Compliance

DPDP Act Penalties Explained: The Up to ₹250 Crore Schedule

Section 33 and the Schedule set penalties from ₹10,000 to ₹250 crore. How the Data Protection Board calculates fines and which breaches cost the most.

Check your DPDP readiness — free More on the blog

DPDP Act Penalties Explained: The Up to ₹250 Crore Schedule

When the Digital Personal Data Protection Act, 2023 was published, the figure that made every boardroom headline was ₹250 crore. Corporate leaders frequently ask whether that number is a theoretical maximum or a real operational threat. The answer lies in Section 33 and the Schedule to the Act. Unlike earlier Indian commercial statutes that imposed token fines of ₹5,000 or ₹10,000, the DPDP penalty architecture was deliberately structured to be punitive, proportional, and impossible to treat as a mere cost of doing business.

The five penalty heads in the Schedule

  • Failure to prevent data breach (Section 8(5)) — up to ₹250 crore. Applies when a Data Fiduciary fails to implement reasonable security safeguards and personal data is compromised.
  • Failure to notify breach (Section 8(6)) — up to ₹200 crore. Applies when an entity attempts to conceal a breach or delays notifying the Data Protection Board and impacted individuals.
  • Breach of children’s data duties (Section 9) — up to ₹200 crore. Imposed for tracking, behavioral monitoring, targeted advertising directed at children, or processing children's data without verifiable parental consent.
  • Significant Data Fiduciary defaults (Section 10) — up to ₹150 crore. Triggered by failure to appoint a resident DPO, failure to engage an independent data auditor, or omitting Data Protection Impact Assessments (DPIA).
  • General statutory contraventions — up to ₹50 crore. Encompassing notice defects under Section 5, consent irregularities under Section 6, and failure to honor Data Principal rights under Section 11.

The eight factors the Board evaluates under Section 33(2)

The ₹250 crore limit is a statutory ceiling per contravention, not an automatic assessment. Under Section 33, the Board must determine the penalty having regard to: The fastest way to turn a manageable security flaw into a catastrophic ₹200 crore penalty is attempting to cover it up instead of reporting it on the statutory timetable.

  • The nature, gravity, and duration of the breach.
  • The type and sensitivity of personal data impacted.
  • Whether the non-compliance was repetitive.
  • Whether the entity gained revenue or avoided financial loss from the default.
  • The speed and effectiveness of mitigation steps taken after discovery.
  • Whether the penalty is proportionate and effective for deterrence.

How to insulate your business against maximum penalties

When an incident occurs, documented response procedures make the legal difference. Having an immediate breach workflow allows you to deploy our data breach report to DPBI template and send a compliant customer breach notification within prescribed hours. Furthermore, Section 32 allows businesses to submit a voluntary undertaking to the Board, committing to specific remediation steps to resolve inquiries without maximum penalties. Review our voluntary undertaking template and read our statutory breakdown of Section 33 DPDP penalties to protect your business.

Common questions

What is the highest penalty under the DPDP Act 2023?

₹250 crore, specified in item 1 of the Schedule for breach in observing the obligation of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach under Section 8(5).

What is the penalty for failing to report a personal data breach?

Up to ₹200 crore under item 2 of the Schedule for failing to give notice of a personal data breach to the Data Protection Board and each affected Data Principal under Section 8(6).

Can company directors go to prison under the DPDP Act?

No. The DPDP Act decriminalised privacy violations in India, replacing imprisonment with substantial civil monetary penalties. Directors and officers do not face criminal jail terms under DPDP, but the financial liability falls directly on the corporate entity.

How does the Data Protection Board determine the penalty amount?

Section 33(2) mandates the Board to consider eight statutory factors: the nature, gravity and duration of breach; type of personal data impacted; repetitive nature; whether non-compliance resulted in financial gain or avoided loss; mitigation measures implemented; and proportionality.

Related reading

  • Late payments to MSME suppliers trigger tax disallowance — If a business does not settle dues to a registered micro or small enterprise within the statutory 45‑day (or 15‑day without contract) window, the amount is added back to taxable profit at year‑end, removing the deduction and increasing income‑tax liability.
  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this