DPDP Penalties for Non-Compliance
Understanding DPDP Act Penalties & Compliance Risks
From ₹10,000 to ₹250 crore per violation — the complete penalty schedule, the two-stage breach notification clock, Significant Data Fiduciary obligations, exemptions, and how the Data Protection Board of India actually enforces the law.
₹250 Cr
Maximum Penalty
72 Hrs
Breach Reporting Window
90 Days
Rights Response Deadline
May 2027
Full Enforcement
Get Started With Digital Anumati
What Is the DPDP Act and Who Does It Apply To?
The Digital Personal Data Protection (DPDP) Act 2023 governs digital personal data processing in India. It applies to organisations operating within India and to entities outside India that process the personal data of individuals located in India in connection with offering goods or services to them.
Three roles matter for enforcement purposes. A Data Fiduciary determines the purpose and means of processing and carries full legal liability. A Data Processor processes data on a Fiduciary’s behalf under contract but is not directly penalised by the Board. A Data Principal is the individual whose data is processed and who holds enforceable rights under the Act.
Who Must Comply?
- Any organisation in India that collects or processes digital personal data
- Foreign organisations processing personal data of individuals in India while offering goods or services to them
- Government instrumentalities, except where specifically exempted by notification
Liability Chain
Data Processors are not directly penalised by the DPBI. The Data Fiduciary remains fully liable for violations committed by vendors or third-party processors acting on its behalf — vendor contracts do not shift statutory liability.
Quick Answer
The Digital Personal Data Protection (DPDP) Act 2023 imposes financial penalties ranging from ₹10,000 to ₹250 crore per violation on organizations that fail to comply with India's data protection law. Penalties are enforced by the Data Protection Board of India (DPBI) under Section 33 of the Act.
DPDP Penalty Schedule
The Schedule to the Act, referenced under Section 33(1), sets the maximum monetary penalty the Data Protection Board of India (DPBI) may impose for each category of non-compliance. These amounts are ceilings, not fixed fines — within that ceiling the DPBI sets the actual quantum using the six factors in Section 33(2).
| Violation Category | Maximum Penalty |
|---|---|
Failure to implement adequate security safeguards (Section 8(5)) | Up to ₹250 Crore |
Failure to notify the DPBI and affected Data Principals of a personal data breach | Up to ₹200 Crore |
Violation of obligations relating to children’s personal data | Up to ₹200 Crore |
Non-compliance by a Significant Data Fiduciary (SDF) | Up to ₹150 Crore |
Consent, notice, and Data Principal rights violations | Up to ₹50 Crore |
Failure to comply with DPBI orders or directions | Up to ₹20 Crore |
Breach of a voluntary undertaking given to the DPBI | Equivalent to original breach penalty |
Violation of duties by a Data Principal (Section 15) | ₹10,000 |
Stacking risk: penalties are imposed per violation, per inquiry. If one investigation uncovers multiple failures — say, a security lapse, a missed breach notification, and a consent violation — the DPBI can penalise each separately. A single enforcement action could theoretically produce cumulative fines exceeding ₹650 crore.
The Breach Notification Clock: A Two-Stage Requirement
The DPDP Rules 2025 (Rule 7) split breach reporting into two distinct stages, not a single 72-hour deadline.
Stage 1 — Immediate Intimation — “Without Delay”
As soon as a Data Fiduciary becomes aware of a breach, it must inform the DPBI without delay, describing the nature, extent, timing, and location of the breach along with its likely impact. The clock starts at the moment of awareness — not once the internal investigation is complete.
Stage 2 — Detailed Report — Within 72 Hours
Within 72 hours, the Fiduciary must submit an updated description of the breach, the circumstances that led to it, remedial and mitigation measures taken, findings on who caused it, and confirmation of the notifications sent to affected Data Principals. A written request can be made to the Board for a time extension beyond 72 hours.
Expensive twice over: the underlying security failure can draw up to ₹250 crore, and a missed or late notification can draw a separate penalty of up to ₹200 crore.
Major DPDP Violations
The areas where businesses face the greatest regulatory exposure under the DPDP Act.
Security Safeguard Failures
Up to ₹250 crore. Failure to implement reasonable technical and organisational safeguards — encryption, access controls, monitoring — under Section 8(5).
Data Breach Notification Failures
Up to ₹200 crore. Missing the immediate-intimation duty on becoming aware of a breach, or the 72-hour detailed report to the DPBI and affected individuals.
Children's Data Violations
Up to ₹200 crore. Processing a child’s personal data without verifiable parental consent, or enabling tracking, behavioural monitoring, or targeted advertising directed at children.
Significant Data Fiduciary Non-Compliance
Up to ₹150 crore. Failing SDF duties under Rule 13: an India-based DPO reporting to the board, an independent data auditor, annual DPIAs and audits, and algorithmic due diligence.
Consent & Rights Violations
Up to ₹50 crore. Invalid or bundled consent, unclear notices, or failure to act on access, correction, or erasure requests.
Non-Compliance with DPBI Orders
Up to ₹20 crore. Ignoring directions issued by the Data Protection Board during or after an inquiry.
Breach of Voluntary Undertakings
Matches the original penalty. Failing to honour remedial commitments made to the DPBI during a hearing removes the benefit of having settled voluntarily.
Data Principal Violations
₹10,000. False complaints, impersonation, or furnishing misleading information — the only penalty category aimed at individuals rather than organisations.
Significant Data Fiduciary (SDF): Criteria and Extra Obligations
The Central Government designates certain Data Fiduciaries as “Significant” based on risk, not just size.
Designation Criteria
- Volume and sensitivity of personal data processed
- Risk to the rights of Data Principals
- Potential impact on the sovereignty and integrity of India
- Risk to electoral democracy, state security, and public order
Additional Obligations (Rule 13)
- Appoint a Data Protection Officer based in India, reporting to the Board of Directors or equivalent governing body
- Appoint an independent data auditor
- Conduct a Data Protection Impact Assessment (DPIA) and a data audit at least once every 12 months
- Carry out algorithmic due diligence to ensure software and algorithms do not pose risks to Data Principal rights
- Comply with any additional data-localisation restrictions the government specifies for certain classes of data
Non-compliance with these enhanced obligations carries a separate penalty of up to ₹150 crore — on top of any penalty for the underlying violation itself.
Who Is Exempt from the DPDP Act?
Exemptions exist, but they are narrower than most organisations assume.
Government Agencies
The Central Government may exempt specified government agencies from all or part of the Act in the interest of national security, public order, sovereignty and integrity of India, and prevention of offences. Government instrumentalities may also process data without consent to deliver services, benefits, licences, permits, or certificates, or to fulfil legal obligations.
Startups
The Central Government can notify exemptions for specific classes of Data Fiduciaries — including startups — from certain provisions, based on the volume and nature of personal data they process. This is discretionary and notification-based, not automatic.
Research, Archiving & Statistics
Processing solely for research, archiving, or statistical purposes is exempt — but only if the data is not used to make any decision specific to an individual Data Principal. Labelling an activity “research” does not itself trigger the exemption.
What Is Never Exempt
Core security-safeguard obligations and breach-notification duties are largely designed to apply broadly. Exemption notifications typically carve out specific provisions rather than granting blanket immunity from the Act.
How the Data Protection Board Enforces Penalties
The DPBI, established under Chapter V of the Act and made operational by the DPDP Rules 2025, is a fully digital quasi-judicial body. Complaints, evidence, hearings, and orders run end-to-end through a dedicated portal and mobile app, so Data Principals can file and track cases without appearing in person. It is not a policy regulator — its sole function is investigation, adjudication, and enforcement.
Who Can Trigger an Enforcement Action?
An inquiry can be initiated by:
- A Data Principal filing a complaint (after first exhausting the Data Fiduciary's internal grievance redressal mechanism)
- A suo motu action by the DPBI on its own motion
- A referral from the Central Government
- A breach notification received from the Data Fiduciary
The DPBI does not need a prior complaint to investigate. If it has reason to believe non-compliance has occurred, it can initiate an inquiry independently.
The 5-Stage Enforcement Process
Stage 1 — Trigger
A complaint, breach notification, government referral, or DPBI suo motu action initiates the process.
Stage 2 — Prima Facie Assessment
The DPBI assesses whether sufficient grounds exist to proceed. The organisation may be asked for an initial written response.
Stage 3 — Formal Inquiry
If a prima facie case is established, the DPBI issues a formal notice, summons documents and records, and may conduct a premises inspection. The organisation has the right to respond and present evidence.
Stage 4 — Hearing and Order
The organisation presents its defence and submits mitigating factors. A voluntary undertaking may be offered at this stage. The DPBI issues a reasoned written order with the penalty quantum — or dismisses the complaint.
Stage 5 — Appeal
The organisation may appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days of the DPBI order. To file an appeal, 50% of the penalty amount must be deposited or security provided. Further appeals on questions of law may be made to the Supreme Court of India.
Key point: DPBI inquiries must be completed within six months under the DPDP Rules 2025, unless extended for specific, recorded reasons.
6 Factors the DPBI Considers Before Imposing a Penalty
Section 33(2) requires the Board to weigh six factors before setting the final penalty amount within the Schedule’s ceiling.
Nature, Gravity, and Duration
How serious the non-compliance was and how long it persisted.
Type of Personal Data Affected
Sensitive categories — financial, health, children's data — attract higher penalties.
Repeat Offences
A prior violation by the same entity results in harsher treatment.
Advantage Gained or Loss Avoided
Whether the organisation profited from, or avoided cost by, the non-compliance.
Remedial Action Taken
Timeliness and effectiveness of the mitigation steps the organisation undertook.
Proportionality
Whether the penalty is effective and proportionate given the entity's size and circumstances.
Organisations that report breaches promptly, cooperate fully with the DPBI, and demonstrate genuine corrective action are, in practice, positioned for lower penalties than those that delay or conceal.
Does the DPDP Act Have Criminal Penalties?
No Imprisonment
The DPDP Act has no provision for imprisonment or any other criminal sanction, for either organisations or individuals within them.
Financial Penalties Only
All enforcement is monetary — ₹10,000 to ₹250 crore per violation, decided by the DPBI, not a criminal court.
No. The DPDP Act 2023 has no provision for imprisonment or any other criminal sanction, for either organisations or individuals within them. All enforcement is monetary and decided by the DPBI.
This is a deliberate policy choice and a sharp break from earlier draft versions of India's data protection legislation, which had included criminal liability. The final Act prioritises financial deterrence to encourage responsible data management while avoiding the chilling effect criminal penalties can have on legitimate data-driven business and innovation.
DPDP Penalties vs GDPR: A Quick Comparison
Side-by-side view of how India's DPDP Act compares with the EU's GDPR on penalties, enforcement, and appeal pathways.
| Feature | DPDP Act (India) | GDPR (EU) |
|---|---|---|
| Maximum penalty | ₹250 crore (~US$30M) per violation | Up to 4% of global annual turnover |
| Penalty structure | Absolute fixed caps set by Schedule | Percentage of revenue — scales with company size |
| Criminal sanctions | None | None at EU level; varies by member state |
| Enforcement body | Data Protection Board of India (DPBI) | National supervisory authorities (e.g. ICO, CNIL) |
| Appeal path | TDSAT → Supreme Court of India | National courts |
| Cumulative penalties | Yes — per violation, per inquiry | Yes — per violation |
Fixed caps cut both ways: for global tech giants, GDPR’s revenue-linked fines can far exceed DPDP’s absolute limits. But for small and mid-sized Indian businesses, a ₹250 crore fine could be company-ending, since the DPDP Act does not adjust penalties based on ability to pay.
Industries Most at Risk
Organizations handling high volumes of sensitive personal data face the highest regulatory exposure under the DPDP Act.
Banks & NBFCs
Financial and identity data at scale, plus frequent third-party data sharing with processors and fintech partners.
Healthcare Providers
Sensitive health records and frequent handling of family or dependent data, including minors.
FinTech Platforms
High-volume onboarding (KYC), consent-manager integrations, and cross-border data flows.
E-commerce Companies
Large consumer databases, marketing consent complexity, and frequent processor relationships across logistics, payments, and ad-tech.
EdTech Platforms
Direct exposure to children's data rules and parental-consent verification requirements.
Social Media Platforms
Scale, behavioural tracking, and a high likelihood of Significant Data Fiduciary designation.
How to Reduce DPDP Penalty Risk
Not a substitute for legal advice — but these are the foundational steps most compliance teams treat as table stakes for reducing DPDP enforcement exposure.
Audit Your Data Processing Activities
Map every category of personal data collected, why it is collected, where it is stored, and how long it is retained.
Fix Consent & Notice Mechanisms
Obtain consent before processing begins, and write notices that are clear, specific, and in plain language.
Implement Security Safeguards
Encryption, role-based access control, vulnerability assessments, and documented security procedures.
Build a Breach Notification Protocol
Internal workflows to detect, escalate, and report breaches — immediate intimation to the DPBI on becoming aware, then a detailed report within 72 hours under Rule 7.
Set Up a Grievance Redressal Mechanism
A responsive internal system, since Data Principals must approach the organisation before filing with the DPBI.
Respond to Data Principal Requests
Handle access, correction, and erasure requests within the mandatory 90-day window.
Prepare for Significant Data Fiduciary Obligations
If processing large volumes of sensitive data, start preparing now for DPO appointment, DPIAs, and independent audits.
Vet Every Processor Contract
Liability for a processor's failure still lands on the Fiduciary, so contracts need enforceable security and breach-reporting clauses.
Key DPDP Enforcement Dates
Important milestones in India's DPDP enforcement and compliance timeline.
August 11, 2023
DPDP Act receives Presidential assent
India formally introduces its digital personal data protection law.
November 13–14, 2025
DPDP Rules 2025 notified
MeitY notifies the final Rules in the Gazette of India under Section 40; the Data Protection Board of India is constituted as a fully digital body.
November 13, 2026
Consent Manager obligations begin
Registration and compliance obligations for Consent Managers take effect.
May 13, 2027
Full operational enforcement
Core DPDP compliance obligations come fully into force across all covered organisations.
August 11, 2023
DPDP Act receives Presidential assent
India formally introduces its digital personal data protection law.
November 13–14, 2025
DPDP Rules 2025 notified
MeitY notifies the final Rules in the Gazette of India under Section 40; the Data Protection Board of India is constituted as a fully digital body.
November 13, 2026
Consent Manager obligations begin
Registration and compliance obligations for Consent Managers take effect.
May 13, 2027
Full operational enforcement
Core DPDP compliance obligations come fully into force across all covered organisations.
Conclusion
The DPDP Act 2023 marks a fundamental shift in how India treats data protection — from a framework of vague obligations to a legally enforceable regime with real financial teeth. The Data Protection Board of India is now constituted and digital-first by design, and enforcement is a matter of when, not if.
For organisations, the priority is clear: understand your obligations, map your exposure against the penalty schedule, get the breach-notification clock and Significant Data Fiduciary requirements right, and build compliance systems that demonstrate genuine accountability — not just paper policies.
The window to May 2027 is not a grace period. It is preparation time. Use it.
This page is for general information and does not constitute legal advice. Verify current obligations against the DPDP Act 2023, the DPDP Rules 2025, and official notifications from MeitY and the Data Protection Board of India before making compliance decisions.
Frequently Asked Questions
₹250 crore per violation, for failure to implement adequate security safeguards under Section 8(5). Multiple violations arising from a single inquiry can result in cumulative fines that exceed this figure.
Prepare for DPDP Enforcement
Build a strong compliance framework before penalties become a business risk. Strengthen consent governance, breach response, and data protection practices with expert guidance.
Talk to a DPDP Expert