Written by

Sumeshwar Pandey

View Profile

DPDP Act Penalties and Enforcement: Who Issues Fines and How Much Can They Cost?

A practical guide to the Data Protection Board’s authority, the seven statutory penalty categories, cumulative exposure and the evidence Indian organisations should prepare before enforcement begins.
Key takeaways
  • The Data Protection Board of India conducts inquiries and may impose monetary penalties; the Central Government and Appellate Tribunal have distinct escalation and review roles.
  • The widely cited ₹250 crore amount applies to a breach of the obligation to take reasonable security safeguards. It is neither an automatic fine nor a universal cap on total exposure.
  • The Schedule contains seven penalty entries, with ceilings ranging from ₹10,000 for a breach of Data Principal duties to ₹250 crore for inadequate security safeguards.[1][7]
  • Actual penalties must be assessed against statutory factors such as gravity, duration, data affected, repetition, financial gain, mitigation, proportionality and impact on the organisation.[1]
  • An enforcement-ready posture depends on contemporaneous evidence, including security records, consent histories, incident files, rights workflows, contracts, audit reports and governance decisions.

DPDP penalties from a leadership and risk perspective

A General Counsel, CISO and CFO reviewing the same data incident will usually ask three different questions. Was there a breach of the Digital Personal Data Protection Act, 2023? Who can take action against the organisation? What amount should be reserved as credible financial exposure? The headline figure of ₹250 crore answers none of those questions on its own.
DPDP exposure must instead be modelled as a set of possible contraventions. A single event could reveal inadequate security safeguards, delayed breach notification and deficient controls for children’s data. Each issue maps to a different Schedule entry, but no maximum amount is automatic. The Data Protection Board of India must inquire into the facts and, where it finds a significant breach, determine an amount within the relevant ceiling by applying the factors in section 33(2).[1]
Leadership reporting should therefore distinguish the theoretical statutory ceiling from a plausible scenario range. The former identifies the outer legal boundary for a category; the latter considers the organisation’s controls, the duration and scale of the failure, previous incidents, mitigation and available evidence. That distinction produces a more defensible risk decision than either dismissing the maxima or treating every incident as a ₹250 crore loss.

Enforcement architecture under the DPDP Act

The Data Protection Board of India is the principal adjudicatory body under the DPDP Act. It may receive specified complaints, intimations and references, conduct an inquiry, issue relevant directions, accept voluntary undertakings and impose a monetary penalty after giving the affected person a reasonable opportunity to be heard. The Board is designed to operate digitally, but it also has civil court-like powers for obtaining evidence, summoning persons and examining relevant records. It is the Board, rather than the Ministry or an individual complainant, that determines a monetary penalty under the Act.[1][4]
The Central Government performs a different role. It establishes the Board, makes rules, may send specified references to it and can exercise the blocking power under section 37 when the statutory conditions are met. That blocking mechanism is not an ordinary first response to an isolated compliance error: it involves repeated penalty findings, advice from the Board, a public-interest assessment and an opportunity for the affected Data Fiduciary to be heard.[1]
Appeals from Board orders lie to the Appellate Tribunal, which is TDSAT for this purpose. The Tribunal reviews the order rather than conducting the initial DPDP inquiry and may confirm, modify or set it aside in accordance with the statutory framework. An organisation assessing enforcement risk should account for the cost and operational burden of the inquiry and appeal process, not only the final monetary outcome.[1][3]
DPDP enforcement also does not displace every other Indian legal regime. The same security incident may need to be assessed under applicable provisions of the Information Technology Act, CERT-In Directions, sector-specific requirements administered by bodies such as financial or securities regulators, contractual commitments and any independently available civil remedies. Each regime has its own trigger, authority and consequence, so parallel proceedings are possible even where they arise from the same underlying event.
Key DPDP enforcement actors and how they relate to organisational risk.
Actor Core DPDP role Key powers relevant to penalties How your organisation interacts with them
Data Protection Board of India Primary adjudicatory body for DPDP contraventions. Receives complaints, breach intimations and references; conducts inquiries; issues directions; accepts voluntary undertakings; imposes monetary penalties. Notified entity for breach intimations and specified complaints; main forum where your evidence, controls and remediation actions will be scrutinised.
Central Government Policy and supervisory role over the DPDP framework. Establishes the Board, issues rules, can refer matters to the Board and, after preconditions are met, order blocking of access to a Data Fiduciary’s services under section 37. May be involved indirectly through references, notifications and any blocking process triggered by repeated contraventions and Board advice.
Appellate Tribunal (TDSAT) Appellate forum for Board orders under the DPDP Act. Can confirm, modify or set aside Board orders in accordance with the statute. Receives appeals where your organisation decides to challenge a Board order; appeal strategy must consider evidence, timelines, cost and operational impact.
Other regulators and legal regimes Sectoral, cybersecurity and general legal frameworks that continue to apply alongside the DPDP Act. Examples include obligations under IT and cybersecurity law, incident reporting, sectoral privacy rules and contractual remedies. You may need to handle DPDP proceedings in parallel with sectoral or contractual processes arising from the same incident, each with its own triggers and evidence expectations.

How a DPDP case reaches the Board and moves through inquiry

A matter may reach the Board through an intimation of a personal data breach, a complaint from a Data Principal after the applicable grievance process, a reference from the Central or a State Government, or a direction from a court. The Act also provides routes for specified Consent Manager registration issues and intermediary non-compliance connected with section 37. The legal basis and supporting record for the referral matter because the Board does not have an unrestricted mandate to examine every commercial disagreement involving data.[1]
Indicative path for a DPDP enforcement matter, from incident to final order:
  1. Incident or issue arises
    A security incident, rights-handling dispute, systemic control failure or other DPDP-relevant event occurs within your environment or that of a processor.
  2. Trigger and referral to the Board
    The issue reaches the Board via breach intimation, a Data Principal complaint, a government reference, a court direction, or a Consent Manager or intermediary route defined in the Act and Rules.
  3. Screening for sufficient grounds
    The Board assesses whether there is enough material to proceed. If the threshold is not met, it may close the matter with recorded reasons.
  4. Inquiry and information requests
    If an inquiry is opened, the Board may seek policies, system logs, notices, consent evidence, incident timelines, processor contracts and proof of corrective actions, while observing principles of natural justice.
  5. Urgent directions and mitigation (where needed)
    For active breaches or high-risk situations, the Board may issue interim directions to contain harm, which can later be varied or cancelled after hearing the affected person.
  6. Voluntary undertaking or mediation (where appropriate)
    The Board may facilitate mediation or accept a voluntary undertaking that commits the organisation to specific remedial actions, potentially affecting how proceedings continue.
  7. Final order: closure or penalty
    At the end of the inquiry, the Board may close the matter or, if it finds a significant contravention, issue a reasoned order imposing a monetary penalty under the relevant Schedule entry.
The Board first considers whether there are sufficient grounds to proceed. If the threshold is not met, it may close the matter and record reasons. If an inquiry begins, the organisation should expect requests for policies, system records, notices, consent evidence, incident timelines, communications, processor information and proof of corrective action. The Board must follow principles of natural justice and is expected to avoid unnecessarily disrupting day-to-day operations while examining the relevant facts.
A breach intimation may also lead to urgent directions intended to remedy or mitigate harm. The organisation’s first response should preserve evidence while containing the incident: identify affected systems and Data Principals, record decision times, document the basis for each containment measure and maintain copies of notifications. Reconstructed timelines prepared weeks later are generally less persuasive than system-generated logs and contemporaneous incident records.
During proceedings, the Board may direct mediation where appropriate or accept a voluntary undertaking. At the end of an inquiry, it may close the proceedings or, if it finds a significant breach, impose a penalty under the applicable Schedule entry. Cooperation does not erase the underlying contravention, but prompt mitigation, complete disclosure and reliable records may be relevant when the Board applies the statutory penalty factors.

Penalty schedule explained: seven categories of violations and their ceilings

The first Schedule entry concerns a Data Fiduciary’s failure to take reasonable security safeguards under section 8(5). The penalty may extend to ₹250 crore. This category could be engaged by facts showing systemic access-control failures, unaddressed vulnerabilities, deficient processor oversight or other inadequate safeguards, but the presence of a cyber incident alone does not establish that reasonable safeguards were absent. The second entry covers failure to notify the Board or affected Data Principals of a personal data breach under section 8(6), with a maximum of ₹200 crore. Security and notification are separate obligations and may therefore require separate analysis.[1][7]
The third entry covers non-compliance with the additional obligations relating to children under section 9 and carries a ceiling of ₹200 crore. Depending on the applicable rules and exemptions, relevant failures may concern parental consent, processing likely to cause detrimental effects, tracking, behavioural monitoring or targeted advertising. The fourth entry applies to a Significant Data Fiduciary’s obligations under section 10(1), with a maximum of ₹150 crore. These obligations can include appointing a Data Protection Officer and independent data auditor, conducting periodic Data Protection Impact Assessments and audits, and implementing other prescribed measures.[1][7]
The fifth entry applies when a Data Principal breaches the duties in section 15 and is capped at ₹10,000. This category concerns individual duties, such as avoiding impersonation or false and frivolous complaints, rather than organisational non-compliance. The sixth entry concerns breach of a voluntary undertaking accepted by the Board. Its ceiling is linked to the maximum that would apply to the underlying contravention for which proceedings were instituted, rather than having a single standalone rupee limit.[1][7]
The seventh and residual entry covers breach of any other provision of the Act or rules and may extend to ₹50 crore. Depending on the precise provision and facts, failures involving notices, consent governance, grievance handling, rights requests or other statutory processes may fall for consideration here. The Schedule’s ₹250 crore figure is attached specifically to the security-safeguard contravention; it is not expressed as a per-person amount and should not be treated as an organisation-wide aggregate cap. Different Schedule entries, distinct contraventions or repeated conduct could produce cumulative exposure above ₹250 crore, although any stacking would depend on the Board’s legal findings and reasoning.[1][7]
Overview of the seven DPDP Schedule penalty entries and common organisational failure patterns.
Schedule entry Underlying obligation (section) Maximum monetary penalty Illustrative organisational failure pattern
1. Security safeguards Failure of a Data Fiduciary to take reasonable security safeguards to prevent personal data breach (section 8(5)). Up to ₹250 crore. Unpatched critical vulnerabilities, weak access controls, absence of basic logging, or unmanaged processor environments leading to a large-scale breach.
2. Breach notification Failure to notify the Board and affected Data Principals of a personal data breach (section 8(6)). Up to ₹200 crore. Delayed, incomplete or missing notifications despite awareness of a qualifying breach, or poor internal detection and escalation that prevents timely notification.
3. Children’s data obligations Non-compliance with additional obligations in relation to children (section 9). Up to ₹200 crore. Absence of reliable age or parental-consent checks, high-risk profiling or targeted advertising directed at children, or processing likely to cause detrimental effects without appropriate safeguards.
4. Significant Data Fiduciary duties Non-compliance by a Significant Data Fiduciary with obligations such as appointing a DPO, conducting DPIAs and independent audits (section 10(1)). Up to ₹150 crore. Failure to appoint mandated roles, superficial or missing DPIAs for high-risk processing, or ignoring audit findings over a prolonged period.
5. Data Principal duties Breach by a Data Principal of duties such as avoiding impersonation or frivolous complaints (section 15). Up to ₹10,000. Persistent misuse of rights mechanisms for harassment, or knowingly providing false information in a manner captured by section 15.
6. Voluntary undertakings Breach of a voluntary undertaking accepted by the Board in relation to specified conduct. Up to the maximum penalty applicable to the underlying contravention for which proceedings were instituted. Offering remediation commitments that are not implemented in practice, leading to further non-compliance with the original obligations covered by the undertaking.
7. Other provisions of the Act and rules Breach of any other provision of the DPDP Act or rules not covered above. Up to ₹50 crore. Gaps in notices or consent management, failures in grievance handling or rights workflows, or other process breaches that do not fall under the specific earlier entries.

How the Data Protection Board sets penalty amounts in practice

Section 33(2) directs the Board to consider the nature, gravity and duration of the breach; the type and nature of the personal data affected; whether the breach is repetitive; any gain obtained or loss avoided; mitigation taken; whether the penalty would be proportionate and effective; and the likely impact of the penalty on the person concerned. These factors make the Schedule ceilings starting boundaries for analysis, not preset tariffs.[1][7]
For nature, gravity and duration, maintain a timestamped chronology from the first relevant control failure through detection, containment and recovery. For the data-related factor, preserve defensible counts of affected people, data fields, systems, locations and processing purposes instead of relying on an early estimate that cannot be reproduced. Prior audit findings, unresolved vulnerabilities and earlier similar incidents will be relevant when repetition is examined.
Evidence concerning gain or avoided loss may include deferred security expenditure, delayed remediation budgets or commercial benefits obtained from disputed processing. Mitigation evidence should identify what changed, when it changed and whether the measure reduced continuing risk. Technical logs, incident tickets, independent assessments and affected-person communications usually provide stronger support than a general statement that the organisation acted promptly.
Proportionality and likely impact require financial and operational context, but size alone should not be assumed to reduce liability. Management should be able to explain the control environment, the resources committed before the incident, why particular decisions were reasonable at the time and how recurrence is being prevented. Missing records can make an otherwise credible account difficult to substantiate, while polished policies that do not match system behaviour may weaken it.

Beyond fines: directions, voluntary undertakings, blocking orders and appeals

Monetary penalties are only one part of the DPDP enforcement toolkit. Following a breach intimation, the Board may direct urgent remedial or mitigation measures and may later modify, suspend or cancel those directions after hearing the affected person. Such directions can create immediate technical and operational work even before the final merits of a penalty are resolved.
A voluntary undertaking can provide a structured route to address specified conduct, but it should be reviewed as an enforceable commitment rather than an informal remediation plan. Once accepted, it can bar proceedings concerning its contents while it remains effective. Breaching it can expose the organisation to the Schedule entry for voluntary undertakings and allow the underlying matter to proceed again. Legal, technology and business owners should verify that every promised measure has an accountable owner, realistic deadline, funding and measurable completion evidence before the undertaking is offered.
Section 37 permits the Central Government, following the required process, to order blocking of access to information that enables a Data Fiduciary to offer goods or services in India. The mechanism is linked to the Board imposing penalties in two or more instances and advising that blocking is in the public interest. For a digital business, the operational impact of blocking could be more material than the penalty itself, which is why repeated non-compliance should be tracked as an escalation risk.[1]
Penalty money is credited to the Consolidated Fund of India; it is not paid to affected individuals as compensation under the DPDP penalty process. That does not eliminate exposure under contracts, sectoral rules or any other independently available cause of action. Appeals to TDSAT can test the Board’s legal and factual conclusions, but an appeal strategy should consider business continuity, evidence preservation, disclosure obligations and cost as well as the disputed amount.[1][6]

When the obligations and penalty provisions commence

The DPDP framework uses phased commencement rather than bringing every obligation and enforcement provision into force at once. As at September 2026, foundational provisions supporting the Board and the rule-making framework had been notified, while key substantive obligations, inquiry provisions and monetary penalty machinery were on an 18-month timetable following the 13 November 2025 notifications. On that published schedule, the principal 18-month tranche would fall in May 2027, subject to the precise wording of the applicable notifications and any later official changes.[2][3][8]
This transition period should not be read as permission to defer implementation until the final commencement date. Consent histories, processor arrangements, data inventories, child-related controls and incident evidence cannot usually be reconstructed reliably at the end of a compliance programme. Your legal team should maintain a provision-by-provision commencement register and verify it against current Gazette notifications, amendments and sectoral directions before reporting readiness or enforcement exposure.

Translating DPDP penalties into organisational risk planning

Begin with scenarios rather than one enterprise-wide maximum. A scenario might involve an exposed cloud repository containing adult and children’s data, followed by an incomplete or delayed notification. The risk register should separately consider the potential security, breach-notification and children’s-data entries, then assign likelihood and plausible penalty bands using the section 33(2) factors. The maxima may be shown as stress-case boundaries, but adding every ceiling without analysing whether each contravention is legally and factually supportable will overstate the model.
Control investment should follow the failure modes that drive both likelihood and severity. Security architecture, processor oversight and tested incident response address the highest-ceiling categories. Child-specific data discovery and age or parental controls matter where relevant processing occurs. Significant Data Fiduciaries need a separate readiness path for statutory roles, impact assessments and audits. Consent, notices, withdrawal, grievance and rights workflows should be assessed against actual system behaviour rather than policy wording alone.
An evidence-ready file should include approved governance policies, data and system maps, current notice versions, consent and withdrawal records, access logs, retention and deletion evidence, breach playbooks, exercise results, incident files, training records, audit findings, remediation tickets and relevant board or committee minutes. Where processors are involved, review contracts for security, incident escalation, cooperation, evidence preservation, audit access, deletion or return, liability allocation and indemnity terms. The purpose is both to verify regulatory controls and to understand whether contract provisions transfer, retain or create additional financial risk.
Keep three analyses separate in leadership reporting. Regulatory obligations should be tied to the current Act, rules and commencement notifications. Contract risk should be based on executed terms, liability caps, indemnities and notification commitments. Claim substantiation should test whether statements made in privacy notices, customer contracts, assurance reports or board papers are supported by operational evidence. A concise dashboard can then show the relevant Schedule entry, credible scenario range, control owner, evidence quality, remediation cost and residual uncertainty without representing the result as a prediction of what the Board will decide.

How Digital Anumati - Service supports DPDP enforcement readiness

Digital Anumati - Service is relevant where consent, notice, withdrawal and rights processes are fragmented across websites, applications, customer systems and manual records. A structured platform can help your organisation preserve consent histories, coordinate preference changes, route rights requests and maintain audit trails that can be retrieved during an internal investigation or regulatory inquiry.
Technology cannot determine legal roles, validate every lawful basis, secure the broader environment or guarantee a particular penalty outcome. Its value depends on accurate configuration, system integration, accountable governance and legal review. Review Digital Anumati - Service against your data flows, evidence requirements and existing control gaps to determine where it can strengthen the wider DPDP programme.

How Digital Anumati - Service helps evidence DPDP compliance

1

Cryptographically verifiable consent receipts

Digital Anumati - Brand reports that in a diagnostic-lab deployment, Digital Anumati - Service generates secure, hashed consent receipts that are provided alongside final pathology reports to demonstrate that data was processed on a lawful basis.

Why it matters for you

For DPDP enforcement, being able to tie each report back to a tamper-evident consent artefact strengthens your position on lawful processing if the Board examines a specific data flow.

2

Breach readiness backed by consent-linked data mapping

In a high-throughput clinical deployment, Digital Anumati - Brand describes 72-hour breach readiness built on data-flow mapping linked to the consent ledger, allowing rapid isolation of affected cohorts when anomalies are detected.

Why it matters for you

When a breach intimation may reach the Board, the ability to quickly identify affected Data Principals and processing contexts supports timely notification and targeted mitigation.

3

Automated retention and deletion pipelines

Digital Anumati - Brand notes that one hospital deployment uses automated pipelines to identify and purge patient data once legal retention periods expire, aligning with data minimisation principles.

Why it matters for you

Documented, automated deletion supports your evidence on retention limits and helps show the Board that unnecessary personal data is not being kept when assessing risk and proportionality.

4

Controlled handling of consent revocation

In another hospital example, Digital Anumati - Brand describes a revocation pipeline that moves records from active operational databases into encrypted cold-storage logs, removing them from active processing while retaining them for legal obligations.

Why it matters for you

Being able to show exactly how withdrawal of consent changed downstream processing and access patterns is relevant when the Board evaluates compliance with rights and purpose limitation.

5

Logged refusals for secondary processing

Digital Anumati - Brand highlights a clinic deployment where explicit rejections of secondary processing are logged in the consent ledger and enforced at the database level to prevent unauthorised sharing.

Why it matters for you

Clear, queryable records of refused purposes help show that your systems respect Data Principal choices, which may be relevant under the residual Schedule entry and when assessing gains or avoided losses.

FAQs

The Data Protection Board of India is empowered to conduct the relevant inquiry and impose a monetary penalty under the Act after giving the affected person a reasonable opportunity to be heard. The Central Government has establishment, rule-making, reference and specified blocking functions, but it does not replace the Board as the initial penalty adjudicator. TDSAT acts as the Appellate Tribunal for challenges to Board orders.[1][5]

Potentially, yes. ₹250 crore is the ceiling for the Schedule entry concerning failure to take reasonable security safeguards, not an aggregate cap covering every contravention by an organisation. If the facts support findings under multiple Schedule entries, or involve distinct or repeated contraventions, cumulative exposure could be higher. The result would depend on how the Board characterises the conduct and applies section 33(2), rather than on automatic addition of maximum figures.[1][7]

There is no general rule that excludes every startup or small entity from the penalty framework. The Central Government may provide specified exemptions for certain classes or processing, but their scope must be checked against current notifications. Size and financial impact may be relevant to the Board’s assessment, yet they do not remove the need to establish reasonable safeguards, maintain evidence or comply with applicable obligations.

No. Monetary penalties imposed under the DPDP Act are credited to the Consolidated Fund of India. The Act’s penalty process does not direct that money to affected Data Principals as compensation. An organisation may nevertheless need to assess separate contractual claims, sectoral proceedings or other legal remedies where they are independently available.[1][6]

Yes. A personal data breach may engage the DPDP framework while also triggering applicable CERT-In reporting requirements, sectoral cybersecurity or outsourcing rules, contractual notices and other legal obligations. Compliance with one notification route does not necessarily satisfy another. The incident plan should identify each authority, contractual counterparty, trigger, deadline, decision owner and required evidence separately.

Sources
  1. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) - Ministry of Electronics and Information Technology, Government of India
  2. Digital Personal Data Protection Rules, 2025 - Ministry of Electronics and Information Technology, Government of India
  3. Government notifies DPDP Rules to empower citizens and protect privacy - Press Information Bureau, Government of India
  4. The Digital Personal Data Protection Bill, 2023 – PRS Legislative Brief - PRS Legislative Research
  5. Digital Personal Data Protection Act, 2023 - Wikipedia
  6. Information Privacy Rights in India: A Study of the Digital Personal Data Protection Act, 2023 - IntechOpen
  7. DPDP Act penalties — all seven entries in the Schedule - India Data Law
  8. NIST Privacy Framework 1.0 to Digital Personal Data Protection Act 2023 and Rules 2025 Crosswalk - National Institute of Standards and Technology (NIST)
  9. Promotion page