By Onkar Sharma
I’ve spent the better part of two decades sitting at the intersection of journalism, corporate communications, and enterprise technology, and if there’s one pattern I keep seeing repeat itself — across industries, across geographies, across company sizes — it’s this: organisations treat regulatory compliance as a cost centre until the day it becomes an existential one. This week gave us a textbook example of exactly that reckoning, and I think it’s worth unpacking in some detail.
What actually happened
On August 5, 2026, Mark Zuckerberg apologised to the Indian government over the presence of child sexual abuse material (CSAM), deepfake content, and what officials described as “shortcomings in the operation” of Meta’s platforms. This wasn’t a routine PR statement issued through a spokesperson. It came directly from the CEO, was conveyed to a parliamentary panel on IT and Communications, and was delivered through senior Meta executives who met India’s Information and Broadcasting Minister, Ashwini Vaishnaw, at his Rail Bhavan office.
What makes this apology consequential rather than symbolic is the legal reasoning behind it. Government sources revealed that Meta was explicitly told its platforms could fall outside the definition of a “neutral intermediary” under Indian law, because Meta actively selects and distributes content to users rather than merely hosting it passively. That distinction matters enormously. Under Section 79 of India’s Information Technology Act, intermediaries — platforms that host third-party content without editorial control — enjoy “safe harbour,” meaning they’re shielded from liability for what users post. The moment a platform is found to be actively curating, ranking, or boosting content — which is exactly what Meta admitted to doing, acknowledging that “a lot of money was paid for boosting certain type of content” — that shield can disappear. Panel chairman Nishikant Dubey was blunt about it, telling Meta it would lose safe harbour provisions entirely if it did not apologise, citing issues ranging from CSAM and harassment to the brief, unexplained removal of a Facebook video of Prime Minister Modi that was restricted for five hours and drew a separate three-day apology deadline from the government.
This is the second time in recent memory that Meta has had to publicly walk something back in India. Earlier, Meta India’s Vice President of Public Policy, Shivnath Thukral, apologised on X after Zuckerberg falsely claimed on a podcast that India’s incumbent government had lost power in the 2024 general election due to its COVID-19 response — a claim Information & Broadcasting Minister Ashwini Vaishnaw publicly fact-checked as untrue.
Two apologies, two different failure modes, one common thread: a global platform operating in a market it hasn’t fully calibrated its compliance posture to.
Why I think this matters beyond Meta
I want to resist the temptation to make this purely a “Big Tech gets its comeuppance” story, because that framing misses the actual lesson. The lesson isn’t about Meta’s size or Zuckerberg’s persona. It’s about a structural risk that applies to any organisation — a 50-person SaaS startup as much as a trillion-dollar platform — operating across jurisdictions with divergent, evolving, and sometimes ambiguous regulatory frameworks.
Non-compliance is pernicious precisely because it rarely announces itself as a single, dramatic failure. It accumulates. A grievance officer appointment that’s delayed by a few weeks. A data localisation requirement that engineering deprioritises because “it’s just a formality.” A content moderation policy written for one legal regime and quietly applied everywhere else. Each of these looks, in isolation, like an operational footnote. Together, they compound into exactly the kind of systemic exposure Meta is now navigating publicly, in front of a parliamentary committee, with its CEO’s name attached to the apology.
I’ve worked inside large enterprises long enough to know why this happens. Compliance functions are frequently under-resourced relative to the speed at which product and growth teams move. Legal and policy teams get looped in after launch decisions, not before. And headquarters — usually in the US or another Western jurisdiction — tends to underestimate how differently “content,” “data,” and “platform neutrality” are defined once you cross into markets like India, the EU, or China, each of which has built its own regulatory philosophy around digital platforms.
The pattern, seen globally
Meta’s India episode isn’t an outlier. It’s part of a well-documented, repeating pattern of platforms colliding with local law because they treated global uniformity as a shortcut rather than a risk.
Meta’s own record in Europe is the clearest illustration of how expensive this pattern can get. In May 2023, Ireland’s Data Protection Commission fined Meta Ireland a record €1.2 billion — the largest penalty ever issued under the EU’s General Data Protection Regulation — for unlawfully transferring the personal data of EU users to the United States without adequate safeguards, in breach of the GDPR’s post-Schrems II data transfer rules. That fine came on top of more than €600 million in separate GDPR penalties the same regulator had imposed on Meta in 2022. The European Data Protection Board specifically noted that Meta’s infringement was “very serious” precisely because the transfers were “systematic, repetitive and continuous” — in other words, not a one-off lapse but a business-as-usual practice that never got re-engineered for the jurisdiction it operated in. (BDO summary; IAPP report)
Before Meta held that record, Amazon did — Luxembourg’s data protection authority fined the company €746 million in 2021, again under GDPR, for its advertising data practices. And WhatsApp was fined €225 million by the Irish DPC in 2021 for failing to properly disclose to users how their data was shared with Meta’s other companies. The through-line across all three cases is the same: platforms built architecture and business practices around one regulatory logic (largely American, permissive by comparison) and treated European rules as an add-on compliance layer rather than a design constraint.
The pattern, seen at home in India
India’s own regulatory history with digital platforms offers just as sharp a set of examples, and I think Indian marketing and communications professionals — my own tribe — need to internalise these as much as any legal or policy team does, because the reputational fallout always lands first on brand and communications functions.
Twitter (before its rebrand to X) lost its intermediary status in India in June 2021 for failing to comply with the newly notified IT (Intermediary Guidelines and Digital Ethics Code) Rules, 2021 — specifically, the requirement to appoint a resident grievance officer, a nodal contact person, and a chief compliance officer, all based in India. The government’s position, later reiterated in an affidavit to the Delhi High Court, was unambiguous: non-compliance with the Rules meant Twitter’s Section 79 safe harbour “stood withdrawn,” making the company a publisher rather than a neutral intermediary, and therefore directly liable for user content on its platform. This is the exact legal mechanism now being invoked against Meta four years later — which tells me Indian regulators have learned to use this lever with increasing confidence and consistency. (The Print; Business Standard)
The 2020 ban of 59 Chinese apps, including TikTok, is another instructive case, though its trigger was framed more around national security than routine regulatory friction. The Ministry of Electronics and Information Technology invoked Section 69A of the IT Act to block TikTok, WeChat, UC Browser, Shein, Club Factory, and dozens of others, citing complaints that these apps were “stealing and surreptitiously transmitting users’ data in an unauthorised manner to servers which have locations outside India.” For TikTok specifically, India was its largest overseas market at the time, and the ban effectively erased that business overnight. The episode is a reminder that data localisation and cross-border data flow aren’t abstract legal clauses — they’re existential product decisions, and getting them wrong can mean losing a market entirely, not just paying a fine. (Forbes; CNBC)
Paytm Payments Bank’s regulatory unwinding, culminating in the RBI’s January 2024 order barring it from accepting fresh deposits, is the fintech-sector equivalent, and it’s arguably the most sobering because it shows how slowly — and then how suddenly — these things play out. The RBI first restricted the bank from onboarding new customers in March 2022, citing “material supervisory concerns.” A comprehensive system audit followed, and its findings of “persistent non-compliances,” particularly around KYC and anti-money-laundering checks, led to the near-total shutdown of the bank’s operations two years later. The RBI Governor was explicit about the sequencing: the central bank engages bilaterally first, nudges regulated entities toward corrective action, and only imposes business restrictions “when such constructive engagement does not work.” Paytm had two years of runway to fix the underlying compliance gaps and, by the regulator’s own account, didn’t close them. The result was a 35% single-day fall in Paytm’s stock price and roughly $2 billion in erased investor wealth. (Business Standard; Ikigai Law analysis)
What strikes me across all four of these cases — two global, two Indian — is that in not one of them did the regulator move first. Every single one involved warnings, notices, extended compliance windows, and multiple opportunities to course-correct before the actual penalty landed. Non-compliance, in other words, is rarely a surprise to the organisation experiencing it. It’s usually a known, tracked, internally-flagged risk that leadership chose to deprioritise against other business pressures — until the deadline it was gambling against finally arrived.
What I’d tell any organisation navigating this
Having watched this pattern from both the media side (as a journalist covering enterprise technology) and the corporate side (building content and communications functions inside large organisations), here’s the framework I’d offer, particularly to marketing, communications, and business leaders who often assume compliance is “someone else’s department”:
Treat local regulatory frameworks as product requirements, not legal footnotes. India’s IT Rules, the EU’s GDPR, RBI’s KYC/AML mandates — these aren’t compliance checkboxes to satisfy after the fact. They need to be architectural constraints baked into product, data, and content decisions from day one, especially for any platform operating content recommendation, ranking, or moderation systems.
Appoint local accountability early, not reactively. Nearly every Indian case above — Twitter in 2021, and implicitly Meta now — traces back to delays in appointing India-resident compliance officers, grievance officers, or nodal contacts. This is one of the cheapest, most controllable compliance actions an organisation can take, and it’s routinely the one that gets deprioritised.
Separate “neutral hosting” from “active curation” internally, before a regulator forces you to. The single legal thread connecting Twitter’s 2021 loss of safe harbour and Meta’s 2026 apology is the same: the moment a platform pays to boost content, ranks it algorithmically, or otherwise exercises editorial-style control, it forfeits the legal protections built for passive intermediaries. Any organisation running recommendation engines or paid content boosting needs a clear-eyed internal assessment of where that line sits in each jurisdiction it operates in.
Escalate compliance gaps to the board, not just the legal team. Paytm’s trajectory — two years between the first RBI restriction and the eventual shutdown of banking services — shows that organisations often have real runway to fix things. What determines the outcome is whether leadership treats early regulatory warnings as urgent or as background noise competing with quarterly growth targets.
Build the crisis communications plan before you need it, not during the apology. Every case here eventually required a public, high-visibility apology — from a CEO, a senior VP, or a corporate statement. The organisations that came across as credible were the ones that could point to concrete remedial action alongside the apology. The ones that looked weakest were those apologising into a vacuum, with no visible operational change behind the words.
A closing thought
There’s a reason this story keeps recurring across sectors and geographies — social media, fintech, e-commerce, edtech — and it isn’t that regulators are becoming more aggressive for its own sake. It’s that the digital economy has matured to a point where jurisdictions are no longer willing to accept “global product, local afterthought” as an operating model. India’s regulatory assertiveness, visible across the Twitter, TikTok, Paytm, and now Meta episodes, is part of a broader global recalibration that includes the EU’s GDPR enforcement and similar moves in markets from Indonesia to Brazil.
For any organisation building or scaling in these environments, the real cost of non-compliance was never just the fine or the restriction. It’s the CEO having to personally apologise to a foreign government, the erased market capitalisation, the lost market access, and — perhaps most lasting of all — the erosion of the one thing brand and communications teams spend years building: institutional trust.

No responses yet