
Introduction
In August, Meta’s technical team and the Ministry of Electronics and Information Technology (MeitY) lead to the government clarifying that Meta’s platforms in India must be governed by Indian law, not merely by the company’s global policies. The discussion focused on content moderation, deepfakes, child sexual abuse material (CSAM), and the opacity of Meta’s recommendation systems, with officials seeking clarity on why flagged synthetic content continues to resurface and how the platform’s algorithms determine what users see. Viewed in isolation, this appears to be a familiar story about intermediary accountability under the Information Technology Act, 2000 (“IT Act”).
Meta’s data practices, its consent architecture for targeted advertising, and its handling of children’s information have already been tested repeatedly by European regulators, with penalties running into billions of euros. India has its own data protection statute, the Digital Personal Data Protection Act, 2023 (“DPDP Act”), built on many of the same principles. The real question, then, is not whether India has comparable law on paper, but whether it currently has comparable capacity to enforce it against a platform like Meta.
Consent on Paper Looks Familiar
The DPDP Act’s consent framework will be familiar to anyone acquainted with the General Data Protection Regulation (“GDPR”). Section 6 of the DPDP Act requires consent to be free, specific, informed, unconditional, and unambiguous, accompanied by clear affirmative action, and limited to what is necessary for the stated purpose. Section 5 obliges a Data Fiduciary to provide notice describing the personal data collected and the purpose of processing, and withdrawal of consent must be as easy as giving it. Section 9 goes further than many comparable regimes by expressly prohibiting behavioural monitoring and targeted advertising directed at children, alongside a requirement for verifiable parental consent. Section 16 addresses cross-border data transfers through a “negative list” approach, restricting transfers only to countries the government specifically notifies the reverse of the GDPR’s adequacy-based, “whitelist” model.
None of this is a weak framework in the abstract. A platform built around behavioural profiling and cross-platform data use, of the kind Meta operates, sits squarely within what these provisions are designed to reach. The difficulty is that a consent standard only does meaningful work once someone is actually testing whether it has been met.
The Enforcement Gap
This is where the comparison with Europe becomes especially significant. The DPDP Rules were notified only in November 2025 more than two years after the Act itself received presidential assent and their implementation is being staggered. The Data Protection Board became operative immediately, but the Consent Manager framework is not expected until around November 2026, and the substantive obligations that actually bind Data Fiduciaries including breach reporting and a penalty regime of up to ₹250 crore will not become enforceable until May 2027.
Ireland’s Data Protection Commission, acting under the GDPR’s one-stop shop mechanism and often at the direction of the European Data Protection Board, fined Meta entities repeatedly. Instagram was fined 405 million euros in 2022 over children’s data, after an inquiry found teenage users’ contact details were exposed through business accounts set to public by default. Facebook and Instagram together were fined 390 million euros in January 2023 after regulators rejected Meta’s reliance on contractual necessity as a legal basis for behavioural advertising, a decision the European Data Protection Board (“EDPB”) later hardened into a binding order applicable across the EU.
In Meta was fined 1.2 billion euros in May 2023, the largest GDPR penalty issued to date, over unlawful transfers of European users’ data to the United States, accompanied by an order to suspend those transfers and cease the unlawful processing entirely. Each of these was accompanied by a binding requirement to change how Meta actually processes data, not merely a monetary penalty. India has produced no equivalent sequence, not because the underlying conduct is absent, but because the machinery capable of testing it has not yet been switched on.
What Has Actually Disciplined Meta in India
In the interim, the closest India has come to holding Meta accountable for a data practice arose not from privacy law but from competition law. In November 2024, the Competition Commission of India (“CCI”) found that WhatsApp’s 2021 privacy policy update, which made data sharing with other Meta companies mandatory on a take-it or leave-it basis, amounted to an abuse of dominant position. The CCI imposed a penalty of ₹213.4 crore along with a five-year prohibition on sharing user data for advertising purposes. The National Company Law Appellate Tribunal (“NCLAT”), in November 2025, upheld the monetary penalty but lifted the outright prohibition, reasoning that a blanket ban could disrupt WhatsApp’s business model provided users were given meaningful choice, and clarified the following month that consent and transparency safeguards would still apply to all data sharing with Meta entities, including for advertising. Both Meta and the CCI have since appealed to the Supreme Court, with the MeitY impleaded as a party, and WhatsApp informed the Court in February 2026 that it would implement a consent-based data sharing framework while the main appeal remains pending.
What is notable about this case is not only its outcome, but its route. A dispute that was substantively about consent, purpose limitation and a user’s ability to control how their data moves between Meta entities was litigated through competition law because the DPDP Act’s own enforcement architecture was not yet available when the conduct occurred. Legal commentary following the case has already this as precisely the gap the DPDP framework is intended to close once it becomes fully operative.
The Part Nobody Has Tested Yet
The MeitY engagement earlier this month is a useful indicator of how India currently exercises leverage over Meta, largely through content moderation obligations and intermediary safe harbour under Section 79 of the IT Act, rather than through the data protection statute built for exactly this purpose. No one in India has yet examined Meta’s ad-targeting architecture the way the EDPB examined its reliance on “contractual necessity”, and no Indian regulator has yet had occasion to test where legitimate processing ends and impermissible profiling begins under Section 4 of the DPDP Act. That test is still to come.
AMLEGALS Remarks
The comparison this raises is not between a strong foreign law and a weak Indian one. On its text, the DPDP Act draws on the same regulatory vocabulary that has repeatedly disciplined Meta in Europe, and in its treatment of children’s data, it goes further than the GDPR does explicitly. What currently separates the two jurisdictions is not the statute, but the track record behind it. A consent standard that has fined the same corporate group more than 2 billion Euros across three separate matters looks materially different from one that has not yet had the opportunity to be tested against a single Data Fiduciary.
For Meta, and for platforms in a comparable position, the 18 months remaining before the DPDP Act’s substantive obligations take full effect are best spent building the consent trails, children’s data safeguards, and cross-border transfer documentation that the Act already requires in text. The conduct that drew Europe’s largest privacy fines sits squarely within what Sections 6, 9, and 16 of the DPDP Act are designed to reach. The only thing India has not yet had is a live regulator asking the question.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
