top of page

DPDPA penalties explained: ceilings up to ₹250 crore, not a bill

6 days ago
6 min read

This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.

₹250 crore is the largest figure in the Schedule to the Digital Personal Data Protection Act, 2023. It is a ceiling for one category of breach, not a fixed fine. The Act also sets out who can trigger an inquiry by the Data Protection Board of India and what the Board must find before it can penalise anyone. It then lists what the Board must weigh when it fixes an amount.

The Schedule: seven ceilings

Section 33(1) points to the Schedule at the end of the Act. Six of its seven rows say the penalty “may extend to” an amount. Row 6 is tied to the breach in the original proceedings.

  • Sl. 1. Breach: Failing to take reasonable security safeguards to prevent a personal data breach (Section 8(5)); Penalty may extend to: ₹250 crore

  • Sl. 2. Breach: Failing to notify the Board or affected Data Principals of a personal data breach (Section 8(6)); Penalty may extend to: ₹200 crore

  • Sl. 3. Breach: Breaching the additional obligations for children (Section 9); Penalty may extend to: ₹200 crore

  • Sl. 4. Breach: Breaching the additional obligations of a Significant Data Fiduciary (Section 10); Penalty may extend to: ₹150 crore

  • Sl. 5. Breach: Breaching the duties of a Data Principal (Section 15); Penalty may extend to: ₹10,000

  • Sl. 6. Breach: Breaching a voluntary undertaking accepted by the Board (Section 32); Penalty may extend to: Up to the amount applicable to the breach for which the Section 28 proceedings were started

  • Sl. 7. Breach: Breaching any other provision of the Act or the Rules; Penalty may extend to: ₹50 crore

The Schedule sets no minimum and no aggregate cap. The Act does not say how penalties for several breaches in one inquiry combine.

Who can start a Board inquiry

Section 27(1) lists the Board’s powers and functions. Each one starts from a specific trigger:

  • (a) an intimation of a personal data breach under Section 8(6), on which the Board may also direct urgent remedial or mitigation measures;

  • (b) a complaint by a Data Principal about a personal data breach, or about a Data Fiduciary’s breach of its obligations to her or of her rights; or a reference from the Central Government or a State Government, or a court’s direction;

  • (c) a complaint by a Data Principal about a Consent Manager;

  • (d) an intimation that a Consent Manager has breached a condition of its registration;

  • (e) a reference from the Central Government about an intermediary breaching Section 37(2).

The list does not include the Board starting an inquiry on its own initiative. For most businesses, the realistic triggers are their own breach intimation, a complaint from a customer or employee, or a government reference.

A Data Principal must first use your grievance redressal mechanism before approaching the Board (Section 13(3)). A grievance process that works gives you the first chance to resolve a complaint.

From trigger to penalty

Section 28 sets the procedure. The Board first decides whether there are sufficient grounds to inquire; if not, it may close the proceedings, recording its reasons (Section 28(3) and (4)). If it inquires, it follows the principles of natural justice and records its reasons (Section 28(6)). It may issue interim orders after hearing the person concerned (Section 28(10)).

Rule 19(9) gives the Board six months from receiving the intimation, complaint, reference or direction to complete the inquiry. It may extend that for recorded reasons, by up to three months at a time.

At the end, after a hearing, the Board either closes the proceedings or proceeds under Section 33 (Section 28(11)). Section 33(1) then sets the threshold: a penalty is possible only if the Board determines, on conclusion of the inquiry, that the breach is significant, and only after giving the person an opportunity of being heard.

The seven factors that set the amount

Section 33(2) lists what the Board must have regard to when it fixes the amount:

  • (a) the nature, gravity and duration of the breach;

  • (b) the type and nature of the personal data affected;

  • (c) whether the breach is repetitive;

  • (d) whether the person realised a gain or avoided a loss as a result;

  • (e) whether the person took action to mitigate the effects, and how timely and effective it was;

  • (f) whether the penalty is proportionate and effective, given the need to secure compliance and deter breaches;

  • (g) the likely impact of the penalty on the person.

Factor (e) is the one you control after something goes wrong. A breach log, a dated mitigation record and notices sent on time are the evidence the Board would look at under it.

Voluntary undertakings and appeals

At any stage of a Section 28 proceeding, the Board may accept a voluntary undertaking, such as a commitment to take or stop an action within a set time (Section 32(1) and (2)). Once accepted, it bars further proceedings on its contents (Section 32(4)). Breaking it is treated as a breach of the Act (Section 32(5)), with the ceiling in Schedule item 6.

Anyone aggrieved by a Board order or direction may appeal to the Appellate Tribunal, which Section 2(a) defines as the Telecom Disputes Settlement and Appellate Tribunal. The appeal is due within sixty days of receiving the order or direction, and the Tribunal may accept a late appeal for sufficient cause (Section 29(2) and (3)). Rule 22 requires the appeal to be filed in digital form. Penalties the Board collects go to the Consolidated Fund of India (Section 34).

When this starts

Sections 27 (except clause (d) of Section 27(1)), 28 to 34, and the duties the Schedule refers to come into force eighteen months after G.S.R. 843(E) was published on 13 November 2025, which is 13 May 2027. Rule 22 starts on the same date under Rule 1(4).

How to use the ceilings

The ceilings show where the Act allows the largest penalties. They are not a cost estimate. Security safeguards carry the highest ceiling (₹250 crore); breach notification and the children’s obligations share the next (₹200 crore). Because the amount depends on Section 33(2), the practical defence is evidence: documented safeguards, a working grievance process, and a record of what you did and when.

One further consequence sits outside the Schedule. Under Section 37(1), the Board may send the Central Government a written reference. It reports that the Board has penalised a Data Fiduciary (the person or business that decides why and how personal data is processed) in two or more instances. It advises blocking public access to information held in any computer resource that enables the Data Fiduciary to offer goods or services to people in India. After hearing the Data Fiduciary, the government may order that blocking in the interests of the general public. Section 37 also starts on 13 May 2027.

Sources

Every section, rule and date above was checked against the official text on 4 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

  • Section 2(a): Appellate Tribunal: the Telecom Disputes Settlement and Appellate Tribunal

  • Section 8(5): Security safeguards (item 1)

  • Section 8(6): Breach intimation (item 2)

  • Section 9: Children (item 3)

  • Section 10: Significant Data Fiduciaries (item 4)

  • Section 13(3): Grievance redressal to be exhausted before approaching the Board

  • Section 15: Duties of Data Principals (item 5)

  • Section 27(1): The Board's powers and the triggers for each, clauses (a) to (e)

  • Section 28: Inquiry procedure, including sub-sections (3), (4), (6), (10) and (11)

  • Section 29: Appeal within sixty days; late appeals for sufficient cause

  • Section 32: Voluntary undertakings (item 6)

  • Section 33(1): Penalty only for a significant breach, on conclusion of an inquiry, after a hearing

  • Section 33(2): Seven factors for the amount

  • Section 34: Penalties credited to the Consolidated Fund of India

  • Section 37: Blocking on a Board reference after penalties in two or more instances (1); intermediary duty referenced in Section 27(1)(e) (2)

  • The Schedule, items 1 to 7: Penalty ceilings: items 1 to 5 and 7 "may extend to" an amount; item 6 follows the original breach

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4): Rule 22 in force eighteen months from publication

  • Rule 19(9): Inquiry within six months, extendable by up to three months at a time

  • Rule 22: Appeal filed in digital form

Notifications

  • G.S.R. 843(E), clause (c): Sections 27 (except 27(1)(d)), 28 to 34 and 37 in force eighteen months from 13 November 2025

See which penalty categories your gaps fall into

The Reality Check workbook in how-to 01 maps each open duty to its penalty category in the Schedule. Its dashboard shows the ceilings and never adds them up.

The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.

Drafting aid, not legal advice.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Cyber Security Services

           CynorSense Solution Pvt. Ltd. is your dedicated partner in the ever-evolving domain of cybersecurity. We are committed to delivering cutting-edge cybersecurity solutions, tailored to meet the unique needs of each client. Our comprehensive suite of services includes DPDPA, Penetration Testing, SOC & SIEM Services, Incident Response, and Cyber Security Consultation.

​

Our expertise extends across Secure Code Review, Vulnerability Assessment and Penetration Testing (VAPT) Services, Security Audits, Risk and Threat Assessment, and Vulnerability Scanning. In addition, we offer services in Malware Analysis, Phishing Simulation, Social Engineering Testing, Web Application Testing, Mobile Application Testing, Network Security Testing, Infrastructure Security Testing, Application Security Testing, and Data Security Testing. 

​

We understand the importance of compliance in today's regulatory environment. Our Compliance Testing services are designed to help your organization navigate the complex landscape of regulations such as DPDPA, ISO 27001, PCI DSS, HIPAA, SOX, GLBA, NERC CIP, FISMA, and the NIST Cybersecurity Framework. 

​

At CynorSense, we blend innovative technology with a robust understanding of the cybersecurity landscape to provide you with the tools and knowledge needed to safeguard your digital assets. Let us be your trusted guide in the realm of cybersecurity, providing the assurance you need in an increasingly interconnected world.

ISO 27001 and ISO 9001 certified company

TELEPHONE:

 +91 80 62 181 669

 ADDRESS: 

 Cynor Sense Solutions Pvt. Ltd.

 Vijay Krishna Towers,   Nanakramguda, Hyderabad,

 Telangana, India - 500032

© 2026 CynorSense Solutions Pvt. Ltd. All rights reserved.

bottom of page