Corporate & Compliance Digest September 28, 2026

We are delighted to share this week's AKP Corporate & Compliance Weekly Digest. Please feel free to write to us with your feedback at info@akandpartners.in.
1. Labour Law & Employment Law
1.1. Ministry of Labour and Employment extends ESIC coverage to additional districts in Gujarat
The Ministry of Labour and Employment has notified 1 October 2026 as the date from which contributions under Section 29 of the Code on Social Security, 2020 and benefits under the Employees’ State Insurance Corporation (ESIC) framework will become applicable to establishments located in 15 previously non-implemented districts and 16 partially implemented districts in Gujarat. The notification extends Employees’ State Insurance (ESI) coverage across the entire areas of the specified districts, enabling eligible employees to avail benefits under Chapter IV of the Code on Social Security, 2020.
1.2. Ministry of Labour and Employment issues corrigendum to Employees’ Provident Fund Scheme, 2026
The Ministry of Labour and Employment has issued a comprehensive corrigendum to the Employees’ Provident Fund Scheme, 2026, notified on 29 June 2026, to rectify drafting, typographical, cross-referencing and terminology-related inaccuracies across multiple provisions of the Scheme. The corrections include amendments to references to chapters, paragraphs, forms, contribution-related terminology, withdrawal provisions, employee classifications, investment-related disclosures and various procedural provisions. The corrigendum is clarificatory in nature and is intended to ensure consistency, accuracy and effective implementation of the Employees’ Provident Fund (EPF) framework without introducing substantive policy change.
2. Securities & Capital Markets
2.1. CDSL defers rollout of OTP-Based transfer-cum-closure facility in CDAS
Central Depository Services (India) Limited ("CDSL") has informed Depository Participants ("DPs") that the implementation of the newly introduced OTP-based Transfer-cum-Closure facility in the CDSL Depository Access System (“CDAS”), which was earlier communicated through Communiqué No. CDSL/OPS/DP/POLCY/2026/656 dated 22 September 2026, has been rescheduled. CDSL has clarified that the functionality will not be implemented on the previously planned date and that the revised rollout date will be notified separately in due course. DPs have been advised to take note of the deferment and await further communication regarding implementation timelines.
2.2. CDSL introduces OTP-Based transfer-cum-closure facility for Demat Accounts
CDSL has introduced an OTP-based Transfer-cum-Closure facility through the CDAS to provide a seamless and investor-friendly mechanism for transfer and closure of demat accounts, subject to approval by the concerned Transferor DP. Investors may submit Transfer-cum-Closure requests through OTP-based authentication, following which the requests will be routed to the Transferor DP through CDAS for verification and processing. Transferor DPs are required to review account details, target demat account information and holding status, and approve or reject the request within two working days of receipt in accordance with applicable Securities and Exchange Board of India (“SEBI”) requirements. DPs have been advised to establish appropriate monitoring mechanisms and internal controls to ensure timely processing and compliance. The facility became effective from 25 September 2026.
2.3. NSDL clarifies Digital Accessibility Compliance Requirements for DPs
National Securities Depository Limited ("NSDL") has issued clarifications on compliance with digital accessibility requirements under the Rights of Persons with Disabilities Act, 2016 and related SEBI guidelines. DPs may rely on accessibility audit reports obtained by software vendors for standard, non-customised investor-facing digital platforms, provided such audits are conducted by an International Association of Accessibility Professionals (IAAP)-certified accessibility professional. However, customised or proprietary platforms, including websites, mobile applications, online account opening systems and Know Your Customer (“KYC”) applications, must undergo independent accessibility audits. NSDL has clarified that ultimate responsibility for compliance remains with the DP and requires submission of initial and final accessibility audit reports by 31 October 2026.
2.4. NSDL to freeze Demat Accounts with Non-Compliant KYC Records
NSDL has informed Participants that demat accounts linked to clients whose KYC records remain non-compliant or invalid in the systems of KYC Registration Agencies ("KRAs"), including cases involving invalid Permanent Account Numbers (PANs), will be frozen for both debit and credit transactions on 3 October 2026. The action will be based on KRA data updated as on 1 October 2026. Participants have been advised to review the account lists made available on the e-PASS portal, engage with affected clients to rectify KYC deficiencies and ensure that only clients having a KRA status of “KYC Registered” or “KYC Validated” are permitted to transact.
2.5. NSDL amends Business Rules for securities held by HUFs jointly with individuals
NSDL has amended its Business Rules by introducing Rule 12.6.5, prescribing the treatment of securities held by a Hindu Undivided Family ("HUF") jointly with individual holder(s) in demat accounts. Under the revised framework, upon the death of an individual joint holder, the HUF will continue as the surviving holder. In the event of the death of the Karta, the existing procedure for appointment of a new Karta and change of records will apply. The amendment also clarifies the treatment of securities upon full or partial partition of an HUF, permitting the opening of new demat accounts for partitioned coparceners and facilitating transfer of securities in accordance with their respective shares. NSDL has further provided that, in case of full partition, the existing joint demat account will be closed, while in cases of partial partition, the HUF account jointly held with the individual holder may continue. Participants have been directed to ensure compliance with the revised Business Rules.
3. Information Technology & Data Protection
3.1. CERT-In issues high-severity advisory on multiple vulnerabilities in Google Chrome
The Indian Computer Emergency Response Team ("CERT-In") has issued Vulnerability Note CIVN-2026-0474 highlighting multiple high-severity vulnerabilities affecting Google Chrome for Windows, macOS and Linux systems. The vulnerabilities arise from issues such as use-after-free, type confusion, race conditions, server-side request forgery and improper authorisation controls, and could enable remote code execution, unauthorised access to sensitive information, spoofing attacks, security bypasses and denial-of-service (DoS) conditions. CERT-In has advised users and organisations to immediately upgrade to the latest patched versions of Google Chrome.
3.2. CERT-In issues critical advisory on F5 BIG-IP APM vulnerability
CERT-In has issued Vulnerability Note CIVN-2026-0475 regarding a critical heap-based buffer overflow vulnerability in affected versions of F5 BIG-IP Access Policy Manager (APM). The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code by sending specially crafted requests to a vulnerable virtual server. CERT-In has warned that the vulnerability is being actively exploited in the wild and has urged organisations using affected F5 BIG-IP APM versions to promptly apply the vendor-recommended security updates.
3.3. CERT-In issues critical advisory on multiple vulnerabilities in Adobe Products
CERT-In has issued Vulnerability Note CIVN-2026-0476 highlighting multiple critical vulnerabilities across several Adobe products, including Adobe InDesign, Adobe Bridge, Adobe Connect, Adobe Experience Manager (AEM) Forms, Adobe Premiere and Adobe Premiere Pro. The vulnerabilities could allow attackers to execute arbitrary code, escalate privileges, bypass security controls, access sensitive information, read arbitrary files and cause denial-of-service conditions. CERT-In has advised affected users and organisations to apply the latest security patches and updates released by Adobe to mitigate the identified risks.
3.4. TRAI notifies Telecom Consumer Protection (Thirteenth Amendment) Regulations, 2026
The Telecom Regulatory Authority of India ("TRAI") has notified the Telecom Consumer Protection (Thirteenth Amendment) Regulations, 2026 to improve affordability and choice for consumers seeking voice and SMS-only services. The amendment mandates Telecom Service Providers ("TSPs") to offer Special Tariff Vouchers ("STVs") exclusively for voice and SMS, with tariffs appropriately reduced in comparison to bundled voice, SMS and data plans. TSPs will be required to provide such STVs for validity periods of 30 days or less, monthly renewable plans aligned to a fixed calendar date, and at least one additional voice-and-SMS-only STV corresponding to longer validity bundled plans. TRAI stated that the revised framework is intended to provide greater flexibility for low-income consumers and users who do not require data services, enabling them to recharge according to their needs and financial capacity.
4. Taxation (Indirect & Direct)
4.1. CBDT notifies fifth amendment to Income-tax Rules, 2026 for TDS on immovable property transfers by Non-Residents
The Central Board of Direct Taxes ("CBDT") has notified the Income-tax (Fifth Amendment) Rules, 2026, effective from 1 October 2026, to operationalise tax deduction at source ("TDS") obligations on consideration paid by a resident individual or HUF for the transfer of immovable property by a non-resident. The amendment revises Rules 215, 218 and 219 of the Income-tax Rules, 2026 and introduces corresponding changes to Form No. 132 and Form No. 141. A new Schedule E has been inserted in Form No. 141, requiring detailed reporting of property transactions, including particulars of buyers and sellers, stamp duty value, sale consideration, instalment-wise payments, tax residency information, capital gains classification and TDS details. The revised framework also prescribes reporting requirements for non-resident sellers and clarifies documentation to support application of lower withholding rates under applicable provisions and tax treaties.
4.2. CBIC invites Stakeholder Comments on Draft Warehousing Operations Regulations, 2026
The Central Board of Indirect Taxes and Customs ("CBIC") has released the Draft Warehousing Operations Regulations, 2026 for public consultation and invited comments, views and suggestions from stakeholders. The draft regulations have been approved for placement in the public domain, and stakeholders have been requested to submit feedback within 15 days from the date of issuance of the communication. CBIC has prescribed a structured format for submission of comments, requiring stakeholders to specify the relevant regulation number, proposed modification and supporting rationale. The initiative forms part of CBIC’s consultative approach towards finalising the regulatory framework governing warehousing operations under customs laws.
5. Regulatory Enforcement (Security and Exchange Board of India)
Authority | Name of the Entity | Amount | Contravention |
SEBI | Kaizen Trust (in the matter of Kaizen Domestic Scheme I)
| INR 10,87,500 (Indian Rupees Ten Lakh Eighty-Seven Thousand Five Hundred only)
| Violation of Regulation 23(1)(a) read with Regulation 24(2) of the SEBI (Venture Capital Funds) Regulations, 1996, due to failure to wind up the scheme and distribute proceeds to investors within the prescribed timeline, resulting in a delay of approximately two years and six months. The matter was settled through a suo motu settlement application.
|
SEBI | Nippon Life India AIF Management Limited
| INR 1,087,500 (Indian Rupees Ten Lakh Eighty-Seven Thousand Five Hundred only)
| Violation of Regulation 29(1)(a) read with Regulation 29(7) of the SEBI (Alternative Investment Funds) Regulations, 2012, arising from failure to wind up the scheme and liquidate investments within the stipulated period after expiry of the scheme tenure. The matter was settled through a suo motu settlement application.
|
SEBI | True North Enterprise Private Limited
| INR 1,087,500 (Indian Rupees Ten Lakh Eighty-Seven Thousand Five Hundred only)
| Violation of Regulation 23(1)(a) read with Regulation 24(2) of the SEBI (Venture Capital Funds) Regulations, 1996, for failure to wind up True North Fund Scheme B within the prescribed timeline. The Scheme's tenure expired on 19 December 2014; however, its tenure was extended beyond the limits permitted under the Placement Memorandum ("PPM"), and the winding-up process was completed with a delay of approximately 10 years, with final distribution to investors taking place in March 2025. The matter was settled through a suo motu settlement application without admission or denial of findings.
|
Disclaimer
The note is prepared for knowledge dissemination and does not constitute legal, financial or commercial advice. AK & Partners or its associates are not responsible for any action taken based on its contents.
For further queries or details, you may contact:
Mr Anuroop Omkar
Founding Partner, AK & Partners





Comments