DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ General awareness

General awareness

DPDP Act penalties: the full Schedule and what triggers them

What are the penalties under the DPDP Act?
The Schedule sets seven ceilings, from Rs 10,000 to Rs 250 crore. Every figure is a maximum, not a per record amount. The Board may impose one only after a concluded inquiry, only if it finds the breach significant, and only after hearing the person. Penalties commence on 13 May 2027.
Who this affects
Every Data Fiduciary and Data Processor, and, in one entry, the Data Principal.
What to do about it
Read the ceilings as a map of what the Act treats as serious, not as a bill. Entry 7 is the one most organisations will actually meet.

Most published summaries of DPDP penalties reproduce two numbers, Rs 250 crore and Rs 200 crore, and stop. That leaves out the five other entries, the conditions that must be satisfied before any penalty is possible, the factors the Board is required to weigh, and the fact that none of it is in force yet.

What follows is the Schedule in full, and the machinery around it, cited to the provisions.

The Schedule in full

The Schedule is read with section 33(1). It has seven entries.

#BreachPenalty
1Failure to take reasonable security safeguards to prevent a personal data breach, section 8(5)Up to Rs 250 crore
2Failure to give the Board or the affected Data Principal notice of a personal data breach, section 8(6)Up to Rs 200 crore
3Breach of the additional obligations in relation to children, section 9Up to Rs 200 crore
4Breach of the additional obligations of a Significant Data Fiduciary, section 10Up to Rs 150 crore
5Breach of the duties of a Data Principal, section 15Up to Rs 10,000
6Breach of any term of a voluntary undertaking accepted by the Board, section 32Up to the ceiling applicable to the breach for which the section 28 proceedings were instituted
7Breach of any other provision of the Act or the rules made under itUp to Rs 50 crore

Every figure is a ceiling

Each entry in column three reads "may extend to". That is a single upper limit for the breach. It is not a fixed penalty, and it is not a rate applied to each affected person.

This matters because a per record reading circulates widely, usually in the form of a large number of affected users multiplied by some assumed figure. Nothing in the Act supports it. There is no per record provision, no multiplier, and no floor. A breach affecting ten million people and a breach affecting ten people sit under the same ceiling, and the difference between them is reflected through the factors in section 33(2), not through arithmetic.

The Schedule tells you the most the Board could impose. It tells you nothing about what it would.

Three things must be true before any penalty

Section 33(1) is short, and it contains three separate conditions.

"If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule."

First, there must be a concluded inquiry. A penalty cannot be the opening move. Second, the Board must determine that the breach is significant. The Act does not define significant, which leaves the Board room, but it does mean an established breach is not automatically a penalised one. Third, the person must have had an opportunity of being heard.

The word "may" carries weight too. Even where all three conditions are met, imposing a penalty is discretionary.

What the Board must weigh

Section 33(2) lists seven matters the Board is required to consider in setting the amount:

  1. the nature, gravity and duration of the breach;
  2. the type and nature of the personal data affected;
  3. whether the breach is repetitive;
  4. whether the person realised a gain or avoided a loss as a result;
  5. whether the person acted to mitigate the effects, and how timely and effective that action was;
  6. whether the penalty is proportionate and effective, having regard to deterrence;
  7. the likely impact of the penalty on the person.

Read as a set, these are the practical answer to the ceilings. Factor five rewards a fast, competent response to an incident. Factor four asks whether you profited. Factor seven allows the Board to take account of what an organisation can actually bear, which is why a Rs 250 crore ceiling is not a Rs 250 crore expectation for a small business.

The entry almost nobody quotes

Entry 5 applies to the Data Principal, the individual, not the organisation. Breach of the duties in section 15 carries a penalty of up to Rs 10,000.

Those duties include not impersonating another person when providing personal data, not suppressing material information, and not registering a false or frivolous grievance or complaint. It is the only entry in the Schedule aimed at the person the Act otherwise protects, and it is routinely left out of summaries that present the Schedule as a list of corporate exposures.

Entry 7 is the one you will actually meet

Entries 1 to 4 cover security safeguards, breach notification, children, and Significant Data Fiduciary duties. Everything else in the Act falls into entry 7, at up to Rs 50 crore.

That residual entry covers most of the operative duties an ordinary organisation has: giving a compliant notice under section 5, having a lawful basis under section 4, honouring Data Principal rights under sections 11 to 14, erasing data when the purpose is served under section 8(7), publishing the contact details of a person able to answer questions under section 8(9), and every obligation created by the Rules rather than the Act.

If you are building a compliance programme, entry 7 is the line item that matters. It is not the headline number, and it is the one your day to day practice is measured against.

Voluntary undertakings, and what breaking one costs

Under section 32 the Board may accept a voluntary undertaking at any stage of proceedings, and accepting one bars further proceedings on that breach. Entry 6 sets the price of breaking it: the penalty may extend to whatever ceiling applied to the breach for which the original section 28 proceedings were instituted.

So an undertaking does not reduce your exposure if you fail to honour it. It defers it, and the original ceiling comes back.

Where the money goes

Section 34 requires that all sums realised by way of penalties be credited to the Consolidated Fund of India.

The practical consequence is often missed. A person whose data is breached receives nothing under this Act. There is no statutory compensation, no damages provision, and no route by which a penalty reaches the affected individual. The DPDP Act gives a Data Principal rights, a complaint mechanism and an appeal. It does not give a rupee. Anyone seeking money for harm has to look outside this statute.

How long an inquiry takes

The Rules 2025 put a clock on it. The Board's inquiry must be completed within six months of receipt of the intimation, complaint, reference or direction under section 27, unless the Board extends it, for reasons recorded in writing, by a further period not exceeding three months at a time.

The Rules also make the Board a digital office. Proceedings are conducted in a manner that does not require anyone's physical presence, without prejudice to the Board's power to summon a person and examine her on oath.

Appeal

Any person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal under section 29, which is the Telecom Disputes Settlement and Appellate Tribunal, per section 2(a). The appeal must be filed within sixty days of receiving the order, though the Tribunal may admit a late appeal if satisfied there was sufficient cause. The Tribunal may confirm, modify or set aside the order.

None of this is in force yet

This is the single most misstated fact about DPDP penalties.

The Act commenced in stages. Notification G.S.R. 843(E) dated 13 November 2025 brought sections 2, 18 to 26, 35 to 43 and parts of section 44 into force immediately. Those are the definitions and the machinery that constitutes the Board. Section 6(9) and section 27(1)(d) follow one year from that date.

Sections 3 to 17 and sections 28 to 34 commence eighteen months from 13 November 2025, which is 13 May 2027. Section 33 and the Schedule sit in that block.

So as of today the Board exists and can be constituted, and the operative duties and the penalty regime both switch on together in May 2027. Claims that companies are exposed to Rs 250 crore penalties now are wrong, and so is the inference some draw from that, which is that there is nothing to do until then. The duties in sections 3 to 17 commence on the same day as the penalties. There is no grace period after commencement in which to start building.

What actually follows from this

Three things.

Treat the Schedule as a statement of what the Act considers serious rather than as a price list. Security safeguards and breach notification carry the two highest ceilings, which tells you where to put effort first.

Work to entry 7. Most of what your organisation does daily sits in the residual entry, and the section 33(2) factors, particularly mitigation and repetitiveness, are decided by whether you have a working practice rather than by what your policy says.

Use the time. The gap to 13 May 2027 is the whole point of a phased commencement. It is there so that the governance exists before the duty attaches, and the factors in section 33(2) reward an organisation that can show it.

If the Board opened an inquiry into us tomorrow, which of the seven factors in section 33(2) could we evidence, and which would we simply have to concede?

#DPDP #DPDPAct2023 #DPDPRules2025 #DataProtection #PrivacyLaw #IndiaLegal #Compliance

Related: the short answer on penalties, breach reporting timelines, what makes a Significant Data Fiduciary, and the full Act map.

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Open Template Builder