Regulation
Most of your security obligations will arrive in a contract
Organisations plan for regulation and are surprised by contracts. For most technology and services firms, the binding obligations are commercial ones.
Facts checked — 2026-09-11
Where do most security obligations come from?
A security schedule in a master services agreement commits you to specific controls, notification windows, audit rights, sub-processor approval and sometimes certification by a date. These are enforceable, they are frequently signed by someone who did not check whether the commitments were achievable, and they rarely reach the security team before signature.
The practical defence is a review step: whoever signs commercial agreements sends the security schedule to whoever will have to deliver it, before signing. It takes an afternoon and prevents the standing problem of discovering, a year in, that you promised an annual penetration test nobody budgeted for.
The bottom line
Read the security schedule before you sign it. Most of what you will be audited against is in there, not in a statute.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.