India's digital-law week of 31 August to 6 September 2026 delivered its most consequential development in data-rights enforcement rather than in data-protection law. On 4 September 2026 the Reserve Bank of India announced penalties totalling Rs 34,91,800 against three of India's four credit information companies — on orders all dated 31 August 2026 — for failing to credit statutory compensation to consumers whose credit records were corrected late. The duty enforced is Rs 100 per calendar day beyond a 30-day clock. Alongside it, CERT-In logged twelve vulnerability notes in five working days, six CRITICAL, two that CERT-In records as under active exploitation.
At a Glance — W36 Scoreboard
| # | Pillar | Development | Issuer | Date | Score |
|---|---|---|---|---|---|
| 1 | data-protection | Rs 34,91,800 across three credit bureaus — CIBIL Rs 26,82,800, CRIF High Mark Rs 6,89,600, Equifax Rs 1,19,400; orders all 31 Aug 2026; identical charge — failure to credit compensation to eligible complainants in time; s.25(1)(iii) r/w s.23(4) CIC(R) Act 2005; duty at s.17 Credit Information Reporting Directions 2025 | RBI | 4 Sep 2026 | 10 |
| 2 | cybersecurity | Twelve CIVNs in five working days — CIVN-2026-0429 to 0440; six CRITICAL; two recorded by CERT-In as actively exploited, both on one day — SonicWall SMA1000 (CVE-2026-83548/83549) and Zimbra (CVE-2026-73570) | CERT-In | 31 Aug – 4 Sep 2026 | 9 |
| 3 | fintech-payments | Sammaan Finserve Rs 4.20 lakh — failure to report borrower credit information to CRILC; s.58G(1)(b) r/w s.58B(5)(aa) RBI Act 1934; plus Hinduja Leyland Finance Rs 6.20 lakh (order 2 Sep). Same batch, opposite end of the same data pipe | RBI | 4 Sep 2026 | 7 |
| 4 | cybersecurity | CIVN-2026-0430 — HIGH; Indian vendor Manacle Technologies multi-tenant ERP; unauthenticated RCE (CVE-2026-84147), IDOR (CVE-2026-84148), publicly accessible .git directory (CVE-2026-84149) | CERT-In | 1 Sep 2026 | 6 |
| 5 | fintech-payments | RBI/2026-27/250 — natural-calamity relief reporting moves to the CIMS portal; monthly SCB return replaced by a half-yearly return; first submission due 30 Oct 2026 | RBI | 2 Sep 2026 | 4 |
| 6 | platforms-intermediaries | SEBI PR 54/2026 — MoU with ESMA on cooperation and exchange of information relating to Central Counterparties. Body text did not render; operative terms not reported. PR 53/2026 (3 Sep) on derivative settlement price and the CAS rollout — no cyber or data content | SEBI | 3–4 Sep 2026 | 4 |
| 7 | telecom-emerging | APNIC 62 opened in Mumbai 4 Sep (to 10 Sep), co-hosted by NIXI under MeitY with ISPAI; 600+ participants across 56 economies; NIXI–APNIC MoU on IPv6 and routing security set for 8 Sep (out of window). PIB release dated 7 Sep (out of window) | MeitY / NIXI | 4 Sep 2026 | 4 |
| 8 | cross-pillar | Portal-verified silence: SEBI circulars, CERT-In advisories, TRAI and IRDAI listings all checked, none carried an in-window item. Unretrievable and therefore reported as gaps: MeitY, DoT, NPCI, TDSAT, eGazette search | Multiple | 6 Sep 2026 | 3 |
TL;DR for Founders
Three things to act on this week:
If you furnish data to a credit bureau, or you are one: the Rs 100-a-day credit-correction compensation is now an enforced obligation, not a paper one. Three of the four bureaus were penalised on the same day for the same failure — not for correcting records late, but for not paying the money once liability had arisen. Check whether your organisation can evidence that compensation, once triggered, reached the complainant's bank account within five working days.
If you run a remote-access appliance or a self-hosted mail platform: CERT-In flagged two products under active exploitation on 3 September — SonicWall SMA1000 and Zimbra. Active exploitation is the trigger that makes the six-hour CERT-In reporting clock live rather than theoretical. Confirm versions today: SMA1000 platform 12.4.3-03453 and earlier and 12.5.0-02835 and earlier, Zimbra Collaboration Suite prior to 10.1.20.
If you sell Indian-built enterprise software: CERT-In issued a note against an Indian ERP vendor this week, and one of the three findings was a publicly accessible .git directory exposing enough repository metadata to reconstruct source code. That is a deployment-hygiene defect, not a coding defect, and it is the cheapest class of finding to eliminate before it becomes a CVE with your company's name attached to it.
Top 3 Developments
1. India Enforced a Data-Correction Right This Week — Under Credit Law, Not Data-Protection Law (Data Protection)
What happened: On 4 September 2026 the Reserve Bank of India issued five enforcement press releases. Three of them concerned credit information companies, and all three rested on orders dated 31 August 2026:
| Entity | Penalty | RBI order date | Press release |
|---|---|---|---|
| TransUnion CIBIL Limited | Rs 26,82,800 | 31 August 2026 | 2026-2027/1042 |
| CRIF High Mark Credit Information Services Private Limited | Rs 6,89,600 | 31 August 2026 | announced 4 September 2026 |
| Equifax Credit Information Services Private Limited | Rs 1,19,400 | 31 August 2026 | announced 4 September 2026 |
| Total | Rs 34,91,800 |
The charge is identical in all three releases, and it is narrow: the company failed to credit the compensation amount to the bank accounts of certain eligible complainants, within the prescribed period. Each action followed a statutory inspection with reference to the company's financial position as on 31 March 2025, supervisory findings of non-compliance, a show-cause notice, a written reply and a personal hearing. RBI records in each release that the penalty is based on deficiencies in regulatory compliance and is not intended to pronounce upon the validity of any transaction or agreement between the company and its customers.
The two instruments engaged. The enforcement power is Section 25(1)(iii) read with Section 23(4) of the Credit Information Companies (Regulation) Act, 2005 (CIC(R) Act 2005). Section 23(4) is the Act's residual provision: it reaches any person who contravenes any provision of the Act or of any rule or order made thereunder, or who makes default in complying with any requirement of the Act or any direction issued thereunder, where no specific punishment is provided elsewhere — and it fixes the exposure at a fine which may extend to one lakh rupees, with a further fine which may extend to five thousand rupees for every day during which a continuing contravention or default continues. Section 25(1)(iii) is what allows RBI to impose that amount administratively rather than by prosecution.
The substantive duty is the framework for compensation to customers for delayed updation and rectification of credit information, now consolidated at Section 17 of the Master Direction — Reserve Bank of India (Credit Information Reporting) Directions, 2025 (RBI/DoR/2024-25/125, dated 6 January 2025). Its operative architecture is a nested clock:
- A complaint about credit information must be resolved within thirty calendar days of the date it was first filed.
- The credit institution — bank, NBFC, housing finance company, All-India Financial Institution, asset reconstruction company or cooperative bank — has twenty-one calendar days to send corrected information to the credit information company.
- The credit information company owes compensation if it fails to resolve within thirty calendar days of being informed, notwithstanding that the credit institution supplied the corrected data inside its twenty-one-day window.
- Compensation accrues at Rs 100 per calendar day of delay beyond the thirty-day limit.
- It must be credited to the complainant's bank account within five working days.
Why this is the week's most important item — Veritect analysis. India's most-discussed data-correction right is Section 12 of the Digital Personal Data Protection Act, 2023, which entitles a Data Principal to correction and erasure of personal data. It is not the right that got enforced this week. The right that got enforced is older, narrower, sectoral — and compensatory rather than penal. It does not require the consumer to establish loss, prove intent, or approach an adjudicator; the sum accrues by the day and is payable into a bank account. That makes it, at present, the most operationally complete personal-data remediation remedy in force in India.
Three consequences follow for anyone building a DPDP compliance programme:
- The enforced failure was payment, not correction. All three bureaus were penalised at the last step in the chain. A grievance workflow that closes the ticket when the record is fixed, without a settled mechanism for computing and disbursing an accrued per-day sum, reproduces exactly the defect RBI sanctioned.
- The sanction rested on an inspection, not a complaint. The reference date is 31 March 2025 in all three cases, which means the finding came out of RBI's routine supervisory cycle. Sectoral regulators discover data-handling defects through inspection long before any data-protection adjudicator exists to hear a citizen's grievance.
- Do not read the spread as a defect-rate ranking. The three amounts differ by a factor of about twenty-two between the largest and smallest. RBI did not disclose how any of the three figures was computed. Under Section 23(4) a single continuing default is capped at one lakh rupees plus five thousand rupees per day, so amounts of this size necessarily reflect either an extended continuing default or multiple contraventions — but which, and in what proportion, is not on the record. Any inference about relative data quality across the three bureaus from these numbers alone would be unsupported.
A live thread this does not close: no notification constituting the Data Protection Board of India under Section 18(1) of the Digital Personal Data Protection Act, 2023 was traced as at 8 September 2026. Because MeitY's own listing surfaces and the eGazette ministry-and-date search could not be reached for this batch (see the gaps section below), that is a statement about what was retrievable, not a conclusion that no such notification exists.
2. Twelve CERT-In Notes in Five Working Days, and Two Products Already Under Attack (Cybersecurity)
What happened: Between 31 August and 4 September 2026 CERT-In published twelve vulnerability notes, CIVN-2026-0429 through CIVN-2026-0440. Notes CIVN-2026-0441 to 0443 fall on 7 September and are outside this window. Every severity rating and exploitation status in the table below is as recorded by CERT-In in the note itself.
| CIVN | Date | Subject | Severity | Key identifiers |
|---|---|---|---|---|
| 0429 | 31 Aug | Cisco Crosswork (Data Gateway, Network Controller, Planning, Workflow Manager) | CRITICAL | CVE-2026-20030, 20357, 20358, 20359 |
| 0430 | 1 Sep | Manacle Technologies ERP System (Indian vendor) | HIGH | CVE-2026-84147, 84148, 84149 |
| 0431 | 2 Sep | cPanel and WHM Domain Parking | HIGH | CVE-2026-65643 |
| 0432 | 2 Sep | Adobe products | not individually retrieved | — |
| 0433 | 3 Sep | Next.js path-traversal RCE (Windows hosts) | CRITICAL | CVE-2026-75604 |
| 0434 | 3 Sep | GiveWP plugin for WordPress | CRITICAL | CVE-2026-82222 |
| 0435 | 3 Sep | Cisco Secure Workload REST API authentication bypass | CRITICAL | CVE-2026-20223 |
| 0436 | 3 Sep | Cisco Nexus 9000 Series Silicon One RCE | CRITICAL | CVE-2026-20212 |
| 0437 | 3 Sep | Sonicwall SMA1000 — actively exploited | CRITICAL | CVE-2026-83548, 83549 |
| 0438 | 3 Sep | Zimbra Collaboration Suite — CVE-2026-73570 actively exploited | HIGH | CVE-2026-73570, 50055, 50054, 10631 |
| 0439 | 4 Sep | Mozilla products | not individually retrieved | — |
| 0440 | 4 Sep | Apache Tomcat | not individually retrieved | — |
Nine of the twelve notes were opened and read individually for this tracker; the severities of CIVN-2026-0432, 0439 and 0440 were not separately confirmed and are left blank rather than assumed.
The two that matter most. CIVN-2026-0437 covers Sonicwall SMA1000 models 6210, 7210 and 8200v across all hypervisors, at platform versions 12.4.3-03453 and earlier and 12.5.0-02835 and earlier. The pair of flaws permits a remote unauthenticated attacker to perform server-side request forgery and a remote authenticated administrator to execute arbitrary operating-system commands, with full appliance compromise as the outcome — and CERT-In states the vulnerabilities are being actively exploited in the wild. CIVN-2026-0438 covers Zimbra Collaboration Suite prior to 10.1.20, where the flaws allow bypass of mail-forwarding restrictions, bypass of access-control or authorisation restrictions, or arbitrary operating-system command execution, and the note records that CVE-2026-73570 is likewise under active exploitation.
Attribution note. The exploitation status above is stated by CERT-In in its own vulnerability notes, which is where we read it; it is not taken from a vendor bulletin or a security-news source. CERT-In does not state in either note whether the finding is its own observation or is relayed from the vendor's advisory, and we have not established which. Treat it as CERT-In records active exploitation, not as Veritect has verified active exploitation. The distinction matters operationally: the reporting trigger under the CERT-In Directions is an incident at your own estate, not a published exploitation finding about the product.
Why the compliance posture changes — Veritect analysis. A CRITICAL rating describes potential impact. Active exploitation describes present reality, and it is the point at which two different legal clocks become relevant at once.
- The Directions issued by CERT-In on 28 April 2022 under Section 70B(6) of the Information Technology Act, 2000 (IT Act 2000) — No. 20(3)/2022-CERT-In, effective 28 June 2022 — require mandatory reporting of listed cyber incidents within six hours of noticing them or being brought to notice. Unauthorised access to IT systems and data, and attacks on servers and network appliances, are within the listed categories. Non-compliance with a CERT-In direction attracts the Section 70B(7) penalty of up to one crore rupees, that figure having been substituted for one lakh rupees by the Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023) with effect from 30 November 2023.
- Both affected products sit at classic initial-access positions. An SMA1000 is the remote-access edge; Zimbra is the mail estate. Compromise at either point is rarely self-contained, and the six-hour clock starts at noticing, which for an already-exploited appliance may mean the moment the CERT-In note is read against an unpatched inventory.
The correct escalation is therefore not only when do we patch, but could we detect and file within six hours if this had already happened to us. The two questions have different owners inside most organisations, and only the second one has a statutory deadline attached.
A second observation on the week's shape: three of the six CRITICAL notes — Cisco Crosswork, Cisco Secure Workload and Cisco Nexus 9000 — are in network management and segmentation infrastructure, and CIVN-2026-0435 specifically yields Site Admin privileges across tenant boundaries. This is the second consecutive week in which the security and network-control stack itself, rather than business applications, carries the heaviest ratings. For entities inside a regulated cyber framework, the patch state of tooling that the framework assumes to be functioning is a distinct category of board-level risk from the patch state of the applications it monitors.
3. The Same Enforcement Batch Closed the Other End of the Credit-Data Pipe (Fintech and Payments)
What happened: The 4 September announcement carried two further penalties, both on non-banking financial companies:
- Sammaan Finserve Limited — Rs 4.20 lakh, by order dated 31 August 2026, for failing to report the credit information of its borrower to the Central Repository of Information on Large Credits (CRILC), in contravention of RBI's directions on Early Recognition of Stress and Reporting to CRILC. The power exercised is Section 58G(1)(b) read with Section 58B(5)(aa) of the Reserve Bank of India Act, 1934 (RBI Act 1934), on statutory inspection with reference to 31 March 2025. Press Release 2026-2027/1044.
- Hinduja Leyland Finance Limited — Rs 6.20 lakh, by order dated 2 September 2026, on two sustained charges: failure to put in place a Board-approved pricing policy for microfinance loans, and undertaking synthetic securitisation. Same statutory power, same inspection reference date. Press Release 2026-2027/1049.
Why we group it with the bureau penalties — Veritect analysis. Read on their own, the CRILC penalty is a supervisory-reporting matter and the Hinduja Leyland penalty is a conduct-and-structuring matter. Read as a batch, RBI acted on both ends of the same credit-data pipe within a single announcement:
- At the furnishing end, a lender that did not push borrower information into the central repository. Data that is never reported cannot be reconciled, and its absence is invisible to the consumer.
- At the aggregation end, three bureaus that did not complete the remediation cycle once a consumer had already found an error and complained.
For a lending business, the compliance consequence is that credit-data obligations are not a single control. Furnishing accuracy and timeliness to CRILC and to the bureaus, complaint intake, the twenty-one-day corrected-data turnaround under Section 17 of the Credit Information Reporting Directions 2025, and the downstream compensation computation are four separately supervised steps, and this week RBI sanctioned failures at two of them on the same day.
Regulatory Action Log — Items 4 to 8
| # | Item | Issuer | Date | What it does | Score |
|---|---|---|---|---|---|
| 4 | CIVN-2026-0430 | CERT-In | 1 Sep 2026 | Three HIGH-severity flaws in the Manacle Technologies multi-tenant ERP, an India-headquartered vendor: unauthenticated remote code execution from improper authentication controls plus inadequate file-type validation on upload (CVE-2026-84147); an insecure direct object reference letting parameter manipulation reach other users' sensitive data (CVE-2026-84148); and a publicly accessible .git directory exposing repository metadata sufficient to reconstruct source code (CVE-2026-84149) | 6 |
| 5 | RBI/2026-27/250, CO.FIDD.FSD.No.S544/05-10-001/2026-27 | RBI | 2 Sep 2026 | Moves reporting of relief measures in natural-calamity-affected areas to the Centralised Information Management System (CIMS) portal; discontinues the monthly return for Scheduled Commercial Banks and substitutes a half-yearly return in a revised format. First submission for the half-year ending 30 September 2026 is due by 30 October 2026, thereafter by 30 April. Applies to all SCBs including RRBs and SFBs, Local Area Banks, Urban and Rural Cooperative Banks, NBFCs and AIFIs | 4 |
| 6 | SEBI Press Release No. 54/2026 | SEBI | 4 Sep 2026 | Announces a Memorandum of Understanding with the European Securities and Markets Authority on cooperation and exchange of information relating to Central Counterparties. The listing entry and headline were retrieved from SEBI's own press-release surface; the body text did not render on either the direct fetch or the reader-proxy fetch, so the legal basis, the categories of information exchanged and the CCPs covered are not reported here | 4 |
| 7 | SEBI Press Release No. 53/2026 | SEBI | 3 Sep 2026 | Announces a review of the settlement-price methodology for derivative contracts in the light of the Closing Auction Session rollout. Market-microstructure, with no cyber, data-protection or information-security content; logged for completeness because it is one of only two SEBI items in the window | 3 |
| 8 | APNIC 62, Mumbai | MeitY / NIXI | opened 4 Sep 2026 | The Asia Pacific Network Information Centre's regional conference, covering the region's 56 economies, opened in Mumbai on 4 September and runs to 10 September, co-hosted by the National Internet Exchange of India (NIXI) under MeitY with the Internet Service Providers Association of India and the Government of Maharashtra, with more than 600 participants on routing security, IPv6 deployment, AI-driven services and network operations. A NIXI–APNIC memorandum of understanding on accelerating IPv6 and routing-security deployment was scheduled for 8 September 2026 — outside this window. Date note: the conference opening is in-window; the PIB release recording it (PRID 2307373) is dated 7 September 2026 and is not | 4 |
Research Gaps and Unretrieved Sources
Per CLAUDE.md §5.10, the following are recorded as gaps. None of them is a finding of silence.
Checked at the issuing authority's own listing page, and genuinely empty for 31 August to 6 September 2026:
- SEBI circulars — the listing runs from a circular of 28 August 2026 straight to 7 September 2026. No SEBI circular issued in the window.
- CERT-In advisories (CIAD series) — the index's most recent entry is CIAD-2026-0043 of 28 August 2026 on multiple vulnerabilities in Oracle products. No CERT-In advisory issued in the window; the twelve items above are all Vulnerability Notes (CIVN series), which is a different instrument class.
- TRAI — the press-release listing's most recent entry is Press Release No. 116 of 28 August 2026. No TRAI direction, regulation, consultation paper or recommendation in the window.
- IRDAI — the circulars listing's most recent entry is the circular of 28 August 2026 on migration of reinsurance regulatory returns to the Integrated Business Analytics Platform. No IRDAI circular in the window.
- PIB, Ministry of Electronics and Information Technology release listing — retrievable, and carried no MeitY instrument dated inside the window. The nearest item is the APNIC 62 release of 7 September 2026.
Not retrievable, and therefore reported as unknown rather than absent:
- meity.gov.in —
/whatsnewand/ministry/whats-newboth returned HTTP 404;/documents/gazette-notificationreturned HTTP 404; the homepage rendered with no dated item later than 31 July 2026. No MeitY gazette notification, advisory or draft rule dated in the window was confirmed either way. - dot.gov.in/whatsnew — rendered navigation and cookie notices only, with no dated content. No Department of Telecommunications instrument was confirmed either way.
- npci.org.in circulars path — HTTP 404.
- tdsat.gov.in judgments path — HTTP 404. No TDSAT order in the window was confirmed either way.
- egazette.gov.in — the portal homepage loaded and listed recent extraordinary gazettes from the Government of Delhi, the Ministry of Railways and the Ministry of Road Transport and Highways, but no working ministry-and-date search was reachable. No G.S.R. or S.O. from MeitY or DoT in the window was confirmed either way.
- SEBI Press Release No. 54/2026 body text — headline and date retrieved from SEBI's own surface; the substantive body did not render. The MoU's terms are not stated in this tracker.
Live threads with no movement traced this week — DPDP Rules 2025 phased rollout, constitution of the Data Protection Board of India under Section 18(1) of the Digital Personal Data Protection Act, 2023, further amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, sub-rules under the Telecommunications Act, 2023, the SEBI Cybersecurity and Cyber Resilience Framework, the Promotion and Regulation of Online Gaming Act, 2025 and its 2026 Rules, and the synthetic-media labelling regime. For each of these the relevant primary surface is MeitY, DoT or eGazette, all three of which were unreachable for this batch. Nothing in this tracker should be read as establishing that no instrument issued in those streams between 31 August and 6 September 2026.
What's Next
| Date | What falls due | Instrument |
|---|---|---|
| 8 September 2026 | NIXI–APNIC memorandum of understanding on accelerating IPv6 and routing-security deployment, signed at APNIC 62, Mumbai | MeitY / NIXI |
| 10 September 2026 | APNIC 62 concludes | MeitY / NIXI |
| 30 October 2026 | First half-yearly natural-calamity relief return through the CIMS portal, for the half-year ending 30 September 2026 | RBI/2026-27/250 |
| 30 November 2026 | Industry Standards Forum of Market Infrastructure Institutions to finalise sub-parameters and detailed measurement criteria for the nine IT Resilience Index parameters | SEBI circular HO/47/18/11(1)2026-MRD-TPD1/I/19509/2026 (24 August 2026) |
| 31 January 2027 | ITRI standard operating procedures, after review by each MII's Standing Committee on Technology, to be submitted to SEBI | same |
| 28 February 2027 | ITRI framework operationalisation including the Early Warning System | same |
| 31 March 2027 | First IT Resilience Index computation half-year | same |
Watch items with no fixed date: whether RBI publishes the computation methodology behind the three credit-bureau penalties (it has not, and the spread cannot be interpreted without it); whether the fourth credit information company faces a comparable order on the same inspection cycle; and whether MeitY's listing surfaces are restored, since their continued unavailability is now the single largest blind spot in this tracker's coverage.
Founder Action Items
- Map your credit-data chain end to end. If you furnish to a bureau or to CRILC, or you consume bureau data, list the four separately supervised steps: furnishing accuracy and timeliness, complaint intake, the twenty-one-day corrected-data turnaround, and compensation computation and disbursement within five working days. RBI sanctioned failures at two of those steps on 4 September 2026.
- Test the payment leg specifically. The penalised failure was not late correction — it was money not reaching eligible complainants' accounts in time. Ask for evidence of the last ten compensation events, with dates of accrual and dates of credit.
- Inventory SonicWall SMA1000 and Zimbra today. Affected: SMA1000 platform 12.4.3-03453 and earlier and 12.5.0-02835 and earlier; Zimbra Collaboration Suite prior to 10.1.20. Both are recorded by CERT-In as actively exploited.
- Rehearse the six-hour filing, not just the patch. Under the CERT-In Directions of 28 April 2022 the clock starts at noticing. Confirm who files, from which mailbox, with what minimum dataset, outside business hours.
- Scan your own public deployments for exposed
.gitdirectories. CIVN-2026-0430 shows CERT-In will issue a CVE against an Indian vendor for it. It is a five-minute check and a permanent finding if missed.
Practitioner Watch-List
- Section 17, Credit Information Reporting Directions 2025 is now a proven enforcement hook. Expect it to be cited in consumer complaints and in banking-ombudsman correspondence, and read it alongside Section 12 of the Digital Personal Data Protection Act, 2023 when advising on correction-request workflows — the sectoral remedy is currently the operative one.
- Section 23(4) CIC(R) Act 2005 arithmetic. The one lakh rupees plus five thousand rupees per day structure is the ceiling for a single continuing default. Any advice on exposure quantum must account for whether the regulator is treating defaults as one continuing contravention or as many; RBI has not published its approach.
- Section 58G(1)(b) read with Section 58B(5)(aa) RBI Act 1934 is the corresponding hook for NBFC reporting failures into CRILC — a different Act, a different power, the same supervisory cycle.
- Section 70B(7) IT Act 2000 remains at one crore rupees following the Jan Vishwas (Amendment of Provisions) Act, 2023 substitution effective 30 November 2023. Do not cite the pre-amendment one lakh figure.
- MeitY portal availability is now a live research risk, not an inconvenience. Where a client needs certainty on whether a MeitY instrument issued in a given week, the eGazette record — not the ministry website — is the surface to insist on.
FAQ
What exactly did the three credit information companies do wrong, and under what law were they penalised?
They did not pay money they owed to consumers whose credit records they had corrected late. The Reserve Bank of India announced on 4 September 2026 that, by orders each dated 31 August 2026, it had imposed monetary penalties of Rs 26,82,800 on TransUnion CIBIL Limited, Rs 6,89,600 on CRIF High Mark Credit Information Services Private Limited and Rs 1,19,400 on Equifax Credit Information Services Private Limited — Rs 34,91,800 in aggregate across three of India's four credit information companies. The sustained charge is worded identically in all three releases: the company failed to credit the compensation amount to the bank accounts of certain eligible complainants within the prescribed period. Two distinct instruments are engaged. The enforcement power is Section 25(1)(iii) read with Section 23(4) of the Credit Information Companies (Regulation) Act, 2005 (CIC(R) Act 2005); Section 23(4) is the Act's residual contravention provision, reaching any person who contravenes any provision of the Act or of any rule or order made thereunder or makes default in complying with any direction issued thereunder where no specific punishment is provided, and it fixes the exposure at a fine which may extend to one lakh rupees, with a further fine which may extend to five thousand rupees for every day during which a continuing contravention or default continues. The substantive duty breached is the framework for compensation to customers for delayed updation and rectification of credit information, now at Section 17 of the Master Direction — Reserve Bank of India (Credit Information Reporting) Directions, 2025 (RBI/DoR/2024-25/125, dated 6 January 2025). Each penalty followed a statutory inspection with reference to the company's financial position as on 31 March 2025, a show-cause notice, a written reply and a personal hearing, and RBI records in each release that the action is based on deficiencies in regulatory compliance and is not intended to pronounce upon the validity of any transaction or agreement between the company and its customers.
How does the Rs 100-a-day credit-report compensation actually work, and who owes it?
It is a per-day sum that accrues automatically once a correction runs past a fixed clock, and it can be owed by either the bureau or the lender depending on who caused the delay. Section 17 of the Master Direction — Reserve Bank of India (Credit Information Reporting) Directions, 2025 fixes compensation at Rs 100 per calendar day where a complaint about credit information is not resolved within thirty calendar days of the date on which the complaint was first filed. The thirty-day outer limit is subdivided. A credit institution — a bank, NBFC, housing finance company, All-India Financial Institution, asset reconstruction company or cooperative bank — has twenty-one calendar days to send the corrected credit information to the credit information company. The credit information company then owes compensation if it fails to resolve the complaint within thirty calendar days of being informed by the complainant or by the credit institution, notwithstanding that the credit institution furnished the updated information to it within its own twenty-one-day window. Once compensation is due, it must be credited to the complainant's bank account within five working days. That last requirement is the one the three bureaus were penalised on: the finding is not that they failed to correct records, but that having become liable they did not put the money into eligible complainants' accounts in time. The design is unusual in Indian data regulation because it is self-executing and compensatory — the consumer does not have to establish loss, apply to a tribunal, or prove intent, and the remedy runs against the data holder by the day.
Two CERT-In notes in this window record active exploitation. What does that change for an Indian regulated entity's obligations?
It moves the item from patch management into incident readiness, because exploitation in the wild means the six-hour reporting clock is now realistically reachable. On 3 September 2026 CERT-In issued CIVN-2026-0437 on Sonicwall SMA1000 — platform versions 12.4.3-03453 and earlier and 12.5.0-02835 and earlier, models 6210, 7210 and 8200v — rated CRITICAL, covering CVE-2026-83548 and CVE-2026-83549, an unauthenticated server-side request forgery and authenticated arbitrary operating-system command execution, and expressly recording that the vulnerabilities are being actively exploited in the wild. On the same day CERT-In issued CIVN-2026-0438 on Zimbra Collaboration Suite prior to version 10.1.20, rated HIGH, in which the note records that CVE-2026-73570 is likewise under active exploitation. In both cases the exploitation finding is CERT-In's own published statement, read from CERT-In's note; neither note discloses whether CERT-In observed the exploitation itself or relayed it from the vendor, and we have not established which. Both products sit at classic initial-access positions — a remote-access appliance at the network edge and a mail platform. The Directions issued by CERT-In on 28 April 2022 under Section 70B(6) of the Information Technology Act, 2000 (IT Act 2000) — No. 20(3)/2022-CERT-In, effective 28 June 2022 — require mandatory reporting of listed cyber incidents within six hours of noticing them or being brought to notice, and the listed categories include unauthorised access to IT systems and data and attacks on servers and network appliances. Failure to comply with a CERT-In direction attracts the Section 70B(7) penalty of up to one crore rupees, that figure having been substituted for one lakh rupees by the Jan Vishwas (Amendment of Provisions) Act, 2023 (Act 18 of 2023) with effect from 30 November 2023. The practical consequence is that for these two products the correct board-level question is no longer only when will we patch, but whether the organisation could detect exploitation and file within six hours if it had already happened.
Methodology and Date Provenance
- Window: ISO week 2026-W36, Monday 31 August 2026 to Sunday 6 September 2026, IST.
- Event dates: for regulator enforcement actions the event date is the announcement date, with the underlying order date stated on the face of the item. All three credit-bureau penalties and the Sammaan Finserve penalty rest on orders dated 31 August 2026; the Hinduja Leyland Finance order is dated 2 September 2026; all five were announced on 4 September 2026 and are treated as in-window on that basis. CERT-In notes are dated by their own issue date.
- Exploitation status: where this tracker says a vulnerability is under active exploitation, that is CERT-In's statement in CERT-In's own vulnerability note, read at cert-in.org.in — not a vendor bulletin and not a security-news report. CERT-In does not disclose whether such a finding is its own observation or is relayed from the vendor, and we have not established which; the claim is therefore attributed to CERT-In throughout and is never asserted in Veritect's own voice.
- CERT-In severities: nine of the twelve notes in the window were opened and read individually. CIVN-2026-0432, 0439 and 0440 were not, and their severities are left blank rather than inferred — the CRITICAL count of six is a count of notes actually read, and is a floor, not a total.
- Sources: every item was read at the issuing authority's own surface — rbi.org.in press releases and notifications, the RBI Master Directions page, cert-in.org.in vulnerability-note and advisory indexes and the individual note pages, sebi.gov.in circulars and press-release listings, trai.gov.in, irdai.gov.in and pib.gov.in. The statutory text of Sections 23 and 25 of the Credit Information Companies (Regulation) Act, 2005 was read in full from the Act, not from a secondary description.
- What is not here: any item that could not be read at a primary source is recorded in the gaps section rather than summarised from elsewhere.
Primary Sources
- RBI Press Release 2026-2027/1042, 4 September 2026 — monetary penalty on TransUnion CIBIL Limited: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=63520
- RBI Press Release, 4 September 2026 — monetary penalty on CRIF High Mark Credit Information Services Private Limited: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=63521
- RBI Press Release, 4 September 2026 — monetary penalty on Equifax Credit Information Services Private Limited: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=63523
- RBI Press Release 2026-2027/1044, 4 September 2026 — monetary penalty on Sammaan Finserve Limited: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=63522
- RBI Press Release 2026-2027/1049, 4 September 2026 — monetary penalty on Hinduja Leyland Finance Limited: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=63527
- Master Direction — Reserve Bank of India (Credit Information Reporting) Directions, 2025, RBI/DoR/2024-25/125, 6 January 2025: https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12764
- RBI circular RBI/2026-27/250, CO.FIDD.FSD.No.S544/05-10-001/2026-27, 2 September 2026: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=13692&Mode=0
- CERT-In Vulnerability Notes index, 2026: https://www.cert-in.org.in/s2cMainServlet?pageid=VLNLIST02&year=2026
- CERT-In Vulnerability Note CIVN-2026-0437, 3 September 2026 (Sonicwall SMA1000, CRITICAL, actively exploited): https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0437
- CERT-In Vulnerability Note CIVN-2026-0438, 3 September 2026 (Zimbra, CVE-2026-73570 actively exploited): https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0438
- CERT-In Vulnerability Note CIVN-2026-0430, 1 September 2026 (Manacle Technologies ERP): https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0430
- CERT-In Advisories index, 2026: https://www.cert-in.org.in/s2cMainServlet?pageid=PUBADVLIST02&year=2026
- SEBI Press Release No. 54/2026, 4 September 2026: https://www.sebi.gov.in/media-and-notifications/press-releases/sep-2026/sebi-signs-mou-with-european-securities-and-markets-authority-on-cooperation-and-exchange-of-information-relating-to-central-counterparties_104279.html
- SEBI Press Release No. 53/2026, 3 September 2026: https://www.sebi.gov.in/media-and-notifications/press-releases/sep-2026/sebi-to-review-settlement-price-methodology-for-derivative-contracts-in-the-light-of-cas-rollout_104260.html
- PIB Press Release PRID 2307373, 7 September 2026 (Ministry of Electronics and Information Technology) — APNIC 62, Mumbai: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2307373
- The Credit Information Companies (Regulation) Act, 2005, Sections 23 and 25 — read in full via the Veritect statute corpus
- The Information Technology Act, 2000, Sections 70B(6) and 70B(7), as amended by the Jan Vishwas (Amendment of Provisions) Act, 2023
Veritect Legal Intelligence. Tier 1 government and regulator sources only. This tracker reports facts drawn from primary records; analysis is original Veritect work. Where a primary record could not be retrieved, the gap is stated as a gap.