DPDP Act Penalties and Enforcement: Who Issues Fines and How Much Can They Cost?
- The Data Protection Board of India conducts inquiries and may impose monetary penalties; the Central Government and Appellate Tribunal have distinct escalation and review roles.
- The widely cited ₹250 crore amount applies to a breach of the obligation to take reasonable security safeguards. It is neither an automatic fine nor a universal cap on total exposure.
- The Schedule contains seven penalty entries, with ceilings ranging from ₹10,000 for a breach of Data Principal duties to ₹250 crore for inadequate security safeguards.[1][7]
- Actual penalties must be assessed against statutory factors such as gravity, duration, data affected, repetition, financial gain, mitigation, proportionality and impact on the organisation.[1]
- An enforcement-ready posture depends on contemporaneous evidence, including security records, consent histories, incident files, rights workflows, contracts, audit reports and governance decisions.
DPDP penalties from a leadership and risk perspective
Enforcement architecture under the DPDP Act
| Actor | Core DPDP role | Key powers relevant to penalties | How your organisation interacts with them |
|---|---|---|---|
| Data Protection Board of India | Primary adjudicatory body for DPDP contraventions. | Receives complaints, breach intimations and references; conducts inquiries; issues directions; accepts voluntary undertakings; imposes monetary penalties. | Notified entity for breach intimations and specified complaints; main forum where your evidence, controls and remediation actions will be scrutinised. |
| Central Government | Policy and supervisory role over the DPDP framework. | Establishes the Board, issues rules, can refer matters to the Board and, after preconditions are met, order blocking of access to a Data Fiduciary’s services under section 37. | May be involved indirectly through references, notifications and any blocking process triggered by repeated contraventions and Board advice. |
| Appellate Tribunal (TDSAT) | Appellate forum for Board orders under the DPDP Act. | Can confirm, modify or set aside Board orders in accordance with the statute. | Receives appeals where your organisation decides to challenge a Board order; appeal strategy must consider evidence, timelines, cost and operational impact. |
| Other regulators and legal regimes | Sectoral, cybersecurity and general legal frameworks that continue to apply alongside the DPDP Act. | Examples include obligations under IT and cybersecurity law, incident reporting, sectoral privacy rules and contractual remedies. | You may need to handle DPDP proceedings in parallel with sectoral or contractual processes arising from the same incident, each with its own triggers and evidence expectations. |
How a DPDP case reaches the Board and moves through inquiry
-
Incident or issue arisesA security incident, rights-handling dispute, systemic control failure or other DPDP-relevant event occurs within your environment or that of a processor.
-
Trigger and referral to the BoardThe issue reaches the Board via breach intimation, a Data Principal complaint, a government reference, a court direction, or a Consent Manager or intermediary route defined in the Act and Rules.
-
Screening for sufficient groundsThe Board assesses whether there is enough material to proceed. If the threshold is not met, it may close the matter with recorded reasons.
-
Inquiry and information requestsIf an inquiry is opened, the Board may seek policies, system logs, notices, consent evidence, incident timelines, processor contracts and proof of corrective actions, while observing principles of natural justice.
-
Urgent directions and mitigation (where needed)For active breaches or high-risk situations, the Board may issue interim directions to contain harm, which can later be varied or cancelled after hearing the affected person.
-
Voluntary undertaking or mediation (where appropriate)The Board may facilitate mediation or accept a voluntary undertaking that commits the organisation to specific remedial actions, potentially affecting how proceedings continue.
-
Final order: closure or penaltyAt the end of the inquiry, the Board may close the matter or, if it finds a significant contravention, issue a reasoned order imposing a monetary penalty under the relevant Schedule entry.
Penalty schedule explained: seven categories of violations and their ceilings
| Schedule entry | Underlying obligation (section) | Maximum monetary penalty | Illustrative organisational failure pattern |
|---|---|---|---|
| 1. Security safeguards | Failure of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach (section 8(5)). | Up to ₹250 crore. | Unpatched critical vulnerabilities, weak access controls, absence of basic logging, or unmanaged processor environments leading to a large-scale breach. |
| 2. Breach notification | Failure to notify the Board and affected Data Principals of a personal data breach (section 8(6)). | Up to ₹200 crore. | Delayed, incomplete or missing notifications despite awareness of a qualifying breach, or poor internal detection and escalation that prevents timely notification. |
| 3. Children’s data obligations | Non-compliance with additional obligations in relation to children (section 9). | Up to ₹200 crore. | Absence of reliable age or parental-consent checks, high-risk profiling or targeted advertising directed at children, or processing likely to cause detrimental effects without appropriate safeguards. |
| 4. Significant Data Fiduciary duties | Non-compliance by a Significant Data Fiduciary with obligations such as appointing a DPO, conducting DPIAs and independent audits (section 10(1)). | Up to ₹150 crore. | Failure to appoint mandated roles, superficial or missing DPIAs for high-risk processing, or ignoring audit findings over a prolonged period. |
| 5. Data Principal duties | Breach by a Data Principal of duties such as avoiding impersonation or frivolous complaints (section 15). | Up to ₹10,000. | Persistent misuse of rights mechanisms for harassment, or knowingly providing false information in a manner captured by section 15. |
| 6. Voluntary undertakings | Breach of a voluntary undertaking accepted by the Board in relation to specified conduct. | Up to the maximum penalty applicable to the underlying contravention for which proceedings were instituted. | Offering remediation commitments that are not implemented in practice, leading to further non-compliance with the original obligations covered by the undertaking. |
| 7. Other provisions of the Act and rules | Breach of any other provision of the DPDP Act or rules not covered above. | Up to ₹50 crore. | Gaps in notices or consent management, failures in grievance handling or rights workflows, or other process breaches that do not fall under the specific earlier entries. |
How the Data Protection Board sets penalty amounts in practice
Beyond fines: directions, voluntary undertakings, blocking orders and appeals
When the obligations and penalty provisions commence
Translating DPDP penalties into organisational risk planning
How Digital Anumati - Service supports DPDP enforcement readiness
How Digital Anumati - Service helps evidence DPDP compliance
Cryptographically verifiable consent receipts
Digital Anumati - Brand reports that in a diagnostic-lab deployment, Digital Anumati - Service generates secure, hashed consent receipts that are provided alongside final pathology reports to demonstrate that data was processed on a lawful basis.
Why it matters for you
For DPDP enforcement, being able to tie each report back to a tamper-evident consent artefact strengthens your position on lawful processing if the Board examines a specific data flow.
Breach readiness backed by consent-linked data mapping
In a high-throughput clinical deployment, Digital Anumati - Brand describes 72-hour breach readiness built on data-flow mapping linked to the consent ledger, allowing rapid isolation of affected cohorts when anomalies are detected.
Why it matters for you
When a breach intimation may reach the Board, the ability to quickly identify affected Data Principals and processing contexts supports timely notification and targeted mitigation.
Automated retention and deletion pipelines
Digital Anumati - Brand notes that one hospital deployment uses automated pipelines to identify and purge patient data once legal retention periods expire, aligning with data minimisation principles.
Why it matters for you
Documented, automated deletion supports your evidence on retention limits and helps show the Board that unnecessary personal data is not being kept when assessing risk and proportionality.
Controlled handling of consent revocation
In another hospital example, Digital Anumati - Brand describes a revocation pipeline that moves records from active operational databases into encrypted cold-storage logs, removing them from active processing while retaining them for legal obligations.
Why it matters for you
Being able to show exactly how withdrawal of consent changed downstream processing and access patterns is relevant when the Board evaluates compliance with rights and purpose limitation.
Logged refusals for secondary processing
Digital Anumati - Brand highlights a clinic deployment where explicit rejections of secondary processing are logged in the consent ledger and enforced at the database level to prevent unauthorised sharing.
Why it matters for you
Clear, queryable records of refused purposes help show that your systems respect Data Principal choices, which may be relevant under the residual Schedule entry and when assessing gains or avoided losses.
The Data Protection Board of India is empowered to conduct the relevant inquiry and impose a monetary penalty under the Act after giving the affected person a reasonable opportunity to be heard. The Central Government has establishment, rule-making, reference and specified blocking functions, but it does not replace the Board as the initial penalty adjudicator. TDSAT acts as the Appellate Tribunal for challenges to Board orders.[1][5]
Potentially, yes. ₹250 crore is the ceiling for the Schedule entry concerning failure to take reasonable security safeguards, not an aggregate cap covering every contravention by an organisation. If the facts support findings under multiple Schedule entries, or involve distinct or repeated contraventions, cumulative exposure could be higher. The result would depend on how the Board characterises the conduct and applies section 33(2), rather than on automatic addition of maximum figures.[1][7]
There is no general rule that excludes every startup or small entity from the penalty framework. The Central Government may provide specified exemptions for certain classes or processing, but their scope must be checked against current notifications. Size and financial impact may be relevant to the Board’s assessment, yet they do not remove the need to establish reasonable safeguards, maintain evidence or comply with applicable obligations.
No. Monetary penalties imposed under the DPDP Act are credited to the Consolidated Fund of India. The Act’s penalty process does not direct that money to affected Data Principals as compensation. An organisation may nevertheless need to assess separate contractual claims, sectoral proceedings or other legal remedies where they are independently available.[1][6]
Yes. A personal data breach may engage the DPDP framework while also triggering applicable CERT-In reporting requirements, sectoral cybersecurity or outsourcing rules, contractual notices and other legal obligations. Compliance with one notification route does not necessarily satisfy another. The incident plan should identify each authority, contractual counterparty, trigger, deadline, decision owner and required evidence separately.
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - Ministry of Electronics and Information Technology, Government of India
- Digital Personal Data Protection Rules, 2025 - Ministry of Electronics and Information Technology, Government of India
- Government notifies DPDP Rules to empower citizens and protect privacy - Press Information Bureau, Government of India
- The Digital Personal Data Protection Bill, 2023 – PRS Legislative Brief - PRS Legislative Research
- Digital Personal Data Protection Act, 2023 - Wikipedia
- Information Privacy Rights in India: A Study of the Digital Personal Data Protection Act, 2023 - IntechOpen
- DPDP Act penalties — all seven entries in the Schedule - India Data Law
- NIST Privacy Framework 1.0 to Digital Personal Data Protection Act 2023 and Rules 2025 Crosswalk - National Institute of Standards and Technology (NIST)
- Promotion page