₹250 crore is the number every DPDP headline quotes. It is neither the ceiling, since the government can double it by notification, nor the penalty most organisations will actually face first, which is the ₹50 crore catch-all covering everyday operational failures.
Here is how the penalty framework really works: every amount, every trigger, the seven factors that set what you pay, and the consequence that is worse than any fine.
The Penalty Table
The Schedule to the Act defines seven categories of breach, each with a maximum penalty:
| Violation | Act section | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards | Section 8(5) | ₹250 crore |
| Failure to notify the Board and Data Principals of a breach | Section 8(6) | ₹200 crore |
| Non-compliance with children's data obligations | Section 9 | ₹200 crore |
| Non-compliance with Significant Data Fiduciary obligations | Section 10 | ₹150 crore |
| Breach of any other provision of the Act or Rules | Various | ₹50 crore |
| Breach of an accepted voluntary undertaking | Section 32 | The penalty for the original breach |
| Data Principal filing a false complaint or suppressing information | Section 15 | ₹10,000 |
These are maximums, not fixed fines. The Data Protection Board sets the actual amount case by case, and only after giving you a hearing.
Key Takeaway
A single incident can trigger multiple categories at once. A breach caused by inadequate security (₹250 crore) that you then fail to notify properly (₹200 crore) carries a theoretical exposure of ₹450 crore from one event. Add a children's data dimension and it reaches ₹650 crore.
₹250 Crore Is Not the Real Ceiling
Section 42 gives the Central Government the power to amend the Schedule by notification, with one limit: the new amount cannot exceed twice the original figure. The true potential maximum for a security-safeguards failure is therefore ₹500 crore.
No such notification has been issued as of June 2026. But the provision exists for exactly one scenario: the government deciding, most likely after a high-profile breach, that the current caps are not deterring anyone.
The 7 Factors That Decide What You Actually Pay
Section 33(2) requires the Board to weigh seven specific factors when setting the amount. They are worth reading as a list of things you can influence before and after an incident:
- Nature, gravity, and duration of the breach. A brief accidental exposure reads differently from a months-long systematic failure.
- Type and nature of the personal data affected. The Act has no formal "sensitive data" category, but financial records, health data, and children's data will weigh heavier in practice.
- Whether the breach is repetitive. Repeat findings aggravate the penalty, and they also build toward blocking orders (below).
- Any gain made or loss avoided. If skipping security spend or selling data without consent was profitable, the Board factors that profit in. Non-compliance is not allowed to be the rational economic choice.
- Mitigation actions taken. Fast containment, honest notification, and real remediation directly reduce the number. This factor is the financial case for having a tested incident response plan.
- Proportionality and effectiveness of the penalty as a deterrent. The amount must fit the breach and actually deter.
- The likely impact of the penalty on the person. The Board considers what the penalty does to the organisation it lands on.
Factor 5 is the one you control most directly. Organisations that can demonstrate rapid containment, transparent notification, and systematic remediation enter the hearing in a materially better position. Our breach notification guide covers exactly what that response sequence looks like.
The Exit Ramp: Voluntary Undertakings
Section 32 offers a way to resolve proceedings without a penalty. At any stage, you can offer the Board a voluntary undertaking: a binding commitment to take specific corrective actions, stop specific conduct, or publicise the undertaking itself.
If the Board accepts it, further proceedings on that matter are barred. The case closes. But the mechanism has teeth: breaching an accepted undertaking is deemed a breach of the Act, and the penalty for the original violation comes back into play in full.
Key Takeaway
The undertaking mechanism rewards organisations that move early with concrete remediation. It is not an escape from liability; it converts payment into verified corrective action, with the original penalty held in reserve if you fail to deliver.
Worse Than a Fine: Blocking Orders
Under Section 37, once the Board has penalised a Data Fiduciary on two or more occasions, it can advise the Central Government to direct intermediaries to block public access to that organisation's platform or services in India.
Two penalty orders, not necessarily for the same type of breach, put blocking on the table. The threshold is penalties imposed, not complaints filed: an organisation that resolves matters through voluntary undertakings never accumulates the count. For any digital business, this is the provision that converts compliance failure into an existential risk.
The Board advises; the Central Government decides. But the mechanism rides on India's existing intermediary-blocking infrastructure, which is actively used. It is not a theoretical power.
How the Board Works
The Data Protection Board of India is not a traditional court:
- Digital-first: proceedings are conducted online, and inquiries must conclude within 6 months, extendable by 3.
- Civil court powers: the Board can summon people, require documents, and take evidence. One deliberate limit: it cannot seize equipment or block access to your premises in a way that disrupts operations.
- Civil penalties only: there is no imprisonment under the DPDP Act. Criminal exposure around a breach comes from other regimes, such as the CERT-In Directions under the IT Act.
- Appeals go to TDSAT: file within 60 days of the Board's order. TDSAT must dispose of the appeal within 6 months, its orders are enforceable as civil court decrees, and the final appeal lies with the Supreme Court.
- Mediation is available: the Board can refer parties to mediation at any stage instead of fighting it out.
Board Decisions Are Public
Penalty orders become a matter of public record. For B2B companies and regulated entities, the published finding that you failed to protect personal data can cost more than the fine: procurement teams and enterprise customers will read it.
What Triggers an Inquiry
The Board does not proactively audit. Proceedings start through four routes:
- Your own breach notification. Reporting a breach under Section 8(6) is mandatory, and the Board may then examine whether the breach reveals a compliance failure.
- A Data Principal complaint, typically after your grievance channel failed to resolve it.
- A complaint about a Consent Manager.
- A reference from the Central Government.
The pattern to notice: the two most likely routes run through your own breach report and your own unresolved complaints. Organisations with weak grievance handling are effectively generating their own enforcement pipeline.
False or frivolous complaints are not free for complainants either: the Board can warn them or impose costs, and Section 15 backs that with the ₹10,000 penalty.
What This Means for Your Compliance Budget
Security is the highest-ROI spend. The legislature put the biggest number (₹250 crore) on the obligation that prevents the most harm. Allocate in the same order.
The ₹50 crore catch-all arrives first. Invalid consent flows, ignored erasure requests, missing grievance responses: the widest range of everyday failures sits in this category, which is why it is the penalty most organisations will face before any headline number.
Breach response plans pay for themselves twice. Once through factor 5 reducing the quantum, and once by keeping your penalty count at zero so Section 37 never enters the conversation.
Not sure where your organisation stands?
Take the free 3-minute DPDP Readiness Assessment and get a personalised compliance score.
Check Your ReadinessThe Timeline
The Board's enforcement and penalty machinery comes into force on 13 November 2026. The core obligations it polices, including security safeguards, consent, and breach notification, are fully in force from 13 May 2027. The phase-by-phase breakdown is in our enforcement timeline chapter.
That sequencing is the practical message: by the time the obligations are enforceable, the regulator will have been operational for half a year. Closing gaps now means doing it on your own schedule rather than under a live inquiry.
Frequently Asked Questions
What is the maximum penalty under the DPDP Act?+
Up to ₹250 crore per breach for failing to implement reasonable security safeguards, the highest cap in the Schedule. The Central Government can amend any Schedule amount by notification up to twice the original figure, taking the potential maximum to ₹500 crore.
Is there imprisonment under the DPDP Act?+
No. The DPDP Act operates entirely through civil penalties. Criminal exposure connected to a data breach comes from other laws, such as the CERT-In reporting obligations under the IT Act, which carry imprisonment of up to one year for non-compliance.
Who decides the penalty amount, and on what basis?+
The Data Protection Board of India, after a hearing. Section 33(2) requires it to weigh seven factors: the breach's nature, gravity and duration, the type of data, repetition, any gain made or loss avoided, mitigation actions taken, the penalty's proportionality and deterrent effect, and its likely impact on the person.
Can DPDP penalties stack for a single incident?+
Yes. Each Schedule category is separate, so one breach caused by inadequate security (₹250 crore) with a failed notification (₹200 crore) carries theoretical exposure of ₹450 crore, and more if children's data is involved.
How do you appeal a Data Protection Board order?+
Appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days, filed digitally. TDSAT must dispose of the appeal within 6 months, and a further appeal lies with the Supreme Court.
What happens to repeat offenders under the DPDP Act?+
Repetition aggravates the penalty amount under Section 33(2), and under Section 37 an organisation penalised two or more times can be recommended for a blocking order: the Central Government directing intermediaries to cut public access to its services in India.
For the full penalty schedule in context of every other obligation, see our DPDP penalties chapter and the complete DPDP Act guide.
Legal Disclaimer: This article is for informational purposes only and does not constitute legal advice. Laws and regulations may change; for advice specific to your organisation's situation, consult a qualified legal professional. While every effort has been made to ensure accuracy, Vratex makes no representations as to the completeness or currency of the information contained herein.
Not sure where your organisation stands?
Take the free 3-minute DPDP Readiness Assessment and get a personalised compliance score with actionable next steps.
Check Your DPDP Readiness