Chandhiok & Mahajan has appointed Deepak Singh as a partner to lead a new Technology, Digital and AI practice. Singh joins from Google, where he served as senior counsel, and the practice launches staffed at nine lawyers rather than growing into that headcount over time. The appointment was announced in mid-July 2026 and reported by Bar & Bench and Law.asia, and set out in the firm's own statement published through Legal 500.
Read as a personnel announcement, it is one more lateral move in a busy year. Read against the statute book, it is something more useful to anyone building a legal career: a firm placing a dated bet, and telling you in advance which skills it intends to buy.
The part the announcement does not say out loud
Law firms do not staff nine lawyers into a brand new practice on a hunch. They do it when they can see demand arriving on a calendar. In India, that calendar is unusually legible, because the obligations are already notified.
India's Digital Personal Data Protection Act was enacted in 2023, but it sat largely dormant until the Digital Personal Data Protection Rules were notified in November 2025. The Rules did not switch the regime on all at once. They set a phased commencement across roughly eighteen months.
| Date | What comes into force |
|---|---|
| 14 November 2025 | Commencement provisions. The Data Protection Board of India is established. |
| 14 November 2026 | Registration of consent managers, and the Board's power to inquire into breaches and impose penalties. |
| 14 May 2027 | The substantive load: notice and consent, security safeguards, breach reporting, children's data, Significant Data Fiduciary obligations, and cross-border transfer restrictions. |
Two further pieces landed in early 2026. In February, the Ministry of Electronics and Information Technology notified amendments to the Intermediary Guidelines and Digital Media Ethics Code Rules, bringing synthetically generated information, meaning AI-generated text, images, audio and video, inside the due diligence obligations that platforms owe. Days later, the government published the India AI Governance Guidelines, which set out principles for safe and trusted AI rather than a standalone AI statute. India's chosen approach is to extend existing law to AI systems instead of legislating a single new act.
The demand curve for this work is not a forecast. It is a commencement schedule. A firm hiring in July 2026 for obligations that bite in November 2026 and May 2027 is not being visionary, it is being punctual.
Set the two together and the shape of the hire becomes obvious. Between now and mid-2027, a large population of Indian and India-facing companies has to build consent infrastructure, appoint data protection officers, run impact assessments, document cross-border transfers, and answer for AI-generated content on their platforms. Penalties under the Act run high, with reporting placing the ceiling for major security failures at INR 250 crore, on the order of USD 26 million. That is the client demand a nine-lawyer practice is being built to absorb.
The career path underneath the headline
Singh's route is worth reading closely, because it inverts the assumption many students hold about how seniority in technology law is earned.
- Started in private practice. He began at K Ashar & Co in Mumbai, acting for banks and technology companies.
- Moved in-house early. Legal counsel at Yahoo! India, then head of litigation at eBay India.
- Went deep at one company. Roughly a decade at Google, covering product counselling, digital regulation, strategic litigation, public policy, data governance and regulatory compliance.
- Returned to a firm as a practice head. Two decades of in-house exposure became the qualification, not a detour from partnership.
He graduated from Government Law College, Mumbai, in 2002. There is no offshore LLM in that sequence and no unbroken firm track. The asset he is being hired for is having sat on the client side of technology regulation while it was being written.
This matters for anyone weighing an in-house move against staying in a firm. In technology and data practice specifically, the traditional penalty for leaving private practice has weakened. Firms building regulatory practices need people who have operated a compliance programme, not only advised on one.
What a nine-lawyer practice actually hires
A practice with this scope does not fill nine seats with partners. Based on the stated remit, which spans AI governance, digital platforms, online safety, content regulation, data access and portability, privacy and cybersecurity, data centres and digital infrastructure, the work divides roughly as follows.
- Regulatory advisory. Mapping DPDP obligations onto a client's actual data flows. Heavy drafting: notices, consent language, retention schedules, processor agreements.
- Product counselling. Sitting with engineering and product teams before launch. The skill is translating a feature into a regulatory exposure, and doing it fast enough that it is not ignored.
- Content and platform regulation. Intermediary obligations, takedown processes, and the new synthetic-content due diligence rules.
- Data centre and infrastructure work. Contracting, localisation and cross-border transfer structuring, which overlaps with project finance and real estate.
- Disputes and investigations. Board inquiries, breach response, and regulatory correspondence once enforcement powers activate.
What these teams screen for
Technology practices tend to hire against a different profile than general corporate teams. From the way these roles are scoped, four things carry disproportionate weight.
- Demonstrated technical literacy. Not coding ability, but the capacity to read a data flow diagram, understand what a processor actually does, and ask a useful question about a model's training data.
- Regulatory reading stamina. This is a field where the operative text changes several times a year. The valuable associate is the one who has read the Rules, not the summary of the Rules.
- Writing for non-lawyers. Product counselling fails when the advice is unreadable to the team receiving it.
- Sector proximity. Internships or first roles at technology companies, fintechs or platform businesses now compete credibly with pure firm pedigree.
Where to find this work
This is not a single-firm trend, and the roles are already posted. Data protection has become the largest identifiable technology-adjacent hiring category in the Indian legal market on our own listings, ahead of the broader technology sector category.
- Data privacy law roles in India, currently the deepest pool of the two.
- Technology and software legal roles in India, covering in-house platform and product counsel positions.
- All legal roles in India, if you want to see how these sit against the wider market.
- Legal internships in India, which is where sector proximity is cheapest to acquire for students.
If you are a student reading this
The practical takeaway is narrower than "learn about AI". The obligations arriving in November 2026 and May 2027 are documentary and procedural. They will be serviced by people who can draft a privacy notice that survives scrutiny, build a record of processing, and run a breach timeline. Those are learnable before qualification, and almost nobody in a graduating cohort has done them.
Read the DPDP Rules directly rather than a summary of them. Take an internship at a company that holds personal data at scale, not only at a firm. Being able to say you have seen a consent flow from the inside is, on current evidence, worth more than another moot.
The wider signal
One firm building one practice proves little on its own. What makes this instructive is the timing and the staffing level together. A nine-lawyer launch, led by someone who spent a decade inside the regulated industry, in the window between two commencement dates, is a firm reading a statute as a hiring plan.
If that reading is correct, the Indian legal market should show a measurable increase in technology, privacy and platform regulation roles through late 2026 and into 2027, concentrated in Delhi, Mumbai and Bengaluru, and split between firm practices and in-house compliance teams. That is a claim with a date attached, which means it can be checked. We intend to check it.
Sources
- Bar & Bench, report of the appointment, July 2026.
- Chandhiok & Mahajan, firm statement published via Legal 500 Legal Developments, July 2026.
- Law.asia, report of the appointment, July 2026.
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules commencement notifications, November 2025.
- Ministry of Electronics and Information Technology, Intermediary Guidelines amendment and India AI Governance Guidelines, February 2026.
LegalAlphabet has no commercial relationship with Chandhiok & Mahajan. This piece was written independently from published sources. If you are at a firm with a move or a mandate worth recording, you can tell us about it through The Deal Record.
