Data protection · Provision

Section 33, DPDP Act 2023 — Penalties, and What They Are For

Section 33, Digital Personal Data Protection Act, 2023

The Board fixes the amount against the Schedule, where the ceiling for a security-safeguards failure is ₹250 crore.

Check your compliance exposure — free All provisions

What the section does

  • Where the Board determines at the end of an inquiry that a breach of the Act is significant, it may impose a monetary penalty specified in the Schedule.
  • The Schedule sets a ceiling of up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach, and up to ₹200 crore for failing to notify the Board or affected persons of a breach.
  • Obligations in relation to children carry up to ₹200 crore, and the additional obligations of a Significant Data Fiduciary up to ₹150 crore. A residuary head covers other breaches up to ₹50 crore.
  • Before fixing an amount the Board considers the nature and gravity of the breach, the type of personal data affected, whether the breach is repetitive, what was gained or avoided, what mitigating action was taken, and whether the amount is proportionate and effective.

Maximum penalty

up to ₹250 crore. A ceiling for the most serious head, not an amount owed automatically. The Board fixes the figure case by case.

Where people go wrong

  • Quoting ₹250 crore as the penalty. It is the top of one head of the Schedule, and the Board sets the actual amount on the factors the section lists.
  • Assuming the amounts are alternatives. Separate lapses engage separate heads.
  • Treating mitigation as irrelevant. What was done after the breach is one of the matters the Board must consider.
  • Planning for the penalty rather than the notification. Failing to report a breach is its own head with its own ceiling.

Common questions

What is the maximum penalty under the DPDP Act?

The Schedule provides up to ₹250 crore for a failure to take reasonable security safeguards to prevent a personal data breach. Other heads carry their own ceilings, including up to ₹200 crore for failing to notify a breach.

Is ₹250 crore a fine every breach attracts?

No. It is a maximum. Section 33(2) requires the Board to fix the amount having regard to the nature, gravity and duration of the breach, the data affected, repetition, gain or loss avoided, mitigation and proportionality.

Who decides the penalty?

The Data Protection Board of India, at the conclusion of an inquiry, and only where it determines that the breach is significant.

Act on this

  • Section 8 — the obligations that are being penalised
  • Free DPDP readiness check

About this summary

A plain-English summary of what this provision requires, not a reproduction of it and not legal advice. Read alongside the bare Act, and take advice on anything turning on your own facts.