The Digital Personal Data Protection Act 2023 backs its obligations with monetary penalties of up to ₹250 crore. Penalties are imposed by the Data Protection Board of India after an inquiry, and they are set out in a Schedule to the Act, graded by the type of breach.
DPDP penalty schedule
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Failure to notify the Board and affected Data Principals of a personal data breach | ₹200 crore |
| Breach of the additional obligations for children's data | ₹200 crore |
| Breach of the additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of any other provision of the Act or Rules | ₹50 crore |
| Breach of duties by a Data Principal | ₹10,000 |
These are ceilings, not fixed fines. Penalties are not calculated as a percentage of turnover, unlike under the EU GDPR.
How the Board decides the amount
When determining a penalty, the Board considers the nature, gravity and duration of the breach, the type and nature of personal data affected, the repetitive nature of the breach, whether the Data Fiduciary acted to mitigate its effects, and whether the penalty is proportionate and effective. Evidence that safeguards were in place and a breach was handled promptly is therefore directly relevant.
Voluntary undertaking
At any stage of a proceeding, the Board may accept a voluntary undertaking from a Data Fiduciary to take specified steps. Where accepted, it bars proceedings on the matter. A later breach of the undertaking can itself be penalised.
Which breaches attract the largest penalties
- Weak security safeguards are the single largest exposure. Encryption, access control, monitoring, backups and one-year log retention are the controls an auditor tests first.
- Late or missing breach notice can be penalised separately from the breach itself.
- Children's data missteps, such as no parental consent or targeted advertising to under-18s, carry the same ceiling as breach notification failures.
How an audit reduces penalty risk
An independent audit finds the control gaps before a breach exposes them, and leaves a dated record of the safeguards you had and the remediation you planned. That evidence matters if the Board ever asks whether your safeguards were reasonable.
See the DPDP audit checklist for the controls tested, and DPDP Rules 2025 explained for the dates they apply from.
