Share 💬 💼
DPDP

DPDPA Penalties Explained: ₹50 Crore to ₹250 Crore Fines — Complete Guide

📅 Mar 02, 2026
👤 Adv. Deepak Kumar
⏱️ 12 min read
📂 DPDP
DPDPA Penalties Explained: ₹50 Crore to ₹250 Crore Fines — Complete Guide
India's DPDPA imposes fines up to ₹250 crore per violation. This complete guide explains every penalty tier, what triggers them, how the Data Protection Board calculates actual amounts, real-world scenarios for Indian businesses, and 10 steps to reduce your risk.
DPDP Act 2023 — Section 33 & The Schedule

India's Digital Personal Data Protection Act, 2023 introduces the most significant financial penalty regime in the country's data protection history. With fines reaching ₹250 crore per violation, the consequences of non-compliance are no longer theoretical — they are real, enforceable, and imminent. This complete guide explains every penalty tier, what triggers them, how they are calculated, and exactly what your business must do to avoid them.

Quick Answer — DPDPA Penalty Schedule at a Glance
Violation Max Penalty
Failure to implement security safeguards resulting in data breach ₹250 Crore
Failure to notify Board & Data Principals of a breach ₹200 Crore
Non-compliance with children's data obligations ₹200 Crore
Breach of Significant Data Fiduciary obligations ₹150 Crore
Any other breach of DPDPA obligations ₹50 Crore
Obstruction of Board proceedings ₹10 Crore
Filing frivolous / false complaint by Data Principal ₹10,000
📋 What This Guide Covers
  1. Who enforces DPDPA penalties?
  2. The complete penalty schedule — Section 33 & The Schedule
  3. Tier 1 — ₹250 Crore: Security safeguard failure
  4. Tier 2 — ₹200 Crore: Breach notification failure
  5. Tier 3 — ₹200 Crore: Children's data violations
  6. Tier 4 — ₹150 Crore: Significant Data Fiduciary non-compliance
  7. Tier 5 — ₹50 Crore: All other violations
  8. How the Board calculates the actual penalty amount
  9. Aggravating vs mitigating factors
  10. Real-world penalty scenarios for Indian businesses
  11. DPDPA vs GDPR — penalty comparison
  12. How to reduce your penalty risk — practical steps

1. Who Enforces DPDPA Penalties? The Data Protection Board of India

Penalties under the DPDPA are enforced by the Data Protection Board of India (DPBI) — established under Section 18 of the Act. The Board is India's dedicated data protection regulator with sweeping investigative and adjudicatory powers.

🔍 Investigate
Receive complaints, initiate suo motu inquiries, summon organisations and demand evidence
⚖️ Adjudicate
Conduct hearings, consider evidence, determine violations and impose penalties
📋 Direct
Order organisations to stop unlawful processing, implement corrective measures, improve security
💰 Penalise
Impose financial penalties up to ₹250 crore — payable to the Consolidated Fund of India

Important: The DPDPA does not impose criminal liability — there is no imprisonment for data protection violations. All penalties are financial. However, the DPDP Rules 2025 prescribe detailed adjudication procedures, and the Board must give every organisation a fair opportunity to be heard before imposing any penalty.

Appeals against Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days, and further to the Supreme Court on questions of law.

2. The Complete Penalty Schedule — Section 33 & The Schedule

Section 33 of the DPDPA empowers the Data Protection Board to impose penalties. The actual amounts are set out in The Schedule annexed to the Act. These figures are maximum caps — the Board determines the actual penalty based on the specific circumstances of each case.

Three critical facts about DPDPA penalties that every business must understand:

⚠️
Penalties are per violation — not per incident
If you have processed data of 10,000 users without valid consent, you have potentially committed 10,000 separate violations. The ₹50 crore cap applies per violation, meaning cumulative exposure can be enormous.
⚠️
Multiple violations in one incident attract multiple penalties
A single data breach can trigger the security safeguard penalty (₹250 Cr) AND the breach notification penalty (₹200 Cr) simultaneously — potentially ₹450 crore in exposure from one incident.
⚠️
No revenue-based cap — unlike GDPR
GDPR caps penalties at 4% of global turnover. DPDPA has no such proportionality protection — a small startup processing children's data negligently faces the same ₹200 crore maximum as a multinational corporation.

3. Tier 1 — ₹250 Crore: Failure to Implement Security Safeguards

₹250 Cr
Maximum Penalty
Triggered by: Section 8(4) violation leading to a personal data breach
This is the highest penalty tier and applies when a Data Fiduciary fails to implement "reasonable security safeguards to prevent personal data breaches" and a breach actually occurs as a result.

What "Reasonable Security Safeguards" Means

The DPDP Rules 2025 (Rule 6) clarify that reasonable security practices include:

  • Encryption of personal data at rest and in transit
  • Access controls — role-based, need-to-know basis only
  • Multi-factor authentication for systems holding personal data
  • Regular security testing and vulnerability assessments
  • Data backup and recovery procedures
  • Monitoring for unauthorised access and anomalous activity
  • Security training for employees handling personal data

Real-World Scenarios That Attract This Penalty

Scenario A — Unencrypted Customer Database
An e-commerce company stores 2 million customer records (names, addresses, payment details) in an unencrypted database. A SQL injection attack exposes all records. The failure to encrypt = failure of reasonable security safeguards. Penalty exposure: up to ₹250 Crore.
Scenario B — No Access Controls on HR System
A company's HR software containing employee Aadhaar numbers, salary data, and bank accounts is accessible to all employees without role-based restrictions. A disgruntled employee downloads and sells the data. Lack of access controls = failure of security safeguards. Penalty exposure: up to ₹250 Crore.
Scenario C — Outdated Software Not Patched
A hospital runs a patient management system on software with known vulnerabilities that have not been patched for over 6 months. Ransomware exploits the vulnerability and exposes 500,000 patient health records. Failure to patch = failure of reasonable security safeguards. Penalty exposure: up to ₹250 Crore.

4. Tier 2 — ₹200 Crore: Failure to Notify a Breach

₹200 Cr
Maximum Penalty
Triggered by: Failure to notify the Data Protection Board and/or affected individuals
This penalty applies separately and in addition to the security failure penalty. You can face both penalties for a single breach event — once for the security failure and again for not reporting it properly.

Notification Requirements Under Rule 7

72 hrs
Notify the Board
ASAP
Notify affected users
BOTH
Both required — not either/or
Your notification must contain:
  • Nature and circumstances of the breach
  • Categories of personal data affected
  • Approximate number of Data Principals impacted
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact details of DPO or designated contact person

Worst case — concealing a breach: Attempting to hide a data breach from the Board and affected individuals is the most serious violation. Courts and regulators globally treat concealment as evidence of deliberate misconduct, which attracts the maximum penalty AND serves as an aggravating factor for the security failure penalty simultaneously.

5. Tier 3 — ₹200 Crore: Children's Data Violations

₹200 Cr
Maximum Penalty
Triggered by: Non-compliance with Section 9 — children's data obligations
The DPDPA treats children's data with particular seriousness. Under Section 9, a child is anyone under 18 — there is no lower age threshold as in GDPR (which allows member states to lower it to 13).

Violations that attract this penalty include:

❌ No Parental Consent
Processing personal data of a child without verifiable parental or guardian consent
❌ Behavioural Monitoring
Tracking or monitoring the behaviour of children — even with parental consent in most cases
❌ Targeted Advertising
Directing targeted advertisements at children based on their data
❌ No Age Verification
Allowing children to use your platform without an age-verification mechanism when required

Who is at risk: Any platform that could be accessed by users under 18 — not just platforms targeting children. If your gaming app, educational platform, e-commerce site, social media tool, or fitness app is accessible to minors without age verification, you are exposed to this penalty tier.

Rule 10 specifies acceptable age-verification methods: Digital Locker verification, Aadhaar-based verification, virtual token linked to parent's identity, or government-issued ID verification.

6. Tier 4 — ₹150 Crore: Significant Data Fiduciary Non-Compliance

₹150 Cr
Maximum Penalty
Triggered by: Failure to meet Section 10 obligations as a Significant Data Fiduciary
SDFs designated by the Central Government face this additional penalty tier for failing to appoint a DPO, conduct DPIAs, complete independent audits, or comply with algorithmic accountability requirements.

7. Tier 5 — ₹50 Crore: All Other Violations

This is the most commonly applicable penalty tier — it covers every DPDPA obligation that is not covered by the higher tiers. This includes:

Obligation Breached Relevant Section Max Penalty
Processing without valid consent or legitimate use Section 4 & 5 ₹50 Crore
Using data beyond the stated purpose Section 8(2) ₹50 Crore
Failing to provide notice before data collection Section 6 ₹50 Crore
Not providing withdrawal of consent mechanism Section 4(6) ₹50 Crore
Retaining data beyond the permitted period Section 8(7) ₹50 Crore
Denying Data Principal rights (access, correction, erasure) Section 11-13 ₹50 Crore
No Grievance Officer appointed or published Section 8(8) ₹50 Crore
No DPA with third-party data processors Section 8(2) ₹50 Crore

8. How the Board Calculates the Actual Penalty Amount

The Schedule amounts are caps — not automatic penalties. The Board must determine the actual penalty based on the factors in Section 33(2). Understanding these factors is critical because they determine whether you pay ₹1 crore or ₹250 crore for the same category of violation.

📊
Nature & Gravity
How serious is the violation? Was it a minor technical breach or a fundamental failure of data protection principles?
⏱️
Duration
How long did the violation continue? A one-day breach is treated very differently from a systemic failure over years.
🔄
Repetitive Nature
Has the same or similar violation occurred before? Repeat offenders face significantly higher penalties.
👥
Number Affected
A breach affecting 100 users is very different from one affecting 10 million. Scale directly impacts penalty quantum.
🛠️
Mitigation Actions
What steps were taken to contain damage, notify those affected, and prevent recurrence? Swift, comprehensive action reduces penalties.
💰
Gains from Breach
Did the entity profit from the violation? Deliberate monetisation of unlawfully processed data attracts maximum penalties.
🤝
Cooperation with Board
Did the entity cooperate with the investigation, disclose information voluntarily, and demonstrate good faith? Cooperation is a significant mitigating factor.
📋
Compliance History
Does the entity have a documented compliance programme? Prior good conduct and evidence of genuine compliance efforts reduce penalties substantially.

9. Aggravating vs Mitigating Factors

🔺 Aggravating Factors — Higher Penalty
  • Deliberate or intentional violation
  • Long duration of non-compliance
  • Large number of individuals affected
  • Sensitive data involved (financial, health, biometric)
  • Children's data affected
  • Prior violations or warnings
  • Concealment of the breach
  • Financial gain from the violation
  • Failure to cooperate with investigation
  • No compliance programme in place
🔻 Mitigating Factors — Lower Penalty
  • Negligence rather than deliberate act
  • Prompt self-reporting to the Board
  • Swift notification to affected individuals
  • Immediate containment actions
  • Small number of individuals affected
  • No prior violations
  • Documented, genuine compliance programme
  • Full cooperation with Board investigation
  • Voluntary undertaking to remedy
  • Demonstrated remediation steps

10. Real-World Penalty Scenarios for Indian Businesses

Scenario 1 — FinTech App Data Breach
Exposure: ₹450 Cr
A lending app stores 5 million users' Aadhaar numbers, PAN cards, and bank statements without encryption. A hacker steals the data. The company waits 3 weeks before informing users and the Board.
Security failure: up to ₹250 Cr Notification failure: up to ₹200 Cr
Scenario 2 — EdTech Platform, Children's Data
Exposure: ₹250 Cr
An online tutoring app allows sign-up without age verification. It tracks study behaviour, serves targeted ads, and sells anonymised (but re-identifiable) data of 200,000 students under 18 to publishers.
Children's data: up to ₹200 Cr No consent notice: up to ₹50 Cr
Scenario 3 — E-Commerce, Marketing Without Consent
Exposure: ₹100 Cr
An online retailer uses order confirmation emails to add customers to a marketing list without a separate opt-in. It also shares customer data with 12 affiliate partners without DPAs. Both ongoing violations for 18 months.
Purpose violation: up to ₹50 Cr No vendor DPAs: up to ₹50 Cr
Scenario 4 — Small Business, Minor Violation
Likely Penalty: ₹50L–2Cr
A small law firm's website contact form has no privacy notice. A user complains to the Board. The firm cooperates fully, immediately adds a privacy notice, provides a written apology and compliance plan, no previous violations.
Cap: ₹50 Cr — but mitigating factors apply Cooperation = significantly reduced penalty

11. DPDPA vs GDPR — Penalty Comparison

Factor DPDPA (India) GDPR (EU)
Maximum Penalty ₹250 Crore (fixed) €20M or 4% global turnover
Revenue-Based Cap ❌ No ✅ Yes — 4% of turnover
Criminal Liability ❌ No criminal penalties Some member states allow it
Per Violation ✅ Yes — per violation ✅ Yes — per violation
Compensation to Individuals ❌ Not directly ✅ Direct compensation right
Penalty Destination Consolidated Fund of India National DPA / State treasury
Proportionality for SMEs Via adjudication factors only Turnover cap protects SMEs

12. How to Reduce Your DPDPA Penalty Risk — 10 Practical Steps

1
Conduct a DPDPA Compliance Audit
Identify every gap in your current data practices before the Board does. A documented audit showing proactive compliance assessment is one of the strongest mitigating factors.
2
Fix Your Consent Mechanisms
Replace every pre-ticked box, implied consent, and "by using this site" notice with valid, specific, affirmative consent. This eliminates the most common ₹50 crore violation category.
3
Implement Security Safeguards Now
Encryption, access controls, MFA, regular patching — these directly protect against the ₹250 crore penalty tier, the highest in the Act. This is the single highest-value compliance investment.
4
Draft a Breach Response Plan
Have notification templates ready, roles assigned, and a 72-hour clock process documented. The difference between a ₹5 crore penalty and ₹200 crore can come down to whether you notified the Board on time.
5
Add Age Verification If Children Can Access Your Platform
Any platform accessible to users under 18 must implement verifiable age-gating. This protects against the ₹200 crore children's data penalty — which applies to millions of Indian websites and apps.
6
Sign DPAs with All Vendors
Every cloud provider, payment gateway, CRM, analytics tool, and marketing platform that processes your customer data needs a signed Data Processing Agreement.
7
Appoint and Publish a Grievance Officer
This is one of the easiest compliance steps — name someone, publish their contact details on your website, and create a complaints handling process. Failure to do this is an unnecessary ₹50 crore exposure.
8
Document Everything
A compliance programme that exists only in someone's head provides no legal protection. Document your data mapping, consent records, vendor DPAs, security measures, and training logs — these are your evidence before the Board.
9
Never Conceal a Breach
Concealment guarantees maximum penalties and destroys the most important mitigating factor — cooperation. Self-reporting within 72 hours consistently results in significantly lower actual penalties in comparable regulatory regimes globally.
10
Engage DPDPA Legal Counsel Early
All communications with your advocates regarding compliance are protected by legal professional privilege. Early legal engagement builds the documented compliance programme that is your strongest defence before the Data Protection Board.

The Bottom Line on DPDPA Penalties

The DPDPA penalty framework is designed to create genuine deterrence — ₹250 crore fines are not symbolic. The Data Protection Board of India is establishing itself as a functioning regulator, and enforcement is expected to intensify as the compliance deadlines of 2027 approach.

The good news is that proactive compliance dramatically reduces penalty exposure. Businesses that build documented compliance programmes, implement security safeguards, and cooperate fully with the Board face a fraction of the penalties that careless or deliberate violators face.

The question is not whether your business will eventually face scrutiny under the DPDPA — it is whether you will be prepared when it happens.

Assess Your Penalty Risk — Free Consultation →
AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp