The History of Indian Privacy — Enforcement

    Penalties with Purpose: What Global Privacy Fines Tell Us About India's Enforcement Era

    Privacy laws are only as credible as their enforcement. Here's what violations have cost around the world — and what Indian businesses should expect when the DPBI starts adjudicating. Written by Yuvaraj S., Founder, truConsent.

    Context

    The Myth of Toothless Privacy Laws

    When GDPR came into force in May 2018, a predictable chorus emerged: the law was ambitious but unenforceable. Companies would pay lip service to compliance, regulators would lack the capacity to act, and the fines would never materialize at the scale the regulation threatened. Many dismissed early privacy laws as symbolic gestures — good-looking governance with no real teeth.

    The fines that followed proved otherwise. By early 2024, GDPR enforcement had crossed €4 billion in total fines. A single case — the Didi Global enforcement in China — reached ¥8 billion (~$1.2 billion). Meta paid €1.2 billion in a single decision. The idea that privacy regulators would not act has been thoroughly discredited.

    India's DPDPA has not been enforced yet. The DPBI is established but adjudication has not begun. The Rules are pending notification. But the penalty structure is written into statute, the institutional architecture is in place, and enforcement is coming. The question for Indian businesses is not if — it is when, and more importantly, whether you will be ready.

    Global Precedents

    Global Fines That Changed the Conversation

    Each of these cases shaped how regulators, courts, and companies understand privacy liability. Each has a direct parallel in India's DPDPA framework.

    LawCompanyFineYearReasonIndia Parallel
    GDPRMeta (Ireland)€1.2 Billion2023Trans-Atlantic data transfers without adequate safeguards. The largest GDPR fine ever issued.Cross-border data transfers will be governed by DPDPA's negative list once Rules are notified.
    GDPRAmazon (Luxembourg)€746 Million2021Cookie consent failures, behavioral advertising served without valid consent.Consent for marketing and behavioral profiling is central to DPDPA.
    GDPRGoogle (France)€150 Million2022Cookie opt-out mechanism designed to be harder than opt-in, violating consent equality.DPDPA requires consent withdrawal to be as easy as consent giving.
    GDPRWhatsApp (Ireland)€225 Million2021Lack of transparency in data processing notices — users not told how data was used.DPDPA mandates clear, itemized notices — purpose, processing activity, named entities.
    GDPRLinkedIn (France)€310 Million2024Behavioral advertising run without a valid legal basis for processing.Direct parallel for Indian platforms running targeted advertising.
    GDPRTikTok (UK)£12.7 Million2023Processing children's data without proper parental consent.DPDPA has India's strictest children's data provisions — verifiable parental consent required for all users under 18.
    GDPRH&M (Germany)€35.3 Million2020Illegal monitoring of employee personal data including health, religion, and family details.HR data is personal data under DPDPA. Workplace data monitoring without consent basis is a violation.
    CCPASephora$1.2 Million2022Failed to disclose data sales and refused to honor Global Privacy Control (GPC) opt-out signals. First major CCPA enforcement action.DPDPA requires explicit opt-in — failing to honor withdrawal signals creates similar exposure.
    PIPL (China)Didi Global¥8.026 Billion (~$1.2B)2022Unlawful data collection, overseas data transfer violations, and security failures at scale.The largest privacy fine outside the EU — a signal that emerging-market regulators can and will act decisively.
    Singapore PDPASingHealth + IHiSSGD 750K + SGD 250K20181.5 million patient records stolen in a cyberattack. Both the healthcare provider and its IT operator were fined separately.DPDPA holds both Data Fiduciaries and Data Processors accountable — processor failures flow back to the fiduciary.
    Singapore PDPAGrabCarSGD 10,0002020Driver personal data leaked due to an insecure system update.Even small-scale breaches from negligent updates are actionable under DPDPA's security safeguards requirement.

    Penalty Architecture

    DPDPA's Penalty Structure: What It Means in Practice

    The Act establishes a tiered penalty framework. The tiers are not graduated by company size — they are graduated by the nature of the violation.

    Tier 1

    Up to ₹50 Crore

    ~$6M

    • Failure to implement reasonable security safeguards (Section 8)
    • Failure to notify DPBI and data principals of a data breach
    • Failure to erase data when purpose is served or consent is withdrawn
    • Non-compliance with children's data provisions

    Tier 2

    Up to ₹150 Crore

    ~$18M

    • Non-compliance by Consent Managers with their obligations under the Act

    Tier 3

    Up to ₹250 Crore

    ~$30M

    • Significant Data Fiduciaries failing to comply with additional obligations
    • Serious or repeated violations at the DPBI's discretion

    Important context: The ₹250 crore figure is not per company — it is per breach instance. A single incident involving inadequate consent, a data breach, and failure to notify could trigger multiple separate penalties. For large businesses processing millions of data principals, the aggregate exposure is significant — and the structural incentive to invest in compliance infrastructure is clear.

    Enforcement Outlook

    How Will India Enforce? A Realistic Assessment

    India's DPBI starts as an adjudicatory body, not a proactive regulator. Unlike GDPR's Data Protection Authorities — which conduct audits, issue guidance, and initiate investigations — the DPBI's primary mechanism is responding to complaints. This is important: it means the first enforcement cases will likely be triggered by aggrieved data principals or whistleblowers, not regulator-initiated investigations.

    The enforcement pattern in most countries that have activated privacy regimes follows a consistent arc: high-profile cases against large, well-known companies establish precedent and signal seriousness. This is followed by an expanding scope that reaches mid-market businesses. India will likely follow the same trajectory. The first DPBI adjudication will be closely watched — and its outcome will set the tone for years.

    India's DPDPA includes a "voluntary undertaking" mechanism — companies can self-report violations and propose remediation measures. This mirrors GDPR's cooperation provisions, which have consistently resulted in reduced penalties when companies engage constructively with regulators rather than contesting at every stage.

    Businesses that build compliance infrastructure before enforcement begins gain a documented advantage: evidence of good-faith effort is explicitly a mitigating factor in penalty calculations. A company that can show the DPBI a functioning consent management system, regular data audits, and a tested breach response plan is materially better positioned than one caught scrambling to retrofit compliance after a complaint is filed.

    Action Plan

    The Pre-Enforcement Checklist: 5 Things to Fix Before the DPBI's First Case

    Enforcement timing is uncertain. Compliance requirements are not. These five items represent the highest-risk gaps in most Indian organizations today.

    01

    Itemize every data collection purpose

    Every data collection form needs a granular purpose statement — not "to improve services" but specific, named purposes for each data element collected.

    02

    Make consent withdrawal live and functional

    Users must be able to withdraw consent in the same number of steps as consenting. Audit every consent touchpoint for withdrawal parity.

    03

    Deploy children's age verification

    India's DPDPA sets the threshold at 18 — stricter than GDPR's 16. Verifiable parental consent is required for all users under 18. This is the area where enforcement is likely to be swift.

    04

    Update all Data Processor agreements

    Your processors' compliance failures are your liability under DPDPA. Every vendor, SaaS tool, and sub-processor agreement must reflect DPDPA obligations.

    05

    Document and test your breach response playbook

    A 72-hour notification timeline is expected. A written, tested playbook — including escalation paths and DPBI notification templates — is your first line of defense in a penalty proceeding.

    India's Licensed Consent Manager

    truConsent is not a CMP. Not a cookie banner.

    India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.