What Is M&A Due Diligence in India?
For most of its history, due diligence in Indian M&A practice has been treated as little more than a pre-signing formality — a box-ticking exercise meant to confirm what the target company already claimed about itself. That picture no longer holds. Over the past decade, three developments have quietly rewritten what due diligence actually involves: the growth of insolvency-driven acquisitions under the Insolvency and Bankruptcy Code, 2016 (“IBC”)[1]; a substantially revamped competition-law merger-control regime; and the phased rollout of the Digital Personal Data Protection Act, 2023 (“DPDP Act”)[2]. Taken together, these changes have turned diligence from a static compliance checklist into something closer to a continuous exercise in risk allocation — one that runs from the moment a deal is contemplated through well after it closes.
This article’s central claim is that Indian M&A due diligence has moved from a document-verification task to something closer to a risk-governance function in its own right. That shift shows up most clearly in four areas: eligibility screening under the insolvency framework, the new deal-value threshold under competition law, data-protection compliance under the DPDP Act, and the still largely unregulated use of artificial intelligence (“AI”) in diligence work. Each of these, this article argues, exposes a widening gap between what the law formally requires and what actually happens in transactional practice — a gap that keeps moving as the underlying law itself keeps changing, which is precisely why diligence teams cannot treat any single year’s summary of the law as a fixed reference point.
The statutory backbone of Indian M&A diligence has not changed much on paper. The Companies Act, 2013[3] still governs corporate authority, related-party transactions, and disclosure; and, for listed targets, the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 and the SEBI (Substantial Acquisition of Shares and Takeovers) Regulations, 2011[5] continue to set the baseline. What has actually changed is what sits around this framework — insolvency eligibility, competition-law deal-value screening, and data protection — none of which featured in a pre-2016 diligence memorandum in anything like their current form.
Section 29A and Insolvency Due Diligence in India
The IBC has, in effect, created a separate category of Indian M&A altogether: the acquisition of distressed assets through the corporate insolvency resolution process (“CIRP”). This route brings with it a diligence discipline that has no close analogue in ordinary private M&A, built around Section 29A of the IBC, which bars specified categories of persons — undischarged insolvents, wilful defaulters, promoters linked to non-performing assets, among others — from submitting resolution plans.[6]
What makes Section 29A unusual is that it points diligence inward as much as outward. A prospective resolution applicant has to interrogate its own eligibility — and that of anyone connected to it — before it can even bid, rather than confining diligence to the target’s affairs alone. The Supreme Court’s decisions in ArcelorMittal India Pvt. Ltd. v. Satish Kumar Gupta[7] and Committee of Creditors of Essar Steel India Ltd. v. Satish Kumar Gupta[8] both grew directly out of Section 29A eligibility disputes during the Essar Steel resolution, and both show how quickly such challenges can turn into protracted litigation that overruns the timelines the Code originally envisaged.
A related risk is that deal certainty does not necessarily end once a resolution plan is approved and implemented. The litigation over Bhushan Power & Steel Ltd. (“BPSL”) is the clearest recent illustration, and its final outcome is now settled — though it took an unusually winding path to get there.
On 2 May 2025, a two-judge Bench of the Supreme Court set aside BPSL’s resolution plan — by then already implemented for roughly four years by JSW Steel Ltd. — and directed liquidation of the company, holding that the plan did not comply with Sections 30(2) and 31(2) of the IBC.
That judgment did not stand. On 31 July 2025, the Supreme Court recalled its own May 2025 judgment on review, restored the appeals, and reheard the matter.
On 26 September 2025, a three-judge Bench led by Chief Justice B.R. Gavai delivered the Court’s final ruling in Kalyani Transco v. M/s Bhushan Power and Steel Limited and Others[9], reported as 2025 INSC 1165. The Court upheld JSW Steel’s resolution plan, held that the delay in implementation was not attributable to the Committee of Creditors or the successful resolution applicant, and dismissed the challenges brought by the erstwhile promoters and operational creditors — foreclosing further attempts to reopen the plan.
The diligence lesson from BPSL is therefore not that resolution-plan approvals remain perpetually vulnerable to being unwound years later — the September 2025 judgment has, for now, closed that particular door and reaffirmed the finality of approved resolution plans. The lesson is narrower but still important: insolvency-route M&A can remain genuinely contested at the Supreme Court level for years after a deal has closed, and diligence teams advising on comparable transactions should track pending review or curative petitions as closely as the underlying resolution plan itself, rather than treating NCLAT approval as the end of the risk. Read together with the Essar Steel litigation, these cases show that insolvency-route diligence has to combine ordinary asset-and-liability verification with a defensible Section 29A eligibility opinion and an ongoing watch on plan-compliance risk — a hybrid diligence product that Indian scholarship has generally treated as a variant of ordinary M&A diligence rather than a distinct discipline in its own right.
Competition Law Due Diligence: The CCI’s 2024 Deal Value Threshold
Competition-law diligence has changed more substantively than any other part of the framework discussed here. The Competition Act, 2002, as amended by the Competition (Amendment) Act, 2023, is now read together with the Competition Commission of India (Combinations) Regulations, 2024, which came into effect on 10 September 2024 and replaced the earlier Combination Regulations of 2011 for transactions notified on or after that date.[4] Transactions notified to the CCI before 10 September 2024 continue to be governed by the 2011 Regulations.
The most significant change is the introduction of a deal value threshold (“DVT”) under Section 5(d) of the Competition Act. Any transaction where the value of the deal — including direct, indirect, immediate, and deferred consideration — exceeds ₹2,000 crore now requires mandatory prior CCI approval if the target has ‘substantial business operations’ in India, even if the transaction would otherwise qualify for the de minimis (small-target) exemption based on assets or turnover.[16] ‘Substantial business operations’ is itself a defined test: for digital-sector targets, it is met where 10% or more of the target’s global business users or end users are based in India; for other sectors, it requires that at least 10% of the target’s global turnover is derived from India and that this India turnover exceeds ₹500 crore.
For diligence purposes, this means the traditional asset-and-turnover threshold analysis under Section 5 is no longer sufficient on its own. Deal teams now need to run a separate deal-value screen alongside it, because the DVT was specifically designed to capture asset-light, data-rich, or early-stage targets — particularly in the digital economy — that could carry significant strategic value while showing negligible book value, and that would previously have escaped CCI review altogether.
DPDP Act and M&A Data Due Diligence
The most consequential recent development in the data-protection space is the phased operationalisation of the DPDP Act. The Digital Personal Data Protection Rules, 2025 were notified on 13–14 November 2025, and the Ministry of Electronics and Information Technology laid out a staggered enforcement timeline: some provisions — including the constitution of the Data Protection Board of India — took effect immediately, consent-manager provisions are due to come into force in November 2026, and the bulk of the substantive obligations around consent, notice, and data-fiduciary duties will apply only from May 2027.[10] Practically, this means Indian M&A practitioners are diligencing targets against a law that is in force but not yet fully operative, which requires judgment calls about which obligations are presently binding and which remain, for now, prospective.
For the pre-signing diligence phase itself — where a target shares personal data (employee records, customer databases, vendor information) with a prospective acquirer — the general consent standard under Section 6 of the DPDP Act continues to apply, requiring consent that is free, specific, informed, unconditional, and unambiguous.[12] It is a mistake, however, to treat this as the only route available in an M&A context. The Act contains a specific, narrower exemption in Section 17(1)(e), which excuses processing from most of the Chapter II and Chapter III obligations where the processing is necessary for a scheme of compromise, arrangement, merger, amalgamation, or reconstruction by demerger, or a transfer of undertaking, that has been approved by a court, tribunal, or other authority competent to do so under law — for instance, a scheme sanctioned by the NCLT under Sections 230–232 of the Companies Act, 2013.[17]
This exemption is considerably narrower than it is sometimes assumed to be. It applies only once a scheme has actually been approved by the competent authority — it is not a general licence to bypass consent during the earlier, pre-approval due diligence phase, when Section 6 continues to govern data sharing. And even where Section 17(1)(e) does apply post-approval, obligations relating to data-security safeguards, accountability of data fiduciaries, and cross-border data-transfer restrictions continue to bind the parties. In practice, this means diligence teams need to map exactly where a transaction sits on this timeline — ordinary due diligence, a court- or NCLT-approved scheme, or post-completion integration — before deciding which provision actually governs a given instance of data sharing, rather than defaulting to a blanket assumption that M&A transactions are broadly exempt from consent requirements.
Separately, data-protection compliance is increasingly a valuation-relevant issue in its own right. Commentators tracking the DPDP Act’s effect on transactions have noted that exposure under the Act’s penalty regime, which can run up to ₹250 crore per instance of non-compliance, is starting to influence deal pricing and negotiation directly.[11] This entire framework also has a constitutional lineage worth noting: its consent-based architecture ultimately traces back to the Supreme Court’s recognition of informational privacy as part of the right to life and personal liberty under Article 21, in Justice K.S. Puttaswamy (Retd.) v. Union of India[13]. That judgment had nothing to do with M&A directly, but it is the constitutional foundation the DPDP Act — and, by extension, the diligence obligations it creates — now rests on.
FDI Due Diligence in Cross-Border Transactions
Any diligence involving cross-border investment now has to reckon with Press Note 3 (2020) scrutiny under India’s FEMA framework[14], which requires prior government approval for investment coming from countries that share a land border with India — a diligence consideration with obvious geopolitical overtones that simply did not exist before 2020. Alongside this, ESG-linked diligence — covering labour compliance, environmental clearances, and governance disclosures under SEBI’s business-responsibility reporting requirements[15] — has stopped being a reputational afterthought and become a genuine workstream, particularly for private equity buyers who answer to their own investor-level ESG covenants.
AI in Legal Due Diligence
One last, more forward-looking point deserves mention. Indian law firms and in-house teams have begun using AI tools to speed up document review, contract abstraction, and red-flag identification in large diligence exercises. This remains, for now, a matter of professional practice rather than settled law — neither the Bar Council of India nor Indian courts have said much yet about privilege preservation, verification obligations, or how liability should be allocated when AI tools materially shape a diligence report. This is offered here as an observation about an emerging trend, not as a statement of settled legal position, but it is one that will need sustained scholarly attention as adoption grows.
Conclusion
Taken together, the developments traced here — IBC-driven eligibility screening now resolved, for the moment, in favour of finality; a competition-law regime that has moved decisively toward deal-value-based scrutiny; and DPDP-anchored data governance that distinguishes sharply between ordinary consent and the narrower approved-scheme exemption — suggest that Indian M&A due diligence has genuinely become a multidisciplinary and continuous function, rather than a discrete step that happens once before signing. The most significant gap in the existing literature sits at the intersection of these developments: how should diligence teams sequence and weigh obligations that are technically in force but not yet fully enforceable, as is presently true under the DPDP Act’s phased rollout, while also tracking a competition-law regime and an insolvency jurisprudence that are both still actively evolving? There is room for empirical work on how Indian transactional lawyers are actually allocating diligence risk during this transitional period, and for a more considered normative framework for AI-assisted diligence before its use becomes the default rather than the exception.
References
- Insolvency and Bankruptcy Code, 2016 (Act No. 31 of 2016).
- Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).
- Companies Act, 2013 (Act No. 18 of 2013), see esp. ss. 188 (related-party transactions) and 129 (financial statements).
- Competition Act, 2002 (Act No. 12 of 2003), as amended by the Competition (Amendment) Act, 2023, s. 5(d); Competition Commission of India (Combinations) Regulations, 2024, notified by the Ministry of Corporate Affairs and effective from 10 September 2024, replacing the Competition Commission of India (Combination Regulations), 2011 for transactions notified thereafter.
- SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015; SEBI (Substantial Acquisition of Shares and Takeovers) Regulations, 2011.
- Insolvency and Bankruptcy Code, 2016, s. 29A (inserted by the Insolvency and Bankruptcy Code (Amendment) Act, 2018, w.r.e.f. 6 June 2018).
- ArcelorMittal India Pvt. Ltd. v. Satish Kumar Gupta, (2019) 2 SCC 1.
- Committee of Creditors of Essar Steel India Ltd. v. Satish Kumar Gupta, (2020) 8 SCC 531 (also reported as 2019 SCC OnLine SC 1478, decided 15 November 2019).
- Kalyani Transco v. M/s Bhushan Power and Steel Limited and Others, 2025 INSC 1165, Supreme Court of India (Civil Appeal No. 1808 of 2020 with connected appeals), three-judge Bench of Gavai, C.J., Satish Chandra Sharma and K. Vinod Chandran, JJ., decided 26 September 2025, upholding JSW Steel Ltd.’s resolution plan for Bhushan Power & Steel Ltd. and dismissing challenges thereto. This judgment followed the Court’s recall, on 31 July 2025, of its earlier judgment dated 2 May 2025 (which had set aside the plan and directed liquidation), on review.
- Digital Personal Data Protection Rules, 2025, notified vide Ministry of Electronics and Information Technology Gazette Notifications G.S.R. 844(E) and G.S.R. 846(E), dated 13 November 2025; enforcement phased to 14 November 2025, 14 November 2026, and 14 May 2027 respectively.
- See e.g. “How India’s M&A Landscape Will Be Reshaped By The Digital Personal Data Protection Rules, 2025,” Mondaq (2025); EY India, “Data protection’s role in M&A transactions” (2026) — cited as illustrative practitioner commentary, not binding authority.
- Digital Personal Data Protection Act, 2023, s. 6 (conditions for valid consent).
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (nine-judge bench).
- Consolidated FDI Policy, Press Note 3 (2020 Series), Department for Promotion of Industry and Internal Trade, read with Foreign Exchange Management (Non-debt Instruments) Rules, 2019.
- SEBI Business Responsibility and Sustainability Reporting (“BRSR”) framework, introduced via SEBI circular dated 10 May 2021, mandating disclosures for the top 1,000 listed companies by market capitalisation.
- Competition Commission of India, Quarterly Newsletter (Fair Play), on the deal value threshold and the Combination Regulations, 2024; see also Competition Commission of India (Combinations) Regulations, 2024, defining ‘substantial business operations in India’.
- Digital Personal Data Protection Act, 2023, s. 17(1)(e) (exemption for processing necessary for a court- or tribunal-approved scheme of compromise, arrangement, merger, amalgamation, demerger, or transfer of undertaking); Companies Act, 2013, ss. 230–232.
