Enforcement guide
DPDP penalties at a glance
The Schedule to the Digital Personal Data Protection Act, 2023 sets different maximum monetary penalties for different contraventions.
Important: these are maximum penalties
The Board does not automatically impose the maximum. Under Section 33(2), it considers the nature, gravity and duration of the breach, affected data, repetition, mitigation, proportionality, and likely impact.
The Schedule
Penalty categories
Failure to take reasonable security safeguards
Safeguards intended to prevent a personal data breach.
Reference: Section 8(5)
Maximum: Up to ₹250 crore
Failure to notify a personal data breach
Notice to the Data Protection Board or affected Data Principals.
Reference: Section 8(6)
Maximum: Up to ₹200 crore
Breach of child-data obligations
Additional obligations when processing children’s personal data.
Reference: Section 9
Maximum: Up to ₹200 crore
Breach of Significant Data Fiduciary obligations
Additional obligations that apply to a Significant Data Fiduciary.
Reference: Section 10
Maximum: Up to ₹150 crore
Breach of Data Principal duties
Includes impersonation and false or frivolous complaints.
Reference: Section 15
Maximum: Up to ₹10,000
Breach of a voluntary undertaking
The penalty can follow the underlying breach.
Reference: Section 32
Maximum: Applicable penalty
Any other breach of the Act or Rules
A residual category where a specific penalty does not apply.
Reference: General provision
Maximum: Up to ₹50 crore
Where to go next
Chapter 13 explains enforcement and adjudication in the wider DPDP framework.
Read Chapter 13General information only; this page is not legal advice. Verify the current Act, Rules, notifications, and amendments before relying on a penalty amount.
