How to Check if Legal Software Is DPDP Act Compliant

Published on: July 23, 2026
Last updated: 21 July 2026

A practical checklist for law firms and in-house legal teams to check whether the case management, litigation tracking, or contract software they use actually supports compliance with India’s Digital Personal Data Protection Act.

How-To Guide · Data Protection

Legal software holds some of the most sensitive personal data an organisation touches: client names and addresses, case histories, employee records, contract terms, and sometimes financial details. When the Digital Personal Data Protection Act, 2023 (DPDP Act) applies to that data, the legal team using the software, not just the vendor, carries real responsibility for how it is handled. This guide sets out exactly what to check, step by step, before you trust any legal software with that data.

The short answer
  • Your firm carries the risk, not just the vendor: under the DPDP Act you are the data fiduciary even when a third-party tool holds the data.
  • Check seven things: data storage location, consent and purpose handling, security safeguards, breach notification, data principal rights support, retention rules, and the written contract.
  • Get it in writing: a sales pitch is not enforceable. A data processing agreement and a breach notification commitment are what actually protect your firm.
  • Legal data needs extra care: case files, client records, and contracts are especially sensitive, so vague answers from a vendor are a bigger risk here than in other software categories.

01Why this matters for legal teams

The DPDP Act, 2023, together with the Digital Personal Data Protection Rules, 2025, is now India’s operating data protection law, with enforcement dates rolling out through 2026 and full operational compliance expected by mid-2027. It applies to any organisation that digitally processes personal data of people in India, with no exemption for small firms or a minimum client count.

Your firm is the data fiduciary, even if the software is not yours

Under the Act, the organisation that decides why and how personal data is processed is the "data fiduciary". For a law firm or in-house legal team, that is you, not your case management vendor. If the software you use loses client data, mishandles consent, or cannot support a data principal’s request to access or correct their information, the legal and financial exposure lands on your organisation first.

Legal data is unusually sensitive

Case files often contain details about disputes, health records in personal injury or insurance matters, financial information in commercial disputes, and identity documents. A leak or misuse of this data does not just embarrass a firm; it can breach client confidentiality obligations that sit on top of DPDP obligations.

The penalties are large enough to matter

The Act allows penalties running into hundreds of crores of rupees for failures such as not taking reasonable security safeguards or not notifying a breach. Even if your firm never faces the maximum penalty, the reputational cost of a data breach involving client case files is severe in a profession built on confidentiality.

If your legal software cannot support a client’s right to access or correct their data, that gap becomes your firm’s problem, not the vendor’s.

02What "DPDP compliant software" actually means

Strictly speaking, the DPDP Act does not certify software as "compliant". It places obligations on data fiduciaries (you) and, where applicable, on data processors (a vendor that processes data on your behalf). So when people ask whether legal software is "DPDP compliant", what they really need to know is: does this software give my organisation what it needs to meet its own obligations?

That is a more useful question, and it breaks down into concrete, checkable items: where the data lives, how consent and purpose are handled, what security controls exist, how a breach would be detected and reported, whether the software can support requests from data principals (clients, employees, opposing parties whose data appears in case files), how long data is kept, and what the vendor actually commits to in writing.

The rest of this guide walks through each of these in the order you should check them. For background on how the Act applies specifically to legal software and legal data, see the DPDP Act for legal software.

03Step 1: Check where the data is stored

Ask the vendor directly where client and case data is hosted, and whether any of it is transferred outside India as part of normal operations, backups, or support.

What to ask

  • Which country or countries is the primary data centre in?
  • Are backups stored in the same jurisdiction, or elsewhere?
  • If support staff or sub-processors are outside India, what data can they access?

The Act permits cross-border transfer of personal data except to countries the Central Government restricts, so storage location alone does not make software non-compliant. But for a law firm, knowing exactly where sensitive case data physically sits, and getting that in writing, is a basic step you should not skip.

The DPDP Act requires that personal data be collected for a specific, lawful purpose and processed only for that purpose, generally with the data principal’s consent or under a recognised legal basis.

What to ask

  • Does the software let you record why a piece of personal data was collected, for example as part of a case file or a contract obligation?
  • Does it stop you (or make it obvious) when data is being used for something outside that original purpose, such as marketing?
  • If the software has its own consent-collection features, are the consent notices clear and in plain language, as the Act requires?

Most litigation and case management data is processed under legal obligations and the "legitimate use" grounds in the Act rather than fresh consent for every case, since it relates to court proceedings and legal representation. But contract management and client onboarding tools often do collect data directly, and that is where consent design matters most.

05Step 3: Check security safeguards

The Act requires data fiduciaries to take "reasonable security safeguards" to prevent a personal data breach. Because your vendor is processing the data on your behalf, you need to know what safeguards it actually has, not just take the word "secure" at face value.

What to ask

  • Encryption: is data encrypted both in transit and at rest?
  • Access controls: can you set role-based permissions, so a junior associate does not see every client’s files by default?
  • Audit logs: does the system record who accessed or changed a record, and when?
  • Independent audits or certifications: has the vendor had a third-party security audit, and can they share a summary or certificate?

A vendor that cannot answer these questions clearly, or answers only in marketing language without specifics, is a warning sign.

06Step 4: Check breach detection and notification

If a personal data breach happens, the Act requires the data fiduciary to notify both the Data Protection Board and the affected data principals. To do that on time, you need your software vendor to tell you about a breach quickly, not weeks later.

What to ask

  • Does the vendor commit, in writing, to notifying you within a specific time window if a breach affecting your data occurs?
  • Do they have a documented incident response process?
  • Will they support you with the information needed to notify the Data Protection Board, such as what data was affected and how many people it touches?

A vendor with no breach notification commitment at all leaves your firm unable to meet its own notification duties on time, which is itself a compliance gap.

07Step 5: Check support for data principal rights

The Act gives individuals rights over their own data, including the right to access what is held about them, correct or update it, and in some circumstances have it erased. For a legal team, "data principals" is a wide group: clients, employees whose HR data you hold, and sometimes opposing parties or witnesses named in case files.

What to ask

  • Can the software locate all records associated with one individual, across matters, without a manual search of every file?
  • Can records be corrected or updated without breaking links to related documents, filings, or case history?
  • Does the vendor have a documented process for you to request deletion or export of data, where the law allows it?

Legal records tied to ongoing or historical litigation are often exempt from deletion requests because they must be retained for legal proceedings, so this is less about deleting case files on demand and more about whether the software can even answer "what do we hold on this person" quickly if asked.

08Step 6: Check retention and deletion practices

Data should not be kept forever "just in case". The Act expects data to be retained only as long as necessary for the purpose it was collected for, subject to other legal retention requirements such as limitation periods and court rules.

What to ask

  • Does the software let you set retention rules by matter type, so closed, non-litigious files can be archived or purged on a schedule?
  • When a record is deleted, is it actually removed from backups within a reasonable time, or does it linger indefinitely?
  • Is there a way to flag records that must be retained longer for statutory or litigation-hold reasons, so they are not accidentally purged?

09Step 7: Check the contract, not just the pitch

A vendor’s website and sales pitch are not what protects you if something goes wrong. The written agreement is. Before signing up, or when renewing, read the data processing terms carefully, or ask for them if they are not offered upfront.

What to ask for

  • A data processing agreement, or equivalent clauses, that name the vendor as a processor acting on your instructions.
  • Disclosure of any sub-processors (cloud hosting, email delivery, analytics) the vendor uses, and what data they touch.
  • A clear breach notification commitment with a time frame.
  • Clarity on what happens to your data if you stop using the software, including export formats and deletion timelines.

If a vendor is reluctant to put any of this in writing, treat that as a bigger warning sign than any single missing feature. For a wider view of how legal teams should think about vendor selection under the Act, see using legal software as a DPDP compliance team.

10A quick compliance checklist

Use this as a working checklist during a vendor demo or renewal review.

AreaQuestion to askGood answer looks like
StorageWhere is data hosted, and where are backups?A clear, specific location, in writing
ConsentHow is purpose limitation handled for collected data?Purpose is recorded and enforced, not assumed
SecurityWhat encryption, access controls, and audit logs exist?Specific, named controls, not just "we are secure"
Breach responseHow and when will we be told about a breach?A written time commitment and process
Data principal rightsCan you locate and correct all records tied to one person quickly?Yes, across matters, without a manual file-by-file search
RetentionCan retention and deletion be set by matter type?Configurable rules, with holds for active litigation
ContractIs there a data processing agreement or equivalent?Yes, offered without being asked twice

This is not legal advice

This checklist is a practical starting point, not a substitute for advice from a data protection or compliance specialist on your specific obligations as a data fiduciary. Requirements can vary by the type and volume of data you handle.

11Red flags to watch for

A few patterns are worth treating as warning signs during evaluation.

  • Vague answers on data location. "It is in the cloud" is not an answer to "which country".
  • No written breach notification commitment. A verbal promise during a sales call is not enforceable.
  • No role-based access control. If every user can see every client’s files by default, that is a structural risk, not a minor gap.
  • Resistance to sharing a data processing agreement. A vendor serious about compliance will have one ready.
  • No clarity on data export or deletion at offboarding. You should know upfront what happens to years of case data if you switch tools later.

None of these alone should be a dealbreaker in every case, but several of them together suggest the vendor has not thought through data protection as seriously as a legal team needs.

12Where Claw fits

Claw is an all-in-one legaltech platform for Indian advocates, law firms, and corporate legal teams, combining AI-based case search, an AI legal assistant (Legal GPT), case management, and compliance automation across all Indian courts and tribunals. Compliance automation is one of its four core pillars, alongside case search, Legal GPT, and case management.

For a checklist like this one, the practical way to evaluate any vendor, including Claw, is to ask the questions in this guide directly: where is data hosted, what security controls exist, how are consent and purpose handled, what is the breach notification commitment, and what does the written agreement say. A serious legal software vendor should be able to answer all of these clearly and in writing rather than only in marketing language.

If you are comparing options, see best DPDP-compliant legal software in India for a wider roundup, and the DPDP Act for legal software for more on how the Act applies to this category. You can reach Claw at clawlaw.in or +91 9316164924 to ask these questions directly.

13Frequently asked questions

What does it mean for legal software to be "DPDP compliant"?

Strictly, the DPDP Act does not certify software as compliant. It places obligations on your organisation as the data fiduciary. "DPDP compliant software" really means software that gives your firm what it needs to meet those obligations: clear data storage location, security safeguards, breach notification, support for data principal rights, and a written data processing agreement.

Is my law firm responsible if the software vendor has a data breach?

Generally yes, in significant part. Under the DPDP Act, your firm is the data fiduciary that decided to use the software and hold the data. A vendor processing data on your behalf is a processor acting under your instructions, so a breach at the vendor typically still triggers your firm's own notification and remediation duties.

Do all legal software vendors have to provide a data processing agreement?

The Act does not mandate a specific document format, but a written agreement setting out how a vendor processes your data on your behalf is standard good practice and something a serious vendor should be able to provide. If a vendor resists sharing one, treat that as a warning sign during evaluation.

Can I delete a client's data from legal software if they ask?

Often not fully, because case files and legal records tied to litigation or statutory retention requirements are usually exempt from deletion on request. What matters more is whether the software can quickly locate and, where appropriate, correct or export the data tied to that person, and whether truly non-essential data can be purged on a schedule.

What is the difference between a data fiduciary and a data processor under the DPDP Act?

A data fiduciary decides why and how personal data is processed, which for a law firm or in-house legal team means you. A data processor processes data on the fiduciary's behalf and instructions, which is typically the role your software vendor plays. Both have obligations, but the fiduciary carries the primary compliance responsibility.

How often should I re-check a vendor's DPDP compliance posture?

At minimum, review it at contract renewal and whenever the vendor changes its infrastructure, sub-processors, or adds new features that touch personal data. Given that DPDP Rules and enforcement dates are still rolling out, it is worth a fresh check at least once a year even outside renewal cycles.

Related Articles

Understanding the Public Premises (Eviction of Unauthorised Occupants) Act, 1971: Supreme Court's Landmark Ruling on Overriding Rent Control Laws

This comprehensive blog examines the Public Premises (Eviction of Unauthorised Occupants) Act, 1971, in light of the Supreme Court's landmark judgment clarifying its overriding effect over State Rent Control legislations. The article explores the Act's provisions, the conflict between PP Act and Rent Control laws, the doctrine of stare decisis, and the practical implications for landlords, tenants, and public entities.

12/15/2025Read more →

Victim Blaming in Sexual Assault Cases: Delhi High Court's Landmark Stance Against Character Assassination

The Delhi High Court has delivered a significant judgment addressing the issue of victim blaming in sexual assault cases, emphasizing that prior familiarity or cordial relationships with the accused cannot justify sexual assault or be used to hold victims responsible. This blog analyzes the court's progressive stance and its implications for future sexual assault cases in India.

10/13/2025Read more →

What is the RTE Act in Education? Understanding the Supreme Court's Stance on Minority School Exemptions

This blog explores the Right to Education (RTE) Act in India, focusing on a recent Supreme Court case where the Court imposed Rs 1 lakh cost on a petitioner for challenging its 2014 judgment that exempted minority schools from RTE provisions. The article examines the RTE Act's framework, the constitutional protection of minority rights under Article 30(1), and the broader implications of judicial discipline and finality of judgments.

12/13/2025Read more →

Explore CLAW

The tools behind the guides

CLAW helps Indian advocates and firms manage cases, track courts and research the law.