Penalties follow an inquiry, never precede one. The Board weighs gravity, duration, repetition, gain or loss, mitigation and proportionality before fixing an amount — and everything realised goes to the Consolidated Fund of India.
Penalties in the Schedule
Entry 1 · § 8(5)Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Entry 2 · § 8(6)Failure to give the Board or affected Data Principals notice of a personal data breach₹200 crore
Entry 3 · § 9Breach of the additional obligations in relation to children₹200 crore
Entry 4 · § 10Breach of the additional obligations of a Significant Data Fiduciary₹150 crore
Entry 7 · any other provisionBreach of any other provision of the Act or the rules made under it₹50 crore
Entry 5 · § 15Breach of a Data Principal's duties₹10,000
Entry 6 · § 32Breach of any term of a voluntary undertaking accepted by the BoardUp to the extent applicable for the breach that triggered the proceedings
How enforcement works
How an inquiry runsThe Board decides whether there are sufficient grounds, records reasons for every step, follows natural justice, and may hold civil-court powers of summons, evidence and inspection. It may issue interim orders — but may not seize equipment or block access to premises in a way that disrupts day-to-day functioning.§ 28
Ways out short of penaltyThe Board may direct mediation where a complaint can be settled, and may accept a voluntary undertaking at any stage — which bars proceedings on its contents. Fail to honour a term and the breach is deemed a breach of the Act itself.§§ 31–32
Appeals and blockingAppeals go to the Appellate Tribunal within sixty days; it aims to dispose of them within six months and functions digitally. After penalties in two or more instances, the Central Government may — in the public interest and after a hearing — direct blocking of the Fiduciary's platform.§§ 29–30, § 37
How the Board determines an amount
Seven factors the Board must weigh · § 33(2)
Nature, gravity and durationType of personal data affectedRepetitive nature of the breachGain realised or loss avoidedMitigation, and how timely it wasProportionality and deterrenceLikely impact on the person
You have read the whole Act. Now certify it.Fifteen questions across all nine chapters and the Schedule. Pass at 70% and your certificate is issued instantly.
DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 2 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.