The short answer: The Schedule to the DPDP Act sets seven penalty heads. The highest — up to two hundred and fifty crore rupees — attaches to failing to take reasonable security safeguards under s. 8(5). Penalties are civil, imposed by the Data Protection Board after inquiry, and are not capped as a percentage of turnover. The penalty provisions commence on 13 May 2027.

Penalties and How Enforcement Works

⚖️ Legal structure: Chapters VI–VIII, ss. 27–34, and the Schedule📅 In force from: 13 May 2027🔍 Source: DPDP Act 2023 · Rules 2025
On this page
  1. An important clarification first
  2. The Schedule, in full
  3. How does the Board decide the amount?
  4. How enforcement actually proceeds
  5. The two penalty regimes a single breach can engage
  6. What the DPDP penalty regime is not
  7. Frequently asked questions

An important clarification first

You will see it stated that the DPDP Act is in force and that non-compliance attracts ₹250 crore penalties today. That is not correct, and it matters.

The penalty and adjudication provisions sit in sections 28 to 34, which the commencement notification brings into force on 13 May 2027, together with the substantive obligations they enforce. The Data Protection Board itself has existed since 13 November 2025 and is operating — but it cannot yet adjudicate a breach of the notice, consent, security or rights provisions, because those provisions have not commenced.

The accurate position is that there is a fixed date, and a defined amount of time before it. That is more useful than an inaccurate present-tense threat, and it is also what a competent adviser will tell your board.

The Schedule, in full

The Schedule is referenced by s. 33(1). Each entry pairs a breach with a maximum.

#BreachPenalty may extend to
1Failure to observe the obligation to take reasonable security safeguards to prevent a personal data breach, under s. 8(5)₹250 crore
2Failure to give the Board or affected Data Principals notice of a personal data breach, under s. 8(6)₹200 crore
3Failure to observe the additional obligations in relation to children, under s. 9₹200 crore
4Failure to observe the additional obligations of a Significant Data Fiduciary, under s. 10₹150 crore
5Breach of the duties of a Data Principal, under s. 15₹10,000
6Breach of any term of a voluntary undertaking accepted by the Board under s. 32Up to the extent applicable to the breach for which proceedings were instituted
7Breach of any other provision of the Act or the rules₹50 crore
Three observations that change how you should read this table.

Under s. 42, the Central Government may amend the Schedule, but no amendment may increase any penalty to more than twice the amount originally enacted.

How does the Board decide the amount?

The maximums in the Schedule are ceilings, not tariffs. s. 33(1) allows the Board to impose a penalty only where it determines, on conclusion of an inquiry, that the breach is significant — and only after giving the person an opportunity of being heard.

s. 33(2) then lists the factors the Board must have regard to:

Read the fifth factor as an instruction to keep records. Mitigation, and the timeliness of it, is an express statutory consideration. An organisation that can produce a dated incident log, a documented containment sequence and evidence of notification is arguing from a materially better position than one reconstructing events afterwards. This is the clearest place in the Act where an evidence trail has direct financial value.

How enforcement actually proceeds

  1. A complaint or a reference reaches the Board. A Data Principal may complain after exhausting the Data Fiduciary's grievance mechanism under s. 13.
  2. The Board decides whether there are sufficient grounds to proceed. It may close a matter, or direct an inquiry.
  3. Inquiry. The Board conducts proceedings, with the powers conferred on it, and adopts techno-legal measures in discharging its functions.
  4. Alternative dispute resolution or voluntary undertaking. The Board may refer a matter for mediation, or accept a voluntary undertaking under s. 32. An accepted undertaking bars further proceedings on its contents — unless its terms are breached, in which case the breach is deemed a breach of the Act.
  5. Determination and penalty. If the breach is significant, the Board may impose a penalty from the Schedule after a hearing.
  6. Appeal. Appeals from the Board's orders lie to the Appellate Tribunal.
  7. Blocking, in repeat cases. Under s. 37, where the Board has imposed penalties on a Data Fiduciary in two or more instances and advises it in the interests of the general public, the Central Government may — after giving that Fiduciary a hearing — direct the blocking of public access to information enabling that Fiduciary to offer goods or services to Data Principals in India.
That last power is worth stating plainly, because it is often left out of penalty discussions: for a repeat offender, the ultimate sanction is not financial but the loss of the ability to operate in the Indian market.

Penalties realised are credited to the Consolidated Fund of India.

The two penalty regimes a single breach can engage

A data breach in India is capable of engaging two separate enforcement regimes, and they work differently.

Under DPDP, failure to take reasonable security safeguards (s. 8(5)) attracts up to ₹250 crore, and failure to give breach intimation (s. 8(6)) up to ₹200 crore. Both are civil monetary penalties imposed by the Board after inquiry, and both commence 13 May 2027.

Under the CERT-In Directions of April 2022, failure to report a cybersecurity incident within 6 hours is dealt with under section 70B(7) of the Information Technology Act, 2000, which provides for imprisonment or a fine — criminal rather than civil liability. That obligation is in force today.

[VERIFY — LEGAL COUNSEL] Confirm the current s. 70B(7) penalty amount before publishing a figure anywhere. Claims of "₹1 crore" for CERT-In non-compliance, which circulate widely in vendor marketing, appear to be incorrect: the provision is materially lower and carries imprisonment.

The distinction worth carrying to a board: DPDP exposure is large, civil, and begins in 2027. CERT-In exposure is smaller, criminal, and applies now. A compliance programme that treats breach reporting as a single 2027 problem has already missed a live obligation.

What the DPDP penalty regime is not

Not turnover-linked. Unlike GDPR's 4% of global annual turnover, DPDP penalties are absolute rupee ceilings. For a very large multinational the DPDP maximum may be lower; for a mid-sized Indian company it can be existential.

Not criminal. These are civil monetary penalties imposed by an adjudicatory body, not offences prosecuted in a criminal court.

Not per-record. The Schedule is drafted by breach of obligation, not per affected individual. But nothing prevents multiple heads applying to one incident — a breach caused by inadequate safeguards and not reported is capable of engaging items 1 and 2.

Not applicable to Data Processors directly. The Data Fiduciary answers to the Board, including for processing carried out on its behalf.

Frequently asked questions

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach under s. 8(5). It is the highest of the seven heads in the Schedule.

Are DPDP penalties in force now?

No. Sections 28 to 34 and the penalty machinery commence on 13 May 2027, alongside the substantive obligations. The Data Protection Board exists and functions today, but cannot yet adjudicate breaches of provisions that have not commenced.

Is the DPDP penalty a percentage of turnover?

No. The Schedule sets absolute rupee ceilings rather than a turnover-linked formula, which is a significant structural difference from GDPR.

Can we be penalised for our vendor's failure?

Yes. s. 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken on its behalf by a Data Processor, notwithstanding any agreement to the contrary. Contractual allocation may give you a claim against the vendor; it does not move your exposure to the Board.

What is a voluntary undertaking under section 32?

An undertaking the Board may accept from a person in relation to a matter, which bars further proceedings on its contents. Breaching its terms is deemed a breach of the Act, and the Board may then proceed to penalty.

Does the DPDP Act create criminal liability?

No. The regime is civil monetary penalties adjudicated by the Board. s. 37 does, however, allow blocking of a repeat offender's public-facing services on a reference from the Board.

See how Consiva handles this automatically

Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.

Start Free — No Credit Card →

Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 27–34, 37, 42 and the Schedule; commencement notification G.S.R. 843(E) dated 13 November 2025. Reference material about the law, not legal advice — see /disclaimer.