Compliance 7 min read 22 November 2025

DPDP Penalties: The Complete Guide — ₹50 Crore to ₹250 Crore

Every penalty under the DPDP Act 2023 — which violations cost how much, how the Data Protection Board sets fines, and what aggravating factors apply.

The DPDP Act 2023 carries some of the stiffest data protection penalties in Asia. Unlike the EU's GDPR — which is a percentage of global turnover — India's penalties are fixed amounts per violation category. Here's every number you need to know.

Quick Answer: What Are the DPDP Penalties?

Under the Schedule to the DPDP Act 2023 (referenced in Section 33), penalties are fixed amounts per violation category: up to ₹250 Crore for a data security failure, ₹200 Crore for failing to notify a breach, ₹200 Crore for children's-data violations, and ₹50 Crore for other breaches such as invalid consent or notice. Data Principals who misuse the system face up to ₹10,000.

The Penalty Schedule (the Schedule to the DPDP Act)

The DPDP Act contains a single Schedule (referred to in Section 33) that maps violation types to maximum penalty amounts. These are maximums — the Data Protection Board determines the actual amount based on factors including severity, intent, and past compliance history.

₹250 Crore — Data Security Failure

This is the highest penalty tier. It applies to:

This covers businesses that don't encrypt sensitive data, use weak passwords on systems holding customer data, or fail to implement basic access controls.

₹200 Crore — Breach Notification Failure

If a data breach occurs and you don't notify the Data Protection Board and affected individuals within 72 hours, the penalty is up to ₹200 Crore. This is separate from and in addition to the security failure penalty. See our 72-hour breach notification guide for how to report.

₹200 Crore — Children's Data Violations

Violations of the obligations for processing children's data under Rule 10:

₹50 Crore — Residual / Other Obligations

This is the Schedule's catch-all entry — it applies to breaches of any obligation not carrying a higher specific penalty, up to ₹50 Crore. In practice that covers general violations such as:

How Does the DPB Determine the Actual Penalty?

The Data Protection Board considers several factors when deciding penalties within the maximum range:

Penalties Are Per Violation, Not Annual

Unlike GDPR (which caps at a percentage of annual turnover), DPDP penalties apply per violation category. A business that:

...could, in principle, face up to ₹500 Crore in aggregate from a single incident. These are ceilings — the Board decides the actual figure using the factors in Section 33.

What Actually Triggers a Penalty

A penalty starts with a specific obligation the Act names, not with a general finding that a business was "not compliant". These are the five failures most likely to surface when a complaint reaches the Board about a small or mid-sized business.

The failureWhere the Act sets itPenalty tier
Consent that is not free, specific, informed, unconditional and unambiguous — a pre-ticked box, a clause inside the terms of service, or one "I agree" button covering collection, marketing and sharing togetherSection 6(1)Up to ₹50 Cr
No notice before or at the point of collection, or a notice the customer cannot read because it is only in English (the Act requires it in English or any Eighth Schedule language)Section 5(1), 5(3)Up to ₹50 Cr
No consent record you can produce. When a customer disputes that they consented, the burden of proving it sits with the businessSection 6(10)Up to ₹50 Cr
No reasonable security safeguards, and a breach follows. The Act does not define "reasonable"; Rule 6 lists the minimum (encryption or masking, access control, logs kept for one year, backups, a breach-response contract with every processor)Section 8(5), Rule 6Up to ₹250 Cr
No breach-response plan. Rule 7 requires informing every affected person and the Board without delay, and a detailed report to the Board within 72 hoursSection 8(6), Rule 7Up to ₹200 Cr

The practical sequence follows from the table. Map every place personal data enters and leaves the business, including WhatsApp groups, the payment gateway and the courier partner's spreadsheet. Fix consent and notice first, because they are customer-facing and the easiest for a complainant to evidence. Write down who does what in the 72 hours after a breach and run it once as a drill. Then keep consent, request and breach records timestamped and retrievable, because Section 6(10) means the records are your defence.

Two further failures are common in businesses that use vendors or software partners: engaging a processor without a written contract (Section 8(2)), and confusing which party is the Data Fiduciary for a given data flow. CyberNX's DPDPA guide for IT and SaaS companies works through consent bundling, processor contracts and fiduciary-versus-processor role confusion in detail, and is a useful companion if your business sells or buys software.

Who Can Complain?

Any individual (Data Principal) whose rights have been violated can complain to the Data Protection Board. The Board can also initiate suo motu investigations if it becomes aware of potential violations.

Is There Any Smaller Business Exemption?

The Act contains a provision for the government to exempt certain classes of Data Fiduciaries — potentially small businesses — from some obligations via notification. However, no such exemption notification has been issued as of the date of this article. Until one is, all businesses are subject to the full penalty schedule.

Real Risk for SMBs

A ₹50 Crore penalty for a small business is effectively a death sentence. But the risks aren't symmetrical — the Board will likely focus enforcement on larger entities first. That said, a complaint from even one customer can trigger an investigation against any business, regardless of size. Getting compliant is far cheaper than the alternative — and when the Board asks for evidence, timestamped consent records and audit logs are what settle the question.

References & Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (the Schedule; Section 33, factors for determining penalties).
  2. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
  3. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 10 (children's data) and Rule 7 (breach intimation).

This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Penalty amounts are maximums under the Schedule; the Board sets the actual figure case by case. Always verify against the current notified text.

DPDP PenaltiesData Protection BoardFinesRisk

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.

Related Articles

← All Blog Posts