#FactCheck - An edited video of Bollywood actor Ranveer Singh criticizing PM getting viral
Research Wing
Innovation and Research
PUBLISHED ON
Apr 27, 2024
10
Executive Summary:
An alleged video is making the rounds on the internet featuring Ranveer Singh criticizing the Prime Minister Narendra Modi and his Government. But after examining the video closely it revealed that it has been tampered with to change the audio. In fact, the original videos posted by different media outlets actually show Ranveer Singh praising Varanasi, professing his love for Lord Shiva, and acknowledging Modiji’s role in enhancing the cultural charms and infrastructural development of the city. Differences in lip synchronization and the fact that the original video has no sign of criticizing PM Modi show that the video has been potentially manipulated in order to spread misinformation.
Claims:
The Viral Video of Bollywood actor Ranveer Singh criticizing Prime Minister Narendra Modi.
Upon receiving the Video we divided the video into keyframes and reverse-searched one of the images, we landed on another video of Ranveer Singh with lookalike appearance, posted by an Instagram account named, “The Indian Opinion News''. In the video Ranveer Singh talks about his experience of visiting Kashi Vishwanath Temple with Bollywood actress Kriti Sanon. When we watched the Full video we found no indication of criticizing PM Modi.
Taking a cue from this we did some keyword search to find the full video of the interview. We found many videos uploaded by media outlets but none of the videos indicates criticizing PM Modi as claimed in the viral video.
Ranveer Singh shared his thoughts about how he feels about Lord Shiva, his opinions on the city and the efforts undertaken by the Prime Minister Modi to keep history and heritage of Varanasi alive as well as the city's ongoing development projects. The discrepancy in the viral video clip is clearly seen when we look at it closely. The lips are not in synchronization with the words which we can hear. It is clearly seen in the original video that the lips are in perfect synchronization with the words of audio. Upon lack of evidence to the claim made and discrepancies in the video prove that the video was edited to misrepresent the original interview of Bollywood Actor Ranveer Singh. Hence, the claim made is misleading and false.
Conclusion:
The video that claims Ranveer Singh criticizing PM Narendra Modi is not genuine. Further investigation shows that it has been edited by changing the audio. The original footage actually shows Singh speaking positively about Varanasi and Modi's work. Differences in lip-syncing and upon lack of evidence highlight the danger of misinformation created by simple editing. Ultimately, the claim made is false and misleading.
Claim: A viral featuring Ranveer Singh criticizing the Prime Minister Narendra Modi and his Government.
India's National Commission for Protection of Child Rights (NCPCR) is set to approach the Ministry of Electronics and Information Technology (MeitY) to recommend mandating a KYC-based system for verifying children's age under the Digital Personal Data Protection (DPDP) Act. The decision to approach or send recommendations to MeitY was taken by NCPCR in a closed-door meeting held on August 13 with social media entities. In the meeting, NCPCR emphasised proposing a KYC-based age verification mechanism. In this background, Section 9 of the Digital Personal Data Protection Act, 2023 defines a child as someone below the age of 18, and Section 9 mandates that such children have to be verified and parental consent will be required before processing their personal data.
Requirement of Verifiable Consent Under Section 9 of DPDP Act
Regarding the processing of children's personal data, Section 9 of the DPDP Act, 2023, provides that for children below 18 years of age, consent from parents/legal guardians is required. The Data Fiduciary shall, before processing any personal data of a child or a person with a disability who has a lawful guardian, obtain verifiable consent from the parent or lawful guardian. Additionally, behavioural monitoring or targeted advertising directed at children is prohibited.
Ongoing debate on Method to obtain Verifiable Consent
Section 9 of the DPDP Act gives parents or lawful guardians more control over their children's data and privacy, and it empowers them to make decisions about how to manage their children's online activities/permissions. However, obtaining such verifiable consent from the parent or legal guardian presents a quandary. It was expected that the upcoming 'DPDP rules,' which have yet to be notified by the Central Government, would shed light on the procedure of obtaining such verifiable consent from a parent or lawful guardian.
However, In the meeting held on 18th July 2024, between MeitY and social media companies to discuss the upcoming Digital Personal Data Protection Rules (DPDP Rules), MeitY stated that it may not intend to prescribe a ‘specific mechanism’ for Data Fiduciaries to verify parental consent for minors using digital services. MeitY instead emphasised obligations put forth on the data fiduciary under section 8(4) of the DPDP Act to implement “appropriate technical and organisational measures” to ensure effective observance of the provisions contained under this act.
In a recent update, MeitY held a review meeting on DPDP rules, where they focused on a method for determining children's ages. It was reported that the ministry is making a few more revisions before releasing the guidelines for public input.
CyberPeace Policy Outlook
CyberPeace in its policy recommendations paper published last month, (available here) also advised obtaining verifiable parental consent through methods such as Government Issued ID, integration of parental consent at ‘entry points’ like app stores, obtaining consent through consent forms, or drawing attention from foreign laws such as California Privacy Law, COPPA, and developing child-friendly SIMs for enhanced child privacy.
CyberPeace in its policy paper also emphasised that when deciding the method to obtain verifiable consent, the respective platforms need to be aligned with the fact that verifiable age verification must be done without compromising user privacy. Balancing user privacy is a question of both technological capabilities and ethical considerations.
DPDP Act is a brand new framework for protecting digital personal data and also puts forth certain obligations on Data Fiduciaries and provides certain rights to Data Principal. With upcoming ‘DPDP Rules’ which are expected to be notified soon, will define the detailed procedure for the implementation of the provisions of the Act. MeitY is refining the DPDP rules before they come out for public consultation. The approach of NCPCR is aimed at ensuring child safety in this digital era. We hope that MeitY comes up with a sound mechanism for obtaining verifiable consent from parents/lawful guardians after taking due consideration to recommendations put forth by various stakeholders, expert organisations and concerned authorities such as NCPCR.
Somewhere in a compliance meeting right now, someone is saying "we have eighteen months, we're fine." That sentence is doing the same thing a snooze button does at 6 a.m.: technically buying time, while quietly making the actual wake up call worse. India's data protection law just started its countdown, and the 18 months everyone keeps citing is not a grace period to procrastinate through. It is closer to a runway before takeoff. Runways exist for one purpose: building up speed until the plane has no choice but to leave the ground. Standing still on one is not a strategy.
What actually got notified, and when
On 13 November 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, giving operational shape to the Digital Personal Data Protection Act that Parliament had passed back in August 2023. Alongside the Rules themselves, MeitY issued a separate Enforcement Notification setting out exactly when different provisions kick in, and a further notification establishing the Data Protection Board of India, headquartered in the National Capital Region with four members. The final Rules followed a genuinely deliberative process, MeitY had floated draft Rules in January 2025 for public consultation and received 6,915 individual inputs from startups, industry bodies, civil society groups, and citizens before finalising the version now in force. The headline structural decision, and the one causing the most confusion in boardrooms, is that the Rules do not commence all at once. They commence in three distinct phases spread across eighteen months, and different obligations become legally binding at each stage.
The phased timeline, laid out plainly
That third date, 13 May 2027, is the one that matters most for the vast majority of organisations, since it is where the bulk of actual operational obligations, the parts that touch product design, customer facing notices, and breach response, become enforceable. Legal commentary tracking the rollout has been consistent that this is described as a hard deadline with no grace period expected once it arrives, since the Data Protection Board is already operational and can begin receiving complaints well before Phase 3 obligations formally take effect.
Why "later" is a genuinely expensive plan
The financial stakes attached to Phase 3 non-compliance are not modest. The Schedule to the DPDP Act sets fixed penalty ceilings rather than turnover linked fines, which sounds gentler than Europe's GDPR model until you look at the actual numbers. Failure to implement reasonable security safeguards that results in a data breach can draw a penalty of up to 250 crore rupees per instance, the single highest tier in the Schedule. Failing to notify the Board or affected individuals after a breach occurs can draw up to 200 crore rupees, as can non-compliance with the Act's specific protections for children's data. Because these are assessed per instance rather than as a single capped exposure, a single incident that trips more than one obligation, say, inadequate safeguards that also delay breach notification, can compound into penalty exposure running into hundreds of crores from one event. All penalties collected go to the Consolidated Fund of India rather than to affected individuals directly, meaning the deterrent is aimed squarely at organisational behaviour, not compensation.
The part everyone keeps underestimating: this is not just a legal department problem
Perhaps the most consequential shift buried inside the DPDP framework is who actually has to own it. Reading the Rules as a checklist for the legal or privacy team alone misses how far the obligations actually reach. Building a compliant consent lifecycle touches product design. Security safeguards touch cybersecurity and IT infrastructure directly. Retention and deletion logic touches data governance and engineering. Third party risk review touches procurement. Breach preparedness touches internal audit and incident response. And increasingly, as organisations deploy AI systems that process personal data, AI governance enters the picture too, since a model trained or fine tuned on personal data inherits the same DPDP obligations as any other processing activity.
That cross functional reality is where most readiness programmes currently fall short. Treating DPDP compliance as a documentation exercise, updating a privacy policy PDF and calling it done, produces the appearance of compliance without the operational substance a Data Protection Board investigation would actually test. A breach response plan that exists only on paper and has never been rehearsed will not hold up against the 72 hour data principal notification window the Rules impose once Phase 3 lands. A consent mechanism bolted onto a website without corresponding backend logic to honour withdrawal requests will not satisfy an actual audit.
What a serious readiness posture looks like right now
Organisations that are ahead of this curve are already treating the eighteen month window as three overlapping workstreams rather than one deadline to hit at the end.
The first is discovery: mapping what personal data exists, where it flows, who owns each system that touches it, and why it is collected in the first place, since compliance is structurally impossible without first knowing what you are protecting. This stage typically surfaces uncomfortable findings, shadow data sets nobody formally owns, vendor integrations nobody fully mapped, legacy systems still holding data well past any reasonable retention justification.
The second is build: standing up the actual mechanisms, consent flows that can genuinely honour a withdrawal request end to end, rights request handling that does not depend on a single overworked employee checking an inbox, retention and deletion logic wired into the systems themselves rather than described only in a policy document, and security controls proportionate to the sensitivity of what is being protected.
The third is proof: generating the internal evidence, audit trails, documented decisions, tested response procedures, that demonstrates governance was real rather than retrofitted after the fact. A Data Protection Board investigation, when it eventually happens, will not be satisfied by a well written policy; it will look for evidence that the policy was actually operational.
The actual question worth asking
The right question was never "when does DPDP become enforceable." Phase 1 already answered that; the law is live, and the Data Protection Board already exists and can act. The better question, the one worth taking into any leadership review between now and May 2027, is simpler and considerably less comfortable: will the organisation actually be ready when each phase's obligations become operational, or will readiness be assembled in a scramble once the deadline stops being theoretical. 18 months sounds long right up until the week it does not, and by the time Phase 3 lands, "we'll get to it" will no longer be a sentence any organisation gets to finish.
A fake photo claiming to show the cricketer Virat Kohli watching a press conference by Rahul Gandhi before a match, has been widely shared on social media. The original photo shows Kohli on his phone with no trace of Gandhi. The incident is claimed to have happened on March 21, 2024, before Kohli's team, Royal Challengers Bangalore (RCB), played Chennai Super Kings (CSK) in the Indian Premier League (IPL). Many Social Media accounts spread the false image and made it viral.
Claims:
The viral photo falsely claims Indian cricketer Virat Kohli was watching a press conference by Congress leader Rahul Gandhi on his phone before an IPL match. Many Social media handlers shared it to suggest Kohli's interest in politics. The photo was shared on various platforms including some online news websites.
After we came across the viral image posted by social media users, we ran a reverse image search of the viral image. Then we landed on the original image posted by an Instagram account named virat__.forever_ on 21 March.
The caption of the Instagram post reads, “VIRAT KOHLI CHILLING BEFORE THE SHOOT FOR JIO ADVERTISEMENT COMMENCE.❤️”
Evidently, there is no image of Congress Leader Rahul Gandhi on the Phone of Virat Kohli. Moreover, the viral image was published after the original image, which was posted on March 21.
Therefore, it’s apparent that the viral image has been altered, borrowing the original image which was shared on March 21.
Conclusion:
To sum up, the Viral Image is altered from the original image, the original image caption tells Cricketer Virat Kohli chilling Before the Jio Advertisement commences but not watching any politician Interview. This shows that in the age of social media, where false information can spread quickly, critical thinking and fact-checking are more important than ever. It is crucial to check if something is real before sharing it, to avoid spreading false stories.
Become a part of our vision to make the digital world safe for all!
Numerous avenues exist for individuals to unite with us and our collaborators in fostering global cyber security
Awareness
Stay Informed: Elevate Your Awareness with Our Latest Events and News Articles Promoting Cyber Peace and Security.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.