DPDP ActPhase 5 -AdvancedEnforcement

What DPDP Penalties Really Look Like - And How to Avoid Them

The headline is ₹250 crore, but the number that matters is the one the Data Protection Board lands on after weighing what you did and what you failed to do. The penalty schedule tier by tier, the factors the Board weighs, why DPDP pays the state and not the individual, and the handful of controls that keep you out of the room.

CM
Chandrika Mulage
Security Engineer
June 9, 2026·📖 8 min read
Legal and regulatory enforcement

Enforcement under DPDP runs through the Data Protection Board, not a courtroom -at least not until an appeal reaches the Appellate Tribunal.

₹250 cr
Security Safeguards
₹200 cr
Breach / Children
₹150 cr
SDF Obligations
DPB
Adjudicates

Every DPDP conversation eventually arrives at the same question: what happens if we get this wrong? The Act answers with a Schedule of monetary penalties running from ₹10,000 to ₹250 crore, adjudicated not by a court but by a dedicated regulator -the Data Protection Board of India. Understanding the shape of that Schedule, and the reasoning the Board applies to it, tells you exactly where to point your compliance budget.

This is the closing piece in our DPDP series. If you have not yet worked through the underlying obligations, start with our plain-English guide to the Act or the 90-day compliance roadmap -this article assumes you already know what the obligations are, and focuses on what happens when they are missed.

1. The Penalty Schedule, Tier by Tier

The Schedule to the DPDP Act sets a maximum penalty for each category of failure. The Board cannot exceed these caps, though as we cover in the next section, it rarely imposes the maximum. Six entries matter most in practice:

FailureProvisionPenalty up to
Failure to take reasonable security safeguards to prevent a personal data breachSection 8(5)₹250 crore
Failure to notify the Board and affected Data Principals of a personal data breachSection 8(6)₹200 crore
Failure to fulfil additional obligations in relation to childrenSection 9₹200 crore
Failure to fulfil additional obligations of a Significant Data FiduciarySection 10₹150 crore
Breach of any other provision of the Act or its RulesGeneral₹50 crore
Breach of duties by a Data Principal (e.g. false or frivolous complaints)Section 15₹10,000
The largest tier is also the most avoidable

₹250 crore -the single biggest entry in the Schedule -sits on Section 8(5), reasonable security safeguards. It is not tied to a rare or exotic failure; it is tied to the baseline expectation that you protect the data you hold. This is the tier that ordinary security hygiene, not legal cleverness, keeps you out of.

Read the ordering carefully. Security safeguards outrank breach notification, which outranks children's data, which outranks Significant Data Fiduciary obligations. The Schedule is effectively telling you where the regulator's priorities sit: prevent the breach first, disclose it properly second, protect the categories that deserve extra care third.

2. How the Board Decides

A Schedule cap is a ceiling, not a price tag. Under Section 33, the Data Protection Board of India conducts an inquiry and then decides the actual amount within that ceiling, guided by a defined set of factors rather than a flat formula. In practice, the factors the Board weighs are:

  • Nature, gravity and duration of the breach -a two-hour misconfiguration is judged differently to a two-year unpatched vulnerability.
  • Type and sensitivity of the personal data affected -financial identifiers and children's data carry more weight than a marketing mailing list.
  • Repetitive nature of the breach -a first-time lapse and a recurring failure at the same fiduciary are not treated the same way twice.
  • Whether the fiduciary made a gain or avoided a loss -cutting corners on security spend to protect margins is treated as an aggravating factor, not a neutral cost decision.
  • Mitigation taken, and how quickly -fast, effective containment and remediation count in your favour; silence and delay do not.
  • Proportionality -the penalty is meant to be effective and proportionate, not simply punitive for its own sake.

This is also why breach notification discipline matters beyond the ₹200 crore cap attached to it directly: how you handle the 72 hours after discovery colours the Board's view of every other factor in the case.

3. No Individual Compensation

One structural point trips up teams that come to DPDP with a GDPR mental model: penalties collected by the Data Protection Board are paid into the Consolidated Fund of India, not distributed to the Data Principals whose data was mishandled. The Board's monetary penalty is a regulatory sanction against the fiduciary, not a compensation mechanism for the individual.

This is a genuine departure from the GDPR, which -through Article 82 -creates a private right for individuals to claim compensation for material or non-material damage arising from a breach of the regulation, litigated separately from any regulatory fine. DPDP does not build an equivalent private right into the Board's process. An affected individual can complain to the Board and trigger an inquiry, but any resulting penalty goes to the state treasury, not to them.

Practically, this changes the incentive calculus at the margins: the Board's inquiry is the whole of your DPDP-specific financial exposure in most cases, rather than a regulatory fine layered on top of a wave of individual claims. It does not, however, change the underlying obligation to protect the data properly in the first place -nor does it foreclose other legal remedies individuals may have outside the DPDP framework.

4. Who Gets Penalised

The Schedule is written primarily against the Data Fiduciary -the entity that determines the purpose and means of processing personal data. The five largest tiers in the Schedule, from ₹250 crore down to ₹50 crore, all sit on the Fiduciary's shoulders. Data Processors acting solely on a Fiduciary's instructions are not directly penalised under the Schedule in the same way, though contractually a Fiduciary will typically push security and breach-notification obligations down to its processors regardless.

Data Principals are not exempt either, though their exposure looks entirely different in scale. Section 15 sets duties for Data Principals -among them, not registering a false or frivolous complaint with a Data Fiduciary or the Board, and not furnishing false particulars or impersonating someone else. Breach of these duties can attract a penalty of up to ₹10,000. It is a small number next to ₹250 crore, but it exists specifically to discourage bad-faith complaints from clogging a young enforcement system.

5. How to Avoid Them

Every tier in the Schedule maps to a specific, buildable control. Work down from the largest exposure:

Against the ₹250 crore tier (security safeguards): encryption of personal data at rest and in transit, access controls built on least privilege, logging and monitoring capable of detecting a breach quickly, regular vulnerability management, and a documented security programme you can point to if the Board asks what "reasonable" meant in your context.

Against the ₹200 crore breach-notification tier: an incident response process that can identify, contain, and assess a breach fast enough to notify the Board and affected Data Principals within the timelines set under the DPDP Rules, with clear internal ownership so notification does not stall waiting for someone to make a decision.

Against the ₹200 crore children's-data tier: verifiable parental consent mechanisms, a prohibition on behavioural tracking and targeted advertising directed at children, and age-verification processes proportionate to your product -covered in detail in our children's data guide.

Against the ₹150 crore Significant Data Fiduciary tier: if you are designated (or might become) an SDF, the additional obligations -a India-based Data Protection Officer, an independent data auditor, periodic Data Protection Impact Assessments -need to be built before designation, not scrambled together after. Our SDF guide walks through what changes.

Underneath all of it: valid, specific consent under the DPDP Act reduces your exposure across nearly every other tier, because a large share of Board inquiries begin with a Data Principal complaint about how their consent was (or was not) obtained.

6. Penalty-Avoidance Checklist

Before an inquiry ever starts

  • Security safeguards documented, implemented, and reviewed on a regular cadence -not just written once at policy sign-off.
  • Breach detection and internal escalation fast enough to meet the notification timelines under the DPDP Rules.
  • Consent flows that are specific, informed, and as easy to withdraw as to give.
  • Children's data flows separated out, age-gated, and free of behavioural tracking.
  • SDF-readiness assessment done in advance, even if you are not yet designated.
  • A named internal owner for DPDP compliance who can produce evidence of all of the above on short notice.
  • Vendor and processor contracts that push equivalent obligations downstream.
  • A record of mitigation and remediation for any past incident, however minor -it is evidence the Board will weigh in your favour.

Enforcement under the DPDP Act is still early -there is little public track record of the Data Protection Board's decisions to point to yet, and the Schedule's caps have not, to date, been tested at scale against named organisations. That absence of precedent is not a reason to relax; it is a reason to build the controls now, while the cost of doing so is a security budget rather than a Board inquiry. The Schedule tells you exactly where the risk is concentrated. The rest is implementation.

Want to know exactly where your penalty exposure sits?

SecComply maps your DPDP obligations against the Schedule, tier by tier, and closes the gaps that carry the largest exposure first -security safeguards, breach response, consent, and SDF readiness.

Book a penalty exposure review →

FAQ

What is the maximum DPDP penalty?

Up to ₹250 crore, for failure to take reasonable security safeguards to prevent a personal data breach. It is the single largest entry in the Schedule to the DPDP Act, well ahead of the ₹200 crore tiers for breach notification failures and children's data violations.

Who decides and imposes penalties?

The Data Protection Board of India. It is the adjudicating body set up under the DPDP Act, and under Section 33 it conducts an inquiry and imposes a monetary penalty up to the cap set in the Schedule for the relevant failure -it is not a court and does not go through the ordinary civil litigation process.

Does DPDP compensate affected individuals?

No. Penalties imposed by the Data Protection Board are paid into the Consolidated Fund of India, not to the affected Data Principals. Unlike the GDPR, the DPDP Act does not create a private right for individuals to claim compensation from a Data Fiduciary through the Board.

Can Data Principals be fined?

Yes. Section 15 sets out duties of Data Principals, including not registering false or frivolous complaints and not impersonating another person. Breach of these duties can attract a penalty of up to ₹10,000 under the Schedule -small next to the Data Fiduciary tiers, but a real deterrent against bad-faith complaints.

What single failure carries the biggest penalty?

Failure to take reasonable security safeguards to prevent a personal data breach, under Section 8(5), capped at ₹250 crore. It sits above breach notification failures, children's data violations, and Significant Data Fiduciary non-compliance, which signals where the Board's attention -and the Schedule's weight -is concentrated.