How DPDP penalties are decided: the Schedule, section 33 and the Board
- The Schedule to the Act sets maximum amounts per type of breach, from up to ₹10,000 (s.15 duties) to up to ₹250 crore (s.8(5) security safeguards).
- A penalty needs an inquiry, a finding that the breach is significant and a hearing (s.28, s.33(1)).
- The Board must weigh seven factors when fixing the amount, including mitigation, repetition and proportionality (s.33(2)(a) to (g)).
- A voluntary undertaking accepted by the Board bars proceedings on its contents (s.32(4)); orders can be appealed to the Appellate Tribunal within sixty days (s.29(2)).
The penalty numbers in the DPDP Act get quoted everywhere, but they are ceilings, not price tags. This guide explains the path from a breach to an actual amount: who can start a case, what the Data Protection Board must find, and the factors it must weigh under section 33.
The penalty ceilings in the Schedule
Section 33(1) lets the Board impose a monetary penalty “specified in the Schedule”. The Schedule has seven entries:
| Schedule item | Breach | Maximum penalty |
|---|---|---|
| 1 | Failing to take reasonable security safeguards to prevent a personal data breach (s.8(5)) | Up to ₹250 crore |
| 2 | Failing to notify the Board or affected Data Principals of a personal data breach (s.8(6)) | Up to ₹200 crore |
| 3 | Breaching the additional obligations for children (s.9) | Up to ₹200 crore |
| 4 | Breaching the additional obligations of a Significant Data Fiduciary (s.10) | Up to ₹150 crore |
| 5 | Breaching the duties of a Data Principal (s.15) | Up to ₹10,000 |
| 6 | Breaching a voluntary undertaking accepted by the Board (s.32) | Up to the amount applicable to the breach for which the s.28 proceedings were started |
| 7 | Breaching any other provision of the Act or the Rules | Up to ₹50 crore |
Item 7 is the catch-all. Notice failures (s.5), consent defects (s.6), erasure lapses (s.8(7)) and grievance handling (s.13) are not named separately, so they fall under it. For a plain overview of the numbers, see DPDP penalties explained.
Step 1: how a case reaches the Board
Section 27(1) ties the Board's inquiry powers to specific triggers:
- a breach intimation from a Data Fiduciary under s.8(6) (s.27(1)(a));
- a complaint by a Data Principal about a personal data breach or a breach of obligations or rights, or a reference from the Central or a State Government, or a court direction (s.27(1)(b));
- a complaint against a Consent Manager, or an intimation that a Consent Manager breached a registration condition (s.27(1)(c) and (d));
- a Central Government reference about an intermediary not complying with a blocking direction under s.37(2) (s.27(1)(e)).
A Data Principal must first exhaust the Data Fiduciary's own grievance process before approaching the Board (s.13(3)). That makes your grievance redressal process the first line of defence.
Step 2: the inquiry
The Board first decides whether there are sufficient grounds to inquire (s.28(3)); if not, it may close the matter with written reasons (s.28(4)). An inquiry follows natural justice, with reasons recorded (s.28(6)). The Board has civil court powers to summon people, receive evidence on affidavit and inspect data, books and documents (s.28(7)), but may not block access to premises or seize equipment in a way that adversely affects day-to-day functioning (s.28(8)). It may issue interim orders after a hearing (s.28(10)). Under Rule 19(9), an inquiry must be completed within six months of receiving the intimation or complaint, extendable by up to three months at a time with written reasons.
At the end, after a further hearing, the Board either closes the proceedings or proceeds under section 33 (s.28(11)).
Step 3: the “significant” test
Section 33(1) allows a penalty only if the Board determines, on conclusion of an inquiry, that the breach is “significant”, and only after giving the person an opportunity of being heard. The definitions in section 2 do not define “significant”, so expect it to be settled through Board practice and appeals.
Step 4: the seven section 33(2) factors
When fixing the amount, the Board “shall have regard to”:
| Factor | Source | Evidence that helps (our suggestion) |
|---|---|---|
| Nature, gravity and duration of the breach | s.33(2)(a) | Detection and containment timestamps from your logs |
| Type and nature of the personal data affected | s.33(2)(b) | A data map showing which categories were actually exposed |
| Repetitive nature of the breach | s.33(2)(c) | Records showing root causes were fixed after earlier incidents |
| Whether the person realised a gain or avoided a loss | s.33(2)(d) | Evidence the processing was not monetised |
| Action taken to mitigate, and its timeliness and effectiveness | s.33(2)(e) | Incident tickets, Rule 7 intimations sent, remedial changes |
| Whether the penalty is proportionate and effective as a deterrent | s.33(2)(f) | Context on scale and the breach's real impact |
| Likely impact of the penalty on the person | s.33(2)(g) | Financial context, where relevant |
Factor (e) is the one you control most. Rule 6(1)(c) and 6(1)(e) already require logs and their retention for one year, and Rule 7(2)(b)(v) asks for the remedial measures in your 72-hour report, so the same records serve both purposes. See reasonable security safeguards and the incident response playbook.
Settling early: voluntary undertakings and mediation
At any stage of a section 28 proceeding the Board may accept a voluntary undertaking, for example to take or stop an action within a set time, or to publicise the undertaking (s.32(1) and (2)). Acceptance bars further proceedings on the contents of the undertaking (s.32(4)). Failing to honour it is treated as a breach of the Act (s.32(5)) and is penalised under Schedule item 6. Separately, the Board may direct parties to attempt mediation if it thinks a complaint can be resolved that way (s.31).
After a penalty: appeal, payment and repeat offenders
- Appeal. Any person aggrieved by a Board order may appeal to the Appellate Tribunal within sixty days of receiving it (s.29(1) and (2)). The Tribunal is the Telecom Disputes Settlement and Appellate Tribunal (s.2(a)). Appeals are filed digitally with a fee (Rule 22(1) and (2)). See Board complaints, inquiry and appeals.
- Where the money goes. Penalties are credited to the Consolidated Fund of India (s.34), not paid to complainants.
- Repeat penalties. If the Board has penalised a Data Fiduciary in two or more instances, it may advise the Central Government to block public access to the information that lets that business offer goods or services in India; the Government may do so after a hearing (s.37(1)).
- Future changes. The Central Government may amend the Schedule, but not to raise any penalty above twice its originally enacted amount (s.42(1)).
Data Principals are not immune: Schedule item 5 covers breach of their own duties, and the Board may warn or impose costs on a complainant whose complaint is false or frivolous (s.28(12)). See duties of Data Principals.
When penalties can apply
Sections 27 (except s.27(1)(d)) and 28 to 34 come into force eighteen months from 13 November 2025, according to the commencement note under section 1(2). Rule 22 on appeals follows the same eighteen-month timeline (Rule 1(4)). Track the dates in our law status and timeline guide.
Frequently asked questions
What is the maximum penalty under the DPDP Act?
The highest Schedule ceiling is up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach under section 8(5) (Schedule item 1).
Are DPDP penalties calculated per record or per day?
No. Each Schedule entry is a maximum that may extend to the stated figure. The Act does not set per-record or per-day amounts; the Board fixes the amount using the section 33(2) factors.
What factors does the Data Protection Board consider when fixing a penalty?
Section 33(2) lists the nature, gravity and duration of the breach; the type of personal data affected; repetition; any gain made or loss avoided; mitigation and how timely and effective it was; proportionality and deterrence; and the likely impact of the penalty on the person.
Can a DPDP penalty be appealed?
Yes. Any person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal within sixty days of receiving it (s.29(1) and (2)). The Tribunal may admit a late appeal if satisfied there was sufficient cause (s.29(3)).
Can the government increase DPDP penalties?
The Central Government may amend the Schedule by notification, but no amendment may raise a penalty to more than twice the amount specified when the Act was originally enacted (s.42(1)).
Does a voluntary undertaking avoid a penalty?
If the Board accepts a voluntary undertaking, that bars proceedings on the matters it covers (s.32(4)). Breaking the undertaking is treated as a breach of the Act (s.32(5)) and can be penalised under Schedule item 6.
Practical next step
Map each Schedule item to the control that prevents it, and start keeping the mitigation evidence the section 33(2)(e) factor rewards. Then run a quick external check of your public pages.