DPDP Audits

DPDP Act Penalties: The ₹250 Crore Schedule Explained

The full DPDP Act 2023 penalty schedule, from ₹250 crore for weak security safeguards to ₹10,000 for Data Principals, and how the Data Protection Board decides the amount.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 4 October 2026

The Digital Personal Data Protection Act 2023 backs its obligations with monetary penalties of up to ₹250 crore. Penalties are imposed by the Data Protection Board of India after an inquiry, and they are set out in a Schedule to the Act, graded by the type of breach.

DPDP penalty schedule

BreachMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Failure to notify the Board and affected Data Principals of a personal data breach₹200 crore
Breach of the additional obligations for children's data₹200 crore
Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Breach of any other provision of the Act or Rules₹50 crore
Breach of duties by a Data Principal₹10,000

These are ceilings, not fixed fines. Penalties are not calculated as a percentage of turnover, unlike under the EU GDPR.

How the Board decides the amount

When determining a penalty, the Board considers the nature, gravity and duration of the breach, the type and nature of personal data affected, the repetitive nature of the breach, whether the Data Fiduciary acted to mitigate its effects, and whether the penalty is proportionate and effective. Evidence that safeguards were in place and a breach was handled promptly is therefore directly relevant.

Voluntary undertaking

At any stage of a proceeding, the Board may accept a voluntary undertaking from a Data Fiduciary to take specified steps. Where accepted, it bars proceedings on the matter. A later breach of the undertaking can itself be penalised.

Which breaches attract the largest penalties

How an audit reduces penalty risk

An independent audit finds the control gaps before a breach exposes them, and leaves a dated record of the safeguards you had and the remediation you planned. That evidence matters if the Board ever asks whether your safeguards were reasonable.

See the DPDP audit checklist for the controls tested, and DPDP Rules 2025 explained for the dates they apply from.

Frequently asked questions

What is the maximum penalty under the DPDP Act?

₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach. Other ceilings are ₹200 crore for failing to notify a breach or meet children's data obligations, ₹150 crore for Significant Data Fiduciary obligations, and ₹50 crore for any other breach.

Are DPDP penalties based on turnover?

No. The Schedule to the Act sets fixed monetary ceilings per type of breach, not a percentage of turnover.

Who imposes penalties under the DPDP Act?

The Data Protection Board of India, after an inquiry. It considers the nature, gravity and duration of the breach, the type of data affected, repetition, mitigation and proportionality.

Can individuals be penalised under the DPDP Act?

Yes. A Data Principal who breaches the duties in the Act, such as filing a false or frivolous grievance, can be penalised up to ₹10,000.

What is a voluntary undertaking under the DPDP Act?

At any stage of a proceeding the Board may accept a voluntary undertaking from a Data Fiduciary to take specified steps. Once accepted it bars proceedings on the matter, and breaching it can itself be penalised.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.