Three global enforcement cases — Sephora (CCPA), H&M (GDPR), Didi (PIPL) — offer a preview of what India's enforcement era will look like. The patterns are clear. Written by Yuvaraj S., Founder, truConsent.
Context
When a new privacy law passes, there's a common assumption: we have time. The enforcement machinery takes years to spin up. The first few years are advisory, not punitive.
This assumption has been wrong in every major jurisdiction. GDPR's first significant fine came within 8 months of enforcement. CCPA's first major action came 18 months in. PIPL's first billion-dollar fine came 12 months after the law took effect.
India's DPDPA passed in August 2023. The DPBI is being established. The Rules are being notified. The window to build compliance infrastructure before enforcement begins is closing.
Case Study 1
Fine: $1.2 Million — First major public CCPA enforcement action
In 2022, the California Attorney General fined Sephora $1.2 million — the first major public CCPA enforcement action. Sephora, a global beauty retailer, had been:
CCPA requires disclosure of any "sale" of personal data. DPDPA requires clear notice of: the specific purposes of processing, the named entities (processors and partners) who will access the data, and the duration of retention. Vague privacy policies are not notice. "To improve your experience" is not a purpose.
CCPA required honouring GPC browser signals. Under DPDPA, the equivalent is honouring consent withdrawal requests through the Consent Manager's Data Principal Rights interface — within 72 hours. Having a "withdraw consent" button that routes to a broken form is not compliance.
Sephora's violation was caused by third-party ad tech collecting and using data. Under DPDPA, Data Fiduciaries are liable for their Data Processors' actions. Your advertising partners, analytics vendors, and marketing platforms are your processors — their data practices are your legal obligation.
CCPA gave companies a 30-day window to fix violations before penalty. DPDPA does not have an equivalent provision. Once a complaint is lodged with the DPBI, the penalty clock starts. The time to fix is now, not after a notice arrives.
Sephora wasn't caught because a customer complained. The AG's office proactively monitored compliance with the CCPA opt-out provisions. India's DPBI may develop similar proactive monitoring capacity over time. Assume you're being watched.
Case Study 2
Fine: €35.3 Million — approximately ₹350 crore at today's rates, higher than DPDPA's maximum per breach
H&M's service centre in Nuremberg created detailed personal dossiers on hundreds of employees. Information collected included:
This information was accessible to over 50 managers across Europe.
DPDPA covers all personal data collected digitally — including employee data. India's workforce management practices often involve extensive data collection: biometrics, attendance, health declarations, performance reviews. Each of these is personal data under DPDPA.
Case Study 3
Fine: ¥8.026 Billion (~$1.2B USD) — approximately ₹10,000 crore
Didi Global, China's ride-hailing giant, listed on the NYSE in June 2021 — while a PIPL investigation was already underway. The Cyberspace Administration of China (CAC) found:
Didi's listing while under investigation triggered the regulator's most aggressive response. The lesson: privacy compliance status is now an M&A and IPO due diligence item.
Any Indian company planning fundraising, acquisition, or public listing should expect DPDPA compliance to be part of due diligence. Investors and acquirers increasingly require evidence of:
Action Plan
Enforcement timing is uncertain. Compliance requirements are not. These eight items represent the highest-risk gaps across most Indian organisations today.
Specific, granular, not generic. Not 'to improve your experience' — but named, concrete purposes for each data element collected.
Ready for DPBI audit at any time. Consent without an audit trail is not defensible consent.
The withdrawal path must work end-to-end. Test it. Time it. A broken withdrawal flow is a visible, provable violation.
India's DPDPA sets the threshold at 18 — stricter than GDPR's 16. Verifiable parental consent is required. This is the area most likely to see early enforcement.
Include DPDPA obligations, audit rights, and breach notification requirements. Your processors' failures are your liability.
Include escalation paths, DPBI notification templates, and communication scripts. Untested playbooks fail under pressure.
Third-party data processors — ad tech, analytics, marketing platforms — must be contractually bound to DPDPA obligations.
Biometrics, attendance, health declarations, and performance data are personal data under DPDPA. Ensure each has a valid consent or legitimate use basis.
Closing
Every major privacy law has had a first case. That case becomes the reference point — companies cite it for years when explaining why they invested in compliance.
India's first DPDPA enforcement case will set the tone for the DPBI's posture, the penalty range regulators find reasonable, and the types of violations that attract the most scrutiny.
The businesses that build compliance infrastructure now — before that case happens — will be the ones citing it as validation, not scrambling to catch up.
India is the only country where a Consent Manager is a licensed intermediary accountable to a regulator. truConsent is built specifically for DPDPA 2023 — consent lifecycle, data principal rights, breach management, and more.