#FactCheck: Old Thundercloud Video from Lviv city in Ukraine Ukraine (2021) Falsely Linked to Delhi NCR, Gurugram and Haryana
Executive Summary:
A viral video claims to show a massive cumulonimbus cloud over Gurugram, Haryana, and Delhi NCR on 3rd September 2025. However, our research reveals the claim is misleading. A reverse image search traced the visuals to Lviv, Ukraine, dating back to August 2021. The footage matches earlier reports and was even covered by the Ukrainian news outlet 24 Kanal, which published the story under the headline “Lviv Covered by Unique Thundercloud: Amazing Video”. Thus, the viral claim linking the phenomenon to a recent event in India is false.
Claim:
A viral video circulating on social media claims to show a massive cloud formation over Gurugram, Haryana, and the Delhi NCR region on 3rd September 2025. The cloud appears to be a cumulonimbus formation, which is typically associated with heavy rainfall, thunderstorms, and severe weather conditions.

Fact Check:
After conducting a reverse image search on key frames of the viral video, we found matching visuals from videos that attribute the phenomenon to Lviv, a city in Ukraine. These videos date back to August 2021, thereby debunking the claim that the footage depicts a recent weather event over Gurugram, Haryana, or the Delhi NCR region.


Further research revealed that a Ukrainian news channel named 24 Kanal, had reported on the Lviv thundercloud phenomenon in August 2021. The report was published under the headline “Lviv Covered by Unique Thundercloud: Amazing Video” ( original in Russian, translated into English).

Conclusion:
The viral video does not depict a recent weather event in Gurugram or Delhi NCR, but rather an old incident from Lviv, Ukraine, recorded in August 2021. Verified sources, including Ukrainian media coverage, confirm this. Hence, the circulating claim is misleading and false.
- Claim: Old Thundercloud Video from Lviv city in Ukraine Ukraine (2021) Falsely Linked to Delhi NCR, Gurugram and Haryana.
- Claimed On: Social Media
- Fact Check: False and Misleading.
Related Blogs

The Digital Personal Data Protection (DPDP) Act, 2023, operationalises data privacy largely through a consent management framework. It aims to give data principles, ie, individuals, control over their personal data by giving them the power to track, change, and withdraw their consent from its processing. However, in practice, consent management is often not straightforward. For example, people may be frequently bombarded with requests, which can lead to fatigue and eventual overlooking of consent requests. This article discusses the way consent management is handled by the DPDP Act, and looks at how India can design the system to genuinely empower users while holding organisations accountable.
Consent Management in the DPDP Act
According to the DPDP Act, consent must be unambiguous, free, specific, and informed. It must also be easy for people to revoke their consent (DPO India, 2023). To this end, the Act creates Consent Managers- registered middlemen- who serve as a link between users and data custodians.
The purpose of consent managers is to streamline and centralise the consent procedure. Users can view, grant, update, or revoke consent across various platforms using the dashboards they offer. They hope to improve transparency and lessen the strain on people to keep track of permissions across different services by standardising the way consent is presented (IAPP, 2024).
The Act draws inspiration from international frameworks such as the GDPR (General Data Protection Regulation), mandating that Indian users be provided with a single platform to manage permissions rather than having to deal with dispersed consent prompts from every service.
The Challenges
Despite the mandate for an interoperable platform for consent management, several key challenges emerge. There is a lack of clarity on how consent management will be operationalised. This creates challenges of accountability and implementation. Thus, :
- If the interface is poorly designed, users could be bombarded with content permissions from apps/platforms/ services that are not fully compliant with the platform.
- If consent notices are vague, frequent, lengthy, or complex, users may continue to grant permissions without meaningful engagement.
- It leaves scope for data fiduciaries to use dark patterns to coerce customers into granting consent through poor UI/UX design.
- The lack of clear, standardised interoperability protocols across sectors could lead to a fragmented system, undermining the goal of a single, easy-to-use platform.
- Consent fatigue could easily appear in India's digital ecosystem, where apps, e-commerce websites, and government services all ask for permissions from over 950 million internet subscribers. Experiences from GDPR countries show that users who are repeatedly prompted eventually become banner blind, which causes them to ignore notices entirely.
- Low levels of literacy (including digital literacy) and unequal access to digital devices among women and marginalised communities create complexities in the substantive coverage of privacy rights.
- Placing the burden of verification of legal guardianship for children and persons with disabilities (PwDs) on data fiduciaries might be ineffective, as SMEs may lack the resources to undertake this activity. This could create new forms of vulnerability for the two groups.
Legal experts claim that this results in what they refer to as a legal fiction, wherein consent is treated as valid by the law despite the fact that it does not represent true understanding or choice (Lawvs, 2023). Additionally, research indicates that users hardly ever read privacy policies in their entirety. People are very likely to tick boxes without fully understanding what they are agreeing to. By drastically limiting user control, this has a bearing on the privacy rights of Indian citizens and residents. (IJLLR, 2023).
Impacts of Weak Consent Management:
According to the Indian Journal of Law and Technology, in an era of asymmetry and information overload, privacy cannot be sufficiently protected by relying only on consent (IJLT, 2023). Almost every individual will be impacted by inadequate consent management.
- For Users: True autonomy is replaced by the appearance of control. Individuals may unintentionally disclose private information, which undermines confidence in digital services.
- For Businesses: Compliance could become a mere formality. Further, if acquired consent is found to be manipulated or invalid, it creates space for legal risks and reputational damage.
- For Regulators: It becomes difficult to oversee a system where consent is frequently disregarded or misinterpreted. When consent is merely formal, the law's promise to protect personal information is undermined.
Way Forward
- Layered and Simplified Notices: Simple language and layers of visual cues should be used in consent requests. Important details like the type of data being gathered, its intended use, and its duration should be made clear up front. Additional explanations are available for users who would like more information. This method enhances comprehension and lessens cognitive overload (Lawvs, 2023).
- Effective Dashboards: Dashboards from consent managers should be user-friendly, cross-platform, and multilingual. Management is made simple by features like alerts, one-click withdrawal or modification, and summaries of active permissions. The system is more predictable and dependable when all services use the same format, which also reduces confusion (IAPP, 2024).
- Dynamic and Contextual Consent: Instead of appearing as generic pop-ups, consent requests should show up when they are pertinent to a user's actions. Users can make well-informed decisions without feeling overburdened by subtle cues, such as emphasising risks when sensitive data is requested (IJLLR, 2023).
- Accountability of Consent Managers: Organisations that offer consent management services must be accountable and independent, through clear certification, auditing, and specific legal accountability frameworks. Even when formal consent is given, strong trustee accountability guarantees that data is not misused (IJLT, 2023).
- Complementary Protections Beyond Consent: Consent continues to be crucial, but some high-risk data processing might call for extra protections. These may consist of increased responsibilities for fiduciaries or proportionality checks. These steps improve people's general protection and lessen the need for frequent consent requests (IJLLR, 2023).
Conclusion
The core of the DPDP Act is to empower users to have control over their data through measures such as consent management. But requesting consent is insufficient; the system must make it simple for people to manage, monitor, and change it. Effectively designed, managed, and executed consent management has the potential to revolutionise user experience and trust in India's digital ecosystem if it is implemented carefully.To make consent management genuinely meaningful, it is imperative to standardise procedures, hold fiduciaries accountable, simplify interfaces, and investigate supplementary protections.
References
Building Trust with Technology: Consent Management Under India’s DPDP Act, 2023
Consent Fatigue and Data Protection Laws: Is ‘Informed Consent’ a Legal Fiction
Beyond Consent: Enhancing India's Digital Personal Data Protection Framework
Top 10 operational impacts of India’s DPDPA – Consent management
.webp)
Introduction
Cybersecurity remains a crucial component in the modern digital era, considering the growing threat landscape caused by our increased reliance on technology and the internet. The Karnataka Government introduced a new ‘Cyber Security Policy 2024’ to address increasing cybercrimes and enhance protection measures for the State's digital infrastructure through awareness, skill development, public-private collaborations, and technology integration. Officials stated that the policy highlights various important aspects including raising awareness and providing education, developing skills, supporting the industry and start-ups, as well as forming partnerships and collaborations for enhancing capacity.
Key Highlights
- The policy consists of two components. The initial segment emphasizes creating a robust cyber security environment involving various sectors such as the public, academia, industry, start-ups, and government. The second aspect of the policy aims to enhance the cybersecurity status of the State's IT resources. Although the initial section will be accessible to the public, the second portion will be restricted to the state's IT teams and departments for their IT implementation.
- The Department of Electronics, IT, BT and S&T, the Department of Personnel and Administrative Reforms (e-Governance),and the Home Department, in collaboration with stakeholders from government and private sectors, have collectively formulated this policy. The Indian Institute of Science, the main institute for the state's K-tech Centre of Excellence for Cyber Security (CySecK), also examined the policy.
- The Department of Electronics, IT, BT and S&T, the Department of Personnel and Administrative Reforms (e-Governance),and the Home Department, in collaboration with stakeholders from government and private sectors, have collectively formulated this policy. The Indian Institute of Science, the main institute for the state's K-tech Centre of Excellence for Cyber Security (CySecK), also examined the policy.
- Approximately ₹103.87 crore will be spent over five years to implement the policy, which would be fulfilled from the budget allocated to the Department of Information Technology and Biotechnology and Science & Technology. A total of ₹23.74 crore would be allocated for offering incentives and concessions.
- The policy focuses on key pillars of building awareness and skills, promoting research and innovation, promoting industry and start-ups, partnerships and collaborations for capacity building.
- Karnataka-based undergraduate and postgraduate interns will receive a monthly stipend of INR 10,000- Rs15,000 fora maximum duration of three months under the internship program. The goal is to support 600 interns at the undergraduate level and 120 interns at the post-graduate level within the policy timeframe.
- Karnataka-based start-ups collaborating with academic institutes can receive matching grants of up to 50% of the total R&D cost for cybersecurity projects, or a maximum of ₹50 lakh.
- Reimbursement will be provided for expenses up to a maximum of INR 1 Lakh for start-ups registered with Karnataka Start-up Cell who engage CERT-In empanelled service providers from Karnataka for cyber security audit.
- The Karnataka government has partnered with Meta to raise awareness on cyber security. By reaching out to educational institutions, schools and colleges, it is piloted to provide training to 1 lakh teachers and educate 1 million children on online safety.
CyberPeace Policy Wing Outlook
The Cyber Security Policy, 2024 launched by the Karnataka government is a testament to the state government's commitment to strengthening the cyber security posture and establishing cyber resilience. By promoting and supporting research and development projects, supporting startups, and providing skill training internships, and capacity building at a larger scale, the policy will serve asa positive step in countering the growing cyber threats and establishing a peaceful digital environment for all. The partnership and collaboration with tech companies will be instrumental in implementing the capacity-building initiatives aimed at building cognitive and skill defenses while navigating the digital world. The policy will inspire other state governments in their policy initiatives for building safe and secure cyber-infrastructure in the states by implementing strategies tailored to the specific needs and demands of each state in building safe digital infrastructure and environment.
References:
- https://www.hindustantimes.com/cities/bengaluru-news/karnataka-govt-launches-new-cyber-security-policy-amid-frequent-scams-101722598078117.html
- https://ciso.economictimes.indiatimes.com/amp/news/grc/karnataka-govt-launches-new-cyber-security-policy/112214121
- https://cybermithra.in/2024/08/09/karnataka-cyber-security-policy/

With AI touching new milestones everyday an increasing need for making it secure is also arising. As these AI companies increase their operations and position in the market as providers of powerful tools in the market. A recent concern due to Anthropic's recent privacy policy update which will be effective from July 8, 2026 shows how companies have begun expanding the amount of personal information they collect in the name of safety, compliance, and trust. While they are being demonstrated as measures to improve safety of users and prevent abuse, it raises important questions about privacy, biometric data, surveillance, data retention, and user autonomy, some of which we will be addressing in this article.
Identity Verification of consumers
One of the most notable update to Anthropic's privacy policy is the category of "Verification Data." According to the policy, users may be asked to verify their age or identity in certain circumstances. Depending on the verification method, Anthropic may collect:
- Images of government-issued identity documents;
- Information appearing on those documents, including identification numbers and date of birth for age verification;
- Photographs or videos of the user;
- Facial geometry templates, which may constitute biometric data under certain legal frameworks; and
- The outcome of the verification process.
At first, this may appear similar to the Know Your Customer (KYC) procedures employed by banks or financial institutions but Claude is not a banking service. It is a consumer AI platform. The issue is not that verification exists, but that the circumstances under which it may be required remain undefined.
THE PROBLEM WITH “CERTAIN CIRCUMSTANCES”
The policy refers to verification being required in "certain circumstances." The public notification from Anthropic mentions that these circumstances may include access to particular features, routine platform integrity checks, abuse prevention mechanisms, policy enforcement activities, or legal compliance obligations. The ambiguity of this phrase raises important concerns. From a user perspective, it is difficult to determine, When verification may be triggered ? Whether verification applies only to suspicious accounts ? Whether access to future features may depend upon verification ? Whether users in particular regions will face more frequent verification requirements ? Whether verification requests may increase as AI regulation expands ? This broad language and discretionary power that the company has along with flexibility in the hands of the company creates uncertainty for users who may have initially joined a platform expecting only an email address and payment information to be required.
Government IDs collection: A new risk category
Almost all AI services have operated without collecting government-issued identity documents. Once a company begins processing such information, the privacy implications change dramatically. Because government issued IDs contain: Full legal names, Dates of birth, Identification numbers, Addresses, Photographs and information regarding nationality. When companies collect these documents, they will have an important database of highly sensitive personal information. Even if the company itself does not retain the documents indefinitely, the existence of a verification process introduces additional privacy and security risks. As per Anthropic has stated that identity verification is conducted through third-party providers such as Persona. According to article on the official site titled ‘Identity verification on Claude’, Persona stores the identity documents and selfie data, while Anthropic retains access to verification records when necessary. From the user's perspective, several important realities remain: First, the data still exists somewhere. Second, another third party organization is now involved in processing highly sensitive personal information. Third, Anthropic retains the ability to access verification records under certain circumstances. Therefore, although Anthropic may not directly maintain copies of every uploaded identity document, the practical result remains that sensitive information enters a broader ecosystem of entities and systems. Identity documents today are among the most valuable forms of personal information from the perspective of fraudsters, cybercriminals, and malicious actors. Therefore, any system that handles such documents becomes an attractive target for attack.
More information on persona’s government ID verification- https://withpersona.com/blog/what-is-government-id-verification
The Biometric Dimension
Another significant aspect of the update is the reference to facial geometry templates. Unlike passwords, biometric identifiers cannot easily be changed if compromised. A person can replace a password or even obtain a new identification card, but they cannot simply obtain a new face. Facial geometry templates are sensitive because they enable automated identity matching. Although these templates, as claimed, are not equivalent to photographs, they are nevertheless derived from unique physical characteristics of a person. In many jurisdictions, including parts of the European Union and several U.S. states, biometric data receives enhanced legal protection because of its permanence and sensitivity, let us see how it unfolds in these jurisdictions.
The Unanswered Retention Question
It is unclear in the policy as to how long the data will be retained because retention limits serve as one of the most important safeguards in modern privacy law, they have given another vague answer that “They're bound to protect it with industry-standard security controls and delete it in line with the retention limits we've set and applicable law.” The longer sensitive information remains stored, the greater the likelihood of unauthorized access, misuse, accidental disclosure, or legal compulsion.
Court Orders and Government Access
Anthropic may be required to disclose information pursuant to valid legal processes such as subpoenas, court orders, warrants, or regulatory directives. The existence of identity verification records means that future requests could potentially be linked to verified identities rather than pseudonymous accounts. This does not mean governments receive unrestricted access to user data. However, it does mean that once identity verification information exists within a company's ecosystem, it may become subject to lawful disclosure requirements. The privacy implications are therefore materially different from those associated with anonymous or pseudonymous AI usage.
Shifting Responsibility onto Users
Another concern is that the privacy policy states that users are responsible for ensuring they possess the necessary rights, permissions, or authority when uploading files, connecting third-party services, or instructing Claude to retrieve information. Anthropic is effectively informing users that they bear responsibility for ensuring that uploaded or connected data is lawfully accessible. As AI assistants gain greater capabilities, this transfer of responsibility from platform to user is likely to become increasingly common. Beyond individual privacy, Anthropic's verification policy also raises larger questions about data sovereignty and the cross-border movement of sensitive personal information. In India, the Justice K.S. Puttaswamy (Retd.) v. Union of India judgment recognized privacy as a fundamental right under Article 21 of the Constitution, affirming that individuals have the right to informational self-determination and control over their personal data. Yet, under Anthropic's verification framework, an Indian user may be required to upload a government-issued identity document and biometric information, which are processed by Persona, a U.S.-based identity verification company acting on behalf of Anthropic. Although users voluntarily consent to this process, it nevertheless results in highly sensitive identity information crossing national borders and entering the control of foreign private entities governed primarily by foreign contractual arrangements and multiple legal regimes. While governments issue identity documents as sovereign instruments of citizenship, their verification and processing are increasingly outsourced to multinational technology companies. Questions arise not only about how securely such information is handled, but also about which country's laws ultimately govern access, retention, disclosure, and accountability when personal data leaves the jurisdiction in which it originated. Under the Digital Personal Data Protection Act, 2023, cross-border transfer of personal data is generally permitted unless the Central Government specifically restricts transfers to certain jurisdictions. Therefore, a foreign company processing identity documents is not, by itself, unlawful but this legality does not eliminate legitimate concerns. Users realistically have limited bargaining power and little practical understanding of how long their identity documents, biometric templates, or verification records will be retained, who within the corporate ecosystem may access them, or how they may be disclosed pursuant to foreign legal processes.
Conclusion
The policy is commendable in some respects because it openly identifies the categories of information that may be collected rather than obscuring them behind vague terminology. However, important concerns remain regarding the extent of verification triggers, the handling of biometric information, the absence of clearly disclosed retention periods, and the long-term implications of linking AI accounts to government-issued identities. As AI systems become more integrated into daily life, these questions will likely become central issues in debates about digital privacy, surveillance, autonomy, and the future governance of artificial intelligence.