Mansi Rana

Data Processing Agreement DPDP Act

Data Processing Agreements (DPA) under the DPDP Act: Clauses Every Contract Now Needs

A Data Processing Agreement is the only document that stops a vendor’s data-handling failure from becoming your organisation’s own legal liability under India’s Digital Personal Data Protection Act, 2023. Under Section 8(1) of the Act, the Data Fiduciary, the organisation determining the purpose and means of processing, remains continuously responsible for compliance in relation to processing carried out on its behalf, even when a third-party Data Processor is actually doing the processing. Section 8(2) goes further: a Data Fiduciary may engage a Data Processor for covered activities only under a valid contract. Without a proper DPA, the engagement itself is not compliant, regardless of how carefully the vendor otherwise handles the data. This guide covers what the DPDP Act and its 2025 Rules require in a Data Processing Agreement DPDP Act, the essential clauses every DPA needs, and the specific compliance deadlines enterprises should track. Where This Obligation Actually Comes From Section 8 of the Digital Personal Data Protection Act, 2023 contains the core provisions governing Data Fiduciaries and Data Processors. The distinction between the two roles matters considerably: the Act’s compliance obligations fall primarily on the Fiduciary, not the Processor, which is exactly why the Fiduciary needs a properly drafted DPA to ensure the Processor’s obligations are contractually locked in, rather than relying on the Processor’s own goodwill or general data-handling reputation. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, alongside the establishment of the Data Protection Board of India, providing the detailed operational requirements the Act itself left to subordinate rulemaking. Critically, the DPDP Act does not prescribe specific mandatory DPA clauses by name. Instead, the required content of a compliant DPA is derived by combining Section 8’s obligations, the DPDP Rules 2025 (particularly Rule 6 on security safeguards), and internationally established best practice for data processing contracts more broadly. One clarifying point worth noting: unlike the EU’s GDPR, which prescribes Standard Contractual Clauses for international data transfers, the DPDP Act leaves DPA drafting to the parties themselves, without a government-issued template clause set. This means the responsibility for getting the DPA’s substantive content right sits squarely with the drafting parties and their legal counsel, not with a government-supplied form that can simply be adopted wholesale. Does the DPA Need to Be a Standalone Document? No. The Act requires a “valid contract,” not necessarily a standalone Data Processing Agreement as a separate document. DPA-equivalent clauses can be incorporated directly into an existing service agreement or Master Service Agreement, provided the substantive requirements described below are genuinely addressed within that broader contract, rather than needing their own dedicated document in every case. Essential Clauses Every Data Processing Agreement DPDP Act Needs 1. Identity, roles, and scope of the parties Clearly establishes which party is the Data Fiduciary and which is the Data Processor (or Processors, where sub-processing is involved), and defines the scope and purpose of processing precisely, since the Processor’s use of personal information should be strictly limited to what the Fiduciary has actually authorised. 2. Categories of personal data and data principals Specifies precisely what categories of personal data are being processed and which categories of data principals (customers, employees, or other individuals) are involved, since this scoping directly determines the applicable security and compliance obligations that follow. 3. Purpose and duration of processing Defines exactly why the processing is happening and for how long, preventing the Processor’s use of the data from quietly expanding beyond the originally authorised purpose over the life of the relationship. 4. Security safeguards Establishes appropriate security obligations specifically, rather than relying on a generic confidentiality clause borrowed from an unrelated template. Rule 6 of the DPDP Rules, 2025 governs this area directly, and the DPA should reflect the specific technical and organisational security measures the Processor commits to maintaining. 5. Data subject rights assistance Requires the Processor to cooperate with and support the Fiduciary’s obligations to respond to data principal requests, such as access, correction, or erasure requests, since the Fiduciary remains ultimately responsible for fulfilling these rights even where the underlying data actually sits with the Processor. 6. Breach notification and incident response This is one of the most operationally critical clauses in any DPA. A well-drafted breach notification clause typically requires the Processor to notify the Fiduciary within 24 hours of becoming aware of a breach, giving the Fiduciary the remaining time within the Act’s 72-hour notification window to prepare and submit its own notification to the Data Protection Board. Unlike the EU’s GDPR, the DPDP Act sets no minimum severity threshold for breach reporting, meaning even comparatively minor breaches can trigger a notification obligation, which makes a tight, enforceable notification timeline in the DPA considerably more important than it might be under a threshold-based regime. The Processor’s incident response plan should also be provided to the Fiduciary, ideally reviewed and refreshed annually. 7. Restrictions on sub-processing Addresses whether and how the Processor can engage its own sub-processors, requiring the Fiduciary’s prior approval before any sub-processor is brought into the processing chain, and ensuring sub-processors are bound by data protection obligations that are at least as protective as those the primary Processor has accepted. 8. Data residency and cross-border transfer terms For sectors or organisations subject to data residency requirements, whether for regulatory reasons or simply as an internal risk-management decision, the DPA should specify explicitly that personal data is processed and stored within India, and that the Processor will not transfer, access, or permit access to that data from outside India without the Fiduciary’s prior written consent for a specific, defined transfer. Section 16 of the DPDP Act separately allows the Central Government to restrict processing outside India to specified countries or territories through notification, which the DPA should be drafted to accommodate as that list develops. A DPA that allows the Processor discretion over where data is backed up or processed, for redundancy or similar reasoning, without the Fiduciary’s specific, informed consent, is a significant red flag rather than a routine

Data Processing Agreements (DPA) under the DPDP Act: Clauses Every Contract Now Needs Read More »

POSH Act Compliance

POSH Act Compliance for Enterprises: ICC Setup & Annual Report Filing

A mid-size IT company had an Internal Complaints Committee on paper. Its Presiding Officer had left the organisation eight months earlier, and nobody had reconstituted the committee. When a complaint was filed, the entire inquiry was challenged on the basis of improper constitution, the proceedings were invalidated, and the employer received a show-cause notice from the District Officer. This is not an isolated case. Across India, many organisations have a POSH policy and an Internal Complaints Committee that exist only on paper, and as of 2025 to 2026, that gap has become a serious legal and compliance risk, not merely a procedural formality. The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 applies to every Indian workplace with 10 or more employees, and a significant regulatory change in 2025 has made POSH Act compliance a matter of direct board-level accountability, not just an HR function’s internal responsibility. This guide covers how enterprises should set up and maintain a compliant Internal Committee, the statutory timelines governing complaint handling, and the annual reporting obligations now extending into corporate board disclosures. What POSH ACT Compliance Requires: The Baseline POSH compliance applies to every Indian workplace with 10 or more employees, regardless of whether any women are currently on the organisation’s rolls. The core obligations span constitution of a compliant Internal Committee, a written POSH policy, mandatory training and sensitisation, defined complaint and inquiry procedures, and annual reporting, each with its own specific requirements. Internal Committee Constitution: Getting the Structure Right Under Section 4 of the POSH Act, every applicable workplace must constitute an Internal Committee, commonly abbreviated as ICC or IC, with a specific, mandatory composition. Minimum four members. The Committee must have at least four members in total. At least 50% women. At least half of the Committee’s members must be women, and the Presiding Officer specifically must be a woman employed at a senior level within the organisation. One external member. The Committee must include at least one external member from an NGO or an organisation committed to the cause of women, or someone with relevant legal or social work background, brought in specifically to bring independence and expertise the internal members may not have. A maximum three-year term. Committee members serve fixed terms, and the Committee needs to be actively reconstituted before that term expires, not allowed to continue informally past its legal tenure. The consequence of getting this structure wrong, or allowing it to lapse without reconstitution, is not a minor technicality. As the mid-size IT company example illustrates, an improperly constituted Committee, including one where a key member such as the Presiding Officer has departed without replacement, can result in an entire inquiry being challenged and invalidated after the fact, precisely when the organisation most needs the process to hold up under scrutiny. The Statutory Inquiry Timeline Once a complaint is received, the POSH Act imposes a strict, defined sequence of timelines that the Internal Committee must follow. 7 days to send the complaint to the respondent after it is received. 90 days to complete the inquiry from the date the complaint was filed. 10 days after the inquiry concludes to issue the Committee’s report. 60 days for the employer to act on the Committee’s recommendations once the report is issued. Where a complainant has a legitimate reason for delay in filing, the Internal Committee can condone that delay by up to three months under the current framework, though this discretion should be exercised and documented carefully rather than applied informally. Confidentiality obligations under Section 16 of the Act apply throughout this entire process. Leaks of complaint details, the identity of parties involved, or inquiry proceedings can themselves trigger penalties and can derail the fairness of the process, which is why maintaining strict, documented confidentiality controls around every stage of a live inquiry is as important as meeting the procedural timelines themselves. Annual Report Filing: What Changed and What Is Required Under Section 21 of the POSH Act, every Internal Committee must submit an annual report to the employer and to the District Officer, typically the District Magistrate for the relevant jurisdiction, detailing the complaints received, resolved, and pending during the year, along with the actions taken. Timing. The annual report covers the calendar year from 1 January to 31 December, and organisations are generally expected to file before 31 January of the following year, since the report summarises the Internal Committee’s activity for the calendar year just completed. Filing method. Two routes are typically available: hand-delivering one signed original to the District Officer and obtaining a stamped duplicate as proof of submission, or sending it via Registered Post with Acknowledgment Due. The postal receipt or stamped duplicate should be retained indefinitely, since it is generally the organisation’s only concrete proof of timely filing if that filing is ever questioned later. While the government’s SheBox portal is being progressively upgraded for digital filing in specific states, hard-copy or registered post submission remains the more reliable route in most districts as of the current filing cycle. The 2025 Change That Makes This a Board-Level Issue In May 2025, the Ministry of Corporate Affairs notified the Companies (Accounts) Second Amendment Rules, 2025, effective from 14 July 2025, fundamentally expanding who must formally disclose POSH compliance and where that disclosure sits. Previously, detailed POSH disclosure within the Board’s Report under Rule 8(5)(x) applied mainly to listed companies or larger companies specifically, leaving many unlisted companies and MSME entities effectively outside formal, mandatory board-level reporting. Under the amended rules, every company other than One Person Companies and Small Companies must now disclose, within its Board’s Report (submitted via the revised e-Form AOC-4), the number of sexual harassment complaints received, disposed of, and pending beyond 90 days, along with an explicit confirmation that a compliant Internal Committee has actually been constituted. The practical effect of this change is significant: this is the same underlying data as the Internal Committee’s Annual Report, but it now also lives inside a

POSH Act Compliance for Enterprises: ICC Setup & Annual Report Filing Read More »

how to draft an NDA in India

How to Draft an NDA in India: Key Clauses, Carve-outs and Enforceability

Pretty much every meaningful business conversation in India eventually runs into a Non-Disclosure Agreement. Founders share product roadmaps with investors. Employers hand financials to senior hires. Vendors exchange source code. Acquirers comb through target company books during diligence. In each of these moments, an NDA is what turns a verbal promise of secrecy into something a court can actually enforce. Legally, the NDA sits inside the Indian Contract Act, 1872, and drafted properly, it converts confidentiality from a handshake into a binding legal obligation. Drafted poorly, and it is simply a document that will not survive the first real dispute. This guide covers how to draft an NDA in India, including essential clauses, enforceability carve-outs, and how Indian courts assess these agreements when challenged. The Legal Basis for NDA Enforceability in India NDAs do not have a distinct, dedicated statute of their own in India and do not require any special government registration to be effective. An NDA’s enforceability flows from the general principles of contract law under the Indian Contract Act, 1872: to be valid, it must have a lawful object, must be supported by lawful consideration, and must be entered into with the free consent of the parties, consistent with Section 10 of the Act. Indian courts have consistently sustained confidentiality obligations under this general contract law framework, but they examine NDAs closely, looking specifically for provisions that are equivocal, inequitable, or that function as a disguised restraint of trade rather than a genuine confidentiality obligation. Generic NDA templates pulled from the internet rarely survive a genuinely contested dispute, precisely because courts review every concrete element: the underlying facts of the business relationship, each individual provision, and, where relevant, whether the document itself was properly stamped. The Clauses Every Defensible NDA Needs A precise, non-vague definition of confidential information “Everything discussed in this meeting is confidential” sounds protective but is actually weak, because it gives a court very little concrete substance to work with when deciding what was actually supposed to be protected if a dispute arises later. An effective NDA specifies categories of information with enough precision that a court can determine, on the facts, whether a specific piece of disclosed information genuinely falls within the definition: trade secrets, financial data, business strategy documents, client and customer lists, and proprietary source code are commonly named categories rather than left to a single, sweeping, undifferentiated phrase. Clear identification of the parties and their roles The agreement should specify who the disclosing party and receiving party are, and where the NDA is mutual (both sides may share confidential information) rather than unilateral (only one side is disclosing), the drafting needs to reflect that structure accurately throughout, rather than using one-directional language in a document intended to bind both parties equally. The duration of the confidentiality obligation An NDA needs to state clearly how long the confidentiality obligation lasts, both during the underlying business relationship and, critically, for how long after that relationship ends. Unreasonable durations, whether unreasonably short (undermining the protection’s practical value) or unreasonably long and indefinite (inviting judicial scrutiny as an unfair restraint), are among the most common drafting failures Indian legal practitioners report seeing across hundreds of reviewed NDAs, alongside vague definitions and missing standard boilerplate. Reasonable steps and treatment as secret Courts examining an NDA increasingly look for language demonstrating that the disclosing party actually treated the information as secret and took genuine, active steps to protect it. A confidentiality clause that simply labels information as “confidential” without describing any protective measures is generally insufficient on its own; the “reasonable steps” standard is best satisfied through a combination of well-drafted contractual language, actual physical and electronic access controls around the information, and consistent labelling or marking procedures applied in practice, not merely promised on paper. Exclusions and carve-outs from the definition of confidential information This is a clause first-time drafters frequently skip, and doing so is a genuine risk to enforceability, not merely an oversight. Standard exclusions typically carve out information that was already known to the receiving party before disclosure, becomes public through no fault of the receiving party, is independently developed by the receiving party without reference to the disclosed confidential information, and is received lawfully from a third party who owed no duty of confidentiality to the original discloser. Including these specific exclusions, tailored to the actual relationship, reduces the risk of overclaiming, and an NDA that overclaims by treating genuinely non-confidential information as protected tends to weaken the enforceability of the core obligation as a whole, since a court may view the entire definition as unreasonably broad. Permitted disclosure and consequences of breach The agreement should specify any circumstances under which disclosure is permitted despite the general confidentiality obligation, such as disclosure required by law or a court order, and should clearly set out the consequences of breach, whether through a specified remedy, a right to injunctive relief, or a liquidated damages provision, so both parties understand what happens if the obligation is violated. IP assignment where the relationship involves creating new work Where the NDA governs a relationship involving development work, such as engaging a freelance developer or a vendor building custom code, a clear IP assignment clause matters as much as the confidentiality clause itself. If the receiving party develops something, a code module, a design, a process, using the disclosing party’s trade secrets or confidential information as a foundation, that new work should be explicitly assigned to the disclosing party rather than left ambiguous, since confidentiality alone does not automatically resolve ownership of derivative work product. Jurisdiction and governing law The jurisdiction clause should name an Indian court with genuine, practical jurisdiction over the parties and the relationship. Naming a foreign court as the governing jurisdiction forces an additional, often costly enforcement step within India if the NDA is ever breached and needs to be enforced against an Indian party, since a foreign judgment typically requires its own separate recognition and enforcement process under Indian law. The

How to Draft an NDA in India: Key Clauses, Carve-outs and Enforceability Read More »

respond to a legal notice India

How to Respond to a Legal Notice in India: A Guide for Businesses

Receiving a legal notice can feel alarming, but it is important to understand what it actually is: a formal written communication, typically drafted by an advocate on a client’s behalf, informing the recipient of a grievance, demand, or intended legal action, and giving them an opportunity to respond or resolve the matter before formal litigation begins. A legal notice is not itself a lawsuit. It is frequently a required or strategic precursor to one, and how a business responds to it, or fails to respond, can significantly shape whether the matter escalates to court or resolves without litigation entirely. This guide covers the general framework for how businesses in India should read, assess, and respond to a legal notice, including how to respond to a legal notice India across different contexts. What a Legal Notice Actually Is A legal notice serves several distinct purposes depending on the context. It puts the recipient formally on notice of a grievance or claim, satisfying a legal requirement in specific proceedings, such as the mandatory demand notice under Section 138 of the Negotiable Instruments Act for cheque dishonour matters, or a notice under Section 80 of the Code of Civil Procedure before suing certain government bodies. It creates a documented record that the sender attempted to resolve the matter amicably before resorting to litigation, which can matter later for costs and conduct assessments in court. And in many cases, it genuinely offers a real opportunity to resolve the underlying dispute without the time, cost, and reputational exposure of formal proceedings. Legal notices vary enormously in their subject matter: contractual disputes over non-payment or non-performance, employment-related grievances, intellectual property infringement claims, defamation, recovery of dues, tenancy disputes, and regulatory or statutory notices from government authorities, among many others. The correct response strategy depends heavily on which of these categories the notice falls into. How to Respond to a Legal Notice India Step 1: Do Not Ignore It, and Do Not Panic The two most common, and most damaging, initial reactions to a legal notice are ignoring it entirely and reacting with immediate, unconsidered defensiveness. Neither serves the business well. Ignoring a legal notice does not make the underlying issue disappear. In many contexts, particularly statutory notices with fixed response windows, failing to respond within the specified time can result in the matter proceeding to litigation without the benefit of the recipient’s position being considered, or in some cases can itself have direct legal consequences, such as an adverse inference being drawn by a court later, or the loss of a specific statutory right that required a timely response to preserve. At the same time, panicking and responding immediately without proper assessment, whether by making an unconsidered admission, an emotionally charged denial, or a hasty payment, can create its own problems, particularly if the response is not carefully drafted and ends up conceding more than the situation actually warrants. Step 2: Read the Notice Carefully and Identify the Core Elements Before drafting any response, extract the essential information from the notice itself. Who sent it, and on what authority. Identify the sender, the advocate or law firm representing them, and confirm the notice is genuinely from a properly authorised source rather than an informal or potentially fraudulent communication. What is being claimed or demanded. Identify the specific factual allegations, the legal basis being relied upon, and the exact relief or remedy being sought, whether that is payment of a specific sum, cessation of a particular activity, or some other specific action. What deadline applies. Many legal notices specify a response window, commonly ranging from a few days to 30 days depending on the nature of the claim and any applicable statutory requirement. Where the notice relates to a specific statutory procedure, such as a Section 138 cheque bounce notice (15 days to pay) or certain regulatory notices, the deadline may be fixed by law rather than by the sender’s discretion, and missing it can have specific, serious legal consequences beyond simply appearing unresponsive. Whether it references a specific legal provision or procedural requirement. Notices that cite a specific section of a specific statute are typically triggering a formal legal process with its own defined rules, and understanding which process is being invoked shapes the entire response strategy. Step 3: Assess the Merits and the Business’s Actual Position Before drafting a response, determine, with the input of legal counsel where the matter is genuinely significant, whether the claim has merit, whether it is entirely without basis, or whether the truth sits somewhere in between, with a partial claim that may be valid and a partial claim that is not. This assessment should draw on the organisation’s own records: the underlying contract or agreement, correspondence and communications relevant to the dispute, any relevant internal documentation, and, where applicable, prior communications between the parties on the same subject matter. A response drafted without this groundwork risks either conceding points that did not need to be conceded, or denying facts that documented evidence clearly contradicts, either of which weakens the organisation’s position if the matter does proceed further. Step 4: Decide on the Right Response Strategy Depending on the assessment, several response strategies are available, and the right choice depends on the specific facts and the organisation’s actual objectives. Comply or settle, where the claim is genuinely valid. Where the underlying claim has merit, and the amount or remedy sought is reasonable, resolving the matter directly, whether through payment, corrective action, or a negotiated settlement, is often the fastest and most cost-effective path, avoiding the time and expense of formal proceedings over a matter that would likely be resolved against the organisation eventually in any case. Deny and rebut, where the claim lacks merit. A well-drafted reply setting out the specific factual and legal basis for disputing the claim, supported by relevant documentation, puts the sender on notice that the matter will be genuinely contested if it proceeds, which can itself discourage weak or opportunistic claims from advancing to

How to Respond to a Legal Notice in India: A Guide for Businesses Read More »

trademark examination report reply

How to Reply to a Trademark Examination Report / Objection in India

Once a trademark application is filed in India and the formalities are found in order, the Trade Marks Registry examines it and either raises no objection or issues an Examination Report. Seeing “Objected” against a trademark application understandably concerns many applicants, but an Examination Report is a routine procedural step, not a rejection. It means the examiner has specific concerns that need clarification before a decision is made on whether the mark can proceed toward registration. What makes this stage genuinely critical is the timeline: the law allows only 30 days from the date of the trademark examination report reply, with no extensions and no second chances in the ordinary course. What an Examination Report Actually Is An Examination Report is the Registry’s formal communication of objections or questions raised during the examination of a trademark application, governed by the Trade Marks Act, 1999 and administered by the Controller General of Patents, Designs and Trade Marks (CGPDTM). It does not mean the trademark has been rejected; it means the examiner is saying, in effect, “we have concerns, please explain or clarify why this trademark should be allowed to proceed.” Objections raised in an Examination Report generally fall into two broad categories. Procedural or formal objections relate to errors and omissions in the filing itself: a missing Power of Attorney, goods or services that do not correctly fall within the class applied for, or defects in the specification of goods or services. Substantive objections relate to the trademark’s actual registrability, most commonly raised under two sections of the Trade Marks Act. The Two Main Grounds for Substantive Objection Section 9 objections relate to the mark’s inherent distinctiveness. A mark may be objected to if it is considered too generic, merely descriptive of the goods or services it covers, or lacking the distinctive character needed to function as a trademark, distinguishing one trader’s goods or services from another’s. Section 11 objections relate to conflicts with existing marks. This is one of the most common reasons applications are objected to: the applied-for mark is considered too similar, in appearance or sound, to an already registered or pending trademark, creating a likelihood of confusion. Even small spelling or phonetic differences can trigger this objection; two marks that sound nearly identical when spoken aloud can be treated as conflicting even if spelled differently. The Strict 30-Day Timeline Under Rule 33(4) of the Trade Marks Rules, 2017, an applicant has one month, generally interpreted as 30 days, from receipt of the Examination Report to file a response. The registry does not send reminders. If no response is filed within the prescribed period, the Registrar may treat the application as abandoned under Section 132 of the Act, and the application effectively ceases to exist, along with whatever brand-building and filing investment was already made against it. A limited extension is available in some circumstances: applicants can request an extension of up to one month by filing Form TM-56, but this should not be relied upon as a routine buffer, since it requires a specific application and is not automatically granted. A specific timing trap worth noting: where the report is served by email, Rule 18(2) deems service at the time of sending, not at the time the applicant actually reads it. Applicants who monitor only physical post, or who do not check the email address on file regularly, risk miscalculating the 30-day window and missing the deadline without realising it had already started running. Step-by-Step: trademark examination report reply Step 1: Identify the exact grounds of objection and the deadline Read the report carefully to identify which sections the objections fall under, whether Section 9 (distinctiveness), Section 11 (conflicting marks, and if so which specific cited marks), or a procedural defect. Note the exact date of the report and calculate the 30-day deadline precisely, accounting for the deemed-service rule if the report was served electronically. Step 2: Gather supporting evidence appropriate to the specific objection For a Section 11 objection citing prior marks, this may include evidence distinguishing the applicant’s mark from the cited marks in terms of goods, services, or actual market usage, or letters of consent or coexistence agreements from the owners of the cited prior marks where such an arrangement can be reached. For a Section 9 distinctiveness objection, evidence supporting acquired distinctiveness is critical, including proof of extensive prior use, sales figures, advertising expenditure, and market recognition. Note that the Section 9(1) proviso specifically requires distinctiveness to have been acquired before the application date; relying only on use of the mark after the application was filed does not satisfy this requirement. Other supporting evidence commonly used includes copies of trademark registrations for the same mark in other countries, to demonstrate international reputation, and third-party dictionary definitions, articles, or references supporting the mark’s inherent distinctiveness. Step 3: Draft the reply addressing each ground specifically An effective reply does not simply assert that the objection is wrong; it addresses each specific ground raised with a reasoned, evidence-backed explanation. Where a Section 11 objection cites a prior mark, the reply should specifically explain why confusion is unlikely, whether due to differences in the marks themselves, differences in the goods or services covered, or differences in the target consumer base and trade channels. Step 4: File the reply through the correct channel with proper authorisation The reply is filed on the IP India online portal (ipindia.gov.in), and where the application is being handled by a trademark agent or attorney rather than the applicant directly, a Power of Attorney authorising that representative to file the reply needs to be in place and submitted correctly alongside the response. Step 5: Prepare for a show cause hearing if one is scheduled If the examiner is not satisfied with the written reply alone, the matter may proceed to a show cause hearing, where the applicant or their representative has the opportunity to make oral submissions directly addressing the examiner’s remaining concerns. Preparing for this hearing with the same rigour as

How to Reply to a Trademark Examination Report / Objection in India Read More »

MOA Party A Party B Memorandum of Agreement

Memorandum of Agreement (MOA): Definition, Purpose, and Sample

A Memorandum of Agreement (MOA) is a legally binding and enforceable type of contract between two or more parties. When parties sign an MOA, it constitutes a formal understanding of exactly what each party can expect from the other, with agreed objectives and a defined allocation of risk between them. Unlike its more casual cousin, the Memorandum of Understanding (MOU), an MOA goes further in detailing the specific terms each party is genuinely agreeing to, and is enforceable under contract law if a party fails to meet its obligations.

Memorandum of Agreement (MOA): Definition, Purpose, and Sample Read More »

procurement contracts

Procurement Contracts: Definition, Types, and Best Practices

A procurement contract is a legally binding agreement between a buying organisation and a supplier that governs the price, scope, delivery, performance, and risk allocation of a sourcing engagement. It goes well beyond what a basic purchase order provides, offering a more comprehensive, protective framework that establishes clear terms for both parties: vendor selection, product or service requirements, payment terms, delivery expectations, performance obligations, and the process for resolving disputes if they arise.

Procurement Contracts: Definition, Types, and Best Practices Read More »

Software License Agreement

Software License Agreement: Definition and Key Clauses

A software license agreement is a legally binding contract between a software creator or owner (the licensor) and the party granted permission to use it (the licensee), setting out the terms under which the software may be used, distributed, and modified, without transferring ownership of the underlying software itself. Software license agreements grant usage rights, not ownership: the licensor retains the intellectual property in the software, and the licensee receives a defined, bounded right to use it. For enterprise legal teams, software license agreements are among the highest-volume and most consequential contract categories to manage, since they directly determine cost, compliance exposure, and operational flexibility across every software tool the organisation depends on. What a Software License Agreement Covers A software license agreement defines how, when, and by whom a piece of software can be used. Usage limits, renewal structures, support terms, and specific restrictions all shape how an organisation can actually deploy and scale that software over time, which is why the terms of the agreement matter well beyond the point of initial signature. Most software license agreements, whether for a simple mobile app or a complex enterprise platform, share a common underlying structure, even though the specific terms vary considerably by software type and licensing model. Identification of the parties. Clearly names the licensor, the software owner, and the licensee, the user or entity being granted the license. Definitions. Clarifies key terms used consistently throughout the agreement, reducing the risk of ambiguity in how central concepts like “authorised users” or “permitted use” are interpreted later. Grant of license. This is the core of the agreement: it specifies exactly what the licensee is permitted to do, use the software on a defined number of devices, for a specific purpose, within a certain geographic area, and whether the license is exclusive or non-exclusive, transferable or non-transferable, revocable or irrevocable. Term of the license. States how long the license remains valid, whether perpetual (a one-time grant with no defined end date) or tied to a subscription period requiring ongoing renewal. License fees and payment terms. Outlines the cost structure, payment schedule, and any applicable taxes associated with the license. Restrictions on use. Details what the licensee is explicitly prohibited from doing, commonly including copying beyond what is licensed, reverse engineering the software, or reselling or sublicensing it without authorisation. Key Clauses That Determine Risk Exposure While the overall structure above is relatively consistent, a small number of specific clauses do most of the work in determining how much risk each party is actually carrying under the agreement. Grant of license (scope). Beyond simply existing, the scope clause needs to specify access rights precisely: on-premises deployment, installation on designated devices, or access via remote servers, since ambiguity here is one of the most common sources of later licensing compliance disputes. Intellectual property rights. Asserts the licensor’s ownership of the software itself and any associated IP, and, where the licensee’s own data or systems interact with the software, should separately confirm that the licensee retains ownership of their own data and IP, with clear limits on how and when the licensor can use it. Fees and payment terms. Beyond the headline pricing, this should address what happens with usage-based or metered pricing models, renewal pricing structures, and any conditions under which fees can be revised during the term. Liability limitations. Caps the licensor’s financial exposure for claims arising from use of the software, typically excluding indirect or consequential damages, and is one of the most heavily negotiated clauses in enterprise software agreements specifically. Indemnification. Addresses how financial risks and liabilities are shared between the parties. Commonly, the software developer agrees to compensate the licensee for losses, damages, or legal claims arising from specific issues, such as a claim that the software infringes a third party’s intellectual property rights. Termination conditions. Specifies the circumstances under which either party can end the agreement, what happens to the licensee’s access and data upon termination, and any notice periods required. Confidentiality. Protects proprietary information shared between the parties during the relationship, relevant both to the licensor’s underlying technology and to any sensitive business information the licensee shares in the course of using the software. Support and maintenance. Defines what ongoing support the licensor provides: how long support services last (for the duration of the license term, or for a separately defined period), the specific types of support offered (bug fixes, updates, troubleshooting), and response time commitments for resolving technical issues. Assignment and transfer. Governs whether either party can assign their rights under the agreement to a third party, for example if the software developer is acquired or restructures, and what approval or restrictions apply to such a transfer. Types of Software Licenses Different license models create meaningfully different legal and commercial obligations, and choosing the right structure depends on the nature of the software and how it will be deployed. Proprietary licenses grant the licensee the right to use the software under terms fully controlled by the licensor, with the source code and underlying technology remaining closed and protected. Open-source licenses allow a party to use, and often modify and redistribute, another party’s code within their own applications, subject to the specific terms of the open-source license involved. Common open-source license types, including Apache, MIT, and GPL, differ significantly in the distribution rights and obligations they impose, and organisations incorporating open-source components need to understand these differences to avoid inadvertent compliance issues. Subscription-based (SaaS) licenses grant access to software hosted and maintained by the provider, typically on an ongoing payment basis, with access contingent on continuous compliance with the subscription terms rather than a one-time grant. Perpetual licenses grant a one-time right to use a specific version of the software indefinitely, usually for a single upfront fee, though ongoing support and updates are often priced and licensed separately. OEM licenses refer to licenses that a manufacturer installs on new devices at the point of manufacture. These are typically non-transferable to a different installation, with limited exceptions

Software License Agreement: Definition and Key Clauses Read More »

Clickwrap Agreement

What Is a Clickwrap Agreement? Definition, Enforceability and Examples

A clickwrap agreement is a digital contract that requires a user to actively confirm their consent, typically by clicking a button such as “I Agree” or “Accept,” or checking a box, before they can access a service, complete a transaction, or create an account. Unlike passive agreement methods, clickwrap ensures that the user clearly and demonstrably acknowledges the terms before proceeding, which is precisely what makes it one of the most consistently enforceable forms of online contract in courts today.

What Is a Clickwrap Agreement? Definition, Enforceability and Examples Read More »

Ratified Contract

What Is a Ratified Contract? Definition, Process and Legal Effect

A ratified contract is an agreement that has been formally confirmed or approved by the parties involved, making it legally binding and enforceable. Ratification is the act of demonstrating clear, voluntary intent to be bound by an agreement, and it plays a specific and important role in two distinct contexts: confirming that both sides have finally agreed to every term of a negotiated contract, and separately, retroactively validating an act or agreement that was entered into without proper authority in the first place.

What Is a Ratified Contract? Definition, Process and Legal Effect Read More »

What Is an RFQ

What Is an RFQ? Definition, Process and When to Use One

An RFQ, or Request for Quotation, is a formal procurement document used by a company or public entity to invite suppliers to submit price quotes for a clearly defined product or service. It is one of the most common tools in procurement, used specifically when the requirements are already well understood and standardised, and the primary factor in the buying decision is price and commercial terms rather than a novel or complex solution.

What Is an RFQ? Definition, Process and When to Use One Read More »

Contract Playbook

What Is a Contract Playbook? Definition, Components and How to Build One

A contract playbook is a standardised set of legal and business guidelines used to review, draft, and negotiate contracts consistently across an organisation. It typically includes approved language, fallback clauses, risk thresholds, and approval routes, giving reviewers clear rules, fallback wording, and defined next steps rather than requiring every contract to be reviewed from scratch by an experienced lawyer.

What Is a Contract Playbook? Definition, Components and How to Build One Read More »