DPDP Act Penalties Explained: Every Violation and Its Cost

The DPDP Act's penalties are what moved data protection from an IT concern to a boardroom one. Unlike GDPR's turnover-linked fines, India uses fixed monetary ceilings per violation — and for a mid-sized company, those ceilings can be existential. Here is the complete schedule, what triggers each penalty, and how the Data Protection Board decides the amount.

The penalty schedule

ViolationMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failure to notify the Board or affected data principals of a personal data breach₹200 crore
Breach of additional obligations relating to children's data₹200 crore
Breach of additional obligations of a Significant Data Fiduciary₹150 crore
Breach of duties by a data principal (impersonation, false complaints, suppressing information)₹10,000
Breach of a voluntary undertaking accepted by the BoardUp to the amount applicable to the underlying breach
Any other breach of the Act or Rules₹50 crore

Reading the schedule correctly

The security-safeguard penalty is the big one — and the easiest to trigger

₹250 crore attaches not to the breach itself, but to failing to have taken reasonable safeguards. That is a much lower bar for a regulator to establish. If a breach occurs and your investigation shows unencrypted personal data on an unmonitored file share with no access control, the safeguard failure is evident from the facts of the breach. Encryption, access control, logging and monitoring aren't best practices here — they are the difference between an incident and a nine-figure exposure.

Breach notification is a separate, additive penalty

A single incident can attract two penalties: one for the safeguard failure, another for failing to notify. Organisations that suppress incidents to avoid reputational damage typically convert a manageable problem into a compounded one.

Children's data sits at the top tier

₹200 crore for children's-data violations puts education institutes, edtech, gaming and any consumer platform with under-18 users in a high-risk category — processing without verifiable parental consent, or tracking and targeting minors, is penalised at nearly the highest level in the Act.

"Any other breach" is not a small residual

₹50 crore is the catch-all for everything else: invalid consent, missing notices, purpose creep, failure to erase, failure to honour rights requests, no grievance mechanism. These are the most common non-compliances in Indian organisations today, and each carries a ceiling that would end most businesses.

How the Board decides the actual amount

These are ceilings, not fixed fines. In determining the penalty, the Board must consider factors set out in the Act:

  • the nature, gravity and duration of the breach;
  • the type and nature of personal data affected;
  • whether the breach is repetitive;
  • whether the person realised a gain or avoided a loss through the breach;
  • what mitigating action was taken, and how timely and effective it was;
  • whether the penalty is proportionate and effective given the need for compliance;
  • the likely impact of the penalty on the person.

Read that list as a scoring rubric. Every item rewards organisations that documented their safeguards, detected quickly, notified promptly, remediated visibly and can prove it. The same underlying breach can land at very different numbers depending on the evidence you can produce — which is an argument for tamper-evident audit trails long before an incident.

Beyond the penalty

The financial penalty is rarely the whole cost. Add breach investigation and forensics, notification to every affected individual, customer attrition, contractual liability to enterprise clients, and — for regulated sectors — parallel action from RBI, IRDAI, SEBI or CERT-In under their own frameworks. Penalties are also credited to the Consolidated Fund of India; there is no settlement-and-move-on mechanism, though the Board can accept voluntary undertakings that suspend proceedings if honoured.

The cheapest risk reduction available

Given the rubric above, the highest-leverage investments are unglamorous: know what personal data you hold and where, encrypt it, control access, log access, be able to detect and scope a breach within hours, and keep evidence of all of it. A discovery and governance platform delivers those five things simultaneously — which is why organisations increasingly treat it as insurance rather than software.

What actually triggers enforcement

Penalties do not arrive out of nowhere. In practice, proceedings begin from a small number of trigger points, and knowing them tells you where to concentrate effort:

  • A data principal complaint after your grievance channel failed to respond — the most common and most preventable route.
  • Your own breach intimation, which opens the question of whether safeguards were adequate.
  • A publicly reported breach — media coverage, a researcher's disclosure, data appearing for sale — which the Board can act on from information received.
  • A government reference, including from a sectoral regulator handling the same incident.

Three of those four are heavily influenced by how you behave before anything goes wrong: an answered grievance rarely becomes a complaint, and a well-documented incident with prompt notification presents very differently from one discovered externally.

How the same breach lands at different numbers

Consider two organisations suffering an identical incident: an unencrypted database of 50,000 customer records exposed through a misconfigured server.

Organisation AOrganisation B
Data inventoryCurrent; knew within hours exactly whose data and which fieldsNone; took nine days to estimate scope
SafeguardsEncryption policy documented, access control and logging in place; misconfiguration was an exceptionNo encryption, no access logs, no monitoring
DetectionOwn monitoring alertNotified by a journalist
NotificationIndividuals intimated in 36 hours; detailed report filed at hour 70Board notified after 11 days; individuals never directly told
RemediationRoot cause fixed, controls hardened, evidence retainedServer taken down; no documented remediation

Same underlying facts. But the Board's statutory factors — gravity and duration, repetitiveness, mitigating action taken and its timeliness, proportionality — point in opposite directions. Organisation B additionally faces the separate notification-failure penalty of up to ₹200 crore that Organisation A avoided entirely. The gap between these outcomes is not luck; it is documentation and preparation.

The board-level view

For directors and promoters, three implications deserve minuting:

  • Penalties are per breach, and additive. A single incident can attract both a safeguard penalty and a notification penalty; multiple deficiencies can be inquired into together.
  • The residual ₹50-crore category covers everyday non-compliance — invalid consent, missing notices, unfulfilled rights requests, no grievance mechanism. These are not exotic failures; they are the current state of most Indian organisations.
  • Insurance and contracts shift some cost, not the obligation. Cyber policies may cover response costs; regulatory penalties are frequently excluded or capped. Enterprise customers are meanwhile writing DPDP indemnities into contracts, creating commercial exposure that arrives before regulatory exposure does.

The board question worth asking each quarter is not "are we compliant?" but "if the Board asked us the six evidence questions tomorrow, what could we produce?"

Frequently asked questions

What is the maximum penalty under the DPDP Act 2023?
₹250 crore, for failure to take reasonable security safeguards to prevent a personal data breach. Failure to notify a breach and violations of children's-data obligations each carry up to ₹200 crore, SDF obligation breaches up to ₹150 crore, and any other breach up to ₹50 crore.
Are DPDP penalties linked to company turnover?
No. Unlike GDPR's turnover-percentage model, the DPDP Act sets fixed monetary ceilings per type of violation. The Board determines the actual amount considering gravity, duration, repetition, mitigation and the likely impact of the penalty.
Can individuals be penalised under the DPDP Act?
Yes. Data principals who impersonate others, suppress material information or file false or frivolous complaints can be penalised up to ₹10,000.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →

Ready to become DPDP compliant?

Get a personalised compliance assessment — free, no obligation.

Book a Free Assessment →