The penalty structure at a glance
The DPDP Act is not a compliance exercise with paper-only consequences. Chapter VI of the Act establishes a financial penalty regime enforced by the Data Protection Board of India — a quasi-judicial body with the power to investigate violations and impose fines. Penalties are capped per violation, not per individual data subject, and they apply from the date the Act comes into force.
DPDP Act penalties are assessed per violation instance — not per affected individual. A single breach of your security obligation is one violation. But if you operate multiple business units that each violated the same obligation, each could be treated as a separate instance. Total exposure can compound quickly.
The Act's full enforcement period began after the DPDP Rules 2025 were notified in January 2025. The Data Protection Board is being constituted through 2026, with full complaint-handling and penalty-imposition capacity expected from mid-2026 onwards. The compliance grace period for most organisations ends in May 2027. Enforcement action is not theoretical — it is a matter of when, not if.
The complete Section 33 penalty schedule
Section 33 of the DPDP Act sets out a schedule of financial penalties for five distinct categories of violation. The categories are not interchangeable — each maps to a specific obligation and carries its own cap:
A single data breach can attract penalties under both Section 33(1) and Section 33(2) — one for having inadequate security that allowed the breach, and one for failing to notify afterwards. Combined maximum exposure from a single breach incident: ₹450 crore. This is why breach response planning — including a clear notification protocol — is as important as breach prevention.
Section 33(1): Security safeguard failures — ₹250 crore
The highest penalty category applies to violations of Section 8(5) of the Act, which requires every Data Fiduciary to implement "reasonable security safeguards" to prevent personal data breaches. The Act does not prescribe a fixed technical standard — "reasonable" is assessed by the Board in light of the nature of the data processed, the scale of operations, and industry norms.
What constitutes reasonable security safeguards? The DPDP Rules 2025 and the Board's eventual guidance will elaborate this, but current benchmarks include:
- Encryption of personal data in transit and at rest
- Access controls limiting who can read or modify personal data
- Data minimisation — not retaining personal data longer than necessary
- Vendor and processor contracts that bind Data Processors to equivalent security standards
- Breach detection and incident response capabilities
- Regular vulnerability assessments and patching
ISO 27001 certification is not a legal shield — the Act does not equate certification with compliance — but it is strong evidence that your security programme is systematic and proportionate. Organisations with no documented security programme, or with known vulnerabilities that were not addressed, face the full force of this provision.
Section 33(2): Breach notification failures — ₹200 crore
When a personal data breach occurs, Section 8(6) requires Data Fiduciaries to notify the Data Protection Board and affected Data Principals. Both arms of notification are mandatory — informing only the Board, or only individuals, does not satisfy the obligation.
What triggers the notification obligation?
Not every security incident triggers mandatory notification. The obligation applies when a breach is "likely to result in harm" to Data Principals — typically where the data affected is sensitive (financial, health, identity), where the breach was large-scale, or where the compromised data could enable identity theft or fraud. The DPDP Rules 2025 provide further guidance on the scope of "likely harm."
Timing of notification
The Act requires notification to be made "in the prescribed manner" — the DPDP Rules 2025 specify the exact timelines and content requirements. As a benchmark, regulators globally expect breach notification within 72 hours of becoming aware of the breach. Delayed notification — even by days — triggers the ₹200 crore exposure. Organisations that notify promptly, even before completing root-cause analysis, are treated more leniently than those who delay while investigating.
Section 33(3): Children's data violations — ₹200 crore
Section 9 of the DPDP Act imposes heightened obligations on Data Fiduciaries that process personal data of children (under 18) or persons with disabilities. Specific requirements include:
- Obtaining verifiable parental consent before processing a child's personal data
- Not processing children's data in a manner that is likely to cause harm to the child
- Not engaging in behavioural monitoring or targeted advertising directed at children
- Not tracking children's online activities, even with parental consent, if the tracking purpose is commercial profiling
Any platform that has users under 18 — gaming apps, edtech, social media, children's content, health apps used by minors — is exposed to this provision. The Board is expected to take an especially strict view of violations here, given the explicit legislative intent to protect children's digital rights.
Section 33(4): Significant Data Fiduciary violations — ₹150 crore
Organisations designated as Significant Data Fiduciaries (SDFs) under Section 10 face a separate penalty for failing to comply with their additional obligations. These obligations include appointing an India-based Data Protection Officer, conducting periodic Data Protection Impact Assessments, undergoing independent data audits, and complying with any additional standards specified by the government. The ₹150 crore cap applies per instance of SDF-specific non-compliance — on top of any other penalties that may apply for breaches of general Data Fiduciary obligations.
Section 33(5): All other violations — ₹50 crore
Section 33(5) is a catch-all for contraventions of any other provision of the Act or the DPDP Rules 2025 that are not covered by Sections 33(1)–33(4). This includes:
- Failing to provide valid consent notice in the prescribed format
- Failing to honour Data Principal rights — access, correction, erasure, grievance
- Failing to appoint a Grievance Officer accessible to Data Principals
- Retaining personal data beyond the permitted retention period without a valid purpose
- Unlawfully transferring personal data to a restricted country
- Failure to comply with a Board order
The ₹50 crore cap per violation may seem lower, but it is still a substantial figure for most Indian businesses — and the Board can treat each non-compliant consent notice, or each instance of ignoring a Data Principal's erasure request, as a separate violation.
How the Data Protection Board determines the penalty amount
The Board does not automatically impose the maximum penalty. Section 33 gives the Board discretion to impose a financial penalty up to the cap. In exercising this discretion, the Board will consider:
- Nature, gravity, and duration of the violation — a one-time configuration error is treated differently from a systematic disregard for consent requirements
- Type of personal data affected — violations involving sensitive data (health, financial, children's) attract higher penalties
- Deliberate vs. negligent — intentional concealment of a breach is far worse than an honest failure to detect it
- Harm caused to Data Principals — whether individuals suffered financial loss, identity theft, or discrimination as a result
- Remedial action taken — what steps the Data Fiduciary took, how quickly, to contain the violation and restore compliance
- History of violations — repeat offenders face enhanced penalties; first-time violations with no prior record attract more lenience
- Cooperation with the Board — voluntary disclosure, transparency, and responsiveness during investigation are strong mitigating factors
A company that suffers a breach, detects it within hours, notifies the Board and affected individuals promptly, cooperates fully with the investigation, and has an existing ISO 27001-certified security programme will face a fraction of the maximum penalty compared to one that concealed the breach, was unresponsive to the Board, and had no documented security controls.
The Board's adjudication process
The Data Protection Board of India is constituted under Chapter V of the DPDP Act. It is a quasi-judicial body — meaning it operates like a court, with procedures for filing complaints, hearings, evidence, and binding orders. The process for a penalty proceeding generally follows these stages:
Step 1: Complaint or suo motu notice
The Board can receive complaints from Data Principals who believe their rights have been violated. It can also initiate proceedings on its own motion (suo motu) when it becomes aware of significant violations — such as a widely reported data breach. A Data Principal must first exhaust the Data Fiduciary's internal grievance process before approaching the Board.
Step 2: Notice to the Data Fiduciary
If the Board determines a complaint warrants investigation, it issues a formal notice to the Data Fiduciary, setting out the alleged violation and allowing the organisation to respond. This is the critical window for organisations to present their case — including evidence of compliance measures, remedial action taken, and mitigating factors.
Step 3: Hearing and decision
The Board conducts a hearing — which can be in-person or virtual — and may call for additional information or documents. After hearing both sides, the Board issues an order that may include a financial penalty, a direction to take remedial action, or both. Board orders are subject to appeal to the High Court.
Step 4: Enforcement
Financial penalties not paid within the prescribed period are treated as government dues and can be recovered accordingly. Repeated non-compliance with Board orders can result in enhanced penalties and, in extreme cases, operational restrictions.
7 steps to reduce your DPDP penalty exposure
Penalty reduction is not about legal argumentation after the fact — it is about building a compliance posture that gives the Board little to find in the first place, and demonstrating responsiveness when issues arise.
-
1
Document your security programme
An undocumented security programme does not exist in the eyes of the Board. Map your technical controls, policies, and procedures. ISO 27001 certification provides structured evidence of a systematic approach and is the strongest documentary defence against Section 33(1) claims.
-
2
Build a breach notification protocol now
Define who is responsible for identifying a breach, who approves notification, and what the Board notification must contain. Rehearse this protocol — table-top breach simulations reveal gaps before they become penalty exposure. The goal is to be able to notify within 72 hours of becoming aware.
-
3
Audit your consent and notice mechanisms
Every collection point — web forms, app screens, verbal consent over phone — must present a consent notice that meets the DPDP Act's format requirements. Invalid consent notices are a Section 33(5) violation for each non-compliant point. Conduct a full audit of all touch-points before enforcement begins.
-
4
Implement a working grievance mechanism
Data Principals must be able to reach a named Grievance Officer and receive a response within the prescribed timeline. An unresponsive or non-existent grievance mechanism is a Board complaint waiting to happen — and is a Section 33(5) violation in its own right. Assign a real person, monitor the inbox, and respond.
-
5
Treat children's data with a separate protocol
If your product has any pathway for under-18 users, implement age verification and parental consent collection now. The ₹200 crore cap under Section 33(3) and the Board's likely severity here make children's data the single highest-risk area per violation. Disable behavioural advertising on all child-accessible flows.
-
6
Conduct a Data Processor audit
You remain liable for your Data Processors' handling of personal data. Review all vendor and cloud contracts to ensure they include DPDP-compliant data processing clauses, security obligations, and breach notification timelines. A breach at your cloud vendor that originates from inadequate contractual controls is your Section 33(1) problem.
-
7
Cooperate with the Board from day one
If the Board sends a notice, respond promptly, transparently, and completely. Attempting to delay, obscure, or minimise will be noted and will increase the penalty. Present evidence of your compliance programme, remedial action, and cooperation — these are the strongest mitigating factors in the Board's discretion.
DPDP penalties vs. GDPR — key differences
Finance teams and boards used to GDPR will have a framing problem when reading DPDP Act penalties. The two regimes are structurally different in important ways:
For large multinationals, GDPR's turnover-linked penalties can dwarf DPDP caps. But for India-focused businesses — particularly mid-size companies processing data of millions of Indian users — the DPDP Act's ₹250 crore ceiling per violation is a serious financial exposure, not a compliance checkbox.
For a complete picture of DPDP Act obligations — all six Data Fiduciary duties, Data Principal rights, and the compliance timeline — see our DPDP Act compliance guide and our free DPDP compliance checklist. If you want to assess your current penalty exposure and close the gaps before the Board begins enforcement, book a free assessment — we'll give you a written report in 48 hours.