Compliance
Section 33 and the Schedule set penalties from ₹10,000 to ₹250 crore. How the Data Protection Board calculates fines and which breaches cost the most.
Check your DPDP readiness — free More on the blogWhen the Digital Personal Data Protection Act, 2023 was published, the figure that made every boardroom headline was ₹250 crore. Corporate leaders frequently ask whether that number is a theoretical maximum or a real operational threat. The answer lies in Section 33 and the Schedule to the Act. Unlike earlier Indian commercial statutes that imposed token fines of ₹5,000 or ₹10,000, the DPDP penalty architecture was deliberately structured to be punitive, proportional, and impossible to treat as a mere cost of doing business.
The ₹250 crore limit is a statutory ceiling per contravention, not an automatic assessment. Under Section 33, the Board must determine the penalty having regard to: The fastest way to turn a manageable security flaw into a catastrophic ₹200 crore penalty is attempting to cover it up instead of reporting it on the statutory timetable.
When an incident occurs, documented response procedures make the legal difference. Having an immediate breach workflow allows you to deploy our data breach report to DPBI template and send a compliant customer breach notification within prescribed hours. Furthermore, Section 32 allows businesses to submit a voluntary undertaking to the Board, committing to specific remediation steps to resolve inquiries without maximum penalties. Review our voluntary undertaking template and read our statutory breakdown of Section 33 DPDP penalties to protect your business.
₹250 crore, specified in item 1 of the Schedule for breach in observing the obligation of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach under Section 8(5).
Up to ₹200 crore under item 2 of the Schedule for failing to give notice of a personal data breach to the Data Protection Board and each affected Data Principal under Section 8(6).
No. The DPDP Act decriminalised privacy violations in India, replacing imprisonment with substantial civil monetary penalties. Directors and officers do not face criminal jail terms under DPDP, but the financial liability falls directly on the corporate entity.
Section 33(2) mandates the Board to consider eight statutory factors: the nature, gravity and duration of breach; type of personal data impacted; repetitive nature; whether non-compliance resulted in financial gain or avoided loss; mitigation measures implemented; and proportionality.
Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this