Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

DPDP Act penalties: fines up to Rs 250 crore explained (2026)

Penalties

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 9 min read

What are the penalties under the DPDP Act 2023?

The short answer

Once section 33 is in force, penalties under the DPDP Act 2023 are monetary, imposed by the Data Protection Board after an inquiry, and capped by the Act's Schedule. The highest cap is 250 crore rupees for a Data Fiduciary failing its reasonable security safeguards obligation under section 8(5). Failing to notify a breach or breaching children's data obligations may each draw up to 200 crore rupees, Significant Data Fiduciary obligations up to 150 crore rupees, any other breach up to 50 crore rupees, and a Data Principal breaching statutory duties up to 10,000 rupees. These provisions sit in the commencement group due 18 months from the notification gazette, which computes to 13 May 2027; that calendar date is interpretation until officially confirmed. As at 3 September 2026, no penalty could be imposed on anybody, for 2 independent reasons: section 33 had not commenced, and no appointment of a Chairperson or Member of the Board had been located on official channels.

More answered questions →

Diagram: The Schedule's penalty caps: every figure a ceiling, and no power to impose one yet, as at 3 September 2026. The same diagram appears further down this article, where it is described in full.
Status as at 3 September 2026: no penalty can be imposed, because the section 33 penalty power is not in force, computed 13 May 2027 and interpretation until officially confirmed, and because no appointment of a Chairperson or Member has been located, in MeitY's library on 3 September 2026 and a wider search dated 28 August 2026.

The DPDP Act 2023 does not scatter penalty amounts through its chapters. Every monetary cap sits in one place, the Schedule at the end of the Act, and one section, section 33, controls who imposes them and how they are sized.

Who imposes penalties, and when

Only the Data Protection Board of India imposes monetary penalties, and only at the end of a process.

DPDP Act 2023, s. 33 · Penalties · verbatim

"If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule."

Section 33(1) of the DPDP Act 2023.

3 gates are built into that sentence. There must be an inquiry that has concluded, the Board must determine that the breach is significant, and the person must have had an opportunity of being heard. A penalty is the outcome of that process, not an automatic consequence of a breach.

The 7 caps in the Schedule

The Schedule pairs each category of breach with a maximum. Every figure is a ceiling that the penalty "may extend to", not a fixed fine.

BreachProvisionMaximum penalty
Failing reasonable security safeguards to prevent personal data breachSection 8(5)Rs 250 crore
Failing to notify the Board or affected Data Principals of a breachSection 8(6)Rs 200 crore
Breach of additional obligations in relation to childrenSection 9Rs 200 crore
Breach of Significant Data Fiduciary obligationsSection 10Rs 150 crore
Breach of duties of Data PrincipalsSection 15Rs 10,000
Breach of a term of a voluntary undertaking accepted by the BoardSection 32Up to the cap for the original breach
Breach of any other provision of the Act or the rulesAny otherRs 50 crore

The Schedule of penalty caps, the gate that stands before them and their commencement status. The headline states that every figure is a ceiling and that there is no power to impose one yet, and the subtitle that a monetary penalty can be imposed only under section 33, which commences 18 months after the Gazette was published. Section 33(1) is printed in full from Gazette pages 16 and 17: the Board may impose a penalty specified in the Schedule only on conclusion of an inquiry, only where it determines the breach is significant, and only after giving the person an opportunity of being heard, which are 3 gates before any figure below applies. Every figure below reads may extend to. The caps are drawn to scale. Entry 1, security safeguards under section 8(5), Rs 250 crore. Entry 2, breach intimation under section 8(6), Rs 200 crore. Entry 3, children's obligations under section 9, Rs 200 crore. Entry 4, Significant Data Fiduciary obligations under section 10, Rs 150 crore. Entry 7, any other provision of the Act or rules, Rs 50 crore. Entry 5, the section 15 duties of a Data Principal, is Rs 10,000 and too small to draw. A panel headed what a cap is not, typed as this site's reading, states that the Board fixes the sum rather than the Schedule, because section 33(2) has the Board have regard to 7 matters when it sets a figure within the cap, among them gravity, duration, repetition and the timeliness of any mitigation; and that entry 6, breach of a voluntary undertaking under section 32, carries no figure of its own, being capped at the amount applicable to the breach whose section 28 proceedings the undertaking settled. A panel headed not in force records that sections 28 to 34 carry the inquiry, the appeal and this penalty power, that notification G.S.R. 843(E) commences them 18 months after its Gazette was published, printed 13 November 2025, and that paragraph (b) puts only section 6(9) and section 27(1)(d) in a 1 year group; that both computed dates, 13 November 2026 and 13 May 2027, are interpretations until officially confirmed; and that the Schedule operates through section 33(1), so on this site's reading it commences with section 33 and no amount is reachable without it, sections 28(11) and 32(5) being the 2 routes to a penalty and both sending the Board to section 33. A second panel records that there is no Board to impose one: G.S.R. 844(E) established the Board on 13 November 2025 and G.S.R. 845(E) notified that it shall consist of four members, but no appointment of a Chairperson or Member has been located, MeitY's library holding none on 3 September 2026 and the wider search of official channels being dated 28 August 2026. The footer records that the Schedule is printed on Gazette page 21 under its heading with the reference See section 33(1), and that entry 5 is its only rupee figure below a crore.

  • Security safeguards, section 8(5): a Data Fiduciary failing to take reasonable security safeguards to prevent personal data breach faces the highest cap, up to 250 crore rupees.
  • Breach notification, section 8(6): failing to give the Board or affected Data Principals notice of a personal data breach, up to 200 crore rupees.
  • Children's data, section 9: breach of the additional obligations in relation to children, up to 200 crore rupees.
  • Significant Data Fiduciary obligations, section 10: breach of the additional obligations placed on a Significant Data Fiduciary, up to 150 crore rupees.
  • Duties of Data Principals, section 15: breach of the statutory duties that the Act places on individuals, up to 10,000 rupees.
  • Voluntary undertakings, section 32: breach of any term of a voluntary undertaking accepted by the Board. This is the 1 entry in the Schedule that names no figure of its own. Its penalty column reads "Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted", so the ceiling is borrowed from the proceedings it settled.
  • Everything else: breach of any other provision of the Act or its rules, up to 50 crore rupees.

The ordering tells its own story. The framework weights security safeguard failures and failure to notify a breach most heavily, then child data and Significant Data Fiduciary duties, with a general residual cap for everything else.

The cap is a ceiling, not the amount

Every figure above is a maximum. The amount actually imposed is chosen by the Board under section 33(2), which directs it to have regard to 7 matters when it fixes a figure within the cap. Documented, prompt mitigation is 1 of those 7, so it is a statutory sizing factor rather than merely good practice. The 7 matters are quoted in full and taken clause by clause in the Board process guide, which owns that question; this page stays with the amounts and the Schedule.

Where the money goes

Section 34 answers a question boards and CFOs often ask: penalties are not compensation to affected individuals. The reverse of that question, what an affected individual actually gets, is answered in can I sue under the DPDP Act.

DPDP Act 2023, s. 34 · Crediting sums realised by way of penalties to Consolidated Fund of India · verbatim

"All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India."

Section 34 of the DPDP Act 2023.

When these provisions begin to operate

Sections 33 and 34 sit in the group that notification G.S.R. 843(E) brings into force 18 months from the publication of its gazette, printed 13 November 2025. That computes to 13 May 2027, and the computed calendar date is interpretation until officially confirmed. The notification names sections only; the Schedule takes effect through section 33(1), so the Schedule is presented as commencing with section 33, which is also a reading rather than an official statement.

The practical consequence: the substantive obligations whose breach these caps punish, such as security safeguards and breach notification under section 8, commence on the same computed date. Building the controls before the enforcement machinery switches on is the entire point of the phased timeline. The company action plan tool sequences that work, and the breach response tool covers the notification duty whose failure carries the 200 crore rupee cap.

Can a penalty be imposed today?

No, and for 2 independent reasons. They are usually run together as though they were 1, or dropped altogether in favour of the headline figure.

Section 33 has not commenced. Be exact about what that means, because the Act uses the word power in more than 1 place: section 27(1) confers on the Board the function to "impose penalty as provided in this Act", and section 33 is what that points to. What section 33 alone supplies is the amount. Every route to that amount runs through section 33 as well. Section 28(11) has the Board, on completion of an inquiry, "either close the proceedings or proceed in accordance with section 33", and section 32(5) sends it the same way when a voluntary undertaking is broken. Sections 28, 32 and 33 are all in the 18 month group, so until they commence there is no route to an amount, however serious a breach was.

The Board that section 33 empowers has no member appointed on the record. Notification G.S.R. 844(E) established the Data Protection Board of India on 13 November 2025, and G.S.R. 845(E) of the same date notified that the Board "shall consist of four members". An establishment notification appoints nobody, and a notified strength is not a staff. No appointment of a Chairperson or of any Member has been located, and the search behind that negative has 2 dates rather than 1. The wider search of official channels is dated 28 August 2026 and belongs to whether the Board is operational, which owns this question and sets out its limits, including that nothing could be read from MeitY's own Data Protection Board page. What this page adds is narrower and fresher: MeitY was still inviting applications for those posts by a circular of 6 May 2026, and MeitY's published document library, re enumerated on 3 September 2026, holds the same 28 DPDP records it held on 1 September, none of them notifying an appointment. A published library is not the Gazette, so neither check is a certified negative.

The 2 reasons are independent, and that is the point of separating them: a commencement date appoints nobody, and an appointment commences nothing.

Nothing in the Schedule begins on the computed 13 November 2026

G.S.R. 843(E) has a 1 year group as well as an 18 month one, and the 1 year group is where the timeline is most often stated wrongly. Paragraph (b) puts exactly 2 provisions in it: section 6(9), which requires every Consent Manager to be registered with the Board, and section 27(1)(d).

Section 27(1)(d) is worth being exact about, because it does use the words "impose penalty":

DPDP Act 2023, s. 27(1)(d) · Powers and functions of Board · verbatim

"on receipt of an intimation of breach of any condition of registration of a Consent Manager, to inquire into such breach and impose penalty as provided in this Act; and"

Section 27(1)(d) of the DPDP Act 2023.

On this site's reading that clause puts no amount in play on 13 November 2026, a computed date that is interpretation until officially confirmed, and the words carrying the reading are "as provided in this Act". The clause refers a penalty to machinery elsewhere and supplies none of its own. The amounts are in the Schedule, which is reachable only through section 33(1); section 33(1) can be reached only "on conclusion of an inquiry"; the Board takes action on a section 27(1) matter under section 28(2); and the 2 provisions that actually send the Board to section 33, sections 28(11) and 32(5), are in the 18 month group, as are sections 28 to 34 entire. So what arrives in November 2026 under this notification is a registration duty and a Board function, with the penalty they refer to waiting on the sections that supply it. No figure in this Schedule becomes payable by anybody on that date.

Section 33, official text with sources →The Schedule, official penalties table with sources →From complaint to penalty: the Board process and the section 33(2) matters →DPDP for founders and small teams →

PenaltiesScheduleSection 33Data Protection Board

Share this: