India's first data-protection adjudication may end without a verdict — and that itself would set the precedent. The gaming platform in the children's-data case has proposed a consent-decree route: a full age-verification rebuild to the Board's specification, two years of third-party audits, deletion of the contested behavioural profiles, and a compensation fund for affected minors' families.
The offer forces the Board's real first decision: whether Indian privacy enforcement prices remediation or deterrence. Accept, and every fiduciary learns violations are negotiable engineering debts; reject and litigate, and the ₹250-crore penalty band gets its first market test — along with years of appeals.
The regulatory craft argument cuts both ways. Consent decrees built modern American privacy practice — binding, auditable, faster than trials; but India's regime is young enough that its first outcome becomes its reputation, and civil-society interveners are urging the Board to write at least a reasoned order on the violations before any settlement.
The platform's calculus is plain: the evidentiary trail — its own age-gate flags feeding ad profiles — made trial odds ugly.
The Board hears the proposal on July 30, with the consent-manager rollout proceeding in parallel. Whichever door it chooses, the era of theoretical Indian privacy law ends this month. Analysis on our tech desk.

