Corporate & Compliance Digest June 22, 2026
- AK & Partners

- Jun 22
- 6 min read
We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.
1. Labour Law & Employment Law
1.1. Gujarat Government issues Draft Amendment Rules on Shops and Establishments – Employment and Conditions of Service
The Government of Gujarat has released draft amendments to the Gujarat Shops and Establishments (Regulation of Employment and Conditions of Service) Rules, aimed at updating employment practices and compliance requirements for establishments. The proposed framework seeks stakeholder feedback and aligns with recent legislative amendments to enhance operational flexibility while safeguarding employee welfare.
1.2. Andaman & Nicobar Administration issue Draft Amendment Rules on Shops and Establishments
The Andaman and Nicobar Administration has issued the draft Andaman and Nicobar Islands Shops and Establishments (Amendment) Rules, 2026, proposing a modernised and digital compliance framework for establishments. The draft introduces lifetime online registration with auto‑approval, eliminating periodic renewals and reducing administrative burden, along with permitting 24x7 (twenty-four by seven) business operations subject to safeguards on working hours, weekly holidays, overtime wages and compensatory leave.
2. Securities & Capital Markets
2.1. CDSL notified conversion of Demat Accounts to BSDA
The Central Depository Services (India) Limited (“CDSL”) has notified the conversion of eligible demat accounts into Basic Services Demat Accounts (“BSDA”), in line with the SEBI framework on financial inclusion and ease of investing. The notification mandates Depository Participants (“DPs”) to automatically convert existing demat accounts into BSDA where eligibility criteria are met, unless the beneficial owner opts out.
2.2. CDSL issued communique on Validation of KYC Records with KRAs and Freezing of Non‑compliant Demat Accounts
CDSL has issued a communiqué directing DPs to ensure validation of Know Your Customer (“KYC”) records with KYC Registration Agencies (“KRAs”). Based on data provided by KRAs identifying invalid or non‑validated Permanent Account Numbers (“PANs”), CDSL has identified corresponding demat accounts and shared DP‑wise lists for necessary follow‑up.
3. Taxation (Direct and Indirect)
3.1. GSTN introduces changes to e-Invoice API and EWB framework
The Goods and Services Tax Network (GSTN) has issued an advisory introducing key changes to the e-Invoice Application Programming Interface (“API”) and e-Way Bill (“EWB”) system, including mandatory capture of Ship to Goods and Services Tax Identification Number (“GSTIN”) in specified transactions and the introduction of a voluntary closure facility for EWBs. Under the revised framework, Ship-to GSTIN must be provided in Bill-to/Ship-to transactions where EWB are generated, with “URP” (Unregistered Person) permitted where GSTIN is unavailable, alongside enhanced validation rules to ensure accuracy and prevent duplication. The advisory also mandates system updates for taxpayers and API integrators, particularly for EWB generation through Invoice Reference Number (IRN) and introduces a structured API-based mechanism for EWB closure post-delivery to improve tracking and compliance. These changes, aimed at strengthening data integrity and operational efficiency, will come into effect from 1 August 2026.
4. Information and Data Protection
4.1. CERT-In Flags Multiple Vulnerabilities in Schneider Electric Products
The Indian Computer Emergency Response Team (“CERT-In”) has issued a high-severity vulnerability note regarding multiple vulnerabilities affecting certain Schneider Electric products, including EcoStruxure IT Data Center Expert, EasyLogic T150 Remote Terminal Unit, Saitel DP Remote Terminal Unit and Controller, and PowerLogic P7. The vulnerabilities arise from issues such as improper access controls, insufficient protection of credentials, incorrect permission assignments, operating system command injection and assertion-related weaknesses. Successful exploitation could enable attackers to gain unauthorised access, disclose sensitive information, execute arbitrary commands or cause denial-of-service (“DoS”) conditions. CERT-In has advised users to promptly apply the security updates released by Schneider Electric.
4.2. CERT-In Warns of Multiple Vulnerabilities in Jenkins
CERT-In has identified multiple high-severity vulnerabilities in Jenkins, an open-source automation server widely used for software development and deployment processes. The vulnerabilities affect Jenkins weekly versions 2.567 and earlier, and Long-Term Support (“LTS”) versions 2.555.2 and earlier. The issues stem from weaknesses including improper deserialisation controls, missing permission checks and insecure handling of configuration files containing secrets. If exploited, attackers could impersonate legitimate users, perform unauthorised actions, access sensitive information, conduct phishing attacks through open redirects, execute cross-site scripting attacks and bypass security restrictions. Organisations using affected versions of Jenkins have been advised to implement the vendor-recommended security updates without delay.
4.3. CERT-In Reports Buffer Overflow Vulnerability in Zyxel GS1900 Series Switches
CERT-In has issued a high-severity advisory concerning a buffer overflow vulnerability in Zyxel GS1900 series switches. The vulnerability exists within the Common Gateway Interface (“CGI”) component of the switch firmware and affects multiple GS1900 series models. According to CERT-In, a local area network (“LAN”)-based unauthenticated attacker could exploit the flaw by sending specially crafted Hypertext Transfer Protocol (“HTTP”) requests to a vulnerable device. Successful exploitation may result in the execution of arbitrary commands on the targeted system, leading to potential remote code execution. Users and organisations operating the affected devices have been advised to install the security patches made available by Zyxel.
4.4. CERT-In Alerts Organisations to Potential Exposure of FortiGate Credentials
CERT-In has reported a large-scale credential exposure campaign, known as “FortiJump”, affecting Fortinet firewalls and Virtual Private Network (“VPN”) gateways. According to CERT-In, threat actors have compiled a database containing verified administrator and VPN credentials linked to internet-facing FortiGate devices. The exposed information reportedly includes usernames, email addresses, plaintext passwords, device configuration details and network metadata. The compromise could enable unauthorised administrative access, facilitate lateral movement within corporate networks, increase the risk of data breaches and support ransomware attacks. Organisations using Fortinet products have been advised to assume potential credential exposure and undertake immediate remediation measures.
4.5. CERT-In Issues Critical Advisory on Multiple Vulnerabilities in Oracle Products
CERT-In has issued a critical advisory regarding multiple vulnerabilities affecting a broad range of Oracle products, including Oracle E-Business Suite, Oracle Enterprise Manager, Oracle Fusion Middleware, Oracle MySQL, Oracle PeopleSoft, Oracle Solaris and Oracle VM VirtualBox, among others. The vulnerabilities could allow attackers to execute arbitrary code, gain elevated privileges, access sensitive information, manipulate data, bypass security controls and trigger denial-of-service conditions. Given the widespread use of Oracle products across sectors such as finance, manufacturing, government and retail, successful exploitation may result in significant operational and security risks. CERT-In has urged affected users to promptly apply Oracle’s latest security updates.
5. MCA Updates
5.1. MCA extends validity of name reservations and E-form resubmission deadlines
The Ministry of Corporate Affairs (“MCA”), has introduced relief measures for stakeholders affected by the disruption caused by the fire incident at its data centre on 5 June 2026. Under the revised framework, approved name reservations whose validity is due to expire between 21 June 2026 and 30 June 2026 (both dates inclusive) will automatically remain valid until 10 July 2026. Further, stakeholders whose company or Limited Liability Partnership (“LLP”) name reservations expired between 5 June 2026 and 20 June 2026 may seek an extension up to 10 July 2026 by raising a request with the MCA Helpdesk on or before 30 June 2026, subject to verification and confirmation of the continued availability of the approved name.
5.2. MCA recognises New Development Bank as a Specified International Institution
The MCA, through Notification No. S.O. 3140(E) dated 16 June 2026, has specified the New Development Bank (“NDB”) for the purposes of Section 2(11)(ii) of the Companies Act, 2013. The NDB was established pursuant to an agreement signed on 15 July 2014 in Fortaleza, Brazil, by the governments of Brazil, Russia, India, China and South Africa. By recognising the NDB as a specified institution under the Companies Act, 2013, the Central Government has formally acknowledged its status for the purposes contemplated under the statutory framework.
6. Regulatory Penalties
Authority | Name of Company | Amount of Penalty Imposed | Contravention |
Registrar of Company, Cuttack | Satguru Metals Limited | ROC Cuttack imposed a penalty of INR 2,00,000 (Indian Rupees Two Lakhs) | The company was required to file Form PAS-6 for the half-year ended September 30, 2024, by November 30, 2024; however, the form remained unfiled even as of June 11, 2026, resulting in a continuing contravention, with the default persisting from the due date until the actual date of compliance. |
Security and Exchange Board of India | OnePaper Research Analysts Private Limited
| SEBI has imposed a total penalty of INR 30,00,000 (Indian Rupees Thirty Lakhs only)
| Violations of the SEBI (Research Analysts) Regulations, 2014 (the “RA Regulations”) and the SEBI (Prohibition of Fraudulent and Unfair Trade Practices) Regulations, 2003 (the “PFUTP Regulations”). |
Disclaimer
The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.
For further queries or details, you may contact:
Mr Anuroop Omkar
Founding Partner, AK & Partners





Comments