Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DPDP penalties explained

DPDP Penalties: The 7 Bands up to ₹250 Crore Explained (2026)

DPDP penalties are set out in the Schedule to the Digital Personal Data Protection Act, 2023: seven bands, from ₹10,000 for a data principal who breaches their own duties to ₹250 crore — roughly €25–28 million at 2026 exchange rates — for a data fiduciary that fails to take reasonable security safeguards to prevent a personal data breach. They are monetary penalties imposed by the Data Protection Board of India after an inquiry, not fines by a court, and section 33(2) lists the seven factors the Board must weigh in setting the amount.

The bands come into force with the substantive provisions on 13 May 2027, and the Board that imposes them has existed since 13 November 2025. This guide sets out every band in the Schedule with the section it attaches to, the section 33 factors, how the inquiry and appeal process works, how DPDP penalties compare with GDPR’s, and the controls that keep an organisation out of the top three bands.

DPDP penalties: the Schedule to the DPDP Act 2023
₹250 crore security safeguards (s.8(5)) · ₹200 crore breach notification (s.8(6)) · ₹200 crore children (s.9) · ₹150 crore Significant Data Fiduciary (s.10) · ₹10,000 data principal duties (s.15) · voluntary undertaking (s.32) · ₹50 crore any other breach.

The Schedule: every DPDP penalty band

Item Breach Section Penalty (may extend to)
1 Breach of the obligation of a data fiduciary to take reasonable security safeguards to prevent personal data breach Section 8(5) ₹250 crore
2 Breach of the obligation to give the Board or the affected data principal notice of a personal data breach Section 8(6) ₹200 crore
3 Breach of additional obligations in relation to children Section 9 ₹200 crore
4 Breach of additional obligations of a Significant Data Fiduciary Section 10 ₹150 crore
5 Breach of duties of a data principal Section 15 ₹10,000
6 Breach of any term of a voluntary undertaking accepted by the Board Section 32 Up to the extent applicable for the breach in respect of which the inquiry proceedings were instituted
7 Breach of any other provision of the Act or the Rules ₹50 crore

Two features of the table matter for planning. The penalties are ceilings — “may extend to” — and the Board sets the actual figure on the section 33(2) factors. And the top three bands attach to three specific duties: security safeguards, breach notification and children’s data. Everything else a fiduciary can get wrong — notice, consent, purpose limitation, retention, data principal rights, transfers — sits in the ₹50 crore band, which is still larger than most GDPR fines ever issued. Our guide to the DPDP Act covers the duties the bands attach to.

Section 33: how the Board sets DPDP penalties

Section 33(1) empowers the Board, after an inquiry under section 28 and after giving the person a reasonable opportunity of being heard, to impose a monetary penalty specified in the Schedule where it determines that a breach is significant. Section 33(2) lists what the Board must have regard to.

Factor (section 33(2)) What it rewards or punishes
(a) The nature, gravity and duration of the breach A short, contained incident is not a systemic failure
(b) The type and nature of the personal data affected Health, financial, children’s and biometric data weigh heavier
(c) Whether the breach is repetitive Prior findings and unremediated recurrences
(d) Whether the person, as a result of the breach, realised a gain or avoided a loss Penalties scale to the economic benefit of non-compliance
(e) Whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of that action Fast, effective response is the strongest mitigating factor available
(f) Whether the monetary penalty is proportionate and effective, having regard to achieving compliance and deterring breach Deterrence and proportionality both count
(g) The likely impact of the imposition of the monetary penalty on the person Size and financial position of the fiduciary

Two other mechanisms shape outcomes. Section 32 lets the Board accept a voluntary undertaking — to take or refrain from specified action, within a specified time — at any stage of proceedings, which bars further proceedings on the matter unless the undertaking is breached (item 6). And section 27 lets the Board direct urgent remedial or mitigation measures on a breach intimation before any inquiry concludes. Penalties are credited to the Consolidated Fund of India (section 34); there is no compensation route to data principals through the Board.

Inquiry, appeal and enforcement

Stage Provision What happens
Trigger Sections 27–28 A breach intimation, a data principal complaint after exhausting the fiduciary’s grievance redressal, a reference from the government, or a court direction
Inquiry Section 28 The Board functions as a digital office, has civil-court powers to summon persons and documents, may issue interim orders, and may close the proceedings or proceed to section 33; a false or frivolous complaint can draw a warning or costs for the complainant
Interim measures Section 27 Directions for urgent remedial or mitigation measures on a breach
Decision Section 33 A monetary penalty, or a voluntary undertaking under section 32
Appeal Section 29 To the Telecom Disputes Settlement and Appellate Tribunal within 60 days (extendable for sufficient cause); the Tribunal aims to dispose within six months
Execution Sections 30 and 34 Appellate Tribunal orders are executable as civil-court decrees; sums realised as penalties are credited to the Consolidated Fund of India

Rule 21 and the Sixth Schedule of the DPDP Rules 2025 set the Board’s techno-legal procedure — digital filings, hearings and orders. Our guide to the DPDP Rules 2025 covers the procedural rules alongside the substantive ones.

DPDP penalties vs GDPR fines

DPDP Act GDPR
Highest band ₹250 crore (≈ €25–28m) — security safeguards €20m or 4% of worldwide annual turnover, whichever is higher
Basis Fixed rupee ceilings per breach type; no turnover link Two tiers linked to turnover
Who imposes Data Protection Board of India, after inquiry Each Member State supervisory authority; one-stop-shop for cross-border cases
Factors Seven in section 33(2) Eleven in Article 83(2)
Compensation Not through the Board Article 82 right to compensation
Settlement Voluntary undertaking (section 32) No equivalent; some authorities settle informally
Appeal TDSAT within 60 days National courts

The practical difference is that DPDP penalties are capped in absolute terms, which for a very large multinational is less than 4% of turnover, and uncapped by turnover, which for a small Indian fiduciary can be existential — a ₹50 crore ceiling for a notice defect applies whatever the fiduciary’s revenue, subject to the factor (g) impact test. Our guide to DPDP Act vs GDPR covers the wider comparison.

Staying out of the top three bands

  1. Security safeguards (₹250 crore). Implement Rule 6’s minimums — encryption, obfuscation, masking or virtual tokens; access control; logs and monitoring for unauthorised access with detection, investigation and remediation; backups for continuity; one-year log retention; contractual security obligations on processors — and be able to evidence each. Section 8(5) is a reasonableness standard; the Rule 6 list is the floor the Board will measure against.
  2. Breach notification (₹200 crore). Rule 7 requires notice to each affected data principal without delay, and to the Board without delay plus a detailed report within 72 hours, extendable on written request. Build the workflow before the incident. Our guide to DPDP breach notification covers the content of each notice.
  3. Children (₹200 crore). Section 9 requires verifiable parental consent before processing a child’s data and prohibits tracking, behavioural monitoring and targeted advertising directed at children. If under-18s can be in your user base, an age-assurance and consent design is the control. Our guide to verifiable parental consent covers Rule 10.
  4. Significant Data Fiduciary duties (₹150 crore). If notified: the India-based DPO, the independent auditor, the annual DPIA and audit, and algorithmic due diligence under Rule 13.
  5. Everything else (₹50 crore). Notice under Rule 3, consent records, purpose limitation, retention and erasure under Rule 8, data principal rights within the published timelines, grievance redressal, processor contracts and transfer conditions under Rule 15.

The single most valuable investment across all bands is the one that improves factor (e): an incident response capability that detects, contains, notifies and remediates quickly, with records that prove it. The Board is directed to weigh the timeliness and effectiveness of mitigation, and it is the factor the fiduciary controls after the breach has happened.

Frequently asked questions

What is the maximum penalty under the DPDP Act?
₹250 crore per breach for failing to take reasonable security safeguards to prevent a personal data breach (Schedule item 1, section 8(5)). Breach-notification failures and children’s-data breaches carry ₹200 crore; Significant Data Fiduciary breaches ₹150 crore; any other breach ₹50 crore.

Are DPDP penalties linked to turnover?
No. The Schedule sets fixed rupee ceilings. The Board must consider the likely impact of the penalty on the person under section 33(2)(g), which is where size enters the assessment.

Who imposes DPDP penalties?
The Data Protection Board of India, after an inquiry under section 28 and an opportunity to be heard, where it finds the breach significant. Appeals go to the Telecom Disputes Settlement and Appellate Tribunal within 60 days.

Can data principals claim compensation?
Not through the Board; penalties go to the Consolidated Fund of India. Data principals complain to the Board after exhausting the fiduciary’s grievance redressal, and civil remedies outside the Act are unaffected.

When do DPDP penalties apply from?
The Schedule and the substantive duties come into force on 13 May 2027 under Rule 1 of the DPDP Rules 2025; the Board and rule-making provisions have been in force since 13 November 2025.

Where this leaves you

Read the Schedule as a priority list: security safeguards, breach notification and children’s data carry the ₹250 crore and ₹200 crore bands and deserve the first investment; the Significant Data Fiduciary duties follow if you are notified; everything else sits at ₹50 crore and is handled by the ordinary programme. Then build the mitigation evidence that section 33(2)(e) rewards, because the Board must weigh it and it is the one factor still in your hands after the breach.

References

More on the DPDP Act

The Rule 6 security safeguards checklist, the breach notification procedure and notice templates, the children’s-data and parental-consent procedure and the Board inquiry response plan are in the DPDP Act Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.