The DPDP penalty schedule
Four caps. Each cap attaches to a specific breach. Together they set the ceiling on what the Data Protection Board can impose. Read this page before you tell your board what "up to Rs. 250 crore" actually means for your business.
01How the schedule actually works
The Schedule to the DPDP Act 2023 lists four maximum penalty amounts. Section 33 tells the Data Protection Board how to pick a figure within each cap.
Each cap is a ceiling, not a fixed fine. The Board weighs the nature and gravity of the breach, the type and volume of personal data affected, the repetitive nature, whether you gained financially or avoided loss, mitigation steps, and other relevant factors. A single incident that triggers two caps (say, a security failure that also results in an unreported breach) can attract both caps.
02The four caps
Each cap ties to one or two specific sections of the Act. Below, each row lists the trigger, the cap, and the practical scenario it targets.
| Cap | Trigger | Section |
|---|---|---|
| Rs. 250 cr | Failure to take reasonable security safeguards to prevent a personal data breach. | Sec. 8(5) |
| Rs. 200 cr | Failure to notify a personal data breach to the Data Protection Board or to affected Data Principals. | Sec. 8(6) |
| Rs. 200 cr | Breach of additional obligations relating to children's personal data under Sec. 9. | Sec. 9 |
| Rs. 150 cr | Breach of additional obligations of a Significant Data Fiduciary under Sec. 10. | Sec. 10 |
| Rs. 50 cr | Any other violation of the DPDP Act or the DPDP Rules by a Data Fiduciary. | All other |
| Rs. 10,000 | Breach of a Data Principal's own duties under Sec. 15 (frivolous complaints, false information). | Sec. 15 |
Each row is a per-instance ceiling. The Board can find multiple instances in a single incident. There is no lifetime cap or annual cap. The Board is expected to publish reasoned orders explaining the amount chosen within each cap.
03Walking through each cap
Rs. 250 crore. Reasonable security safeguards under Sec. 8(5).
This is the highest cap and applies to a failure of your security controls. The Schedule does not say what "reasonable" means, but Section 8(5) obliges you to protect personal data by taking reasonable security safeguards to prevent a personal data breach. In practice the Board is expected to look at encryption at rest and in transit, access controls, patching cadence, secure development, vendor risk practice, and incident-response readiness. If any of these are absent or clearly below industry practice for your sector and scale, the Board can invoke this cap.
Sector regulators (RBI, IRDAI, SEBI) already publish security baselines. Falling short of your sector baseline will make the Rs. 250 crore cap easy for the Board to reach for.
Rs. 200 crore. Failure to notify a personal data breach under Sec. 8(6).
Section 8(6) requires you to notify the Data Protection Board and each affected Data Principal of any personal data breach. Rule 7 of the DPDP Rules 2025 will prescribe the form and timelines when Rule 7 comes into force on 14 May 2027. Missing either the Board notice or the Data Principal notice puts you in this cap.
Note the overlap with CERT-In. Under the CERT-In Directions of 28 April 2022, most cyber incidents must be reported to CERT-In within 6 hours. That obligation is separate from Section 8(6). Reporting to CERT-In does not satisfy Section 8(6).
Rs. 200 crore. Breach of children's data obligations under Sec. 9.
Section 9 sets three obligations for the processing of personal data of any Data Principal under 18. First, verifiable parental consent. Second, no tracking or behavioural monitoring of children. Third, no targeted advertising to children. Rule 10 of the DPDP Rules 2025 prescribes the mechanics of verifiable parental consent.
This cap sits alongside the security-safeguard cap. If your product processes children's data and you also fail a security check, both caps can attach to one incident.
Rs. 150 crore. Breach of Significant Data Fiduciary obligations under Sec. 10.
Sec. 10 applies only if the Central Government has designated you a Significant Data Fiduciary by notice. As of September 2026 no SDF designations have been publicly issued. Once you are designated, Rule 12 imposes an India-resident DPO, an annual DPIA, and an annual independent audit. Rule 13 adds an algorithm due-diligence obligation. Any failure across those four gives the Board this cap.
Rs. 50 crore. Any other violation.
The catch-all cap for anything that is not Sec. 8(5), Sec. 8(6), Sec. 9 or Sec. 10. This picks up most Data Principal rights failures under Sec. 11 to 14 (access, correction, erasure, nomination, grievance), consent hygiene under Sec. 6 and Sec. 7, retention failures under Rule 8, and Consent Manager failures under Rule 4. It is the cap the Board is likely to reach for most often in the first two years.
04The cap is a ceiling, not the fine. Here's how the Board picks a number.
Section 33(2) tells the Board to weigh six factors and record its reasons. There is no priority order among them, so no factor is a trump card.
The first factor is nature, gravity and duration. A one-hour misconfiguration is not the same as a two-year covert harvesting programme, even if the affected record count is similar. Duration matters as much as breadth.
The second, type and nature of the personal data, is where health records, financial data, biometric identifiers and children's data push the number up. Data the Data Principal has already made public pulls it down.
Third, repetition. Once the Board publishes its order register (Rule 22, from 14 May 2027), second offences will be easy to spot and fines are expected to scale sharply.
Fourth, gain or avoided loss. If the breach saved you compliance spend or if you monetised the data, the Board considers that quantum.
Fifth, mitigation. Fast notification to the Board and to the affected Data Principals, honest cooperation during investigation, and demonstrable remediation all reduce the amount. Silence and stalling do the opposite.
Sixth, the residual proportionality check. This is where turnover, market share, and repeat-offender status come in — the Board's escape hatch to keep the number sensible relative to the entity in front of it.