Penalties Under DPDPA — Complete Guide

DPDPA penalties are administrative, Schedule-capped, and discretionary — not formula-based. The maximum penalty is ₹250 crore for failure to implement adequate security safeguards. The Data Protection Board determines the actual amount after considering seven mandatory factors in Section 33(2). The Schedule caps can rise only if the Central Government amends the Schedule by notification under Section 42 — and never to more than twice the original amounts. No such notification has been issued. This page explains the full framework, the inquiry process, and what factors weigh against you.

1. Overview of the Penalty Framework

The Digital Personal Data Protection Act, 2023 (DPDPA) establishes a Schedule-capped monetary penalty framework administered by the Data Protection Board of India (DPBI) under Section 33. Penalties are administrative in nature and are imposed only after the Board concludes an inquiry, determines that a breach is significant, and gives the person an opportunity of being heard.

The Act does not prescribe a mathematical formula, turnover-linked multiplier, or per-person calculation for arriving at the exact penalty amount. Instead, the Board exercises discretion within statutory caps, guided by mandatory consideration factors under Section 33(2). The caps themselves can change only through the Central Government's power to amend the Schedule under Section 42.


2. Penalty Quantum Under the Schedule

The Schedule to the Act (read with Section 33(1)) specifies seven categories of breach and their corresponding maximum penalties. The statutory text uses the formulation "May extend to…" for each category.

ItemBreach CategoryLiable PersonProvisionMaximum Penalty
1Failure to take reasonable security safeguards to prevent personal data breachData FiduciarySection 8(5)₹250 crore
2Failure to give notice of personal data breach to the Board or affected Data PrincipalData FiduciarySection 8(6)₹200 crore
3Breach of additional obligations in relation to childrenData FiduciarySection 9₹200 crore
4Breach of additional obligations of Significant Data FiduciarySignificant Data FiduciarySection 10₹150 crore
5Breach of duties of Data PrincipalData PrincipalSection 15₹10,000
6Breach of voluntary undertaking accepted by the BoardPerson who gave the undertakingSection 32Up to applicable underlying penalty
7Breach of any other provision of the Act or RulesAny personAny other provision₹50 crore

3. The Statutory Trigger for Penalty

A monetary penalty is not automatic. The statutory structure requires the following sequential conditions to be satisfied:

  1. 1Breach of the Act or Rules — there must be a contravention of a provision.
  2. 2Inquiry by the Board — the DPBI must conduct an inquiry under Section 28.
  3. 3Significance determination — the Board must conclude that the breach is significant.
  4. 4Opportunity of being heard — the person must be given a reasonable opportunity to present their case.
  5. 5Schedule-based cap — the penalty must fall within the amount specified in the Schedule for that category.

Statutory structure: Breach + Inquiry + Significance + Hearing + Schedule Cap = Monetary Penalty under Section 33.


4. Factors for Determining the Penalty Amount

Under Section 33(2), the Board shall have regard to the following factors when fixing the quantum within the Schedule cap. These are statutory considerations, not numerical weights or percentage multipliers.

FactorDescription
Nature, gravity and duration of the breachWhat the breach was, how serious it was, and how long it continued
Type and nature of personal data affectedWhether sensitive, financial, health, or children's data was involved
Repetitive nature of the breachWhether it was a first-time or recurring violation
Gain realised or loss avoidedWhether the person profited or avoided costs by the breach
Mitigation action, and its timeliness and effectivenessWhether the person took steps to reduce the effects and consequences of the breach, and how prompt and effective those steps were
Proportionality and deterrenceWhether the penalty secures observance and deters future breach
Likely impact of penalty on the personFinancial capacity and effect on operations

5. Can the Caps Increase? Section 42

The Board cannot go above the Schedule. The only route to higher caps is Section 42: the Central Government may amend the Schedule by notification, but never so as to increase any penalty to more than twice the amount originally enacted. No such notification has been issued — the figures below are the statutory ceiling on any future amendment, not penalties the Board can impose today.

Schedule ItemBase CapCeiling if the Schedule is ever amended (Section 42, max 2×)
Item 1 — Security safeguards₹250 crore₹500 crore
Item 2 — Breach notification₹200 crore₹400 crore
Item 3 — Children's obligations₹200 crore₹400 crore
Item 4 — Significant Data Fiduciary₹150 crore₹300 crore
Item 7 — Residual category₹50 crore₹100 crore

6. Detailed Penalty Categories

6.1 Failure to Take Reasonable Security Safeguards (Schedule Item 1)

  • Liable person: Data Fiduciary
  • Provision: Section 8(5)
  • Penalty cap: ₹250 crore (Schedule Item 1)
  • Description: Failure to protect personal data in its possession or control, including processing undertaken by a Data Processor on its behalf, by taking reasonable security safeguards to prevent a personal data breach.

6.2 Failure to Notify Personal Data Breach (Schedule Item 2)

  • Liable person: Data Fiduciary
  • Provision: Section 8(6)
  • Penalty cap: ₹200 crore (Schedule Item 2)
  • Description: Failure to give the Board and each affected Data Principal intimation of a personal data breach.

6.3 Breach of Additional Obligations Relating to Children (Schedule Item 3)

  • Liable person: Data Fiduciary
  • Provision: Section 9
  • Penalty cap: ₹200 crore (Schedule Item 3)
  • Description: Breach of obligations such as obtaining verifiable parental consent, prohibiting tracking or behavioural monitoring, and prohibiting targeted advertising directed at children.

6.4 Breach of Additional Obligations of Significant Data Fiduciary (Schedule Item 4)

  • Liable person: Significant Data Fiduciary
  • Provision: Section 10
  • Penalty cap: ₹150 crore (Schedule Item 4)
  • Description: Non-compliance with additional obligations such as appointment of a Data Protection Officer, undertaking a Data Protection Impact Assessment, and periodic audits.

6.5 Breach of Duties of Data Principal (Schedule Item 5)

  • Liable person: Data Principal
  • Provision: Section 15
  • Penalty cap: ₹10,000
  • Description: Breach of duties such as not registering a false or frivolous complaint and not furnishing false information.

6.6 Breach of Voluntary Undertaking (Schedule Item 6)

  • Liable person: Person whose undertaking has been accepted
  • Provision: Section 32
  • Penalty cap: Up to the amount applicable for the underlying breach in respect of which proceedings under Section 28 were instituted
  • Description: Where the Board accepts a voluntary undertaking, breach of any term may attract penalty up to the extent applicable for the original breach.

6.7 Breach of Any Other Provision — Residual Category (Schedule Item 7)

  • Liable person: Any person
  • Provision: Any other provision of the Act or Rules
  • Penalty cap: ₹50 crore (Schedule Item 7)
  • Description: This residual category captures all breaches not specifically covered by Items 1 to 6, ensuring no gap in enforcement.

7. Role-Wise Penalty Exposure

7.1 Data Fiduciary

BreachProvisionMaximum Penalty
Failure to take reasonable security safeguardsSection 8(5)₹250 crore
Failure to notify personal data breachSection 8(6)₹200 crore
Breach of obligations relating to childrenSection 9₹200 crore
Breach of any other provision (residual)Any other provision₹50 crore

7.2 Significant Data Fiduciary

BreachProvisionMaximum Penalty
Breach of additional obligations of SDFSection 10₹150 crore
Failure to take reasonable security safeguardsSection 8(5)₹250 crore
Failure to notify personal data breachSection 8(6)₹200 crore
Breach of obligations relating to childrenSection 9₹200 crore
Breach of any other provision (residual)Any other provision₹50 crore

7.3 Data Principal

BreachProvisionMaximum Penalty
Breach of duties of Data PrincipalSection 15₹10,000

7.4 Person Giving Voluntary Undertaking

BreachProvisionMaximum Penalty
Breach of accepted voluntary undertakingSection 32Up to applicable penalty for underlying breach

7.5 Any Other Person

BreachProvisionMaximum Penalty
Breach of any other provision of Act or RulesResidual category₹50 crore

8. Penalties Alongside Other Remedies

The DPDPA does not contain a clause declaring penalties “without prejudice” to other action — but nothing in it displaces other laws either. What the Act does provide: the Board’s powers under Section 27 include directing urgent remedial measures and inquiring into and penalising the same breach; and a voluntary undertaking accepted under Section 32bars further DPDPA proceedings on its contents (Section 32(4)) — while breaching that undertaking is itself treated as a breach (Section 32(5)). Two practical implications:

  • Parallel proceedings: The DPDPA does not exclude criminal, civil or sectoral action (IT Act, RBI, SEBI) over the same facts. Those regimes run on their own terms.
  • Separate penalties for separate breaches: A single incident may fall under more than one Schedule item. A breach caused by inadequate security (Item 1) coupled with a failure to notify (Item 2) could attract separate penalties of up to ₹250 crore and ₹200 crore respectively.

9. Destination of Penalty Sums

All sums realised by way of penalties imposed by the Board are credited to the Consolidated Fund of India under Section 34 of the Act. Penalties are not paid as compensation to affected Data Principals. Affected individuals must pursue remedies for compensation separately under other applicable laws.


10. Statutory Safeguards and Limits

AspectStatutory Position
Maximum base penalty₹250 crore (Item 1)
Ceiling on any future increase₹500 crore — only by a Central Government notification amending the Schedule under Section 42 (capped at 2×); none issued
Minimum penaltyNot specified — the Board may impose nil or nominal penalties for technical or trivial breaches
Per-person calculationNot prescribed
Turnover-linked formulaNot prescribed
ImprisonmentNot provided under the DPDPA
Opportunity to be heardMandatory before penalty imposition
AppealAvailable to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29

11. Final Statutory Position

The DPDPA penalty framework is a discretionary, Schedule-capped, administrative monetary penalty system. The Board determines the actual amount by weighing the seven statutory factors under Section 33(2); the Schedule caps themselves can change only by a Central Government notification under Section 42, capped at twice the original amounts. There is no fixed formula, but there is a clear statutory ceiling and a structured inquiry process that every organisation must understand to assess its compliance risk accurately.

Disclaimer: This guide is prepared for informational purposes only and does not constitute legal advice. For specific compliance guidance under the DPDPA, consult a qualified data protection professional.