DPDP penalties: what non-compliance actually costs.
The Act's Schedule sets fixed maximum penalties by violation type — and unlike some global frameworks, they don't scale down because your company is small.
The Schedule, by violation type
Section 33 of the DPDP Act empowers the Data Protection Board of India to impose financial penalties for specific categories of violation, each with its own ceiling:
| Violation | Maximum penalty |
|---|---|
| Breach of the obligation to take reasonable security safeguards to prevent personal data breach | Up to ₹250 crore |
| Breach of the obligation to give the Board or affected Data Principals the required notice of a personal data breach | Up to ₹200 crore |
| Breach of additional obligations in relation to processing of personal data of children | Up to ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | Up to ₹150 crore |
| Breach of any other provision of the Act or the Rules made thereunder | Up to ₹50 crore |
| Breach of the duties of a Data Principal under Section 15 (for example, providing false information) | Up to ₹10,000 |
| Breach of any term of a voluntary undertaking accepted by the Board under Section 32 | Up to the penalty applicable to the underlying breach |
These are maximum statutory ceilings, not fixed fines. When deciding the amount to impose in any individual case, the Board considers the factors set out in Section 33 — including the nature, gravity and duration of the contravention, the type of data involved, whether it was repeated, action taken to mitigate the effect, and the likely impact of the penalty on the person concerned.
Why the "fixed amount" structure matters at every size
This is the detail that catches organisations off guard, especially smaller ones. Unlike GDPR, which caps penalties as a percentage of global turnover, DPDP's ceilings are fixed absolute rupee amounts and apply regardless of organisational turnover. Section 33 of the Act does, however, require the Board to consider proportionality and the likely impact of the penalty on the person concerned when deciding the actual amount to impose. A ₹250 crore ceiling would be a rounding error for a large conglomerate — and existential for a small to mid-size company. Building substantive compliance is the practical answer at every scale.
A single incident can involve more than one contravention
A single event may involve more than one statutory obligation. For example, an inquiry might examine both the adequacy of security safeguards and whether breach-notification requirements were followed — two distinct provisions of the Act. Any penalty in each case would depend on the Board's findings under the applicable section. A poorly handled breach can therefore compound across multiple obligations.
What actually reduces exposure: the Board explicitly weighs prompt, good-faith remediation. A documented incident response process, evidence that staff knew what to do and did it quickly, and a track record of no prior violations all work in an organisation's favour when the Board is deciding an actual amount — not just the maximum ceiling.
When can penalties actually be imposed?
The Data Protection Board of India has been legally established. Appointments to the Board and its operational arrangements are being completed. Most substantive provisions of the Act, including the penalty regime, are scheduled to commence on 13 May 2027. Some legal commentators expect enforcement activity — investigations, directions, and possibly early orders — during the run-up to that date. The prudent takeaway either way is the same: the exposure exists in the law now, and building genuine compliance — not paper compliance — before enforcement begins is the only strategy that works regardless of exact timing.
DPDPA Compliance Training