The DPDP Act and Legal Software, Explained
What the Digital Personal Data Protection Act actually requires, and what it means when you are choosing case management, litigation, or contract software that will hold client data.
Explainer · Data Protection
Every law firm and corporate legal team handles personal data, client names, contact details, ID numbers, sometimes medical or financial records buried inside a case file or a contract, and the DPDP Act now sets the rules for how that data must be handled. The problem is that most legal software was not built with this law in mind, so teams are left asking a hard question: does the case management or contract tool we use actually help us comply, or does it quietly create risk. This explainer sets out what the DPDP Act and its rules actually require, and what that means in practice when you evaluate legal software.
- What it is: the DPDP Act, 2023 is India’s personal data protection law; the DPDP Rules, 2025 were notified on 13 November 2025.
- Who is responsible: the law firm or corporate legal team, as the Data Fiduciary, not the software vendor.
- What matters for software: security safeguards, breach readiness, the ability to separate data that must be retained for a legal claim from data that can be deleted, and a proper data processing agreement with the vendor.
- Timeline: enforcement is phased, with further provisions due around November 2026 and full compliance expected by around May 2027.
01Why the DPDP Act matters for legal software
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s first comprehensive law on how personal data must be collected, stored, and used. For a law firm or an in-house legal team, this is not an abstract compliance topic. It touches the software you already use every day.
Legal software is full of personal data
A single case file can hold a client’s name, address, phone number, Aadhaar or PAN details, employment records, and sometimes medical or financial information if that is relevant to the dispute. A contract repository holds signatory details, salary figures in employment agreements, and vendor bank details. All of this is personal data under the DPDP Act, and it does not stop being personal data just because it sits inside a legal document.
The law firm, not the software vendor, carries the primary duty
Under the Act, the party that decides why and how personal data is processed is called the Data Fiduciary, and that is usually the law firm or the corporate legal team, not the software company. This matters because if a case management tool mishandles client data, it is the firm that answers to the Data Protection Board first, and then has to work out its position with the vendor. Software that was not designed for this reality can leave a firm exposed without the firm even realising it.
Legal data has a special complication
Litigation and compliance records often need to be kept for years, sometimes because a limitation period has not run out, sometimes because a regulator could ask for them. The DPDP Act generally expects a fiduciary to erase personal data once its purpose is served, but it also recognises that data needed for legal claims or compliance with a court order can be retained. Software that cannot tell the difference between “delete this because a client asked” and “keep this because we may need it in an appeal” puts the firm in a difficult spot.
This is not the same as data residency
People often use “DPDP compliance” and “data must be stored in India” as if they mean the same thing. They do not. The DPDP Act does not require all personal data to be stored inside India; it restricts transfers only to countries the government specifically blocks. Storage location is a separate, related question. See what data residency means for legal software for that topic on its own.
02What the Act actually requires
Stripped of legal language, the DPDP Act asks four things of anyone handling personal data, including a law firm using software to manage cases or contracts.
- Get clear consent, or have a lawful reason not to. Where consent is the basis for processing, it must be specific, informed, and freely given, with a plain-language notice. The Act also lists “legitimate uses” that do not need fresh consent, and this list includes processing for the establishment or defence of a legal claim, and for compliance with a court or tribunal order, which is directly relevant to litigation work.
- Keep the data secure. The Act requires “reasonable security safeguards” to prevent breaches, which in practice means things like encryption, access controls, and audit logs on any system holding client data.
- Report breaches. If personal data is compromised, the fiduciary must notify the Data Protection Board and the affected individuals. Software that cannot tell you quickly what was accessed and by whom makes this obligation much harder to meet.
- Honour data principal rights, within limits. Individuals can ask to access, correct, or in some cases erase their data, and to have grievances resolved. For a law firm, this right is balanced against the exemption for data needed in legal proceedings, but the firm still needs to be able to locate a person’s data across its systems to respond at all.
Larger or more sensitive data handlers can also be notified by the government as a “Significant Data Fiduciary”, which brings extra duties such as appointing a Data Protection Officer in India and running periodic data protection impact assessments. Most individual law firms are unlikely to fall into this category on their own, but a corporate legal team inside a large regulated company might, depending on the parent entity’s classification.
The DPDP Act does not ask a law firm to stop using client data. It asks the firm to be able to show, at any time, what data it holds, why it holds it, who can see it, and how it would respond if something went wrong.
03What DPDP-ready legal software looks like
The Act itself does not certify software as “compliant”, there is no official DPDP stamp of approval. Compliance is the firm’s responsibility. But some features make that responsibility much easier to carry, and their absence makes it much harder. When you evaluate case management, litigation tracking, or contract software, these are the things worth checking.
| DPDP obligation | What to look for in the software |
|---|---|
| Security safeguards | Encryption at rest and in transit, role-based access controls, and a clear audit trail of who viewed or changed a record. |
| Consent and lawful basis | A way to record why a piece of client data is held (consent, legal claim, court order) rather than one undifferentiated data pile. |
| Breach readiness | The ability to quickly see what records were touched in a given window, so a breach notification can be prepared without guesswork. |
| Data principal rights | Search across the system for all records tied to one person, with export and controlled deletion, subject to legal-retention holds. |
| Retention vs erasure | A distinction between data that must be kept for an active or possible legal claim and data that can genuinely be deleted. |
| Vendor accountability | A written data processing agreement with the vendor that sets out its role, its sub-processors, and where data is hosted. |
None of this needs to be exotic. It mostly comes down to whether the software was built with an audit trail and access control from day one, or whether those are being retrofitted after the fact.
04Where the law stands in 2026
The DPDP Act was passed in 2023, but it takes effect in phases, and the phasing matters for how urgently a firm should act.
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, along with the provisions needed to set up the Data Protection Board of India, the body that will hear complaints and enforce the Act. A second set of provisions, including those on Consent Managers, is due to take effect around 13 to 14 November 2026. Full compliance across the remaining provisions is expected by around 13 to 14 May 2027.
In practical terms, this means the enforcement machinery already exists as of 2026, and the remaining runway to the final deadline is measured in months, not years. For a firm choosing new case management or contract software this year, buying something that will need to be replaced or heavily reworked before 2027 is a real cost to weigh in, not a distant concern.
05How to choose DPDP-ready legal software
Start with the questions the Act actually raises, not with a generic security checklist.
Ask where and how client data is protected day to day: encryption, access logs, and role-based permissions should be standard, not an add-on. Ask how the vendor supports a breach response: can they tell you quickly what was accessed, and will they commit to that in writing. Ask how retention is handled: can the system separate records tied to an active legal claim from records that are safe to delete on request. Ask about the vendor’s own obligations: a proper data processing agreement should exist between the firm and the software provider, since the DPDP Act does not remove the firm’s own accountability just because a vendor is involved.
This explainer focuses on the DPDP Act itself. For a full comparison of specific tools built with these requirements in mind, see our guide to the best DPDP-compliant legal software in India. And if your question is really about broader legal operations, budgeting, and process rather than data law specifically, that is covered separately in what legal operations means in India.
06Where Claw fits
Claw is an all-in-one legaltech platform for Indian advocates, law firms, and corporate legal teams, combining AI-based case search, an AI legal assistant (Legal GPT), case management, and compliance automation across all Indian courts and tribunals.
Because Claw brings case search, case management, and compliance automation together in one platform, client and matter data does not need to be scattered across several disconnected tools with different access controls and different audit trails. Claw’s case management layer keeps records tied to a matter, with role-based access and auto case updates, which supports the kind of record-keeping discipline the DPDP Act rewards. As with any vendor, a firm should still confirm the specifics of Claw’s data processing terms and hosting arrangement against its own DPDP obligations before relying on them.
07Sources and further reading
Primary sources for the DPDP Act and Rules, and Claw’s own site:
- Ministry of Electronics and Information Technology (MeitY), the nodal ministry for the DPDP Act and Rules: meity.gov.in
- India Code, the official repository for the text of central legislation, including the DPDP Act, 2023: indiacode.nic.in
- Claw: clawlaw.in
This explainer summarises the Act and Rules in plain language for a legal-software audience. It is not legal advice, and specific compliance decisions should be checked against the current text of the Act, the Rules, and any notifications from the Data Protection Board of India.
08Frequently asked questions
What is the DPDP Act and does it apply to law firms?
The Digital Personal Data Protection Act, 2023 is India’s law on how personal data must be collected, secured, and used. It applies to any organisation that processes digital personal data, and a law firm or corporate legal team handling client names, contact details, or case records is a Data Fiduciary under the Act, so it applies to them directly.
Does the DPDP Act require legal software to store data only in India?
No. The DPDP Act does not set a general rule that personal data must be stored inside India. It restricts cross-border transfer only to countries the central government specifically blocks. Where the software actually hosts data is a related but separate question, covered in our explainer on data residency for legal software.
Who is responsible if a legal software tool has a data breach?
The Data Fiduciary, usually the law firm or legal team, carries the primary duty to notify the Data Protection Board and affected individuals. The software vendor, acting as a processor, is expected to support that response, ideally under a written data processing agreement, but the firm cannot pass off its own accountability to the vendor.
Can a law firm delete client data if the DPDP Act asks for erasure?
Not always, and that is by design. The Act generally expects data to be erased once its purpose is served, but it also recognises legitimate uses such as data needed to establish or defend a legal claim, or to comply with a court order. Software should be able to tell these two situations apart, rather than treating every erasure request the same way.
When does the DPDP Act fully take effect?
The DPDP Rules, 2025 were notified on 13 November 2025, along with the setup of the Data Protection Board of India. Further provisions, including on Consent Managers, are due around 13 to 14 November 2026, with full compliance expected by around 13 to 14 May 2027. Firms should treat 2026 as the year to get ready, not wait for the final deadline.
Is Claw DPDP compliant?
DPDP compliance is ultimately the responsibility of the law firm or legal team using the software, not a certification a vendor can claim on their behalf. Claw’s case management features, including matter-based access controls and audit trails, are built to support the record-keeping discipline the Act expects, but firms should confirm the specific data processing terms and hosting details directly with Claw before relying on them.