DPDP Act penalties for non-compliance

DPDP Act Penalties For Non-Compliance

DPDP Act penalties for non-compliance are fixed rupee ceilings set out in the Schedule to the Digital Personal Data Protection Act, 2023, running from 10,000 rupees at the bottom to 250 crore rupees at the top. The Data Protection Board of India imposes them under section 33, and only after an inquiry in which it finds the breach significant and gives the person concerned an opportunity of being heard. Every figure is preceded by the words “may extend to”, so each is a maximum rather than a tariff, and not one of them is linked to turnover. Neither section 33 nor the Schedule is in force today: notification G.S.R. 843(E) places both in an eighteen-month tranche ending in May 2027, and until then the operative exposure sits in section 43A of the Information Technology Act, 2000, which carries no cap at all.

This article sets out the DPDP Act penalties for non-compliance as the Schedule and section 33 state them.

The 250 crore figure travels well. What travels with it less often is where the money goes. Section 34 credits every sum realised by way of penalty under the Act to the Consolidated Fund of India, so the affected individual receives nothing out of it. The Act builds a regulatory fine, not a compensation route, and that single distinction changes how a business should model the risk.

Two boundaries are worth fixing early. The Act creates no offence and no term of imprisonment anywhere in its 44 sections, so every consequence under it is money. And the Data Principal isn’t only a beneficiary of the regime (entry 5 of the Schedule points squarely at her, with 10,000 rupees payable for a breach of the duties in section 15).



DPDP Act penalties for non-compliance under the Schedule

The DPDP Act penalties for non-compliance sit in a Schedule of seven entries, each pairing a described breach with a maximum amount, and section 33 is the only route by which any of them can be imposed. Four entries carry large figures, one carries a small one, one borrows its ceiling from elsewhere, and the last catches everything the Act does not list separately.

Entry 1 is the largest and the narrowest. It reaches a breach of the Data Fiduciary’s obligation under section 8(5) to take reasonable security safeguards to prevent a personal data breach, and the ceiling is 250 crore rupees. Section 8(5) doesn’t define the safeguards, which is why the certification market has moved into the gap: an audited control framework such as the one behind the ISO 27001 lead auditor route is currently the closest thing to evidence of what “reasonable” looked like on the day of the incident.

Entry 2 is the one that surprises people. A failure to give the Board or each affected Data Principal notice of a personal data breach under section 8(6) carries a ceiling of 200 crore rupees, second on the whole ladder. That is a procedural duty, not a security duty. Only 50 crore rupees separates failing to protect data from failing to disclose that the protection failed, which puts a rehearsed data breach response plan in the same risk tier as the security programme itself.

Entry 3 matches entry 2 at 200 crore rupees and covers the additional obligations in relation to children under section 9. Section 2(f) sets the age at eighteen, section 9(1) requires verifiable parental consent, and section 9(3) bars tracking, behavioural monitoring and advertising targeted at children outright, with no consent override available. Any Indian edtech firm, tutoring platform or paediatric practice sits inside this entry by default.

Entry 4 covers the additional obligations of a Significant Data Fiduciary under section 10, at 150 crore rupees. And nobody is exposed to it yet, because the Central Government hasn’t notified any entity or class of entities as a Significant Data Fiduciary (until it does, this head sits dormant).

Then the ladder drops sharply. Entry 5 reaches a breach of the duties of the Data Principal under section 15, and the ceiling is 10,000 rupees. Section 15 asks an individual not to impersonate, not to suppress material information, and not to register a false or frivolous grievance or complaint. Read it with section 28(12), which lets the Board issue a warning or impose costs on a complainant at any stage after receipt, and the shape of the regime becomes clearer: the Act is guarding the Board’s docket as well as the citizen’s data.

Entry 6 has no figure of its own. Where a person breaches a term of a voluntary undertaking accepted by the Board under section 32, the penalty may extend to whatever was applicable for the breach in respect of which the section 28 proceedings were instituted. It borrows the ceiling of the original head, which makes a broken settlement no cheaper than the fight it replaced.

Entry 7 is the residual, at 50 crore rupees, and in practice it’ll be the busiest of the seven. Every obligation the Schedule does not name separately falls here: the section 5 notice, the section 6 consent standard, the rights in sections 11 to 14, section 16’s cross-border restrictions, and the whole of the DPDP Rules, 2025. So a defective privacy notice and an unlawful consent flow both land in the same 50 crore bucket, which is one reason the consent and notice rules deserve more attention than their absence from the headline figures suggests.

Three qualifications travel with the whole ladder, and they matter more than the figures do. Each amount is a ceiling and not a starting point, because “may extend to” is the statutory formula. Each is a fixed rupee sum rather than a share of revenue, which is a structural choice with consequences taken up further below. And section 33(1) permits a penalty only where the Board determines, on conclusion of an inquiry and after a hearing, that the breach is significant.

So how does a single incident actually reach a nine-figure exposure? By touching more than one entry. The Schedule contains no aggregation rule and no cap on the total, so a company that fails on security and then fails on disclosure faces two heads, priced separately.

Consider a mid-size Indian software company holding records for 40,000 customers. A backup store is left publicly readable for eleven days, an outside researcher reports it, and the configuration is corrected the same afternoon. Nobody tells the Board, and nobody tells a single customer.

Two entries are engaged, not one. Entry 1 reaches the section 8(5) failure at up to 250 crore rupees, entry 2 reaches the section 8(6) silence at up to 200 crore, and the theoretical maximum is 450 crore. The second 200 crore of that was incurred entirely after the fault had been found and fixed.

Advertisement

One further point about the figures themselves. Section 42, which is already in force, empowers the Central Government to amend the Schedule by notification, subject only to the requirement in section 41 that it be laid before Parliament. The amounts can therefore move before they have ever been applied to anybody.

The DPDP penalty ladder and the route to it

Not in force until May 2027
The ceilings The Schedule, read with section 33
Rs 250 cr Reasonable security safeguardsEntry 1, section 8(5)
Rs 200 cr Notice of a personal data breachEntry 2, section 8(6)
Rs 200 cr Additional obligations on childrenEntry 3, section 9
Rs 150 cr Significant Data Fiduciary dutiesEntry 4, section 10
Rs 50 cr Any other provision of the Act or the RulesEntry 7, the residual
Borrowed Term of a voluntary undertakingEntry 6, section 32
Rs 10,000 Duties of the Data PrincipalEntry 5, section 15
Every figure reads “may extend to”, so each is a ceiling and not a tariff. There is no aggregation rule and no cap on the total, so one incident that reaches two entries is priced twice.
The route Sections 27 to 33, rules 19 and 22
1 Trigger. A breach intimation under section 8(6), a Data Principal complaint, a government reference or a court direction.
2 Grounds gate. The Board decides whether grounds are sufficient, and may close the proceedings there for reasons recorded in writing.
3 Inquiry. Natural justice, with civil court powers of summons, evidence on affidavit, discovery and inspection.
4 Clock. Six months from the intimation or complaint, extendable by three months at a time on written reasons.
5 Hearing and finding. A penalty follows only where the Board finds the breach significant, after an opportunity of being heard.
6 Appeal. Sixty days to the Appellate Tribunal, whose order is executable as a decree of a civil court.
Section 28(8) bars the Board from taking equipment into custody or preventing access to premises. Section 39, already in force, bars any civil suit or injunction on a matter the Board can decide.
What fixes the amount: the seven factors in section 33(2)
Nature, gravity and duration Type of data affected Repetition Gain realised or loss avoided Mitigation and its timeliness Proportionality and deterrence Impact on the person

Commencement. Sections 28 to 34 and the Schedule commence eighteen months after the notifications of 13 November 2025. Rules 17 to 21 and section 39 have been in force since publication.

Source: the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Ministry of Electronics and Information Technology.

Position as of 7 September 2026 SkillArbitrage

How the Data Protection Board decides a penalty

The Board decides a penalty at the end of an inquiry under section 28, and the amount is then fixed by the seven factors listed in section 33(2). Neither step is discretionary in form: both require reasons to be recorded in writing, and both are appealable.

A matter reaches the Board through one of four doors, set out in section 27(1). An intimation of a personal data breach under section 8(6) is the first, and it lets the Board direct urgent remedial or mitigation measures before any question of penalty arises. The others are a complaint by a Data Principal, a reference from the Central or a State Government or a direction of a court, and a government reference about an intermediary under section 37(2).

What happens next is a filter rather than a hearing. Section 28(3) requires the Board to decide whether there are sufficient grounds to proceed at all, and section 28(4) lets it close the proceedings there, for reasons recorded in writing. Only on sufficient grounds does section 28(5) open an inquiry into the affairs of the person, which section 28(6) then binds to the principles of natural justice.

Inside the inquiry the Board holds the powers of a civil court under the Code of Civil Procedure, 1908 in four respects: summoning attendance and examining a person on oath, receiving evidence on affidavit and requiring discovery and production of documents, inspecting any data, book, register or books of account, and such other matters as may be prescribed. Section 28(9) also lets it requisition a police or government officer for assistance.

Section 28(8) is the limit, and it’s a real one. The Board and its officers may not prevent access to any premises, and may not take into custody any equipment or item that would adversely affect a person’s day-to-day functioning. This is not a raid power, and framing it as one (as a good deal of vendor marketing does) misreads the section.

The clock comes from the Rules rather than the Act. Rule 19 of the Digital Personal Data Protection Rules, 2025 requires an inquiry to be completed within six months of the intimation or complaint, extendable by not more than three months at a time on reasons recorded in writing. Worth flagging: rule 19 has been in force since November 2025, while the section 28 inquiry it times has not.

Section 28(10) permits interim orders during the inquiry, again after a hearing and with reasons. Section 28(11) closes it: the Board either shuts the proceedings or proceeds under section 33. And section 28(12) runs the other way, allowing a warning or costs against a complainant whose complaint the Board considers false or frivolous.

So what actually fixes the number? Section 33(2) directs the Board to consider the nature, gravity and duration of the breach, the type and nature of the personal data affected, the repetitive nature of the breach, whether the person realised a gain or avoided a loss as a result, whether the person acted to mitigate the effects and consequences and how timely and effective that action was, whether the penalty is proportionate and effective as a deterrent, and the likely impact of the penalty on the person.

Sort those seven by what a business can still influence once an incident has happened, and the list shrinks to one. Duration is partly controllable, repetition is history, gain is a matter of fact, and proportionality and impact belong to the Board. Mitigation, specifically its timeliness and effectiveness, is the only factor that stays open after the event. The practical reality is that everything a compliance programme does in the first week of an incident is aimed at factor (e).

Run the earlier facts through section 33(2). Factor (a) records eleven days of open exposure affecting 40,000 people. Factor (c) is neutral on a first incident, and factor (d) finds no gain realised and no loss avoided, since the exposure was accidental rather than exploitative.

Factor (e) is where the company loses ground, because it fixed the technical fault within hours and then said nothing at all, which is mitigation of the cause without any mitigation of the consequences. Factor (g), the likely impact of the penalty on the person, is the only one pulling the number down.

Two off-ramps exist before an order. Section 32 lets the Board accept a voluntary undertaking at any stage of a section 28 proceeding, committing the person to act or refrain from acting within a set time and to publicise the undertaking, and section 32(4) makes acceptance a bar on further proceedings about its contents.

Break the undertaking, though, and section 32(5) deems the failure a breach of the Act and returns the matter to section 33 with entry 6’s borrowed ceiling attached. Section 31 supplies the second off-ramp, allowing a referral to mediation where the Board thinks resolution likely.

An order is appealable to the Telecom Disputes Settlement and Appellate Tribunal, which section 44 designates as the Appellate Tribunal for this Act. Section 29 gives sixty days from receipt (a short window by Indian appellate standards), with delay condonable for sufficient cause, and rule 22 pegs the fee to an appeal under the Telecom Regulatory Authority of India Act, 1997, payable by UPI unless the Chairperson waives it. The Tribunal is to endeavour to dispose of the appeal within six months. Section 30 then makes its order executable as a decree of a civil court, either by the Tribunal itself or by a local civil court it transmits the order to.

What a company cannot do is take the dispute elsewhere. Section 39, which came into force in November 2025, bars any civil court from entertaining a suit or proceeding on a matter the Board is empowered to decide, and bars any court or authority from granting an injunction against action taken under the Act. That bar is live today, three years before the penalty power it protects. Anyone building this expertise as a career, whether in-house or as a data privacy consultant, is really learning a tribunal-facing practice rather than a courtroom one.

When DPDP Act penalties for non-compliance take effect

DPDP Act penalties for non-compliance take effect eighteen months after the commencement notification of 13 November 2025, which lands them in May 2027. Notification G.S.R. 843(E), issued under section 1(2), places sections 28 to 34 and the Schedule together in that final tranche, so the inquiry power, the penalty power and the amounts all arrive on one date. The full three-tranche timeline sits in the DPDP Act compliance checklist and is not repeated here.

A second reason operates independently of the first. The Data Protection Board of India was established in law by notification G.S.R. 844(E) on 13 November 2025, with its membership fixed at four Members besides a Chairperson, and it has been an empty institution since. MeitY’s circular of 6 May 2026 invited applications for all five posts, a further notification followed on 6 June 2026, and reporting on 1 August 2026 recorded that none had been filled. That is a moving fact rather than a settled one, and it is the single item on this page most likely to have changed by the time it is read.

Meanwhile a good deal of the enforcement chapter is already live. Sections 18 to 26 constitute the Board and set the qualifications, terms and disqualifications for its members. Section 35 protects action taken in good faith, section 39 bars the civil courts, section 42 allows the Schedule to be amended, and rules 17 to 21 govern appointments, meetings, the quorum of one third, the casting vote and the six-month inquiry clock. The machinery is assembled and the power isn’t switched on.

So is an Indian business unexposed until May 2027? Not remotely. The older statute is still standing. Section 44(2) of the DPDP Act, which deletes section 43A of the Information Technology Act, 2000, sits in the same eighteen-month tranche as the penalty power, so section 43A survives until the day the Schedule arrives.

That surviving section is, in one specific way, harsher than what replaces it. Section 43A makes a body corporate that is negligent in implementing and maintaining reasonable security practices liable to pay compensation to the person affected, and Parliament removed the five crore rupee ceiling from it in 2008. There’s no statutory maximum. Section 46 gives an adjudicating officer jurisdiction over claims up to five crore rupees, with anything larger going to the competent court, and the standard of “reasonable security practices” comes from the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Section 72A of the same Act is untouched by the DPDP Act altogether. It punishes disclosure of personal information in breach of a lawful contract, made knowingly or with intent to cause wrongful loss or gain, with imprisonment up to three years or a fine up to five lakh rupees or both. But it’s the only imprisonment risk anywhere in this area, and it’ll still be there after May 2027. Separately, the CERT-In Directions of April 2022, issued under section 70B(6), require a listed cyber incident to be reported within six hours of noticing it, a deadline that no DPDP provision softens or replaces.

Put the two regimes side by side and the switchover in 2027 inverts the remedy. Today an affected individual can claim uncapped compensation under section 43A and keep it. From May 2027 the Board imposes a capped penalty that section 34 sends to the Consolidated Fund, and the individual whose data was exposed recovers nothing under the Act. Based on what we’ve seen in exposure models built for Indian companies this year, that inversion is the most commonly missed variable: the headline number goes up, and the number payable to claimants goes down.

The comparison people reach for is the General Data Protection Regulation, and it does not hold. Article 83(5) of the GDPR sets its top tier at 20 million euro or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, with a lower tier at 10 million euro or 2%. The DPDP Schedule has no percentage, no floor and no scaling factor.

So the two laws bite in opposite directions by size. For a large multinational the GDPR ceiling rises with revenue while the Indian one stops dead at 250 crore rupees. For an Indian company turning over 200 crore rupees a year, 4% would be eight crore, while the DPDP ceiling for a single security failure exceeds its entire annual revenue. Frankly, this gets overlooked: a flat cap is regressive, and it bears hardest on the mid-market firms with the least compliance budget.

Frequently asked questions

Can a company director be held personally liable under the DPDP Act?

The penalty lands on the company itself. Section 33 penalises a “person”, which section 2(s) defines to include a company, and the Act carries no offences-by-companies clause of the kind section 85 of the IT Act contains. Personal criminal exposure comes from section 72A of the IT Act instead.

Does the DPDP Act pay compensation to the person whose data was breached?

Section 34 credits every penalty realised under the Act to the Consolidated Fund of India, so nothing reaches the Data Principal. Until May 2027, section 43A of the IT Act 2000 gives an uncapped compensation claim, adjudicated by an officer under section 46 up to five crore rupees.

Does the DPDP Act carry any prison sentence?

Every consequence under the Digital Personal Data Protection Act, 2023 is a monetary penalty payable to the government, and the Act creates no criminal offence at all. Imprisonment in this area comes only from section 72A of the IT Act 2000, which allows up to three years.

Can a Data Processor be penalised directly under the DPDP Act?

The Data Fiduciary carries the liability. Section 8(1) makes it responsible for compliance whatever the contract says, and the four largest Schedule entries attach to its obligations, so a processor’s exposure is mostly contractual. Entry 7 stays available for any provision it breaches itself.

References

Official guidance and regulations

  1. CERT-In Directions under section 70B(6) of the Information Technology Act, 2000. Indian Computer Emergency Response Team, April 2022
  2. IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, G.S.R. 313(E). India Code, Government of India
  3. MeitY circular F. No. 2(1)/2026-Pers.I, Data Protection Board appointments. MeitY, 6 May 2026
  4. Notification G.S.R. 843(E), commencement of the DPDP Act, 2023. MeitY, 13 November 2025
  5. Notification G.S.R. 844(E), establishment of the Data Protection Board of India. MeitY, 13 November 2025
  6. Regulation (EU) 2016/679, General Data Protection Regulation, Article 83. EUR-Lex, European Union
  7. The Digital Personal Data Protection Act, 2023, including the Schedule and section 33. MeitY, Government of India
  8. The Digital Personal Data Protection Rules, 2025, G.S.R. 846(E). MeitY, 13 November 2025
  9. The Information Technology Act, 2000, sections 43A, 46, 72A and 85. India Code, Government of India

Legislative history

  1. Digital Personal Data Protection Bill, 2023 Bill Track. PRS Legislative Research

Secondary sources

  1. Enforcement of the DPDP Act and notification of the DPDP Rules. Shardul Amarchand Mangaldas & Co
  2. India’s Data Protection Board: established in law, absent in fact. LiveLaw, 1 August 2026
  3. India’s Data Protection Board: the enforcer that isn’t there yet. Mondaq, 17 April 2026

This article is informational and educational only and is not legal advice. The DPDP Act and the DPDP Rules 2025 are in phased commencement, and the position stated here is as of September 2026. Consult a qualified professional before acting.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *