DPDPA penalties explained: ceilings up to ₹250 crore, not a bill
This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.
₹250 crore is the largest figure in the Schedule to the Digital Personal Data Protection Act, 2023. It is a ceiling for one category of breach, not a fixed fine. The Act also sets out who can trigger an inquiry by the Data Protection Board of India and what the Board must find before it can penalise anyone. It then lists what the Board must weigh when it fixes an amount.
The Schedule: seven ceilings
Section 33(1) points to the Schedule at the end of the Act. Six of its seven rows say the penalty “may extend to” an amount. Row 6 is tied to the breach in the original proceedings.
Sl. 1. Breach: Failing to take reasonable security safeguards to prevent a personal data breach (Section 8(5)); Penalty may extend to: ₹250 crore
Sl. 2. Breach: Failing to notify the Board or affected Data Principals of a personal data breach (Section 8(6)); Penalty may extend to: ₹200 crore
Sl. 3. Breach: Breaching the additional obligations for children (Section 9); Penalty may extend to: ₹200 crore
Sl. 4. Breach: Breaching the additional obligations of a Significant Data Fiduciary (Section 10); Penalty may extend to: ₹150 crore
Sl. 5. Breach: Breaching the duties of a Data Principal (Section 15); Penalty may extend to: ₹10,000
Sl. 6. Breach: Breaching a voluntary undertaking accepted by the Board (Section 32); Penalty may extend to: Up to the amount applicable to the breach for which the Section 28 proceedings were started
Sl. 7. Breach: Breaching any other provision of the Act or the Rules; Penalty may extend to: ₹50 crore
The Schedule sets no minimum and no aggregate cap. The Act does not say how penalties for several breaches in one inquiry combine.
Who can start a Board inquiry
Section 27(1) lists the Board’s powers and functions. Each one starts from a specific trigger:
(a) an intimation of a personal data breach under Section 8(6), on which the Board may also direct urgent remedial or mitigation measures;
(b) a complaint by a Data Principal about a personal data breach, or about a Data Fiduciary’s breach of its obligations to her or of her rights; or a reference from the Central Government or a State Government, or a court’s direction;
(c) a complaint by a Data Principal about a Consent Manager;
(d) an intimation that a Consent Manager has breached a condition of its registration;
(e) a reference from the Central Government about an intermediary breaching Section 37(2).
The list does not include the Board starting an inquiry on its own initiative. For most businesses, the realistic triggers are their own breach intimation, a complaint from a customer or employee, or a government reference.
A Data Principal must first use your grievance redressal mechanism before approaching the Board (Section 13(3)). A grievance process that works gives you the first chance to resolve a complaint.
From trigger to penalty
Section 28 sets the procedure. The Board first decides whether there are sufficient grounds to inquire; if not, it may close the proceedings, recording its reasons (Section 28(3) and (4)). If it inquires, it follows the principles of natural justice and records its reasons (Section 28(6)). It may issue interim orders after hearing the person concerned (Section 28(10)).
Rule 19(9) gives the Board six months from receiving the intimation, complaint, reference or direction to complete the inquiry. It may extend that for recorded reasons, by up to three months at a time.
At the end, after a hearing, the Board either closes the proceedings or proceeds under Section 33 (Section 28(11)). Section 33(1) then sets the threshold: a penalty is possible only if the Board determines, on conclusion of the inquiry, that the breach is significant, and only after giving the person an opportunity of being heard.
The seven factors that set the amount
Section 33(2) lists what the Board must have regard to when it fixes the amount:
(a) the nature, gravity and duration of the breach;
(b) the type and nature of the personal data affected;
(c) whether the breach is repetitive;
(d) whether the person realised a gain or avoided a loss as a result;
(e) whether the person took action to mitigate the effects, and how timely and effective it was;
(f) whether the penalty is proportionate and effective, given the need to secure compliance and deter breaches;
(g) the likely impact of the penalty on the person.
Factor (e) is the one you control after something goes wrong. A breach log, a dated mitigation record and notices sent on time are the evidence the Board would look at under it.
Voluntary undertakings and appeals
At any stage of a Section 28 proceeding, the Board may accept a voluntary undertaking, such as a commitment to take or stop an action within a set time (Section 32(1) and (2)). Once accepted, it bars further proceedings on its contents (Section 32(4)). Breaking it is treated as a breach of the Act (Section 32(5)), with the ceiling in Schedule item 6.
Anyone aggrieved by a Board order or direction may appeal to the Appellate Tribunal, which Section 2(a) defines as the Telecom Disputes Settlement and Appellate Tribunal. The appeal is due within sixty days of receiving the order or direction, and the Tribunal may accept a late appeal for sufficient cause (Section 29(2) and (3)). Rule 22 requires the appeal to be filed in digital form. Penalties the Board collects go to the Consolidated Fund of India (Section 34).
When this starts
Sections 27 (except clause (d) of Section 27(1)), 28 to 34, and the duties the Schedule refers to come into force eighteen months after G.S.R. 843(E) was published on 13 November 2025, which is 13 May 2027. Rule 22 starts on the same date under Rule 1(4).
How to use the ceilings
The ceilings show where the Act allows the largest penalties. They are not a cost estimate. Security safeguards carry the highest ceiling (₹250 crore); breach notification and the children’s obligations share the next (₹200 crore). Because the amount depends on Section 33(2), the practical defence is evidence: documented safeguards, a working grievance process, and a record of what you did and when.
One further consequence sits outside the Schedule. Under Section 37(1), the Board may send the Central Government a written reference. It reports that the Board has penalised a Data Fiduciary (the person or business that decides why and how personal data is processed) in two or more instances. It advises blocking public access to information held in any computer resource that enables the Data Fiduciary to offer goods or services to people in India. After hearing the Data Fiduciary, the government may order that blocking in the interests of the general public. Section 37 also starts on 13 May 2027.
Sources
Every section, rule and date above was checked against the official text on 4 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Section 2(a): Appellate Tribunal: the Telecom Disputes Settlement and Appellate Tribunal
Section 8(5): Security safeguards (item 1)
Section 8(6): Breach intimation (item 2)
Section 9: Children (item 3)
Section 10: Significant Data Fiduciaries (item 4)
Section 13(3): Grievance redressal to be exhausted before approaching the Board
Section 15: Duties of Data Principals (item 5)
Section 27(1): The Board's powers and the triggers for each, clauses (a) to (e)
Section 28: Inquiry procedure, including sub-sections (3), (4), (6), (10) and (11)
Section 29: Appeal within sixty days; late appeals for sufficient cause
Section 32: Voluntary undertakings (item 6)
Section 33(1): Penalty only for a significant breach, on conclusion of an inquiry, after a hearing
Section 33(2): Seven factors for the amount
Section 34: Penalties credited to the Consolidated Fund of India
Section 37: Blocking on a Board reference after penalties in two or more instances (1); intermediary duty referenced in Section 27(1)(e) (2)
The Schedule, items 1 to 7: Penalty ceilings: items 1 to 5 and 7 "may extend to" an amount; item 6 follows the original breach
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
Rule 1(4): Rule 22 in force eighteen months from publication
Rule 19(9): Inquiry within six months, extendable by up to three months at a time
Rule 22: Appeal filed in digital form
Notifications
G.S.R. 843(E), clause (c): Sections 27 (except 27(1)(d)), 28 to 34 and 37 in force eighteen months from 13 November 2025
See which penalty categories your gaps fall into
The Reality Check workbook in how-to 01 maps each open duty to its penalty category in the Schedule. Its dashboard shows the ceilings and never adds them up.
The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.
Drafting aid, not legal advice.




Comments