DPDPAcademyKnow the law. Prove it.
Home/Penalty calculator
The Schedule · § 33

The Schedule Sets a Ceiling. Seven Factors Set the Number.

No tool can tell you what the Board would impose, and one that prints a figure is guessing. What can be shown is the statutory maximum for each head, and which way each of the seven factors in section 33(2) pushes on your facts.

Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8.

Statutory maximum for this headMay extend to two hundred and fifty crore rupees.This is the ceiling the Schedule sets, not a starting point and not an expected figure.
2 · Which way does each factor point on your facts?
Nature, gravity and duration§ 33(2)(a)
Type and nature of the data affected§ 33(2)(b)
Repetitive nature of the breach§ 33(2)(c)
Gain realised or loss avoided§ 33(2)(d)
Mitigation, and how timely it was§ 33(2)(e)
Proportionality and deterrence§ 33(2)(f)
Likely impact of the penalty on the person§ 33(2)(g)
What this tells you

Move the factors to see how the argument shifts. None of them is weighted in the Act.

There is deliberately no number here. The Act assigns no weights to the seven factors and sets no formula, so any figure a calculator produced would be invented. What it can show is which way your facts push, and which of them you can still change.

Nothing you select leaves your browser. Every head and every factor is also written out below, so the page works without the tool.

The Schedule · see § 33(1)

Seven heads, seven ceilings

Sl.BreachMaximum penalty
1.Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8.May extend to two hundred and fifty crore rupees.
2.Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8.May extend to two hundred crore rupees.
3.Breach in observance of additional obligations in relation to children under section 9.May extend to two hundred crore rupees.
4.Breach in observance of additional obligations of Significant Data Fiduciary under section 10.May extend to one hundred and fifty crore rupees.
5.Breach in observance of the duties under section 15.May extend to ten thousand rupees.
6.Breach of any term of voluntary undertaking accepted by the Board under section 32.Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted.
7.Breach of any other provision of this Act or the rules made thereunder.May extend to fifty crore rupees.

Reproduced from the Schedule to the Act. [See section 33 (1)]

§ 33(2)

The seven factors, and which you can still change

The Board must have regard to each of these in fixing an amount. The Act gives them no weights and no order of priority - but two of them are decided long before any breach occurs.

§ 33(2)(a)Nature, gravity and durationHow serious the breach was and how long it ran. Duration is doing real work here: the same exposure left open for months reads differently from one closed in hours.
§ 33(2)(b)Type and nature of the personal data affectedThe Act has no sensitive-data tier, but the Board is told to have regard to the type of data at the penalty stage. Sensitivity re-enters here, as a factor rather than a category.
§ 33(2)(c)Repetitive nature of the breachWhether this has happened before. Two or more penalties can also trigger the section 37 blocking route, which is a separate and far heavier consequence.
§ 33(2)(d)Gain realised or loss avoidedWhether the person profited from the breach or dodged a cost by it - cutting a security programme, for instance, and banking the saving.
§ 33(2)(e)Mitigation, and its timelinessWhether action was taken to mitigate the effects and consequences, and how quickly and effectively.This is the one factor you can move entirely before anything happens. A rehearsed incident response is a penalty argument, not just good hygiene.
§ 33(2)(f)Proportionality and deterrenceWhether the penalty is proportionate and effective, having regard to the need to secure observance of the Act and deter breach.
§ 33(2)(g)Likely impact on the personWhat the penalty would do to the person it is imposed on. This is why the ₹250 crore ceiling is a ceiling and rarely an expectation.
Before the number

Two gates stand before any penalty

First, section 28(3): the Board decides whether there are sufficient grounds to proceed at all, and may close the matter with reasons recorded. Second, section 33(1): a penalty follows only where it determines the breach is significant, after giving an opportunity to be heard.

A third exit sits in between. Under section 32 the Board may accept a voluntary undertaking at any stage, and acceptance bars proceedings on what it covers - though failing to honour a term is itself deemed a breach of the Act.

The whole path is drawn out on the penalties page, and the provisions are at section 33 and the Schedule.

FAQ

DPDP penalties, answered

What is the maximum penalty under the DPDP Act?

₹250 crore, for breach of the obligation in section 8(5) to take reasonable security safeguards to prevent a personal data breach. That is the highest of the seven heads in the Schedule.

Can a tool calculate what I would actually be fined?

No, and any tool that outputs a figure is inventing it. Section 33(1) requires the Board to determine that the breach is significant before any penalty, and section 33(2) lists seven factors with no weights and no formula. The Schedule sets ceilings; the Board sets amounts, recording its reasons.

What is the smallest penalty in the Schedule?

Up to ₹10,000, for breach of the Data Principal's own duties under section 15. It is the only head aimed at the individual rather than an organisation, and GDPR has no equivalent.

Does the money go to the person whose data was breached?

No. Section 34 credits all sums realised by way of penalty to the Consolidated Fund of India. The DPDP Act creates no compensation route at all, and section 39 bars civil courts from matters the Board can decide.

Can a penalty be appealed?

Yes, to the Appellate Tribunal - TDSAT - within sixty days of receiving the order, under section 29. The Tribunal endeavours to dispose of appeals within six months.

When can penalties first be imposed?

Sections 28 to 34 sit in the eighteen-month tranche of the commencement notification, so mid-May 2027. The Board itself was established in November 2025.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →