The Digital Personal Data Protection Act, 2023 sets maximum penalties, not fixed ones. Here is the full schedule, the factors the Data Protection Board must weigh, and what happens between a complaint and a penalty.
By Amar Gite and Santosh Sangle, Legismith Partners LLP · Reviewed 30 September 2026
| Breach | Maximum penalty |
|---|---|
| Failing to take reasonable security safeguards to prevent a personal data breach (section 8(5)) | ₹250 crore |
| Failing to notify the Board or affected Data Principals of a personal data breach (section 8(6)) | ₹200 crore |
| Breaching the additional obligations for children's data (section 9) | ₹200 crore |
| Breaching the additional obligations of a Significant Data Fiduciary (section 10) | ₹150 crore |
| Breaching the duties of a Data Principal (section 15) | ₹10,000 |
| Breaching a voluntary undertaking accepted by the Board (section 32) | Up to the penalty for the original breach |
| Breaching any other provision of the Act or the Rules | ₹50 crore |
Source: the Schedule to the Digital Personal Data Protection Act, 2023, read with section 33(1). Penalties are paid into the Consolidated Fund of India (section 34).
The Board can only impose a penalty after an inquiry finds a significant breach and the business has been heard. It must then weigh these factors under section 33(2).
Proceedings usually begin with a complaint from a Data Principal, a breach intimation from the business itself, or a reference from the government or a court.
The Board decides whether there are sufficient grounds, inquires into the matter and gives the business a chance to be heard.
At any stage, the Board may accept a voluntary undertaking to take or stop certain action. Once accepted, it bars proceedings on that matter unless the undertaking is breached.
If the breach is found significant, the Board imposes a penalty within the Schedule, weighing the seven factors above.
Any person aggrieved by the Board's order may appeal to the Telecom Disputes Settlement and Appellate Tribunal within 60 days of receiving it. The Tribunal may allow a late appeal for sufficient cause.
₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach. It is a ceiling: the Board sets the actual amount case by case.
Yes. Failing to notify the Data Protection Board or affected Data Principals of a personal data breach can attract a penalty of up to ₹200 crore.
Yes, but only for breaching the duties of a Data Principal in section 15, such as filing a false or frivolous complaint. The maximum penalty for that is ₹10,000.
Under section 33(2) it weighs seven factors: the nature, gravity and duration of the breach, the data affected, repetition, any gain made or loss avoided, the steps taken to mitigate, proportionality, and the likely impact of the penalty on the business.
Yes. An appeal lies to the Telecom Disputes Settlement and Appellate Tribunal within 60 days of receiving the Board's order, and the Tribunal may admit a late appeal if there was sufficient cause.
Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote for a readiness check.
Prefer chat? WhatsApp us.
General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.
We use essential cookies to run this website and keep our enquiry forms secure. With your permission we would also like to use analytics cookies, to see how the site is used, and advertising cookies, to measure our Google Ads. These collect your IP address, device and browser details and the pages you visit, and share them with Google and Cloudflare. You can change or withdraw your choice at any time using Cookie settings at the bottom of every page, or write to [email protected].
Disclaimer: Under the Bar Council of India rules, advocates may not advertise or solicit work. This website only shares general information on intellectual property. It is not an advertisement, a solicitation or legal advice, and using it does not create a lawyer–client relationship.