Skip to content

DPDP Act Penalties: Up to ₹250 Crore, Explained

DPDP Act penalties in one table: ₹250 crore for weak security, ₹200 crore for unreported breaches or children's data, ₹150 crore for SDFs, and how fines are set.

By the GRC-Flow team · Published · 6 min read

Key takeaways

  • The highest penalty under the DPDP Act is up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach.
  • Not reporting a breach to the Board and affected people, and breaking the duties for children's data, can each cost up to ₹200 crore.
  • Significant Data Fiduciaries face up to ₹150 crore for missing their extra duties, and any other breach of the Act or Rules up to ₹50 crore.
  • Penalties are per instance and decided by the Data Protection Board after an inquiry, weighing factors such as the nature, gravity and duration of the breach.

The penalty schedule

The Schedule to the DPDP Act 2023 sets a maximum for each type of breach:

BreachProvisionMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breachSection 8(5)₹250 crore
Failure to notify the Board and affected Data Principals of a personal data breachSection 8(6)₹200 crore
Breach of the additional obligations for children's dataSection 9₹200 crore
Breach of the additional obligations of a Significant Data FiduciarySection 10₹150 crore
Breach of a voluntary undertaking accepted by the BoardSection 32Up to the amount for the breach it covered
Breach of any other provision of the Act or RulesVarious₹50 crore
Breach of duties by a Data PrincipalSection 15₹10,000

How the Board decides the amount

The amounts are caps. The Data Protection Board sets the actual penalty after an inquiry, considering factors such as:

  • the nature, gravity and duration of the breach;
  • the type and nature of the personal data affected;
  • whether the breach was repeated;
  • any gain made or loss avoided because of it;
  • what the organisation did to mitigate the effects, and how quickly;
  • whether the penalty is proportionate and effective, and its likely impact on the organisation.

That last list is your defence. An organisation that can show its safeguards, its breach response and its records is in a very different position from one that cannot.

The two that catch most companies

Weak security safeguards (₹250 crore)

The Rules spell out the minimum: encryption or masking, access control, logging and monitoring, backups, and contracts that bind processors to the same standards. If a breach happens and these were missing, this is the penalty in play.

Not reporting a breach (₹200 crore)

Under the DPDP Rules, every personal data breach must be reported to the affected people and the Board without delay, with a detailed report to the Board within 72 hours. There is no "low risk" exemption as there is under GDPR. A missed report is a separate breach from the incident itself.

How to reduce your exposure

  1. Map where personal data lives and who can reach it.
  2. Put the Rule 6 safeguards in place, and keep proof that they work.
  3. Write and rehearse a breach playbook with the 72-hour clock.
  4. Check children's data flows for parental consent and no tracking.
  5. Keep evidence for every control, so you can show the Board what you did.

Our DPDP compliance checklist covers each step. GRC Flow keeps a risk register scored by likelihood and impact, tracks each breach against the 72-hour deadline, and stores the evidence behind each control.

Frequently asked questions

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore, for a Data Fiduciary's failure to take reasonable security safeguards to prevent a personal data breach (Section 8(5) read with the Schedule).

Who imposes penalties under the DPDP Act?

The Data Protection Board of India, after an inquiry. Its orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

Can individuals be fined under the DPDP Act?

Yes, but only lightly: a Data Principal who breaks their duties under Section 15 (for example filing a false or frivolous complaint) can face a penalty of up to ₹10,000.

Is there a penalty for every breach, or a percentage of turnover like GDPR?

The DPDP Act sets fixed maximum amounts per type of breach, not a percentage of turnover. The Board decides the actual amount within that cap.

Sources

This guide explains the law in general terms and is not legal advice. Check specific situations with a qualified lawyer.