You will see it stated that the DPDP Act is in force and that non-compliance attracts ₹250 crore penalties today. That is not correct, and it matters.
The penalty and adjudication provisions sit in sections 28 to 34, which the commencement notification brings into force on 13 May 2027, together with the substantive obligations they enforce. The Data Protection Board itself has existed since 13 November 2025 and is operating — but it cannot yet adjudicate a breach of the notice, consent, security or rights provisions, because those provisions have not commenced.
The accurate position is that there is a fixed date, and a defined amount of time before it. That is more useful than an inaccurate present-tense threat, and it is also what a competent adviser will tell your board.
The Schedule is referenced by s. 33(1). Each entry pairs a breach with a maximum.
| # | Breach | Penalty may extend to |
|---|---|---|
| 1 | Failure to observe the obligation to take reasonable security safeguards to prevent a personal data breach, under s. 8(5) | ₹250 crore |
| 2 | Failure to give the Board or affected Data Principals notice of a personal data breach, under s. 8(6) | ₹200 crore |
| 3 | Failure to observe the additional obligations in relation to children, under s. 9 | ₹200 crore |
| 4 | Failure to observe the additional obligations of a Significant Data Fiduciary, under s. 10 | ₹150 crore |
| 5 | Breach of the duties of a Data Principal, under s. 15 | ₹10,000 |
| 6 | Breach of any term of a voluntary undertaking accepted by the Board under s. 32 | Up to the extent applicable to the breach for which proceedings were instituted |
| 7 | Breach of any other provision of the Act or the rules | ₹50 crore |
Under s. 42, the Central Government may amend the Schedule, but no amendment may increase any penalty to more than twice the amount originally enacted.
The maximums in the Schedule are ceilings, not tariffs. s. 33(1) allows the Board to impose a penalty only where it determines, on conclusion of an inquiry, that the breach is significant — and only after giving the person an opportunity of being heard.
s. 33(2) then lists the factors the Board must have regard to:
Penalties realised are credited to the Consolidated Fund of India.
A data breach in India is capable of engaging two separate enforcement regimes, and they work differently.
Under DPDP, failure to take reasonable security safeguards (s. 8(5)) attracts up to ₹250 crore, and failure to give breach intimation (s. 8(6)) up to ₹200 crore. Both are civil monetary penalties imposed by the Board after inquiry, and both commence 13 May 2027.
Under the CERT-In Directions of April 2022, failure to report a cybersecurity incident within 6 hours is dealt with under section 70B(7) of the Information Technology Act, 2000, which provides for imprisonment or a fine — criminal rather than civil liability. That obligation is in force today.
The distinction worth carrying to a board: DPDP exposure is large, civil, and begins in 2027. CERT-In exposure is smaller, criminal, and applies now. A compliance programme that treats breach reporting as a single 2027 problem has already missed a live obligation.
Not turnover-linked. Unlike GDPR's 4% of global annual turnover, DPDP penalties are absolute rupee ceilings. For a very large multinational the DPDP maximum may be lower; for a mid-sized Indian company it can be existential.
Not criminal. These are civil monetary penalties imposed by an adjudicatory body, not offences prosecuted in a criminal court.
Not per-record. The Schedule is drafted by breach of obligation, not per affected individual. But nothing prevents multiple heads applying to one incident — a breach caused by inadequate safeguards and not reported is capable of engaging items 1 and 2.
Not applicable to Data Processors directly. The Data Fiduciary answers to the Board, including for processing carried out on its behalf.
Up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach under s. 8(5). It is the highest of the seven heads in the Schedule.
No. Sections 28 to 34 and the penalty machinery commence on 13 May 2027, alongside the substantive obligations. The Data Protection Board exists and functions today, but cannot yet adjudicate breaches of provisions that have not commenced.
No. The Schedule sets absolute rupee ceilings rather than a turnover-linked formula, which is a significant structural difference from GDPR.
Yes. s. 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken on its behalf by a Data Processor, notwithstanding any agreement to the contrary. Contractual allocation may give you a claim against the vendor; it does not move your exposure to the Board.
An undertaking the Board may accept from a person in relation to a matter, which bars further proceedings on its contents. Breaching its terms is deemed a breach of the Act, and the Board may then proceed to penalty.
No. The regime is civil monetary penalties adjudicated by the Board. s. 37 does, however, allow blocking of a repeat offender's public-facing services on a reference from the Board.
Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.
Start Free — No Credit Card →Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 27–34, 37, 42 and the Schedule; commencement notification G.S.R. 843(E) dated 13 November 2025. Reference material about the law, not legal advice — see /disclaimer.