DPDPAcademyKnow the law. Prove it.
Home/Penalties & Enforcement
Chapters VI–VIII · The Schedule

Seven Penalty Heads, Up To ₹250 Crore

Penalties follow an inquiry, never precede one. The Board weighs gravity, duration, repetition, gain or loss, mitigation and proportionality before fixing an amount - and everything realised goes to the Consolidated Fund of India.

Penalties in the Schedule

Entry 1 · § 8(5)Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Entry 2 · § 8(6)Failure to give the Board or affected Data Principals notice of a personal data breach₹200 crore
Entry 3 · § 9Breach of the additional obligations in relation to children₹200 crore
Entry 4 · § 10Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Entry 7 · any other provisionBreach of any other provision of the Act or the rules made under it₹50 crore
Entry 5 · § 15Breach of a Data Principal's duties₹10,000
Entry 6 · § 32Breach of any term of a voluntary undertaking accepted by the BoardUp to the extent applicable for the breach that triggered the proceedings

How enforcement works

How an inquiry runsThe Board decides whether there are sufficient grounds, records reasons for every step, follows natural justice, and may hold civil-court powers of summons, evidence and inspection. It may issue interim orders - but may not seize equipment or block access to premises in a way that disrupts day-to-day functioning.§ 28
Ways out short of penaltyThe Board may direct mediation where a complaint can be settled, and may accept a voluntary undertaking at any stage - which bars proceedings on its contents. Fail to honour a term and the breach is deemed a breach of the Act itself.§§ 31–32
Appeals and blockingAppeals go to the Appellate Tribunal within sixty days; it aims to dispose of them within six months and functions digitally. After penalties in two or more instances, the Central Government may - in the public interest and after a hearing - direct blocking of the Fiduciary's platform.§§ 29–30, § 37

How the Board determines an amount

Seven factors the Board must weigh · § 33(2)
Nature, gravity and durationType of personal data affectedRepetitive nature of the breachGain realised or loss avoidedMitigation, and how timely it wasProportionality and deterrenceLikely impact on the person
You have read the whole Act. Now certify it.Fifteen questions across all nine chapters and the Schedule. Pass at 70% and your certificate is issued instantly.
At a glance

How a breach becomes a number

How a DPDP breach becomes a penaltyA personal data breach triggers notification to the Board and to affected Data Principals under section 8(6). That notification is itself an intake route under section 27(1)(a). The Board then decides whether there are sufficient grounds under section 28(3); if not it closes the matter with reasons recorded under section 28(4). If it inquires, the matter may still end in an accepted voluntary undertaking under section 32, which bars further proceedings. A penalty follows only where the Board determines the breach is significant under section 33(1). The amount is then fixed against the seven factors in section 33(2), capped by the Schedule, and is appealable to the Appellate Tribunal within sixty days under section 29.Personal data breach§ 2(u)Notify Board + principals§ 8(6) · Rule 7Board intake§ 27(1)(a)Sufficient grounds?§ 28(3)noClosed, reasons recorded§ 28(4)yesInquiry§ 28(5)–(7)Undertaking accepted§ 32 - barSignificant breach?§ 33(1)yesSeven factors set the amount§ 33(2), capped by the ScheduleAppeal: TDSAT§ 29 · 60 daysGreen edges endthe matter withno penalty.
From breach to penalty. Two exits close the matter without any penalty at all, and the amount is set by the seven factors in section 33(2) - the Schedule only caps it.
§ 27(1) · Before any inquiry

Four ways a matter reaches the Board

The page above covers how an inquiry runs. This is the step before it - and the first route in is the one organisations underestimate.

§ 27(1)(a)Your own breach reportOn receiving an intimation of a personal data breach under section 8(6), the Board may direct urgent remedial or mitigation measures, and inquire into the breach.Reporting is mandatory and reporting is a trigger. The duty to notify under section 8(6) and the exposure to inquiry run through the same event, which is why the mitigation you can evidence matters so much at the section 33(2) stage.
§ 27(1)(b)A Data Principal's complaintAbout a personal data breach, about a Data Fiduciary's observance of its obligations in relation to her personal data, or about the exercise of her rights.She must exhaust the Fiduciary's own grievance mechanism first - section 13(3) - so a working grievance process is a genuine filter, not just a compliance box.
§ 27(1)(c)–(d)Consent Manager failuresA complaint about a Consent Manager's obligations towards her personal data, or an intimation that one has broken a condition of its registration.Relevant from November 2026, when registration opens under Rule 4.
§ 27(1)(e)A Government reference about an intermediaryWhere the Central Government refers a breach of section 37(2) - an intermediary failing to comply with a blocking direction.
Worked example

From a leaked database to a number

A misconfigured backup exposes 40,000 customer records. Trace the provisions in order and you can see where the amount is actually decided - and it is not in the Schedule.

§ 8(6) + Rule 7You notify. Affected Data Principals without delay; the Board without delay, then a detailed report within 72 hours. There is no harm threshold to hide behind - 40,000 records or four, the duty is the same.
§ 27(1)(a)That notification is itself the Board's route in. It may direct urgent remedial measures immediately, and inquire into the breach.
§ 28(3)–(4)The Board decides whether there are sufficient grounds. If not, it closes the matter with reasons recorded. Many notifications should end here.
§ 33(1)If it does inquire, a penalty follows only where the Board determines the breach is significant, after giving you an opportunity to be heard.
Schedule, entry 1The relevant head is failure to take reasonable security safeguards under section 8(5) - the ₹250 crore ceiling. A ceiling, not a starting point.
§ 33(2)The number is then set against seven factors. A misconfiguration caught and closed in hours, with processors instructed and customers told, argues differently from the same exposure left open for months.

Two of the seven factors are the ones you can influence before anything happens. Mitigation is credited explicitly, and its timeliness is part of the test - which makes a rehearsed incident response a penalty argument rather than merely good hygiene. The last factor lets the Board weigh the penalty's likely impact on the person, which is why the ceiling is rarely the expectation.

§ 34 · § 39

Nobody gets paid, and no court will hear it

Section 34 credits every sum realised by way of penalty to the Consolidated Fund of India. Not a rupee reaches the person whose data was exposed. This Act creates no compensation route at all - unlike the outgoing section 43A of the IT Act, which awarded damages to the person harmed and remains available until section 44(2) commences, and unlike GDPR Article 82.

Section 39 then bars civil courts from entertaining any suit or proceeding in a matter the Board is empowered to decide, and bars injunctions against action taken under the Act. The Board and the Appellate Tribunal are the entire forum.

For a compliance programme this changes the shape of the risk rather than its size: no class of private claimants, one regulator, and nothing to settle with the individual. For the individual it is the most significant thing the Act does not give her. See what section 43A still allows until 2027 and how this differs from GDPR.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →