The DPDP Act 2023 does not levy penalties automatically or across the board — it sets ceilings, and the Data Protection Board of India decides the actual amount case by case. That distinction gets lost in most headlines about "₹250 crore fines." This FAQ walks through what the penalties actually are, who sets them, what happens if you're on the receiving end, and how the framework compares internationally.
1. What penalties can be imposed under the DPDP Act 2023?
Short answerThe Data Protection Board of India can impose monetary penalties on a Data Fiduciary (or Data Processor, where relevant) for specific breaches listed in the Schedule to the Act. It can also impose a much smaller penalty directly on a Data Principal who breaches their own duties under Section 15 — for example, filing a false or frivolous complaint. There is no imprisonment provision in the DPDP Act; enforcement is entirely monetary and administrative (cessation orders, corrective directions, penalties).
2. What is the maximum penalty under the DPDP Act?
Short answer₹250 crore — the ceiling for a Data Fiduciary's failure to take reasonable security safeguards to prevent a personal data breach (Section 8(5)). This is the figure most often quoted as "the DPDP penalty," but it is only the ceiling for one specific violation, not a general cap that applies to every failure.
3. What is the full table of penalties by violation?
The Schedule to the DPDP Act sets out seven penalty categories. These are maximum figures — "may extend to" — not fixed amounts.
| Violation | Provision | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a breach | s.8(5) | ₹250 crore |
| Failure to notify the Board / affected Data Principals of a breach | s.8(6) | ₹200 crore |
| Breach of additional obligations for children's data | s.9 | ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | s.10 | ₹150 crore |
| Breach of any other provision of the Act or Rules (catch-all) | — | ₹50 crore |
| Breach of a voluntary undertaking accepted by the Board | s.32 | Up to the original violation's ceiling |
| Breach of a Data Principal's own duties (e.g. false complaint) | s.15 | ₹10,000 |
4. Why is the security-safeguards penalty the highest?
Short answerBecause it is the provision most directly tied to preventable harm at scale. Section 8(5) requires "reasonable security safeguards" to prevent a personal data breach in the first place — it is the upstream obligation that, if met, would have prevented most other violations (breach notification failures, harm to data principals) from ever arising. Lawmakers set its ceiling highest to reflect that it is the most consequential single failure a Data Fiduciary can have.
5. Who actually decides the penalty amount — is it always the maximum?
Short answerNo. The Data Protection Board decides the actual figure within the ceiling for that violation category, after considering the specific facts. The Act does not mandate automatic maximum penalties, and nothing in the Schedule or the Board's rules suggests penalties default to the ceiling.
6. What factors does the Board consider when fixing a penalty?
The Act directs the Board to weigh, among other things: the nature, gravity and duration of the non-compliance; the type of personal data affected; whether the violation was repeated; any gain made or loss avoided by the Data Fiduciary because of the non-compliance; the promptness and effectiveness of any remedial action; and the need for the penalty to be proportionate and act as a deterrent. The Board can also adjust a penalty up or down — up to twice the base amount in either direction — based on these factors.
"DPDP penalties are absolute rupee ceilings, not a percentage of turnover — a mid-sized firm and a large conglomerate face the same maximum for the same violation."
— DPDP Act 2023, Schedule; contrast with GDPR's turnover-linked caps7. Can a penalty be reduced through a voluntary undertaking?
Short answerYes, in a specific and limited sense. Under Section 32, a Data Fiduciary under inquiry can offer the Board a voluntary undertaking — a binding commitment to take (or stop) certain actions. If the Board accepts it, the original proceedings can be closed on those terms. But breaking that undertaking later is itself a violation, penalised up to the ceiling that applied to the original matter — so it is a way to resolve a case on cooperative terms, not a way to cap exposure below the statutory ceiling.
8. Can a company appeal a DPDP penalty? What's the process?
Short answerYes. Section 29 of the Act provides an appeal to the Appellate Tribunal — the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) — against any order or direction of the Data Protection Board, including a penalty order. The appeal must be filed within 60 days of receiving the Board's order (extendable at the Tribunal's discretion for sufficient cause). A further appeal from the Tribunal's decision follows the procedure under Section 18 of the TRAI Act, 1997, which can carry a matter up to the Supreme Court.
9. Do repeat violations attract a higher penalty?
Short answerYes, indirectly. Repetition is explicitly one of the factors the Board must weigh when fixing a penalty within the applicable ceiling — a Data Fiduciary that has been penalised or warned for the same type of violation before should expect the Board to treat a repeat as an aggravating factor, pushing the figure higher within (or, per the Board's adjustment power, up to twice) the ceiling. The Schedule itself does not set a separate, higher ceiling specifically for "second offences" — the escalation happens through the factor-weighing process, not a distinct penalty band.
10. Is there a penalty specifically for violations involving children's data?
Short answerYes — up to ₹200 crore for breach of the additional obligations under Section 9, which covers verifiable parental consent, a bar on tracking/behavioural monitoring and targeted advertising directed at children, and related safeguards. Children's data is treated as a high-priority enforcement area in most privacy regimes globally, and DPDP's ceiling for it sits just below the top tier.
11. What about Significant Data Fiduciaries (SDFs) — do they face higher exposure?
Short answerSDFs carry additional obligations under Section 10 (appointing a DPO, conducting DPIAs and periodic audits, and other enhanced accountability measures), and failing those specific obligations carries its own ceiling of ₹150 crore. An SDF is not automatically exposed to a higher penalty for every violation — but it does have more obligations that can independently trigger a penalty, and a failure that also breaches core provisions (like security safeguards) would still be assessed under that provision's own, higher ceiling.
12. Is there a cap on how many violations can be charged at once?
Short answerNo. Penalties are assessed per violation, and the Act does not cap how many distinct violations a single incident can be charged with. A breach that stems from inadequate security safeguards, is not notified on time, and involves children's data can in principle be assessed against three separate ceilings simultaneously — which is why aggregate exposure from a systemic failure can run well beyond any single figure in the Schedule.
13. How does DPDP Act penalty compare to GDPR fines?
Short answerGDPR caps fines as a percentage of a company's global annual turnover — up to 4% for the most serious infringements, or a fixed floor (whichever is higher). That means exposure scales automatically with company size. DPDP takes the opposite approach: fixed rupee ceilings per violation, with no reference to turnover at all. In practice, this makes DPDP penalties proportionately more severe for small and mid-sized organisations (a ₹250 crore ceiling is a much bigger share of a smaller firm's revenue) and, because there is no turnover cap and no limit on the number of violations charged, potentially larger in cumulative terms for very large firms with systemic failures.
14. When do these penalty provisions actually start applying?
Short answerThe DPDP Rules 2025 were notified on 14 November 2025, and the Act's substantive obligations — notice and consent requirements, breach reporting, security safeguards, verifiable consent for children's and persons-with-disabilities data, SDF obligations, and Data Principal rights — become operative roughly 18 months later, around mid-May 2027. The Data Protection Board itself and certain administrative provisions took effect from the notification date; full enforcement of the penalty provisions tied to these substantive obligations follows the phased timeline. Organisations should treat the intervening period as the compliance runway, not a grace period with no consequence — the Board can act on egregious or already-covered violations sooner, and being unprepared when the phased deadlines land is its own risk.
15. Where can I check my organisation's actual exposure, not just the ceiling figures?
Short answerThe ceiling figures in this FAQ answer "what's the maximum," not "what would we actually face." For a structured, scenario-based walkthrough of how the Board is likely to weigh gravity, duration, repetition and mitigation for BFSI-style situations, see our companion guide below. For a live, editable estimate against your own violation scenario, CreativeCyber's DPDP Penalty Calculator is the faster starting point.
The Practical Takeaway
Three things are worth remembering above the individual figures. First, ceilings are not defaults — the Board sets the actual number based on gravity, duration, repetition and how you respond, so a documented, fast, cooperative response measurably reduces exposure within the same ceiling. Second, penalties stack per violation with no cap on count, so a single systemic failure can trigger several ceilings at once — the aggregate, not any single line in the Schedule, is the real number to model. Third, there is a real appeal path (Tribunal within 60 days, then further appeal under the TRAI Act framework) — a Board order is not the end of the process, but relying on appeal instead of prevention is a strategy of last resort, not a plan.