DPDP penalties: the amounts in the Schedule and how the Board applies them
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Penalties under the DPDP Act 2023 are monetary, imposed by the Data Protection Board after an inquiry, and capped by the Act's Schedule. The highest cap is two hundred and fifty crore rupees for a Data Fiduciary failing its reasonable security safeguards obligation under section 8(5). Failing to notify a breach or breaching children's data obligations may each draw up to two hundred crore rupees, Significant Data Fiduciary obligations up to one hundred and fifty crore rupees, any other breach up to fifty crore rupees, and a Data Principal breaching statutory duties up to ten thousand rupees. These provisions sit in the commencement group due eighteen months from the notification gazette, which computes to 13 May 2027; that calendar date is interpretation until officially confirmed.
The DPDP Act 2023 does not scatter penalty amounts through its chapters. Every monetary cap sits in one place, the Schedule at the end of the Act, and one section, section 33, controls who imposes them and how they are sized.
Who imposes penalties, and when
Only the Data Protection Board of India imposes monetary penalties, and only at the end of a process.
"If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule."
Section 33(1) of the DPDP Act 2023.
Three gates are built into that sentence. There must be an inquiry that has concluded, the Board must determine that the breach is significant, and the person must have had an opportunity of being heard. A penalty is the outcome of that process, not an automatic consequence of a breach.
The seven caps in the Schedule
The Schedule pairs each category of breach with a maximum. Every figure is a ceiling that the penalty "may extend to", not a fixed fine.
- Security safeguards, section 8(5): a Data Fiduciary failing to take reasonable security safeguards to prevent personal data breach faces the highest cap, up to two hundred and fifty crore rupees.
- Breach notification, section 8(6): failing to give the Board or affected Data Principals notice of a personal data breach, up to two hundred crore rupees.
- Children's data, section 9: breach of the additional obligations in relation to children, up to two hundred crore rupees.
- Significant Data Fiduciary obligations, section 10: breach of the additional obligations placed on a Significant Data Fiduciary, up to one hundred and fifty crore rupees.
- Duties of Data Principals, section 15: breach of the statutory duties that the Act places on individuals, up to ten thousand rupees.
- Voluntary undertakings, section 32: breach of any term of a voluntary undertaking accepted by the Board, up to the amount applicable to the breach for which those proceedings were instituted.
- Everything else: breach of any other provision of the Act or its rules, up to fifty crore rupees.
The ordering tells its own story. The framework weights security safeguard failures and failure to notify a breach most heavily, then child data and Significant Data Fiduciary duties, with a general residual cap for everything else.
How the Board sizes a penalty
Section 33(2) lists the matters the Board must have regard to when it fixes an amount within a cap: the nature, gravity and duration of the breach; the type and nature of the personal data affected; whether the breach is repetitive; whether the person gained or avoided loss as a result; the mitigation taken and how timely and effective it was; whether the amount is proportionate and effective as a deterrent; and the likely impact of the penalty on the person. Documented, prompt mitigation is not just good practice, it is a statutory sizing factor.
Where the money goes
Section 34 answers a question boards and CFOs often ask: penalties are not compensation to affected individuals.
"All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India."
Section 34 of the DPDP Act 2023.
When these provisions begin to operate
Sections 33 and 34 sit in the group that notification G.S.R. 843(E) brings into force eighteen months from the publication of its gazette, printed 13 November 2025. That computes to 13 May 2027, and the computed calendar date is interpretation until officially confirmed. The notification names sections only; the Schedule takes effect through section 33(1), so the Schedule is presented as commencing with section 33, which is also a reading rather than an official statement.
The practical consequence: the substantive obligations whose breach these caps punish, such as security safeguards and breach notification under section 8, commence on the same computed date. Building the controls before the enforcement machinery switches on is the entire point of the phased timeline. The company action plan tool sequences that work, and the breach response tool covers the notification duty whose failure carries the two hundred crore rupee cap.
Related tool
Compliance Plan
Generate one company level action plan and see the work for your role first.
Open
Related tool
Breach Response Assistant
Turn breach obligations into a clear response workflow with the exact Rule 7 steps.
Open
Section 33, official text with sources →The Schedule, official penalties table with sources →
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 33, p. 16. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 33(1). Section 33 begins on Gazette page 16 and concludes on page 17.
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), The Schedule Schedule, p. 21. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026The Schedule is printed as a three column table (serial number, breach description, penalty cap). All seven amounts restated in this article are taken row by row from the printed table.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 34, p. 17. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Section 34.
- [4]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 17 August 2026Notification G.S.R. 843(E), Gazette issue No. 757, printed date 13 November 2025. Sections 33 and 34 fall within sections 28 to 34 in this group. The missing space in the phrase "section 6,sections 7 to 10" appears as printed in the Gazette text layer.
- [5]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 17 August 2026The calendar date 13 May 2027 is computed from the printed publication date of 13 November 2025 plus eighteen months and is presented as interpretation until officially confirmed. The notification names sections only; the Schedule operates through section 33(1), so the Schedule is presented as commencing with section 33, which is also interpretation.