DPDPA Penalties Explained: How the ₹250 Crore Fines Actually Work

The Schedule to the DPDP Act 2023 fixes monetary ceilings per class of violation — not percentages of turnover like the GDPR. The headline numbers:
| Violation | Ceiling |
|---|---|
| Failure to take reasonable security safeguards to prevent a breach — Section 8(5) | ₹250 crore |
| Failure to notify a personal data breach — Section 8(6) | ₹200 crore |
| Breach of obligations relating to children — Section 9 | ₹200 crore |
| Breach of Significant Data Fiduciary obligations — Section 10 | ₹150 crore |
| Breach of a Data Principal's duties — Section 15 | ₹10,000 |
| Any other breach of the Act or Rules | ₹50 crore |
Two things make these ceilings sharper than they look:
- They apply per instance. A pattern of failures can stack.
- Security failure is the top ceiling. The legislature put the single largest number on not preventing the breach — a clear signal that "we got hacked" is not a defence if safeguards were unreasonable.
How the Board sets the actual amount
Section 33 requires the Data Protection Board to consider the nature, gravity and duration of the breach; the type and nature of data affected; repetitiveness; whether the entity gained from the violation; the mitigating steps taken and their timeliness; and the proportionality and likely deterrent impact of the penalty.
Translated: your evidence determines your penalty. Two companies with an identical breach can face very different outcomes based on what they can prove — documented safeguards, a tested incident plan, prompt notification and cooperative conduct all pull the number down.
Voluntary undertakings: the escape valve
Section 32 lets an entity offer a voluntary undertaking — commitments to remedial action the Board may accept, halting proceedings. A credible compliance record is your negotiating capital.
Reducing exposure, practically
- Maintain and evidence reasonable security safeguards — encryption, access control, logging, vendor DPAs.
- Keep a breach playbook and rehearse it (see our 72-hour playbook).
- Log every consent, request and notification with timestamps.
- Run periodic assessments — start with the penalty calculator and the readiness assessment.
Data Adhikaar turns each of these into an always-on agent workflow, with a hash-chained Evidence Vault your auditors — and the Board — can rely on.
Data Adhikaar Editorial Team
DPDPA Compliance Specialists, Qodequay Technologies
Get DPDPA-ready before the enforcement window closes.
Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.
Or call +91 98226 28174