DPDP Act penalties: fines up to Rs 250 crore explained (2026)
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 9 min read
What are the penalties under the DPDP Act 2023?
The short answer
Once section 33 is in force, penalties under the DPDP Act 2023 are monetary, imposed by the Data Protection Board after an inquiry, and capped by the Act's Schedule. The highest cap is 250 crore rupees for a Data Fiduciary failing its reasonable security safeguards obligation under section 8(5). Failing to notify a breach or breaching children's data obligations may each draw up to 200 crore rupees, Significant Data Fiduciary obligations up to 150 crore rupees, any other breach up to 50 crore rupees, and a Data Principal breaching statutory duties up to 10,000 rupees. These provisions sit in the commencement group due 18 months from the notification gazette, which computes to 13 May 2027; that calendar date is interpretation until officially confirmed. As at 3 September 2026, no penalty could be imposed on anybody, for 2 independent reasons: section 33 had not commenced, and no appointment of a Chairperson or Member of the Board had been located on official channels.

The DPDP Act 2023 does not scatter penalty amounts through its chapters. Every monetary cap sits in one place, the Schedule at the end of the Act, and one section, section 33, controls who imposes them and how they are sized.
Who imposes penalties, and when
Only the Data Protection Board of India imposes monetary penalties, and only at the end of a process.
"If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule."
Section 33(1) of the DPDP Act 2023.
3 gates are built into that sentence. There must be an inquiry that has concluded, the Board must determine that the breach is significant, and the person must have had an opportunity of being heard. A penalty is the outcome of that process, not an automatic consequence of a breach.
The 7 caps in the Schedule
The Schedule pairs each category of breach with a maximum. Every figure is a ceiling that the penalty "may extend to", not a fixed fine.
| Breach | Provision | Maximum penalty |
|---|---|---|
| Failing reasonable security safeguards to prevent personal data breach | Section 8(5) | Rs 250 crore |
| Failing to notify the Board or affected Data Principals of a breach | Section 8(6) | Rs 200 crore |
| Breach of additional obligations in relation to children | Section 9 | Rs 200 crore |
| Breach of Significant Data Fiduciary obligations | Section 10 | Rs 150 crore |
| Breach of duties of Data Principals | Section 15 | Rs 10,000 |
| Breach of a term of a voluntary undertaking accepted by the Board | Section 32 | Up to the cap for the original breach |
| Breach of any other provision of the Act or the rules | Any other | Rs 50 crore |
- Security safeguards, section 8(5): a Data Fiduciary failing to take reasonable security safeguards to prevent personal data breach faces the highest cap, up to 250 crore rupees.
- Breach notification, section 8(6): failing to give the Board or affected Data Principals notice of a personal data breach, up to 200 crore rupees.
- Children's data, section 9: breach of the additional obligations in relation to children, up to 200 crore rupees.
- Significant Data Fiduciary obligations, section 10: breach of the additional obligations placed on a Significant Data Fiduciary, up to 150 crore rupees.
- Duties of Data Principals, section 15: breach of the statutory duties that the Act places on individuals, up to 10,000 rupees.
- Voluntary undertakings, section 32: breach of any term of a voluntary undertaking accepted by the Board. This is the 1 entry in the Schedule that names no figure of its own. Its penalty column reads "Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted", so the ceiling is borrowed from the proceedings it settled.
- Everything else: breach of any other provision of the Act or its rules, up to 50 crore rupees.
The ordering tells its own story. The framework weights security safeguard failures and failure to notify a breach most heavily, then child data and Significant Data Fiduciary duties, with a general residual cap for everything else.
The cap is a ceiling, not the amount
Every figure above is a maximum. The amount actually imposed is chosen by the Board under section 33(2), which directs it to have regard to 7 matters when it fixes a figure within the cap. Documented, prompt mitigation is 1 of those 7, so it is a statutory sizing factor rather than merely good practice. The 7 matters are quoted in full and taken clause by clause in the Board process guide, which owns that question; this page stays with the amounts and the Schedule.
Where the money goes
Section 34 answers a question boards and CFOs often ask: penalties are not compensation to affected individuals. The reverse of that question, what an affected individual actually gets, is answered in can I sue under the DPDP Act.
"All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India."
Section 34 of the DPDP Act 2023.
When these provisions begin to operate
Sections 33 and 34 sit in the group that notification G.S.R. 843(E) brings into force 18 months from the publication of its gazette, printed 13 November 2025. That computes to 13 May 2027, and the computed calendar date is interpretation until officially confirmed. The notification names sections only; the Schedule takes effect through section 33(1), so the Schedule is presented as commencing with section 33, which is also a reading rather than an official statement.
The practical consequence: the substantive obligations whose breach these caps punish, such as security safeguards and breach notification under section 8, commence on the same computed date. Building the controls before the enforcement machinery switches on is the entire point of the phased timeline. The company action plan tool sequences that work, and the breach response tool covers the notification duty whose failure carries the 200 crore rupee cap.
Can a penalty be imposed today?
No, and for 2 independent reasons. They are usually run together as though they were 1, or dropped altogether in favour of the headline figure.
Section 33 has not commenced. Be exact about what that means, because the Act uses the word power in more than 1 place: section 27(1) confers on the Board the function to "impose penalty as provided in this Act", and section 33 is what that points to. What section 33 alone supplies is the amount. Every route to that amount runs through section 33 as well. Section 28(11) has the Board, on completion of an inquiry, "either close the proceedings or proceed in accordance with section 33", and section 32(5) sends it the same way when a voluntary undertaking is broken. Sections 28, 32 and 33 are all in the 18 month group, so until they commence there is no route to an amount, however serious a breach was.
The Board that section 33 empowers has no member appointed on the record. Notification G.S.R. 844(E) established the Data Protection Board of India on 13 November 2025, and G.S.R. 845(E) of the same date notified that the Board "shall consist of four members". An establishment notification appoints nobody, and a notified strength is not a staff. No appointment of a Chairperson or of any Member has been located, and the search behind that negative has 2 dates rather than 1. The wider search of official channels is dated 28 August 2026 and belongs to whether the Board is operational, which owns this question and sets out its limits, including that nothing could be read from MeitY's own Data Protection Board page. What this page adds is narrower and fresher: MeitY was still inviting applications for those posts by a circular of 6 May 2026, and MeitY's published document library, re enumerated on 3 September 2026, holds the same 28 DPDP records it held on 1 September, none of them notifying an appointment. A published library is not the Gazette, so neither check is a certified negative.
The 2 reasons are independent, and that is the point of separating them: a commencement date appoints nobody, and an appointment commences nothing.
Nothing in the Schedule begins on the computed 13 November 2026
G.S.R. 843(E) has a 1 year group as well as an 18 month one, and the 1 year group is where the timeline is most often stated wrongly. Paragraph (b) puts exactly 2 provisions in it: section 6(9), which requires every Consent Manager to be registered with the Board, and section 27(1)(d).
Section 27(1)(d) is worth being exact about, because it does use the words "impose penalty":
"on receipt of an intimation of breach of any condition of registration of a Consent Manager, to inquire into such breach and impose penalty as provided in this Act; and"
Section 27(1)(d) of the DPDP Act 2023.
On this site's reading that clause puts no amount in play on 13 November 2026, a computed date that is interpretation until officially confirmed, and the words carrying the reading are "as provided in this Act". The clause refers a penalty to machinery elsewhere and supplies none of its own. The amounts are in the Schedule, which is reachable only through section 33(1); section 33(1) can be reached only "on conclusion of an inquiry"; the Board takes action on a section 27(1) matter under section 28(2); and the 2 provisions that actually send the Board to section 33, sections 28(11) and 32(5), are in the 18 month group, as are sections 28 to 34 entire. So what arrives in November 2026 under this notification is a registration duty and a Board function, with the penalty they refer to waiting on the sections that supply it. No figure in this Schedule becomes payable by anybody on that date.
Related tool
Compliance Plan
Generate 1 company level action plan and see the work for your role first.
Open
Related tool
Data Breach Response Playbook
Rule 7 is not in force yet, so plan its breach steps now, including the 72 hour submission to the Board, against the exact requirements.
Open
Section 33, official text with sources →The Schedule, official penalties table with sources →From complaint to penalty: the Board process and the section 33(2) matters →DPDP for founders and small teams →