The History of Indian Privacy — Enforcement Case Studies

    If You Wait for India's First DPDPA Fine, You've Already Lost

    Three global enforcement cases — Sephora (CCPA), H&M (GDPR), Didi (PIPL) — offer a preview of what India's enforcement era will look like. The patterns are clear. Written by Yuvaraj S., Founder, truConsent.

    Context

    The Myth of the Compliance Grace Period

    When a new privacy law passes, there's a common assumption: we have time. The enforcement machinery takes years to spin up. The first few years are advisory, not punitive.

    This assumption has been wrong in every major jurisdiction. GDPR's first significant fine came within 8 months of enforcement. CCPA's first major action came 18 months in. PIPL's first billion-dollar fine came 12 months after the law took effect.

    India's DPDPA passed in August 2023. The DPBI is being established. The Rules are being notified. The window to build compliance infrastructure before enforcement begins is closing.

    Case Study 1

    Sephora (CCPA, 2022)

    Fine: $1.2 Million — First major public CCPA enforcement action

    What happened

    In 2022, the California Attorney General fined Sephora $1.2 million — the first major public CCPA enforcement action. Sephora, a global beauty retailer, had been:

    • 1.Selling consumers' personal data (browsing behaviour, purchase history) to advertising technology companies without disclosure
    • 2.Failing to honour Global Privacy Control (GPC) signals — a browser setting that signals opt-out of data sale
    • 3.Failing to remediate the violations within the mandatory 30-day cure period

    The significance

    • This wasn't a small company or a startup. It was a global brand with sophisticated legal and compliance teams.
    • The AG's investigation was triggered by routine monitoring, not a breach or complaint.
    • The fine was relatively modest ($1.2M), but the reputational signal was large.

    5 Lessons for Indian Businesses

    Lesson 1

    Disclosure is non-negotiable.

    CCPA requires disclosure of any "sale" of personal data. DPDPA requires clear notice of: the specific purposes of processing, the named entities (processors and partners) who will access the data, and the duration of retention. Vague privacy policies are not notice. "To improve your experience" is not a purpose.

    Lesson 2

    Opt-out mechanisms must actually work.

    CCPA required honouring GPC browser signals. Under DPDPA, the equivalent is honouring consent withdrawal requests through the Consent Manager's Data Principal Rights interface — within 72 hours. Having a "withdraw consent" button that routes to a broken form is not compliance.

    Lesson 3

    Your advertising stack is your compliance risk.

    Sephora's violation was caused by third-party ad tech collecting and using data. Under DPDPA, Data Fiduciaries are liable for their Data Processors' actions. Your advertising partners, analytics vendors, and marketing platforms are your processors — their data practices are your legal obligation.

    Lesson 4

    There is no cure period in DPDPA.

    CCPA gave companies a 30-day window to fix violations before penalty. DPDPA does not have an equivalent provision. Once a complaint is lodged with the DPBI, the penalty clock starts. The time to fix is now, not after a notice arrives.

    Lesson 5

    Regulators use monitoring, not just complaints.

    Sephora wasn't caught because a customer complained. The AG's office proactively monitored compliance with the CCPA opt-out provisions. India's DPBI may develop similar proactive monitoring capacity over time. Assume you're being watched.

    Case Study 2

    H&M Germany (GDPR, 2020) — ₹350 Crore Equivalent

    Fine: €35.3 Million — approximately ₹350 crore at today's rates, higher than DPDPA's maximum per breach

    What happened

    H&M's service centre in Nuremberg created detailed personal dossiers on hundreds of employees. Information collected included:

    • Religious beliefs and family circumstances gathered during "welcome back" conversations after holidays
    • Medical diagnoses discussed in return-from-sick-leave conversations
    • Performance evaluations linked to personal circumstances

    This information was accessible to over 50 managers across Europe.

    Why it matters for Indian businesses

    DPDPA covers all personal data collected digitally — including employee data. India's workforce management practices often involve extensive data collection: biometrics, attendance, health declarations, performance reviews. Each of these is personal data under DPDPA.

    Specific India risks

    • Collecting health data during medical leave approvals without consent basis
    • Storing biometric attendance data without security safeguards
    • Using employee personal data for non-employment purposes

    Case Study 3

    Didi Global (PIPL, 2022) — ₹10,000 Crore Equivalent

    Fine: ¥8.026 Billion (~$1.2B USD) — approximately ₹10,000 crore

    What happened

    Didi Global, China's ride-hailing giant, listed on the NYSE in June 2021 — while a PIPL investigation was already underway. The Cyberspace Administration of China (CAC) found:

    • Illegal collection of personal data from 107 million+ users
    • Illegal transfer of data outside China
    • Serious security failures

    The IPO factor

    Didi's listing while under investigation triggered the regulator's most aggressive response. The lesson: privacy compliance status is now an M&A and IPO due diligence item.

    Why it matters for Indian businesses

    Any Indian company planning fundraising, acquisition, or public listing should expect DPDPA compliance to be part of due diligence. Investors and acquirers increasingly require evidence of:

    • Active consent management (with audit logs)
    • Data Principal rights implementation
    • Breach response playbook
    • Processor agreement management

    Action Plan

    The Pre-Enforcement Compliance Checklist

    Enforcement timing is uncertain. Compliance requirements are not. These eight items represent the highest-risk gaps across most Indian organisations today.

    01

    Every data collection form has an itemized purpose statement

    Specific, granular, not generic. Not 'to improve your experience' — but named, concrete purposes for each data element collected.

    02

    Consent records are stored with timestamps, purpose-linkage, and withdrawal logs

    Ready for DPBI audit at any time. Consent without an audit trail is not defensible consent.

    03

    Consent withdrawal is functional and the 72-hour SLA is operational

    The withdrawal path must work end-to-end. Test it. Time it. A broken withdrawal flow is a visible, provable violation.

    04

    Age verification or declaration is in place for any service that might be used by users under 18

    India's DPDPA sets the threshold at 18 — stricter than GDPR's 16. Verifiable parental consent is required. This is the area most likely to see early enforcement.

    05

    All Data Processor agreements are updated

    Include DPDPA obligations, audit rights, and breach notification requirements. Your processors' failures are your liability.

    06

    A documented 72-hour breach response playbook exists and has been tested

    Include escalation paths, DPBI notification templates, and communication scripts. Untested playbooks fail under pressure.

    07

    Your advertising and analytics stack has been reviewed

    Third-party data processors — ad tech, analytics, marketing platforms — must be contractually bound to DPDPA obligations.

    08

    Employee data practices have been reviewed against DPDPA obligations

    Biometrics, attendance, health declarations, and performance data are personal data under DPDPA. Ensure each has a valid consent or legitimate use basis.

    Closing

    Enforcement Is Coming. The Question Is Whether You're Ready.

    Every major privacy law has had a first case. That case becomes the reference point — companies cite it for years when explaining why they invested in compliance.

    India's first DPDPA enforcement case will set the tone for the DPBI's posture, the penalty range regulators find reasonable, and the types of violations that attract the most scrutiny.

    The businesses that build compliance infrastructure now — before that case happens — will be the ones citing it as validation, not scrambling to catch up.

    India's Licensed Consent Manager

    truConsent is not a CMP. Not a cookie banner.

    India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.