DPDPA Phase II enforcement 13 November 2026 — penalties up to ₹250 crore. Check your readiness →
Book a Demo
Penalties

DPDPA Penalties Explained: How the ₹250 Crore Fines Actually Work

Data Adhikaar Editorial Team 6 July 2026 2 min read
DPDPA Penalties Explained: How the ₹250 Crore Fines Actually Work

The Schedule to the DPDP Act 2023 fixes monetary ceilings per class of violation — not percentages of turnover like the GDPR. The headline numbers:

ViolationCeiling
Failure to take reasonable security safeguards to prevent a breach — Section 8(5)₹250 crore
Failure to notify a personal data breach — Section 8(6)₹200 crore
Breach of obligations relating to children — Section 9₹200 crore
Breach of Significant Data Fiduciary obligations — Section 10₹150 crore
Breach of a Data Principal's duties — Section 15₹10,000
Any other breach of the Act or Rules₹50 crore

Two things make these ceilings sharper than they look:

  1. They apply per instance. A pattern of failures can stack.
  2. Security failure is the top ceiling. The legislature put the single largest number on not preventing the breach — a clear signal that "we got hacked" is not a defence if safeguards were unreasonable.

How the Board sets the actual amount

Section 33 requires the Data Protection Board to consider the nature, gravity and duration of the breach; the type and nature of data affected; repetitiveness; whether the entity gained from the violation; the mitigating steps taken and their timeliness; and the proportionality and likely deterrent impact of the penalty.

Translated: your evidence determines your penalty. Two companies with an identical breach can face very different outcomes based on what they can prove — documented safeguards, a tested incident plan, prompt notification and cooperative conduct all pull the number down.

Voluntary undertakings: the escape valve

Section 32 lets an entity offer a voluntary undertaking — commitments to remedial action the Board may accept, halting proceedings. A credible compliance record is your negotiating capital.

Reducing exposure, practically

  • Maintain and evidence reasonable security safeguards — encryption, access control, logging, vendor DPAs.
  • Keep a breach playbook and rehearse it (see our 72-hour playbook).
  • Log every consent, request and notification with timestamps.
  • Run periodic assessments — start with the penalty calculator and the readiness assessment.

Data Adhikaar turns each of these into an always-on agent workflow, with a hash-chained Evidence Vault your auditors — and the Board — can rely on.

#dpdpa-penalties#data-protection-board#fines#compliance

Data Adhikaar Editorial Team

DPDPA Compliance Specialists, Qodequay Technologies

Get DPDPA-ready before the enforcement window closes.

Start with a free readiness assessment, or book a demo of the Data Adhikaar agent fabric.

Or call +91 98226 28174