The Indian commercial legal landscape has undergone significant transformation over the past eighteen months. From a landmark Constitution Bench ruling on the scope of judicial intervention in arbitration to new regulatory frameworks governing data protection and corporate governance, practitioners and businesses alike must recalibrate their compliance and dispute-resolution strategies. This update examines the most consequential developments across three critical domains: arbitration, data protection, and corporate governance.
I. Arbitration: The Supreme Court Clarifies Its Power to Modify Awards
In April 2025, a five-judge Constitution Bench of the Supreme Court delivered its judgment in Gayatri Balasamy v. ISG Novasoft Technologies, addressing a long-standing ambiguity under Section 34 of the Arbitration and Conciliation Act, 1996. The central question was whether a court hearing a challenge to an arbitral award possesses the limited power to modify the award, or whether its jurisdiction is restricted strictly to setting aside the award in its entirety.
By a 4:1 majority, the Court held that courts do possess a limited power of modification under Section 34. The majority recognised that the restricted power of severing an award under the proviso to Section 34(2)(a)(iv) implies a corresponding power to vary or modify the award to the extent necessary to sever the invalid portion. The Court clarified that this power is distinct from appellate review and is confined to correcting "computational, clerical or typographical errors, as well as other manifest errors apparent on the face of the record." While modifications to pendente lite interest were disallowed, the Bench permitted changes to post-award interest.
Justice K.V. Viswanathan, in his dissent, maintained that Section 34 strictly permits only setting aside or remitting awards, and that any modification power would violate the UNCITRAL Model Law and the principle of minimal curial intervention.
Practical Implication
The judgment significantly alters the remedial landscape for award-debtors and award-creditors. Parties challenging awards under Section 34 may now seek selective modification rather than total annulment, potentially reducing the time and cost of re-arbitration. However, the narrow scope of the modification power means that parties cannot use Section 34 as a disguised appeal. Businesses should review their arbitration clauses to ensure they align with this clarified regime, particularly regarding interest and severability provisions.
II. Data Protection: RBI's Lifecycle Approach and the DPDP Regime
In April 2026, the Reserve Bank of India issued a comprehensive Advisory outlining a lifecycle approach for safeguarding customer data. While not introducing binding requirements per se, the Advisory consolidates observed industry practices into a structured framework intended to strengthen data protection controls across regulated entities.
The Advisory covers thirteen thematic areas, including governance and oversight mechanisms, data classification and consent management, third-party risk management, emerging technology risk management, and a cloud security framework.
Financial institutions and fintechs must treat this Advisory as a de facto compliance benchmark. The RBI's emphasis on board-level oversight, automated consent management, and AI governance means that data protection is no longer merely an IT function but a board-level governance priority.
The Digital Personal Data Protection Act, 2023 and Rules, 2025
The Digital Personal Data Protection Act, 2023 (DPDP Act), along with the Digital Personal Data Protection Rules, 2025, continues to reshape India's data governance framework. With a phased rollout continuing through 2027, the Act establishes a consent-centric regime where explicit, informed consent is required for most processing of personal data.
Key implications for commercial enterprises include purpose limitation and data minimisation, the classification of Significant Data Fiduciaries (SDFs), and expanded rights of Data Principals including access, correction, erasure, and grievance redressal.
III. Corporate Governance: Dematerialisation and the CCI-IBC Interplay
The Ministry of Corporate Affairs has mandated that all private companies (other than small companies) must dematerialise their securities effective 1 July 2025. This reform, while progressive in enhancing transparency and investor protection, has highlighted several procedural challenges, particularly for cross-border investors and legacy shareholders.
In a significant ruling in Independent Sugar Corporation Ltd. v. Girish Sriram Juneja (2025), the Supreme Court held that prior approval from the Competition Commission of India (CCI) is mandatory before a Resolution Plan involving a combination is put to vote by the Committee of Creditors (CoC) under the Insolvency and Bankruptcy Code, 2016.
Conclusion
The developments surveyed above reflect a broader trend: Indian commercial law is becoming more granular, more compliance-intensive, and more insistent on board-level accountability. Whether it is the calibrated expansion of judicial power in arbitration, the RBI's lifecycle approach to data protection, or the mandatory sequencing of CCI and CoC approvals in insolvency, businesses can no longer treat legal compliance as a post-facto exercise. Proactive legal strategy — embedded in governance structures, contractual frameworks, and operational workflows — is now essential.
The views expressed in this article are for informational purposes only and do not constitute legal advice. For specific guidance on how these developments affect your business, please contact the firm.