Recent high-profile incidents, including a major insurer’s data breach and WazirX’s $230 million crypto hack, highlight how prompt and clear corporate responses are shaping public trust in India’s surveillance economy.
Indian consumers have become increasingly sceptical of promises about data protection, and recent breaches have made that suspicion harder for companies to shake. In one of the most damaging examples, a major insurer’s 2024 breach reportedly exposed policyholder medical and financial records for sale on Telegram, and the company’s initial denial deepened the reputational damage when the evidence became impossible to dispute.
WazirX offered a contrasting case. After a July 18, 2024 security breach that led to the theft of more than $230 million in digital assets, the cryptocurrency exchange moved quickly to frame the incident as a problem that could still be addressed. According to reports from TechCrunch, The Block and The Times of India, the attack targeted a multisignature Ethereum wallet, forced the exchange to suspend withdrawals and sent its WRX token lower. WazirX later announced a recovery effort that included a bounty of up to $10,000 for information helping to freeze the stolen funds and a reward of 10% of recovered assets for ethical hackers.
That response mattered because it shaped the story around the breach as much as the breach itself. As The Block reported, the exchange presented the bounty as part of a wider recovery programme, an approach that suggested active mitigation rather than legal caution or public silence. By contrast, the damage to the insurer’s credibility stemmed less from the leak than from the sequence of denials that preceded acknowledgement. In both cases, the gap between what happened and what was said about it became central to public judgement.
The broader regulatory environment has also raised the standard for how companies speak about data. India’s Digital Personal Data Protection Act, passed in 2023, has been moving towards operational implementation through 2025 and 2026, pushing firms to rewrite privacy policies in plainer language and to describe consent and data use more clearly. Fintech and health-tech companies have responded by making privacy controls more visible to users. PhonePe and CRED, for example, have both treated data control as a product feature rather than a buried setting.
Payment companies have drawn on a different trust narrative: localisation. RBI rules requiring payment data to be stored on servers within India have allowed firms such as Razorpay to market domestic storage as a reassurance to businesses wary of foreign cloud dependence. That message has emotional force as well as technical meaning, especially after the backlash to WhatsApp’s privacy policy in 2021, when some users shifted towards Signal and Telegram over fears about data sharing with Meta. In this context, “your data stays in India” is not just compliance language; it is a signal of sovereignty.
The lesson across these episodes is that privacy claims are now judged almost in real time. Leaked databases, researcher disclosures and media reporting can expose contradictions within hours, not months. Companies that fare better after a breach tend to disclose the scale early, explain remediation in precise technical terms and treat regulatory timelines as a minimum rather than a target. WazirX’s own case shows the limits of that strategy, however. Even after its recovery efforts, reports in September 2024 said the hacker had begun moving stolen ether through Tornado Cash, while restructuring plans suggested customers might recover only a portion of their funds.
The deeper problem remains unchanged. India’s digital economy depends on collecting the very information consumers are now most wary of sharing. UPI needs transaction data to function. Health platforms need medical records. Ride-hailing services require constant location access. The challenge for companies is not to pretend that data collection can be avoided, but to show, with enough speed and specificity, that it is being handled honestly. In a surveillance economy, trust is no longer built by broad assurances. It is built by the detail that survives scrutiny.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





