Compliance 6 min read 22 November 2025

DPDP Penalties: The Complete Guide — ₹50 Crore to ₹250 Crore

A detailed breakdown of every penalty under the DPDP Act 2023. Which violations cost how much, how the Data Protection Board determines fines, and what aggravating factors apply.

The DPDP Act 2023 carries some of the stiffest data protection penalties in Asia. Unlike the EU's GDPR — which is a percentage of global turnover — India's penalties are fixed amounts per violation category. Here's every number you need to know.

Quick Answer: What Are the DPDP Penalties?

Under the Schedule to the DPDP Act 2023 (referenced in Section 33), penalties are fixed amounts per violation category: up to ₹250 Crore for a data security failure, ₹200 Crore for failing to notify a breach, ₹200 Crore for children's-data violations, and ₹50 Crore for other breaches such as invalid consent or notice. Data Principals who misuse the system face up to ₹10,000.

The Penalty Schedule (the Schedule to the DPDP Act)

The DPDP Act contains a single Schedule (referred to in Section 33) that maps violation types to maximum penalty amounts. These are maximums — the Data Protection Board determines the actual amount based on factors including severity, intent, and past compliance history.

₹250 Crore — Data Security Failure

This is the highest penalty tier. It applies to:

  • Failure to implement reasonable security safeguards to prevent personal data breaches (Section 8(5)) — the core obligation explained in our business responsibilities guide
  • A breach occurring because of inadequate security measures

This covers businesses that don't encrypt sensitive data, use weak passwords on systems holding customer data, or fail to implement basic access controls.

₹200 Crore — Breach Notification Failure

If a data breach occurs and you don't notify the Data Protection Board and affected individuals within 72 hours, the penalty is up to ₹200 Crore. This is separate from and in addition to the security failure penalty. See our 72-hour breach notification guide for how to report.

₹200 Crore — Children's Data Violations

Violations of the obligations for processing children's data under Rule 10:

  • Processing a minor's data without verified parental consent (see our parental consent guide for schools and EdTech)
  • Serving behavioural advertising to a child
  • Tracking or monitoring a child's online behaviour without consent

₹50 Crore — Residual / Other Obligations

This is the Schedule's catch-all entry — it applies to breaches of any obligation not carrying a higher specific penalty, up to ₹50 Crore. In practice that covers general violations such as:

  • Collecting data without a proper consent notice (Section 5)
  • Processing data beyond what was consented to
  • Failing to respond to Data Subject Requests within the specified timeframe
  • Not deleting data when purpose is fulfilled (Section 8(7))
  • Violations by Data Processors that the Fiduciary is responsible for

How Does the DPB Determine the Actual Penalty?

The Data Protection Board considers several factors when deciding penalties within the maximum range:

  • Nature and gravity of the breach — how many people affected, sensitivity of data
  • Duration — how long the violation continued
  • Type of data — financial, health, or children's data carries higher weight
  • Repetition — previous violations by the same entity
  • Gains made by the Data Fiduciary from the violation
  • Actions taken to mitigate the harm after discovery
  • Cooperation with the Board during investigation

Penalties Are Per Violation, Not Annual

Unlike GDPR (which caps at a percentage of annual turnover), DPDP penalties apply per violation category. A business that:

  • Fails to get consent (up to ₹50 Cr)
  • Has a breach because of poor security (up to ₹250 Cr)
  • Fails to notify the breach within 72 hours (up to ₹200 Cr)

...could, in principle, face up to ₹500 Crore in aggregate from a single incident. These are ceilings — the Board decides the actual figure using the factors in Section 33.

Who Can Complain?

Any individual (Data Principal) whose rights have been violated can complain to the Data Protection Board. The Board can also initiate suo motu investigations if it becomes aware of potential violations.

Is There Any Smaller Business Exemption?

The Act contains a provision for the government to exempt certain classes of Data Fiduciaries — potentially small businesses — from some obligations via notification. However, no such exemption notification has been issued as of the date of this article. Until one is, all businesses are subject to the full penalty schedule.

Real Risk for SMBs

A ₹50 Crore penalty for a small business is effectively a death sentence. But the risks aren't symmetrical — the Board will likely focus enforcement on larger entities first. That said, a complaint from even one customer can trigger an investigation against any business, regardless of size. Getting compliant is far cheaper than the alternative — and when the Board asks for evidence, timestamped consent records and audit logs are what settle the question.

References & Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (the Schedule; Section 33, factors for determining penalties).
  2. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
  3. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 10 (children's data) and Rule 7 (breach intimation).

This article is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Penalty amounts are maximums under the Schedule; the Board sets the actual figure case by case. Always verify against the current notified text.

DPDP PenaltiesData Protection BoardFinesRisk

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.