Privacy laws are only as credible as their enforcement. Here's what violations have cost around the world — and what Indian businesses should expect when the DPBI starts adjudicating. Written by Yuvaraj S., Founder, truConsent.
Context
When GDPR came into force in May 2018, a predictable chorus emerged: the law was ambitious but unenforceable. Companies would pay lip service to compliance, regulators would lack the capacity to act, and the fines would never materialize at the scale the regulation threatened. Many dismissed early privacy laws as symbolic gestures — good-looking governance with no real teeth.
The fines that followed proved otherwise. By early 2024, GDPR enforcement had crossed €4 billion in total fines. A single case — the Didi Global enforcement in China — reached ¥8 billion (~$1.2 billion). Meta paid €1.2 billion in a single decision. The idea that privacy regulators would not act has been thoroughly discredited.
India's DPDPA has not been enforced yet. The DPBI is established but adjudication has not begun. The Rules are pending notification. But the penalty structure is written into statute, the institutional architecture is in place, and enforcement is coming. The question for Indian businesses is not if — it is when, and more importantly, whether you will be ready.
Global Precedents
Each of these cases shaped how regulators, courts, and companies understand privacy liability. Each has a direct parallel in India's DPDPA framework.
| Law | Company | Fine | Year | Reason | India Parallel |
|---|---|---|---|---|---|
| GDPR | Meta (Ireland) | €1.2 Billion | 2023 | Trans-Atlantic data transfers without adequate safeguards. The largest GDPR fine ever issued. | Cross-border data transfers will be governed by DPDPA's negative list once Rules are notified. |
| GDPR | Amazon (Luxembourg) | €746 Million | 2021 | Cookie consent failures, behavioral advertising served without valid consent. | Consent for marketing and behavioral profiling is central to DPDPA. |
| GDPR | Google (France) | €150 Million | 2022 | Cookie opt-out mechanism designed to be harder than opt-in, violating consent equality. | DPDPA requires consent withdrawal to be as easy as consent giving. |
| GDPR | WhatsApp (Ireland) | €225 Million | 2021 | Lack of transparency in data processing notices — users not told how data was used. | DPDPA mandates clear, itemized notices — purpose, processing activity, named entities. |
| GDPR | LinkedIn (France) | €310 Million | 2024 | Behavioral advertising run without a valid legal basis for processing. | Direct parallel for Indian platforms running targeted advertising. |
| GDPR | TikTok (UK) | £12.7 Million | 2023 | Processing children's data without proper parental consent. | DPDPA has India's strictest children's data provisions — verifiable parental consent required for all users under 18. |
| GDPR | H&M (Germany) | €35.3 Million | 2020 | Illegal monitoring of employee personal data including health, religion, and family details. | HR data is personal data under DPDPA. Workplace data monitoring without consent basis is a violation. |
| CCPA | Sephora | $1.2 Million | 2022 | Failed to disclose data sales and refused to honor Global Privacy Control (GPC) opt-out signals. First major CCPA enforcement action. | DPDPA requires explicit opt-in — failing to honor withdrawal signals creates similar exposure. |
| PIPL (China) | Didi Global | ¥8.026 Billion (~$1.2B) | 2022 | Unlawful data collection, overseas data transfer violations, and security failures at scale. | The largest privacy fine outside the EU — a signal that emerging-market regulators can and will act decisively. |
| Singapore PDPA | SingHealth + IHiS | SGD 750K + SGD 250K | 2018 | 1.5 million patient records stolen in a cyberattack. Both the healthcare provider and its IT operator were fined separately. | DPDPA holds both Data Fiduciaries and Data Processors accountable — processor failures flow back to the fiduciary. |
| Singapore PDPA | GrabCar | SGD 10,000 | 2020 | Driver personal data leaked due to an insecure system update. | Even small-scale breaches from negligent updates are actionable under DPDPA's security safeguards requirement. |
Penalty Architecture
The Act establishes a tiered penalty framework. The tiers are not graduated by company size — they are graduated by the nature of the violation.
Tier 1
Up to ₹50 Crore
~$6M
Tier 2
Up to ₹150 Crore
~$18M
Tier 3
Up to ₹250 Crore
~$30M
Important context: The ₹250 crore figure is not per company — it is per breach instance. A single incident involving inadequate consent, a data breach, and failure to notify could trigger multiple separate penalties. For large businesses processing millions of data principals, the aggregate exposure is significant — and the structural incentive to invest in compliance infrastructure is clear.
Enforcement Outlook
India's DPBI starts as an adjudicatory body, not a proactive regulator. Unlike GDPR's Data Protection Authorities — which conduct audits, issue guidance, and initiate investigations — the DPBI's primary mechanism is responding to complaints. This is important: it means the first enforcement cases will likely be triggered by aggrieved data principals or whistleblowers, not regulator-initiated investigations.
The enforcement pattern in most countries that have activated privacy regimes follows a consistent arc: high-profile cases against large, well-known companies establish precedent and signal seriousness. This is followed by an expanding scope that reaches mid-market businesses. India will likely follow the same trajectory. The first DPBI adjudication will be closely watched — and its outcome will set the tone for years.
India's DPDPA includes a "voluntary undertaking" mechanism — companies can self-report violations and propose remediation measures. This mirrors GDPR's cooperation provisions, which have consistently resulted in reduced penalties when companies engage constructively with regulators rather than contesting at every stage.
Businesses that build compliance infrastructure before enforcement begins gain a documented advantage: evidence of good-faith effort is explicitly a mitigating factor in penalty calculations. A company that can show the DPBI a functioning consent management system, regular data audits, and a tested breach response plan is materially better positioned than one caught scrambling to retrofit compliance after a complaint is filed.
Action Plan
Enforcement timing is uncertain. Compliance requirements are not. These five items represent the highest-risk gaps in most Indian organizations today.
Every data collection form needs a granular purpose statement — not "to improve services" but specific, named purposes for each data element collected.
Users must be able to withdraw consent in the same number of steps as consenting. Audit every consent touchpoint for withdrawal parity.
India's DPDPA sets the threshold at 18 — stricter than GDPR's 16. Verifiable parental consent is required for all users under 18. This is the area where enforcement is likely to be swift.
Your processors' compliance failures are your liability under DPDPA. Every vendor, SaaS tool, and sub-processor agreement must reflect DPDPA obligations.
A 72-hour notification timeline is expected. A written, tested playbook — including escalation paths and DPBI notification templates — is your first line of defense in a penalty proceeding.
India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.