POSH & Corporate Compliance Lawyers

Keep your organisation audit-ready and lawful.

Regulatory risk compounds silently — until an inspection, a notice or a complaint lands. Expert Jurist builds compliance systems that hold up under scrutiny: labour-law registers and employment contracts, POSH Act committees and policies, data-protection and IT Act compliance, and industry-specific frameworks. We turn a scattered set of obligations into a clear, maintained calendar so you stay audit-ready rather than scrambling after the fact.

Compliance rarely fails loudly. It fails as a quiet accumulation of unmet obligations — a committee never constituted, a register never maintained, a policy downloaded but never implemented — that stays invisible until an inspection, a complaint or a notice brings it all to the surface at once, usually at the worst possible time. By then the choice is between a scramble and a penalty, when a modest ongoing effort would have avoided both.

We turn that scattered burden into a system you can actually maintain. We audit what applies to you, fix the gaps in priority order, put the policies, registers, contracts and committees in place, train your people, and keep a calendar so nothing lapses. From POSH Act compliance and employment documentation to the emerging obligations under India's data-protection law, our aim is to keep you quietly, continuously audit-ready — so a regulator's visit is an inconvenience, not a crisis.

Crucially, we translate compliance from a list of intimidating statutes into a short, practical set of things your team actually has to do — and then help them do it. The goal is not a binder that sits on a shelf but a living system your managers understand, so that staying compliant becomes part of how the business runs rather than a fire drill before every audit.

What we handle

Frequently asked questions

Is POSH compliance mandatory for my company?

Yes — every workplace with 10 or more employees must constitute an Internal Committee, adopt a prevention-of-sexual-harassment policy, sensitise employees and file an annual return. Non-compliance attracts penalties and can affect licences on repeat default. We set the whole framework up and keep it current.

How must the Internal Committee be constituted?

The Internal Committee must be chaired by a senior woman employee, include employee members and — importantly — an external member from an NGO or someone familiar with issues of sexual harassment. Getting the composition wrong can invalidate an inquiry, so we constitute it correctly and can serve as your external member.

How quickly must a POSH complaint be dealt with?

The law sets tight timelines: an inquiry is to be completed within a defined period and the employer must act on the committee's report soon after. Because the clock runs from the complaint, having a trained committee and a clear process ready in advance is what keeps you compliant when a complaint actually arrives.

What employment documents should every company have?

At minimum: appointment letters and employment agreements with clear terms, confidentiality and IP-assignment clauses, an employee handbook, and the statutory policies (including POSH). Well-drafted contracts prevent the most common disputes — over notice periods, confidentiality, and ownership of work — before they start.

Which labour-law registrations apply to my business?

It depends on headcount, wages and sector, but common ones include Shops and Establishments registration, provident-fund and employees'-insurance coverage above thresholds, and professional-tax registration. We run a gap audit and get you registered where required, then maintain the registers and returns.

We collect customer data. What does the new data-protection law require?

India's Digital Personal Data Protection Act, 2023 introduces obligations around consent, purpose limitation, security safeguards and the rights of individuals whose data you hold, with rules being rolled out. Getting your privacy notice, consent flows and data-handling practices in order now avoids a costly retrofit later. We advise on practical, proportionate compliance.

Do we need an IT Act / cyber-security policy?

If you operate online or handle sensitive personal data, the Information Technology Act and its rules impose security-practice and grievance obligations, and sound internal policies reduce both legal and reputational risk. We draft IT and acceptable-use policies suited to your operations.

Can you run our POSH programme end-to-end?

Yes. Our POSHGuard Terminal platform manages your Internal Committee, confidential complaint filing, employee training and quizzes, and record-keeping, with our advocates available as the external committee member. It turns a compliance headache into a maintained, audit-ready system.

What are the consequences of non-compliance?

Depending on the law, consequences range from monetary penalties and prosecution to adverse findings in inspections and, for POSH, licence-related consequences on repeat default — quite apart from the reputational damage of a mishandled complaint. Proactive compliance is far cheaper than a defence after the fact.

We're an early-stage startup. How much compliance do we really need?

More than founders expect, but it can be phased sensibly. We identify what is legally mandatory now (incorporation-linked filings, basic labour and tax registrations, POSH once you cross the threshold) versus what can follow as you scale, so you stay lawful without drowning in paperwork.

Book a consultation · All practice areas