Compliance

Understanding DPDP Act Section 33 Penalties for Data Breaches

Section 33 of the Digital Personal Data Protection Act lets the Data Protection Board set monetary penalties up to a ceiling of ₹250 crore for serious security‑safeguard failures, with lower caps for other breaches, meaning the actual cost depends on the Board’s assessment of each case.

Check your DPDP readiness — free More on the blog

Understanding DPDP Act Section 33 Penalties for Data Breaches

The Digital Personal Data Protection Act of 2023 introduces a new enforcement regime for organisations that handle personal data. Section 33 empowers the Data Protection Board to impose monetary penalties after an inquiry finds a breach to be significant. The Board does not apply a flat fine; instead it fixes an amount within the ranges laid down in the Schedule, taking into account a range of factors about the breach and the entity’s response.

How the penalty ceiling works

The Schedule attached to the Act lists several heads of breach, each with its own maximum amount. The highest ceiling, ₹250 crore, applies to a failure to implement reasonable security safeguards that could prevent a data breach. Other heads include up to ₹200 crore for not notifying the Board or affected persons, up to ₹200 crore for violations involving children’s data, up to ₹150 crore for additional duties of a Significant Data Fiduciary, and a residuary head of up to ₹50 crore for other breaches.

Factors the Board considers when fixing the amount

Before deciding the exact figure, the Board looks at the nature and gravity of the breach, the type of personal data involved, whether the breach was repetitive, any gain or loss avoided, the mitigation steps taken after the incident, and whether the amount is proportionate and effective as a deterrent. These considerations ensure that the penalty reflects both the seriousness of the violation and the steps taken to remediate it.

Common misconceptions to avoid

Many businesses mistakenly quote the top ceiling as the penalty they will inevitably pay. In reality, the Board tailors each penalty to the specific circumstances, meaning the actual cost can be far lower if the breach is minor, promptly reported, and swiftly mitigated. Conversely, repeated or egregious failures can push the amount close to the ceiling. Planning solely for the maximum penalty can lead to misallocation of resources. A more effective approach is to invest in robust security safeguards, establish clear breach‑notification procedures, and maintain records that demonstrate compliance. These steps not only reduce the likelihood of a breach but also provide strong mitigating evidence if an inquiry occurs. The Act also distinguishes between different categories of data fiduciaries. A Significant Data Fiduciary, which processes large volumes of sensitive data, faces a separate ceiling of ₹150 crore for additional obligations. Understanding which category your organisation falls into helps you gauge the potential exposure and align your compliance programme accordingly. If a breach does occur, the first priority should be timely notification to the Board and affected individuals. This not only satisfies the statutory duty but also serves as a mitigating factor when the Board assesses the penalty. Delays or failures to notify trigger a separate head with a ceiling of ₹200 crore, adding to the overall financial risk. In summary, Section 33 creates a flexible penalty framework that balances deterrence with proportionality. The maximum exposure of ₹250 crore applies only to the most serious security‑safeguard failures, while other breaches have lower caps. The Board’s discretion, guided by a detailed set of factors, means the actual cost varies widely across cases.

  • The ₹250 crore figure is a ceiling, not an automatic fine for every breach
  • Separate breaches trigger separate heads and may attract multiple penalties
  • Mitigation actions are relevant and can reduce the amount fixed
  • Failure to report a breach has its own ceiling and should not be overlooked

Common questions

What is the highest monetary penalty possible under Section 33 of the DPDP Act?

The Schedule sets a ceiling of up to ₹250 crore for a failure to take reasonable security safeguards to prevent a personal data breach. This is the maximum for that specific head, not an automatic fine for every breach.

Does the Data Protection Board automatically apply the ceiling amount for every breach?

No. The Board fixes the penalty after an inquiry, considering the breach’s nature, gravity, data type, repetition, mitigation and proportionality. The actual amount can be lower than the ceiling.

Can multiple penalty heads apply to a single incident?

Yes. Separate lapses trigger separate heads, each with its own ceiling. For example, failing to secure data and failing to notify the Board are distinct violations and may attract penalties under both heads.

How does mitigation affect the penalty amount?

Mitigation is one of the factors the Board must consider. Prompt remedial actions, cooperation with the Board and steps to prevent recurrence can lead to a lower penalty within the prescribed ceiling.

Related reading

  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
  • Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this