India Data Law

What are the penalties under the DPDP Act?

Verified August 2026

The Schedule to the Act sets seven penalty entries. The largest is 250 crore rupees, for failing to take reasonable security safeguards. No penalty has been imposed, for two reasons. The penalty sections do not come into force until 13 May 2027, and the Board that would impose them has no members.

The seven entries

The breachSectionUp to
Failure to take reasonable security safeguards to prevent a personal data breach.s.8(5)₹250 crore
Failure to notify the Board or the affected Data Principals of a personal data breach.s.8(6)₹200 crore
Breach of the additional obligations that apply to children's personal data.s.9₹200 crore
Breach of the additional obligations of a Significant Data Fiduciary.s.10₹150 crore
Breach of the duties the Act places on a Data Principal.s.15₹10,000
Breach of a term of a voluntary undertaking accepted by the Board.s.32The penalty for the breach the undertaking covered
Breach of any other provision of the Act or the Rules.Residual₹50 crore

Note the fifth entry. The Act places duties on the Data Principal. A breach of those duties carries a penalty of ten thousand rupees. The General Data Protection Regulation of the European Union has no equivalent provision.

How an amount is decided

Section 33(2) requires the Board to consider a set of factors before fixing an amount. The figures above are maximum amounts. The Board fixes each amount case by case. Section 33(2) names seven matters. They are the nature, gravity and duration of the breach. The type and nature of the personal data affected. Whether the breach is repetitive. Whether the person gained, or avoided a loss, as a result. What the person did to mitigate the effects, and how timely and effective that action was. Whether the penalty is proportionate and effective. The likely impact of the penalty on the person.

The Schedule can be changed, within a limit

Section 42 lets the Central Government amend the Schedule by notification. There is a ceiling on that power. No notification may increase a penalty to more than twice what the Act originally specified.

Why no penalty has been imposed

Sections 33 and 34, which carry the penalty and adjudication machinery, are in the group that starts on 13 May 2027. The obligations behind these penalties start on the same date. The Board, which is the only body that can impose a penalty, has no appointed chairperson and no appointed members. See the position on the Board and the status tracker.

What would change this page

A notification under section 42 amending the Schedule. An appointment to the Data Protection Board. The arrival of 13 May 2027, which makes the Schedule operative. The first order imposing a penalty, which would show how section 33(2) is applied in practice.