Enforcement

How DPDP penalties are decided: the Schedule, section 33 and the Board

Audience: founders, compliance owners, security and legal leads · Last reviewed: October 2026

The penalty numbers in the DPDP Act get quoted everywhere, but they are ceilings, not price tags. This guide explains the path from a breach to an actual amount: who can start a case, what the Data Protection Board must find, and the factors it must weigh under section 33.

Every Schedule entry says the penalty “may extend to” the stated figure. The Schedule does not set per-record or per-day amounts; the Board fixes the figure case by case (s.33(2)).

The penalty ceilings in the Schedule

Section 33(1) lets the Board impose a monetary penalty “specified in the Schedule”. The Schedule has seven entries:

Schedule itemBreachMaximum penalty
1Failing to take reasonable security safeguards to prevent a personal data breach (s.8(5))Up to ₹250 crore
2Failing to notify the Board or affected Data Principals of a personal data breach (s.8(6))Up to ₹200 crore
3Breaching the additional obligations for children (s.9)Up to ₹200 crore
4Breaching the additional obligations of a Significant Data Fiduciary (s.10)Up to ₹150 crore
5Breaching the duties of a Data Principal (s.15)Up to ₹10,000
6Breaching a voluntary undertaking accepted by the Board (s.32)Up to the amount applicable to the breach for which the s.28 proceedings were started
7Breaching any other provision of the Act or the RulesUp to ₹50 crore

Item 7 is the catch-all. Notice failures (s.5), consent defects (s.6), erasure lapses (s.8(7)) and grievance handling (s.13) are not named separately, so they fall under it. For a plain overview of the numbers, see DPDP penalties explained.

Step 1: how a case reaches the Board

Section 27(1) ties the Board's inquiry powers to specific triggers:

  • a breach intimation from a Data Fiduciary under s.8(6) (s.27(1)(a));
  • a complaint by a Data Principal about a personal data breach or a breach of obligations or rights, or a reference from the Central or a State Government, or a court direction (s.27(1)(b));
  • a complaint against a Consent Manager, or an intimation that a Consent Manager breached a registration condition (s.27(1)(c) and (d));
  • a Central Government reference about an intermediary not complying with a blocking direction under s.37(2) (s.27(1)(e)).

A Data Principal must first exhaust the Data Fiduciary's own grievance process before approaching the Board (s.13(3)). That makes your grievance redressal process the first line of defence.

Step 2: the inquiry

The Board first decides whether there are sufficient grounds to inquire (s.28(3)); if not, it may close the matter with written reasons (s.28(4)). An inquiry follows natural justice, with reasons recorded (s.28(6)). The Board has civil court powers to summon people, receive evidence on affidavit and inspect data, books and documents (s.28(7)), but may not block access to premises or seize equipment in a way that adversely affects day-to-day functioning (s.28(8)). It may issue interim orders after a hearing (s.28(10)). Under Rule 19(9), an inquiry must be completed within six months of receiving the intimation or complaint, extendable by up to three months at a time with written reasons.

At the end, after a further hearing, the Board either closes the proceedings or proceeds under section 33 (s.28(11)).

Step 3: the “significant” test

Section 33(1) allows a penalty only if the Board determines, on conclusion of an inquiry, that the breach is “significant”, and only after giving the person an opportunity of being heard. The definitions in section 2 do not define “significant”, so expect it to be settled through Board practice and appeals.

Step 4: the seven section 33(2) factors

When fixing the amount, the Board “shall have regard to”:

FactorSourceEvidence that helps (our suggestion)
Nature, gravity and duration of the breachs.33(2)(a)Detection and containment timestamps from your logs
Type and nature of the personal data affecteds.33(2)(b)A data map showing which categories were actually exposed
Repetitive nature of the breachs.33(2)(c)Records showing root causes were fixed after earlier incidents
Whether the person realised a gain or avoided a losss.33(2)(d)Evidence the processing was not monetised
Action taken to mitigate, and its timeliness and effectivenesss.33(2)(e)Incident tickets, Rule 7 intimations sent, remedial changes
Whether the penalty is proportionate and effective as a deterrents.33(2)(f)Context on scale and the breach's real impact
Likely impact of the penalty on the persons.33(2)(g)Financial context, where relevant

Factor (e) is the one you control most. Rule 6(1)(c) and 6(1)(e) already require logs and their retention for one year, and Rule 7(2)(b)(v) asks for the remedial measures in your 72-hour report, so the same records serve both purposes. See reasonable security safeguards and the incident response playbook.

Settling early: voluntary undertakings and mediation

At any stage of a section 28 proceeding the Board may accept a voluntary undertaking, for example to take or stop an action within a set time, or to publicise the undertaking (s.32(1) and (2)). Acceptance bars further proceedings on the contents of the undertaking (s.32(4)). Failing to honour it is treated as a breach of the Act (s.32(5)) and is penalised under Schedule item 6. Separately, the Board may direct parties to attempt mediation if it thinks a complaint can be resolved that way (s.31).

After a penalty: appeal, payment and repeat offenders

  • Appeal. Any person aggrieved by a Board order may appeal to the Appellate Tribunal within sixty days of receiving it (s.29(1) and (2)). The Tribunal is the Telecom Disputes Settlement and Appellate Tribunal (s.2(a)). Appeals are filed digitally with a fee (Rule 22(1) and (2)). See Board complaints, inquiry and appeals.
  • Where the money goes. Penalties are credited to the Consolidated Fund of India (s.34), not paid to complainants.
  • Repeat penalties. If the Board has penalised a Data Fiduciary in two or more instances, it may advise the Central Government to block public access to the information that lets that business offer goods or services in India; the Government may do so after a hearing (s.37(1)).
  • Future changes. The Central Government may amend the Schedule, but not to raise any penalty above twice its originally enacted amount (s.42(1)).

Data Principals are not immune: Schedule item 5 covers breach of their own duties, and the Board may warn or impose costs on a complainant whose complaint is false or frivolous (s.28(12)). See duties of Data Principals.

When penalties can apply

Sections 27 (except s.27(1)(d)) and 28 to 34 come into force eighteen months from 13 November 2025, according to the commencement note under section 1(2). Rule 22 on appeals follows the same eighteen-month timeline (Rule 1(4)). Track the dates in our law status and timeline guide.

Frequently asked questions

What is the maximum penalty under the DPDP Act?

The highest Schedule ceiling is up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach under section 8(5) (Schedule item 1).

Are DPDP penalties calculated per record or per day?

No. Each Schedule entry is a maximum that may extend to the stated figure. The Act does not set per-record or per-day amounts; the Board fixes the amount using the section 33(2) factors.

What factors does the Data Protection Board consider when fixing a penalty?

Section 33(2) lists the nature, gravity and duration of the breach; the type of personal data affected; repetition; any gain made or loss avoided; mitigation and how timely and effective it was; proportionality and deterrence; and the likely impact of the penalty on the person.

Can a DPDP penalty be appealed?

Yes. Any person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal within sixty days of receiving it (s.29(1) and (2)). The Tribunal may admit a late appeal if satisfied there was sufficient cause (s.29(3)).

Can the government increase DPDP penalties?

The Central Government may amend the Schedule by notification, but no amendment may raise a penalty to more than twice the amount specified when the Act was originally enacted (s.42(1)).

Does a voluntary undertaking avoid a penalty?

If the Board accepts a voluntary undertaking, that bars proceedings on the matters it covers (s.32(4)). Breaking the undertaking is treated as a breach of the Act (s.32(5)) and can be penalised under Schedule item 6.

Practical next step

Map each Schedule item to the control that prevents it, and start keeping the mitigation evidence the section 33(2)(e) factor rewards. Then run a quick external check of your public pages.

Advertisement