← All 13 practice areas
Practice area 6 of 13

Compliance
under Indian law.

Indian statutory compliance is 49 live recurring obligations across nine regulators — GST, income-tax, MCA/ROC, LLP, EPF/ESI, labour, RBI, FEMA and SEBI — each with its own citation, applicability test and penalty ladder. The dates are statutory and do not shift for Sundays; regulators extend only by ad-hoc notification. This hub maps the governing provisions to the calendar, the ROC forms and the DPDP readiness assessment.

Last reviewed: 19 August 2026 · every citation on this page names the dataset it came from

What's in this hub
  • 10governing provisions
  • 12product capabilities
  • 5free tools
  • 1free templates
  • 50compliance deadlines
  • 5audiences
Assembled from what LexVio actually ships. Nothing here is a roadmap item.
What this area covers

Compliance in India is not one calendar but nine, stacked. GST alone runs GSTR-1 under s.37(1) of the CGST Act, 2017 with Rule 59(1), GSTR-3B under s.39(1) with Rule 61(1), the annual GSTR-9 under s.44 with Rule 80(1), and the GSTR-9C reconciliation under Rule 80(3) — plus CMP-08 and GSTR-4 for composition dealers, GSTR-7 for TDS deductors under s.51, GSTR-8 for e-commerce TCS under s.52, and ITC-04 for job work under s.143.

Income-tax adds monthly TDS/TCS deposit under s.397 of the Income-tax Act, 2025 with Rule 218 of the Income-tax Rules 2026, four quarterly statements under s.397(3)(b), four advance-tax instalments under s.408, the return under s.263(1), the tax-audit report under s.63, and the transfer-pricing report under s.172. MCA adds AGM, AOC-4, MGT-7/7A, ADT-1, DPT-3, MSME-1 and DIR-3 KYC; LLPs add Forms 11 and 8. EPF/ESI, labour, RBI's ECB-2, FEMA's FLA and ODI APR, and SEBI LODR quarterly and annual filings complete the set.

Privacy is the newest layer and the one most organisations have mis-dated. The DPDP Act, 2023 commenced in phases under G.S.R. 843(E): 13 November 2025 stood up the Data Protection Board only, 13 November 2026 opens Consent Manager registration under s.6(9) and nothing else, and 13 May 2027 brings the entire operative regime — ss.3-5, s.6(1)-(8) and (10), ss.7-17, and the penalty machinery in ss.28-34 with the Schedule. The readiness quiz groups every gap it finds against those dates.

Indian law that governs this

The provisions, with their section numbers.

Each row names the dataset it was taken from — the seeded statute library, the compliance calendar's own statutory reference, the bare Limitation Act, or the DPDP research set. Nothing here was written from memory.

Act
Provision
What it says
Source
The Central Goods and Services Tax Act, 2017
s.37(1)
Furnishing details of outward supplies (GSTR-1)
Read with Rule 59(1) of the CGST Rules 2017; the 11th of the following month was fixed by Notification 83/2020-Central Tax.
Compliance calendar
The Central Goods and Services Tax Act, 2017
s.39(1)
Furnishing of returns (GSTR-3B)
Read with Rule 61(1) of the CGST Rules 2017.
Compliance calendar
The Central Goods and Services Tax Act, 2017
s.44
Annual return (GSTR-9 / GSTR-9C)
Read with Rules 80(1) and 80(3) — the annual return and the reconciliation statement respectively.
Compliance calendar
The Income-tax Act, 2025
s.397
TDS/TCS deposit and quarterly statements
Read with Rule 218 for deposit and Rules 217/219 for the quarterly statements (Forms 138/140/143/144).
Compliance calendar
The Income-tax Act, 2025
s.263(1)
Return of income
Successor of s.139(1) of the Income-tax Act, 1961. Sub-sections (4) and (5) carry the belated and revised return windows.
Compliance calendar
The Companies Act, 2013
ss.92(4), 137(1), 139(1)
Annual return; financial statements; auditor appointment
Read with Rule 11 of the Management & Administration Rules, Rule 12 of the Accounts Rules and Rule 4(2) of the Audit and Auditors Rules — MGT-7, AOC-4 and ADT-1.
Compliance calendar
The Code on Social Security, 2020
ss.16, 29
EPF and ESI monthly contributions
The EPF Scheme 1952 and ESI (General) Regulations 1950 provisions are saved during the transition to the Code.
Compliance calendar
The SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015
Regs. 13(3), 27(2), 31(1)(b), 33(3)(d)
Quarterly filings and annual audited results
Read with the SEBI Integrated Filing framework. Listed entities only.
Compliance calendar
The Foreign Exchange Management Act, 1999
FLA / ECB-2 / APR
Reporting under FEMA
The annual Foreign Liabilities & Assets return, the monthly ECB-2 return, and the Annual Performance Report under Regulation 10 of the FEM (Overseas Investment) Regulations 2022.
Compliance calendar
The Digital Personal Data Protection Act, 2023
ss.3-17, 28-34
The operative regime, in force from 13 May 2027
Application and extraterritorial reach, grounds for processing, notice, consent, Data Fiduciary obligations, children's data, Significant Data Fiduciaries, Data Principal rights, cross-border restriction, and the penalty machinery with the Schedule.
DPDP dataset
Free, no login

Tools that apply to this work.

Each runs in your browser. Nothing is uploaded anywhere, and none of them needs an account.

Free tool
Compliance Deadline Calendar

Every recurring statutory due date, month by month, each carrying its own citation.

Open tool →
Free tool
ROC Form Finder

The nine MCA/ROC filings a company or LLP must diarise, with the due rule and late-fee ladder.

Open tool →
Free tool
DPDP Readiness Quiz

15-question weighted self-assessment against the DPDP Act 2023 and the DPDP Rules 2025.

Open tool →
Free tool
Interest & Late Fee Calculator

Interest under 234A/234B/234C, CGST s.50, TDS 201(1A) and the 234E fee, each with its citation.

Open tool →
Free tool
GSTIN Validator

Validate a GSTIN's checksum and decode state code, PAN and entity type — runs in your browser.

Open tool →
Drafting starting points

Free templates for this area.

Free to copy, modify and use commercially, without attribution. They are starting points, not advice — have a qualified advocate or company secretary review anything before you sign it.

Data Protection / Privacy
Data Processing Agreement (DPDP Act 2023) — India

Drafted to the DPDP Act 2023 and DPDP Rules 2025, not a re-badged GDPR Article 28 DPA. Statutory Data Fiduciary / Data Processor / Data Principal vocabulary, the Rule 6 security floor including the one-year log minimum, a breach window short enough for the Fiduciary's own 72-hour Board report, and cross-border handled the way Section 16 actually works.

Inside LexVio

The capabilities that do this work.

Every one of these is a real feature page with its own status — Live, Beta or Soon. If it says Beta, it is in beta.

CapabilityLive
Filing calendar

Every deadline that applies to your entity in one calendar, with advance alerts.

CapabilityLive
Regulator monitoring

SEBI, RBI, MCA/ROC, and GST circulars + filings tracked end-to-end.

CapabilityLive
Regulatory change feed

New circulars summarised and filterable by Act, regulator, and effective date.

CapabilityBeta
DPDP readiness assessment

Self-serve gap analysis against DPDP Act §6 + §13 with a remediation plan.

CapabilityLive
Pre-built agents

Vendor-onboarding review, weekly compliance scan, GST reconciliation — ready to enable.

CapabilityBeta
Custom workflow agents

Build your own multi-step agent with triggers, conditions, and actions. No code.

CapabilityLive
Scheduled runs

Cron-style scheduling — daily, weekly, or on the GST due-date.

CapabilityBeta
Approval workflows

Human-in-the-loop gates between agent steps.

CapabilityLive
Webhooks

Outgoing webhooks on key events — scan-complete, alert-fired, deadline-hit.

CapabilityLive
Activity audit log

A searchable record of state-changing actions across the workspace.

CapabilityLive
GST computation helper

GST math, ITC reconciliation against GSTR-2B, and e-invoicing validation.

CapabilityLive
TDS detection in contracts

Auto-flags TDS obligations from contract clauses — section, rate, threshold, due date.

Where it lives

The modules this area draws on.

Module
Compliance AI

SEBI, RBI, MCA/ROC and GST monitoring with alerts ahead of every deadline.

Module
Workflow Agents

No-code agents that automate multi-step legal, compliance and tax workflows.

Module
Tax AI

Income tax, TDS, GST, IFRS and IndAS read in the context of your own contracts and filings.

Who this is for

The people who do compliance work.

Audience
CA / CS

AI for the contracts your clients keep sending you.

Audience
Small Businesses

Legal protection without the legal fees.

Audience
Enterprise / MNC

Custom AI. Unlimited seats. Your data, your cloud.

Audience
Financial Institutions

AI-native SEBI, RBI and AMFI compliance.

Audience
Law Firms

Deliver more client work with white-label AI.

Recurring obligations

50 compliance deadlines touch this area.

These are the statutory dates, not the extended ones — there is no automatic carry-forward when a due date falls on a Sunday or a gazetted holiday, and regulators grant relief only by ad-hoc notification. Every row states who it applies to; almost none of them applies to every entity.

GST10
  • GSTR-1 — Outward supplies
  • GSTR-3B — Summary return
  • CMP-08 — Composition quarterly statement
  • GSTR-4 — Composition annual return
  • GSTR-9 — Annual return
  • GSTR-9C — Reconciliation statement
  • GSTR-7 — TDS return (deductor)
  • GSTR-8 — TCS return (e-commerce)
  • ITC-04 — Job-work declaration (Apr-Sep)
  • ITC-04 — Job-work declaration (Oct-Mar)
Income-tax15
  • TDS / TCS payment
  • TDS / TCS — Q1 statement
  • TDS / TCS — Q2 statement
  • TDS / TCS — Q3 statement
  • TDS / TCS — Q4 statement
  • Advance Tax — Q1 (15%)
  • Advance Tax — Q2 (45%)
  • Advance Tax — Q3 (75%)
  • Advance Tax — Q4 (100%)
  • ITR filing — Individuals / HUFs (no audit)
  • Tax audit report (ex-3CA/3CB + 3CD)
  • ITR filing — Companies / audit cases
  • Transfer pricing accountant's report (ex-3CEB)
  • ITR filing — TP cases
  • Belated / revised return
MCA / ROC8
  • AGM — Annual General Meeting
  • AOC-4 — Financial statements filing
  • MGT-7 / MGT-7A — Annual return
  • DIR-3 KYC — Director KYC (now triennial)
  • DPT-3 — Return of deposits
  • MSME-1 — H1 (Apr-Sep) outstanding
  • MSME-1 — H2 (Oct-Mar) outstanding
  • ADT-1 — Auditor appointment
LLP2
  • LLP Form 11 — Annual return
  • LLP Form 8 — Statement of account & solvency
EPF / ESI4
  • EPF — Monthly contribution + ECR
  • ESI — Monthly contribution
  • ESI — Half-yearly return of contributions (Apr-Sep)
  • ESI — Half-yearly return of contributions (Oct-Mar)
Labour3
  • POSH — Annual Report to District Officer
  • Statutory bonus — Annual disbursal
  • Annual return — contract labour / establishment (ex-CLRA Form XXV)
RBI1
  • ECB-2 — Monthly ECB return
FEMA2
  • FLA — Foreign Liabilities & Assets return
  • APR — Annual Performance Report (ODI)
SEBI5
  • SEBI LODR — Quarterly filings (Q4, Jan-Mar)
  • SEBI LODR — Quarterly filings (Q1, Apr-Jun)
  • SEBI LODR — Quarterly filings (Q2, Jul-Sep)
  • SEBI LODR — Quarterly filings (Q3, Oct-Dec)
  • SEBI LODR — Annual audited financial results (Reg 33)
Open the full compliance calendar →
Questions

Compliance — the questions people actually ask.

How many statutory deadlines does an Indian company actually have?

The compliance calendar carries 49 live recurring obligations across nine regulators, but almost none of them apply to every entity — each row states who it applies to. A private company with no listing, no ECB, no FDI, no composition scheme and fewer than 20 employees will match a small fraction of them. The applicability line is the part to read first.

When does the DPDP Act actually start biting?

13 May 2027 for substantive compliance and enforcement. The commencement notification G.S.R. 843(E) split the Act into three phases: 13 November 2025 brought only the Data Protection Board provisions into force — the institution, not the jurisdiction, and s.27's complaint power was not among them. 13 November 2026 brings only s.6(9) and s.27(1)(d), which concern Consent Manager registration. Everything else — notice, consent, security safeguards, breach intimation, children's data, Data Principal rights, cross-border, and the penalty Schedule — commences at eighteen months, on 13 May 2027.

Do the calendar's dates account for extensions?

No, and that is deliberate. The dates encoded are the statutory dates. Regulators extend ad hoc by notification — Notification 01/2026-Central Tax moved the March-2026 GSTR-3B from 20 to 21 April 2026, and CBDT moved the AY 2025-26 tax-audit specified date from 30 September to 31 October 2025 — and encoding those retroactively would make the calendar unreliable in the other direction. Track extension notifications separately; use the calendar for the date to work backwards from.

What can LexVio automate here rather than just track?

Pre-built agents cover vendor-onboarding review, a weekly compliance scan and GST reconciliation. Custom agents let you build a multi-step workflow with triggers, conditions and actions without code, and approval workflows put a human gate between agent steps. Scheduled runs are cron-style — daily, weekly, or on the GST due date — and webhooks fire outward on scan-complete, alert-fired and deadline-hit.

← Previous area
Intellectual Property
Next area →
Tax & Regulatory
Back to all 13 practice areas →

A map of the material, not advice on your matter. These hubs point at statutory text, free calculators and product capabilities. They are not legal advice, they do not create an advocate-client relationship, and they are no substitute for reading the bare Act as currently amended. Indian law is fact- and state-specific — stamp duty, registration and several employment obligations vary by state, and limitation turns on facts a web page cannot know. Take advice on your own facts before acting.

The law is in the document.
Let LexVio read it first.

Paste any contract. Get a Legal Health Score and the top risks in 30 seconds. No account needed.

Try the free scanner →