Knowledge centre · Data privacy

DPDP Act Penalties Explained: Up to ₹250 Crore, and How the Board Decides

The Digital Personal Data Protection Act, 2023 sets maximum penalties, not fixed ones. Here is the full schedule, the factors the Data Protection Board must weigh, and what happens between a complaint and a penalty.

Maximum ₹250 crore 7 factors the Board weighs Appeal within 60 days
What are the penalties under the DPDP Act? The Schedule to the DPDP Act, 2023 allows the Data Protection Board to impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a breach or for breaching the rules on children's data, up to ₹150 crore for a Significant Data Fiduciary's extra duties, and up to ₹50 crore for any other breach.
The Schedule

The full DPDP penalty schedule

BreachMaximum penalty
Failing to take reasonable security safeguards to prevent a personal data breach (section 8(5))₹250 crore
Failing to notify the Board or affected Data Principals of a personal data breach (section 8(6))₹200 crore
Breaching the additional obligations for children's data (section 9)₹200 crore
Breaching the additional obligations of a Significant Data Fiduciary (section 10)₹150 crore
Breaching the duties of a Data Principal (section 15)₹10,000
Breaching a voluntary undertaking accepted by the Board (section 32)Up to the penalty for the original breach
Breaching any other provision of the Act or the Rules₹50 crore

Source: the Schedule to the Digital Personal Data Protection Act, 2023, read with section 33(1). Penalties are paid into the Consolidated Fund of India (section 34).

How the Board decides

The seven factors behind every penalty

The Board can only impose a penalty after an inquiry finds a significant breach and the business has been heard. It must then weigh these factors under section 33(2).

1. Nature, gravity and durationHow serious the breach was and how long it lasted.
2. The data affectedThe type and nature of the personal data involved.
3. RepetitionWhether the breach has happened before.
4. Gain or loss avoidedWhether the business gained, or avoided a loss, by the breach.
5. MitigationWhether the business acted to limit the damage, and how quickly and effectively.
6. Proportion and deterrenceWhether the amount is proportionate and effective in securing compliance.
7. Impact of the penaltyThe likely effect of the penalty on the business itself.
What this means in practice: factor 5 is the one you control after the fact. A documented breach playbook, a report filed within 72 hours and a record of your safeguards are the strongest evidence you can put before the Board. That is why our DPDP Compliance Pack includes a breach response playbook and a security safeguards map.
The process

From complaint to penalty, and appeal

Trigger

A complaint, a breach intimation or a reference

Proceedings usually begin with a complaint from a Data Principal, a breach intimation from the business itself, or a reference from the government or a court.

Section 28

Inquiry

The Board decides whether there are sufficient grounds, inquires into the matter and gives the business a chance to be heard.

Section 32

Voluntary undertaking

At any stage, the Board may accept a voluntary undertaking to take or stop certain action. Once accepted, it bars proceedings on that matter unless the undertaking is breached.

Section 33

Penalty

If the breach is found significant, the Board imposes a penalty within the Schedule, weighing the seven factors above.

Section 29

Appeal to TDSAT

Any person aggrieved by the Board's order may appeal to the Telecom Disputes Settlement and Appellate Tribunal within 60 days of receiving it. The Tribunal may allow a late appeal for sufficient cause.

FAQs

DPDP Act penalties: common questions

₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach. It is a ceiling: the Board sets the actual amount case by case.

Yes. Failing to notify the Data Protection Board or affected Data Principals of a personal data breach can attract a penalty of up to ₹200 crore.

Yes, but only for breaching the duties of a Data Principal in section 15, such as filing a false or frivolous complaint. The maximum penalty for that is ₹10,000.

Under section 33(2) it weighs seven factors: the nature, gravity and duration of the breach, the data affected, repetition, any gain made or loss avoided, the steps taken to mitigate, proportionality, and the likely impact of the penalty on the business.

Yes. An appeal lies to the Telecom Disputes Settlement and Appellate Tribunal within 60 days of receiving the Board's order, and the Tribunal may admit a late appeal if there was sufficient cause.

Know your exposure before the Board asks.

Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote for a readiness check.

    Send Us Your Enquiry

    Fill in the form below and our team will respond within 24 hours.

    Prefer chat? WhatsApp us.

    General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.

    Scroll to Top