DPDP Penalties: ₹250 Crore Risk and Enforcement Tiers in India
A breakdown of every penalty provision in the DPDP Act 2023. Understand the financial exposure, the enforcement mechanism, and what triggers each penalty tier.
On This Page
- The Financial Architecture of Non-Compliance
- Penalty Tiers Under the DPDP Act
- What Triggers Each Penalty Tier
- ₹250 Crore: Security Safeguard Failures
- ₹200 Crore: Breach Notification Failures
- ₹200 Crore: Children’s Data Violations
- ₹150 Crore: Significant Data Fiduciary Failures
- ₹50 Crore: General Non-Compliance
- The Data Protection Board of India
- DPDP vs GDPR: Penalty Comparison
- Enforcement Timeline
- What This Means for Your Organisation
The Financial Architecture of Non-Compliance
The Digital Personal Data Protection Act, 2023 is not advisory legislation. It is an enforcement statute with monetary penalties that may extend to ₹250 crore. The Act establishes a tiered penalty framework administered by the Data Protection Board of India (DPBI), with adjudication powers that operate independent of civil courts.
If your organisation processes personal data of Indian residents, these numbers define your maximum financial exposure. Understanding the structure is not optional.
For a full overview of the Act itself, see our guide to the DPDP Act.
Penalty Tiers Under the DPDP Act
The Act prescribes penalties across five violation categories relevant to Data Fiduciaries. Each tier corresponds to a specific class of obligation. The amounts represent upper bounds; the DPBI retains discretion to impose lower amounts based on the nature and severity of the breach.
| Violation | Maximum Penalty | Obligation Breached |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a data breach | ₹250 crore | Section 8(5) |
| Failure to notify the DPBI and affected Data Principals of a breach | ₹200 crore | Section 8(6) |
| Non-compliance with obligations related to children’s data | ₹200 crore | Section 9 |
| Non-compliance with additional obligations of a Significant Data Fiduciary | ₹150 crore | Section 10 |
| Non-compliance with any other provision of the Act or its rules | ₹50 crore | Residual category |
Each amount above is a ceiling for the obligation named beside it. A single data breach event that also involves delayed notification and children’s data could trigger multiple tiers simultaneously, each penalised under its own Schedule entry.
What Triggers Each Penalty Tier
₹250 Crore: Security Safeguard Failures
This is the highest penalty and it targets a specific obligation: Data Fiduciaries must implement “reasonable security safeguards” to protect personal data against breaches. The Act does not prescribe specific technical controls. Instead, reasonableness will be assessed by the DPBI on a case-by-case basis.
Factors likely to influence this assessment include whether the organisation maintained encryption at rest and in transit, implemented access controls, conducted regular security audits, and followed industry-standard practices for its sector.
The absence of a defined technical standard is intentional. It places the burden on the Data Fiduciary to demonstrate that their safeguards were proportionate to the data they held and the risks they faced.
₹200 Crore: Breach Notification Failures
When a personal data breach occurs, the Data Fiduciary must notify both the DPBI and each affected Data Principal. The DPDP Rules, notified on 13 November 2025, set the window at 72 hours for the detailed report to the Board.
The penalty targets two distinct failures: not reporting to the Board, and not informing the individuals whose data was compromised. Delayed notification is treated with the same severity as non-notification.
For a detailed walkthrough of notification obligations, see our breach notification guide.
₹200 Crore: Children’s Data Violations
Section 9 of the Act imposes additional obligations when processing data of individuals under 18 years of age. These include:
- Obtaining verifiable parental consent before processing
- Prohibiting behavioural tracking or targeted advertising directed at children
- Prohibiting processing that causes demonstrable harm to children
Organisations operating ed-tech platforms, gaming services, or any consumer-facing product with a user base that includes minors must treat this tier as a primary risk vector. It carries the same ceiling as breach notification failure.
₹150 Crore: Significant Data Fiduciary Failures
Entities notified as Significant Data Fiduciaries under Section 10 carry additional obligations: an India-based Data Protection Officer, periodic Data Protection Impact Assessments, and an independent data auditor. Failing any of these additional obligations is its own penalty tier, separate from the baseline duties every Data Fiduciary carries.
₹50 Crore: General Non-Compliance
This residual category covers all other violations. It includes failures related to:
- Purpose limitation (processing data beyond the stated purpose)
- Data retention (holding data longer than necessary)
- Data Principal rights (failing to respond to access, correction, or erasure requests)
- Consent management (collecting data without valid, informed consent)
- Appointing a Data Protection Officer when required
While ₹50 crore is the lowest tier, it applies to the broadest range of obligations. For most organisations, these operational compliance gaps represent the most probable enforcement exposure.
Review our DPDP compliance checklist to identify which obligations apply to your operations.
The Data Protection Board of India
The DPBI is the adjudicatory body established under Section 18 of the Act. It is not a regulator in the traditional sense. It does not issue licenses or conduct routine inspections. Its function is to receive complaints, conduct inquiries, and impose penalties.
Key characteristics of the Board:
- Digital-first proceedings. The Act mandates that proceedings before the Board will be conducted digitally. This lowers the barrier for complaints and accelerates adjudication timelines.
- Independent adjudication. Board decisions carry the weight of a civil court order. Appeals go to the Telecom Disputes Settlement Appellate Tribunal (TDSAT), not to lower courts.
- Complaint-driven enforcement. Any Data Principal may file a complaint. The Board may also initiate inquiries based on credible information, including media reports or whistleblower disclosures.
The Board has not yet commenced operations as of March 2026. However, the enforcement provisions apply from the date of notification, which means that compliance obligations are active even before the first penalty is imposed.
DPDP vs GDPR: Penalty Comparison
For organisations with cross-border operations, the comparison to the EU’s General Data Protection Regulation provides useful context.
| Parameter | DPDP Act 2023 | GDPR |
|---|---|---|
| Maximum penalty | ₹250 crore (~€27 million) | €20 million or 4% of global annual turnover, whichever is higher |
| Penalty calculation | Fixed maximum per violation category | Percentage-based, scaled to revenue |
| Adjudication body | Data Protection Board of India | National Data Protection Authorities (per EU member state) |
| Criminal liability | None (civil penalties only) | Varies by member state |
| Private right of action | Not provided | Yes, individuals can sue for damages |
The DPDP Act’s fixed-cap model means that for large enterprises, the maximum penalty may represent a smaller proportion of revenue than a GDPR fine. However, for mid-market and growth-stage companies, ₹250 crore is an existential figure. The Act does not scale penalties to organisational size, which means a 50-person company faces the same theoretical maximum as a conglomerate.
Enforcement Timeline
The Act received Presidential assent on 11 August 2023. The enforcement timeline depends on the notification of rules by the Central Government. As of March 2026:
- The Act has been passed and published
- The DPDP Rules 2025 were notified on 13 November 2025 and are final
- Rule 4 on Consent Managers applies from 13 November 2026; Rules 3 and 5 to 16 become enforceable on 13 May 2027
- The Data Protection Board of India had no appointed Chairperson or Members as of August 2026; the enforcement machinery is being assembled now
This pre-enforcement window is narrowing. Organisations that treat it as a grace period rather than a preparation window will face compressed timelines once enforcement begins.
What This Means for Your Organisation
The penalty framework under the DPDP Act is designed to make non-compliance more expensive than compliance. The tiered structure signals legislative intent: security safeguards and breach notification are the highest-priority obligations, followed by children’s data protections, with general compliance as the baseline expectation.
The strategic response is not to wait for the Board to begin operations. It is to establish compliance infrastructure now, while the cost of remediation is lower and the operational disruption is minimal.
Run a free DPDP Gap Assessment to identify where your organisation stands against the DPDP Act’s requirements. The assessment maps your current data practices against each obligation category and highlights your areas of highest penalty exposure.
Frequently asked questions
What is the maximum penalty under the DPDP Act 2023?
Up to ₹250 crore for failing to implement reasonable security safeguards that results in a personal data breach, under Section 8(5) read with the Schedule to the Act. This is the highest of five penalty tiers. The Schedule sets a ceiling for each obligation breached, and Section 33(2)(c) directs the Board to weigh the repetitive nature of a breach when fixing the amount within that ceiling.
What are the DPDP penalty tiers?
Five tiers apply to Data Fiduciaries: ₹250 crore for security safeguard failures, ₹200 crore for failing to notify a breach to the Board and affected individuals, ₹200 crore for children's data violations under Section 9, ₹150 crore for a Significant Data Fiduciary failing its additional obligations under Section 10, and ₹50 crore for any other violation of the Act or its rules.
Who imposes penalties under the DPDP Act?
The Data Protection Board of India. The Schedule amounts are upper bounds; the Board has discretion to impose lower amounts based on the nature and severity of the violation, mitigation efforts, and the circumstances of each case.
Can one incident trigger multiple DPDP penalties?
Yes. Each obligation breached is penalised under its own Schedule entry, so a single breach event that also involves delayed notification and children's data can trigger several tiers at once. For one incident spanning the major tiers, the ceilings sum to ₹700 crore before the separate Significant Data Fiduciary tier is counted.
When does DPDP penalty enforcement begin?
The DPDP Rules were notified on 13 November 2025, and substantive penalty enforcement is expected from May 2027. Rule 4 applies from 13 November 2026, when registration becomes mandatory for anyone operating as a Consent Manager. Compliance work needs to precede these dates because implementation has lead time.
What is the deadline to report a data breach under the DPDP Act?
72 hours for the detailed report to the Data Protection Board under the DPDP Rules, alongside notification to every affected Data Principal. Failing either notification carries a penalty of up to ₹200 crore, separate from the penalty for the safeguard failure that caused the breach.
Know where you stand on DPDP compliance
Run the free DPDP Gap Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
DPDP Penalties in India: Risk Assessment and Exposure Calculator
A practical guide to DPDP Act 2023 penalty tiers, how penalties are calculated, and how to use risk assessment to quantify your organisation's exposure.
9 min read
Compliance AreasDPDP Breach Notification Timeline: 72-Hour Rule (India 2026)
Miss the 72-hour window and the exposure is ₹200 crore under Section 8(6). The Board deadline, the 6-hour CERT-In rule, and the reporting steps, mapped.
9 min read
Compliance AreasSignificant Data Fiduciary (SDF): DPO and Audit Rules in India
SDF designation under Section 10 of the DPDP Act triggers a DPO in India, data protection impact assessments, and independent audits. Who qualifies and how to prepare.
6 min read
Compliance AreasChildren's Data Protection: Parental Consent Under DPDP in India
Up to ₹200 crore. Section 9 of the DPDP Act bans tracking, behavioural profiling, and targeted ads aimed at under-18s, even with parental consent, and requires verifiable parental consent before any processing begins.
6 min read