DPDP Act penalties are set out in a Schedule to the Digital Personal Data Protection Act, 2023, and that Schedule fixes seven bands. The highest, up to 250 crore rupees, attaches to exactly one duty: failure to take reasonable security safeguards to prevent a personal data breach, under section 8(5). Failure to notify a breach is a separate band of up to 200 crore rupees. Most other contraventions fall into a residual band of up to 50 crore rupees.
That distinction matters because the figures in circulation are wrong in three specific ways. 250 crore is quoted as the general exposure for any DPDP failure. Penalties are described as doubleable, producing a 500 crore headline with no basis in the Act. And the figures are read as tariffs when every entry reads "may extend to."
Where DPDP Act Penalties Come From
DPDP Act penalties come from the Schedule to the Act, and the power to impose them from section 33(1), which lets the Data Protection Board of India impose the penalty specified in the Schedule after an inquiry and an opportunity to be heard. Two things follow.
First, the bands are keyed to duties, not to harm: the Schedule names the provision breached and attaches a ceiling to it, so you reason from which duty you failed rather than from how bad the outcome was. Second, nothing is automatic, because an inquiry and a hearing come first.
The duties themselves mostly live in the Rules notified under the Act while the penalty hooks live in the Act's sections, and our DPDP compliance checklist maps those duties rule by rule.
The Full DPDP Fine Structure
The DPDP fine structure is seven bands, reproduced below as the Schedule sets them out. These are maxima.
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach, under section 8(5) | Up to 250 crore rupees |
| Failure to give the Board or affected Data Principals notice of a personal data breach, under section 8(6) | Up to 200 crore rupees |
| Breach of the additional obligations in relation to children, under section 9 | Up to 200 crore rupees |
| Breach of the additional obligations of a Significant Data Fiduciary, under section 10 | Up to 150 crore rupees |
| Breach of a Data Principal's own duties under section 15 | Up to 10,000 rupees |
| Breach of a voluntary undertaking accepted by the Board under section 32 | Up to the amount applicable to the breach that prompted the section 28 proceedings |
| Breach of any other provision of the Act or Rules | Up to 50 crore rupees |
The two largest bands both concern breaches: preventing one, and telling people about one. The Significant Data Fiduciary band applies only to an entity the Central Government has notified as significant, so it is irrelevant to most companies until that notification arrives.
The seventh row is the one teams underestimate. Notice, consent, retention, erasure, rights fulfilment, grievance redressal, cross-border conditions and the processor-contract requirement have no band of their own, so all of them land in "any other provision" at up to 50 crore rupees.
Why 250 Crore Is Not a General-Purpose Number
250 crore is not a general-purpose number. It is the ceiling on one duty, the security-safeguards duty under section 8(5), and quoting it as the cost of DPDP failure generally overstates the exposure on most duties by a factor of five.
Brief a board that every DPDP failure carries 250 crore of exposure and you get an undifferentiated programme spending as much effort on publishing a contact person as on log retention. The bands tell you where the legislature put the weight. The inverse error is as common: 50 crore rupees reads as low stakes next to 250, and it is not low stakes for a midmarket company.
No Provision Lets the Board Double a Penalty
Penalties cannot be doubled, and the 500 crore figure in circulation has no basis in the Act. Section 33 has exactly two sub-sections: sub-section (1), the power to impose the penalty specified in the Schedule, and sub-section (2), the seven matters the Board must have regard to in fixing the amount. There is no sub-section (3), no doubling provision and no tier above the Schedule.
The claim probably comes from a misreading of repetition. Whether a breach was repetitive is one of the matters the Board weighs under section 33(2), so repetition can push an amount toward the ceiling of its band but not past it. 250 crore rupees is the highest figure anywhere in the Schedule.
Want your exposure mapped to the right band?
Share your work email and we'll walk your current safeguards, breach runbook and notice against the Schedule, and mark which of the seven bands each gap would actually fall into.
The Schedule Sets Ceilings, Not Tariffs
The Schedule sets ceilings, not tariffs. Every entry reads "may extend to," and section 33(2) requires the Board to have regard to seven matters in fixing an amount:
- The nature, gravity and duration of the breach.
- The type of personal data affected.
- Whether the breach was repetitive.
- Any gain realised or loss avoided as a result of the breach.
- Mitigation taken, and whether it was timely.
- Proportionality and effectiveness of the penalty in securing compliance.
- The likely impact of the penalty on the person on whom it is imposed.
Read that as an instruction about conduct rather than a description of arithmetic. Four of the seven are things you control before the Board sees your file: duration, repetition, mitigation, and to a degree the type of data you were holding at all.
What the Seven Matters Mean for How You Behave
The seven matters in section 33(2) mean incident response investment bears directly on penalty exposure, which is unusual and worth exploiting. Most compliance spending is justified as risk reduction in the abstract. Here the statute names timely mitigation as a factor the regulator must weigh.
Before an Incident
Before an incident, the work that pays is the work that shortens duration and proves it. Duration is the first of the seven matters, and duration is a detection problem: finding unauthorised access in hours rather than months is not a difference in how bad the underlying weakness was.
Three things do most of that work. Logging and monitoring complete enough to establish when access began and stopped, which rule 6 requires anyway. Access controls tight enough that the affected data set is bounded rather than "everything the compromised account could reach." And data minimisation, because the type of personal data affected is the second matter, and the cheapest way to improve it is not to hold the data.
A factor you cannot demonstrate cannot help you, so keep the artefacts that show a timeline.
During an Incident
During an incident the clock you are running is not only the notification clock, it is the mitigation factor. Section 33(2) asks whether mitigation was taken and whether it was timely, so containment in the first day is material to the amount the Board may later fix.
The Rules reinforce this. The intimation you owe each affected individual must describe mitigation already implemented or under way, and the detailed submission to the Board must cover mitigation implemented or proposed plus remedial measures to prevent recurrence. You report your mitigation into exactly the record the penalty factors are assessed against. Our guide to DPDP breach notification covers both clocks, including the one that is not seventy-two hours.
Run that backwards into your runbook: record the time of awareness, each containment action with its timestamp, and the recurrence-prevention work rather than only containment.
Why Rule 6 and Rule 7 Deserve Disproportionate Attention
Rule 6 and rule 7 deserve disproportionate attention because they sit under the two largest bands. Rule 6 sets the minimum security safeguards, and failure on safeguards is the 250 crore band. Rule 7 sets breach intimation, and failure to notify is the 200 crore band. Every other operational duty falls into the 50 crore residual band.
Rule 6 is also the most prescriptive rule in the set, which makes it unusually testable. It names seven minimum measures: encryption, obfuscation, masking or virtual tokens for the data itself; access control over the computer resources used; logs, monitoring and review sufficient to detect unauthorised access; measures for continued processing such as backups; retention of those logs and personal data for one year unless another law requires otherwise; a contractual provision requiring any Data Processor to take reasonable safeguards; and appropriate technical and organisational measures for effective observance. A rule that lists its floor can be tested item by item, so treat the DPDP security safeguards as a checklist rather than a principle.
Rule 7 carries the second band and the most misreported requirement. Each affected Data Principal must be told without delay. The Board gets a first intimation without delay and a detailed submission within seventy-two hours of your becoming aware, or a longer period it allows on written request. The individuals' clock is the tighter one, and teams that have internalised a single seventy-two-hour deadline will miss it.
A Data Fiduciary with limited budget should close rule 6 and rule 7 before perfecting anything else, because these two are where a failure is most expensive and where the quality of your response feeds into the amount.
How a Data Protection Board Penalty Gets Imposed
A Data Protection Board penalty is the end of a process, not an automatic consequence. Section 33(1) conditions the power on an inquiry and an opportunity to be heard, so there is a proceeding, you participate in it, and the amount is fixed against the seven matters in section 33(2) rather than read off a table.
So be able to produce a coherent account of yourself. The factors the Board must weigh are facts about your conduct, and facts about conduct are established with records. An organisation that can show when it detected, what it contained and what it changed is arguing from evidence; one reconstructing that later is arguing from assertion.
When Your DPDP Non-Compliance Exposure Begins
DPDP non-compliance exposure on the operational duties is dated, because the duties these penalties attach to commence in the eighteen-month tranche. Rule 1 splits commencement into three. Rules 1, 2 and 17 to 21, which constitute the Data Protection Board and govern its appointments and procedure, came into force on Gazette publication, 14 November 2025. Rule 4, Consent Manager registration, commences one year after publication, in mid-November 2026.
Everything carrying real penalty exposure sits in the third tranche: rules 3 and 5 to 16 plus 22 and 23, covering notice, consent, security safeguards, breach intimation, retention and erasure, contact person, children's data, Significant Data Fiduciary duties, data-principal rights, cross-border transfer and research exemptions. Those commence eighteen months after publication, in mid-May 2027.
So the Board exists before the duties it will enforce, and the eighteen-month tranche is a single cliff rather than a ramp: nothing in rules 3 or 5 to 16 phases in gradually. You know the date, which helps. The trap is that itemising what personal data you hold, and evidencing access to it, takes longer than the time left if you start late.
There Is No Enforcement Record to Read
There is no enforcement record to read, and any article telling you how the Board is likely to behave is guessing. The Board is newly constituted, the provisions constituting it came into force on 14 November 2025, and the duties it will enforce do not commence until mid-May 2027. There are no decisions, no published quantum, no pattern of leniency or severity to extrapolate from.
Say that plainly to your board rather than filling the gap. The ceilings are known, the factors the Board must weigh are known, and the amounts it will fix are not knowable yet. Read the statute as the instruction it is instead: section 33(2) names the conduct the Board must take into account, and that list does not depend on how aggressive it turns out to be. The notified text and subsequent instruments are published by the Ministry of Electronics and Information Technology, which is the source worth checking rather than secondary summaries.
DPDP Penalty Questions Teams Ask
These are the DPDP penalty questions teams ask once they have seen the Schedule, including the three where the widely circulated answer is simply wrong.
250 crore rupees, and it attaches to one duty only: failure to take reasonable security safeguards to prevent a personal data breach, under section 8(5). Failure to give the Board or affected Data Principals notice of a breach, under section 8(6), carries up to 200 crore rupees, as does breach of the additional obligations in relation to children under section 9. Breach of any other provision of the Act or Rules carries up to 50 crore rupees.
No. Section 33 has exactly two sub-sections: sub-section (1) lets the Board impose the penalty specified in the Schedule, and sub-section (2) lists the seven matters it must have regard to in fixing the amount. There is no sub-section (3) and no doubling provision, so claims of 500 crore exposure have no basis in the Act. Repetition is one of the seven matters, which can move an amount toward the top of its band but not above it.
No. Every entry reads "may extend to," so the figures are ceilings rather than tariffs. Section 33(2) requires the Board to have regard to seven matters in fixing an amount, including the nature, gravity and duration of the breach, the type of personal data affected, whether it was repetitive, mitigation taken and its timeliness, and proportionality. Prompt mitigation is written into the statute as a factor, so your incident response bears on the amount.
No. Section 33(1) lets the Board impose a penalty after an inquiry and an opportunity to be heard. This is a proceeding you participate in, not an automatic fine issued on receipt of a breach report.
The duties these penalties attach to commence in the eighteen-month tranche under rule 1, eighteen months after Gazette publication on 14 November 2025, which falls in mid-May 2027. That tranche covers rules 3 and 5 to 16 plus 22 and 23, including the security-safeguards and breach-intimation duties under the two largest bands. The provisions constituting the Board are already in force.
Build the evidence the penalty factors are assessed against
Book a demo and we'll show how Konfirmity tracks the rule 6 safeguards, holds the log retention floor, and runs a breach register that records awareness, containment and notification times in the form section 33(2) is assessed on.
Book a demo
Build Against the Two Largest Bands First
The Schedule gives you a priority order that is hard to argue with. Two bands, safeguards and breach notification, sit far above the rest, and both describe the same event from different sides. Closing rule 6 completely and rehearsing rule 7 until the two clocks are muscle memory addresses most of your quantified exposure.
Then build for the factors rather than the ceiling. Duration, repetition and timely mitigation are the parts of section 33(2) you influence, and all three come down to detection, containment and record-keeping.
Start by working out which duties bind you at all, since the Significant Data Fiduciary band applies only to entities the Central Government has notified. Our Significant Data Fiduciary duties guide covers that category, and the DPDP compliance checklist walks every duty and its commencement date. Book a demo and we will map your safeguards and breach process against the bands they actually sit under.

