaded from this website is completely at the user’s volition and any transmission, receipt or use of this site would not create any lawyer-client relationship.
* All material and information (except any statutory instruments or judicial precedents) on this website is the property of Upscale Legal, and no part thereof shall be used, with or without adaptation, without the express prior written consent of Upscale Legal