In 2024, Ticketmaster disclosed a breach affecting 560 million customers. The fine was not the most damaging part. The most damaging part was the revelation that the company could not demonstrate what security controls were in place before the breach. Status claims — "we follow best practices", "we have a security programme" — collapsed under regulatory scrutiny. The same dynamic is now reaching Indian companies under DPDP.
The status trap
Most companies approach data protection as a status game. They acquire a badge (ISO 27001, SOC 2, or similar), display it on their website, and consider the matter closed. The problem is that a badge certifies a point-in-time assessment by an auditor who visited your systems on a specific date. It does not prove that your controls worked last Tuesday, or that your data was protected in the three months since the audit.
Regulators and breach investigators do not ask "do you have a certificate?" They ask "show me your access logs from the week before the incident", "when was this encryption configuration last verified?", "what evidence do you have that this control was operational at the time of the breach?" These are questions that no certificate can answer.
What evidence actually means
Evidence, in the context of data protection, means timestamped, source-linked records of control activity. Not assertions about policies. Not screenshots assembled after the fact. Records that prove a specific control was operational at a specific time, with a verifiable audit trail.
- Timestamped: The exact date and time of verification or detection, not an approximate quarter.
- Source-linked: Tied to the specific system, not a generic policy statement.
- Continuous: Generated automatically as a side effect of normal operations, not assembled during an audit.
- Verifiable: Tamper-evident — the record itself proves it was not created after the fact.
IBM's 2025 Cost of a Data Breach Report found that organisations with automated security tooling saved an average of ₹140 crore per breach compared to those relying on manual processes. The gap is widening every year.
The GDPR precedent India is inheriting
Europe's GDPR enforcement has run for seven years. The pattern is consistent: the largest fines have not gone to companies that suffered breaches — they have gone to companies that could not demonstrate they had appropriate controls before the breach. Meta's €1.2B fine, Amazon's €746M fine — both centred on the inability to prove processing was lawful, not merely on the fact that data was misused.
DPDP's penalty structure mirrors this logic. The ₹250 crore cap is for situations where reasonable security safeguards were not implemented — a question that is answered by evidence, not by policy documents.
Three moments when evidence is demanded
- Enterprise procurement: B2B customers with their own compliance obligations are requiring vendors to demonstrate data protection practices. A questionnaire answered with "we have a policy" fails; evidence of a running data inventory and active risk management passes.
- Investor due diligence: Post-DPDP, data risk has joined financial risk and operational risk as a standard due diligence category. Investors are asking specifically about personal data exposure, breach notification capability, and evidence of controls.
- Regulatory investigation: The Data Protection Board can initiate investigations on its own motion, not just on complaint. The standard of proof will be evidence, not assertions.
The shift from reporting to continuous signalling
The technology industry is undergoing a shift in how compliance is understood. The old model: gather evidence annually, produce a report, receive a certificate. The new model: emit evidence continuously as a byproduct of normal system operation, and surface it on demand.
This is the same shift that happened in infrastructure monitoring a decade ago. Nobody serious about reliability runs quarterly server health checks anymore — monitoring is continuous, alerts are real-time, and historical data is always available. Data protection is heading in the same direction, driven by the same force: the cost of finding out about a problem after the fact is catastrophically higher than detecting it continuously.
Takeaway
The question is not whether your company is compliant today. The question is whether you can prove it — specifically, at the moment someone asks. Every risk finding, every scan result, every access control review generates evidence only if you have a system designed to capture it. Otherwise, you are back to assembling screenshots three weeks after the question was asked.