Sekurzen Logo

Enforcement guide

DPDP penalties at a glance

The Schedule to the Digital Personal Data Protection Act, 2023 sets different maximum monetary penalties for different contraventions.

Important: these are maximum penalties

The Board does not automatically impose the maximum. Under Section 33(2), it considers the nature, gravity and duration of the breach, affected data, repetition, mitigation, proportionality, and likely impact.

The Schedule

Penalty categories

7 categories

Failure to take reasonable security safeguards

Safeguards intended to prevent a personal data breach.

Reference: Section 8(5)

Maximum: Up to ₹250 crore

Failure to notify a personal data breach

Notice to the Data Protection Board or affected Data Principals.

Reference: Section 8(6)

Maximum: Up to ₹200 crore

Breach of child-data obligations

Additional obligations when processing children’s personal data.

Reference: Section 9

Maximum: Up to ₹200 crore

Breach of Significant Data Fiduciary obligations

Additional obligations that apply to a Significant Data Fiduciary.

Reference: Section 10

Maximum: Up to ₹150 crore

Breach of Data Principal duties

Includes impersonation and false or frivolous complaints.

Reference: Section 15

Maximum: Up to ₹10,000

Breach of a voluntary undertaking

The penalty can follow the underlying breach.

Reference: Section 32

Maximum: Applicable penalty

Any other breach of the Act or Rules

A residual category where a specific penalty does not apply.

Reference: General provision

Maximum: Up to ₹50 crore

Where to go next

Chapter 13 explains enforcement and adjudication in the wider DPDP framework.

Read Chapter 13

Primary source

Based on Section 33 and the Schedule to the official Act text.

Open the Act (PDF)

General information only; this page is not legal advice. Verify the current Act, Rules, notifications, and amendments before relying on a penalty amount.