'Too Small to Be Fined' Is Over: What GDPR's 2026 Enforcement Wave Means for Indian SMEs Under DPDP
A EUR 825 million GDPR fine against Uber in August 2026 is the latest sign that privacy regulators no longer spare smaller companies. Here is what that enforcement trend means for Indian SMEs preparing for the DPDP Act's May 2027 deadline.
On 21 August 2026, the Dutch data protection authority fined Uber €824.99 million. It was the second-largest penalty ever issued under the GDPR, behind only the €1.2 billion levied against Meta in 2023. When a headline like that crosses a founder's desk in Bengaluru or Pune, the reflex is to file it under "big company problem." That reflex is exactly where DPDP Act enforcement risk begins for a small or mid-sized Indian business, because the assumption that regulators only chase giants no longer holds anywhere.
The number smaller companies keep misreading
Cumulative GDPR fines have now passed €7.1 billion. The headline totals are driven by a handful of nine-figure cases, so it is easy to conclude that enforcement is a Big Tech story. The data says otherwise. Between January 2023 and early 2026, European regulators issued more fines against smaller businesses than in the previous five years combined, according to enforcement trackers compiled from published decisions. Authorities across the EU now receive on the order of 440 breach notifications a day.
The pattern matters for India because the DPDP Act, 2023 was written in the same regulatory generation as the GDPR and borrows its enforcement logic: a dedicated regulator, high monetary ceilings, and complaints that can come from any affected individual. India's Data Protection Board is being assembled to do the same job the Dutch and Irish authorities have been doing for years. Small size is not a shield in that model. It is often the reason a company got sloppy in the first place.
What the Uber case actually turned on
The Dutch authority did not fine Uber for a hack. It fined the company for letting software deactivate drivers' accounts between 2018 and 2022 with no human reviewing the decision and without telling drivers clearly that an algorithm had judged them. The legal hook was the GDPR's restriction on fully automated decisions that significantly affect a person.
Here is the honest distinction Indian businesses should hold onto: the DPDP Act does not contain a direct equivalent to that automated-decision rule. If your startup runs credit scoring or fraud flags through a model, DPDP does not, as written, give a person the right to demand human review the way European law does. So the Uber fine is not a one-to-one warning about algorithms under Indian law.
What it does warn about is everything around the algorithm. Uber's real failure was in notice and transparency, telling people what was being done with their data and why. Those obligations sit at the centre of the DPDP framework. A notice that is vague, buried, or missing is one of the easiest violations for a regulator to establish, and it does not require a data breach to trigger.
India's clock is fixed; the excuses are running out
The DPDP Rules, 2025 were notified in mid-November 2025, and the timeline is now concrete rather than speculative. The Data Protection Board's institutional provisions came into force immediately. The consent manager registration framework becomes operational around 13 November 2026. The substantive duties that apply to ordinary businesses, notice, valid consent, data-principal rights, breach notification, and security safeguards, take full effect around 13 May 2027.
That last date is the one a mid-sized company should circle. It is far enough away to feel comfortable and close enough that a proper programme, vendor contracts, a working consent flow, a breach playbook, cannot be assembled in a panic the week before.
The penalty ceilings are set out in the Act's Schedule and they are not decorative. Failure to maintain reasonable security safeguards can draw up to ₹250 crore. Failure to notify the Board and affected individuals of a breach can draw up to ₹200 crore, and the Board has signalled a 72-hour expectation for breach reporting. Those two are separate slabs, so a single badly handled incident, weak security that causes a breach, then a missed notification, can attract both. For a company doing ₹50 crore in annual revenue, either number is existential.
Where a smaller Indian business is genuinely exposed
Three areas account for most of the risk, and none of them depend on you being large. The first is security. "Reasonable safeguards" is judged after the fact, and a leaked customer database with plaintext passwords is difficult to defend regardless of headcount. The second is consent and notice, the paperwork that proves you told people what you collect and got a lawful basis to collect it. The third is your vendors, because you stay responsible for personal data even after it moves to a payroll tool, a cloud CRM, or an offshore analytics contractor.
A useful early step is a plain data map: what personal data you hold, where it lives, who you share it with, and why. That single document tells you whether you are closer to compliant than you feared or further away than you hoped. A structured privacy impact assessment turns that map into a prioritised list of fixes.
What to actually do before May 2027
Start with the cheap, high-value moves. Rewrite your privacy notice so a normal person can understand it. Fix the obvious security gaps, encryption, access controls, and removing data you no longer need. Put a written breach-response process in place and rehearse it once, so the 72-hour window is a checklist rather than a scramble. Get data-processing terms into your vendor contracts. Decide who owns privacy internally, even if that person wears three other hats today.
If you also sell into Europe or process EU residents' data, treat GDPR and DPDP as one programme rather than two, since the underlying discipline overlaps heavily; our note on GDPR compliance consulting covers where they diverge. For the India-specific groundwork, our DPDP Act compliance overview lays out the obligations in sequence.
The lesson from a €825 million fine is not that Indian regulators will match that number tomorrow. It is that the era of assuming you are too small to be looked at has ended in every jurisdiction that has stood up a real privacy regulator, and India is standing one up now. The businesses that come out fine are the ones that started while the deadline still felt distant.
This article is general guidance for Indian businesses and not legal advice; your obligations depend on your specific facts. For a tailored view, work through our DPDP compliance checklist or get in touch for a readiness conversation.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation