At a glanceThe DPDP Act sets financial penalties, not jail. The Schedule runs in tiers: up to ₹250 crore for failing to keep personal data secure, up to ₹200 crore for a mishandled data breach and for children’s-data failures, up to ₹150 crore for a Significant Data Fiduciary’s extra duties, and up to ₹50 crore for most other breaches. These are ceilings — the Data Protection Board sets the actual amount after an inquiry.
Educational resource only. This explains the penalty framework under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and its Rules; it is not formal legal advice.
How big are the penalties?
The penalties are civil and financial, capped tier by tier in the Act’s Schedule — and the ceilings are high. The Schedule ties a maximum penalty to each category of failure:
| Failure | Maximum penalty |
|---|---|
| Not taking reasonable security safeguards to protect data (Section 8(5)) | up to ₹250 crore |
| Not notifying a personal data breach to the Board or affected people (Section 8(6)) | up to ₹200 crore |
| Breaching the obligations for children’s data (Section 9) | up to ₹200 crore |
| A Significant Data Fiduciary’s additional obligations (Section 10) | up to ₹150 crore |
| Any other breach of the Act or its Rules | up to ₹50 crore |
| A Data Principal breaching their own duties (Section 15) | up to ₹10,000 |
The number that gets quoted — “₹250 crore” — is the top of the range, reserved for a security failure. But note that even the residuary “any other breach” line reaches ₹50 crore, so there is no small-print corner of the Act that carries a token fine.
Who decides the amount, and how?
The Data Protection Board of India (DPBI) sets the actual penalty after an inquiry — the Schedule numbers are ceilings, not automatic fines. A breach doesn’t trigger a fixed amount; the Board (the DPBI) decides where within the range a case lands, and it weighs defined factors: the nature, gravity and duration of the breach, the type of data affected, whether it was repetitive, any gain the business made or loss it avoided, whether it acted to mitigate, and whether the penalty is proportionate and effective.
The practical read: genuine effort counts. A business that took reasonable steps, caught a problem, and mitigated it is treated differently from one that ignored its obligations — even if both technically breached.
Which mistake is the most expensive?
Weak security is the single costliest failure — up to ₹250 crore — and it’s assessed on its own, separate from whether you reported the breach. The top tier attaches to not having reasonable security safeguards in place. That matters because a real incident often triggers two lines at once: the failure to secure the data (up to ₹250 crore) and the failure to notify the breach properly (up to ₹200 crore).
Reporting the breach correctly does not cure the underlying security failure that let it happen — they’re penalised separately. So DPDP compliance is about both prevention and response, not one or the other.
Do affected individuals get compensation?
No — DPDP penalties are paid to the government, not to the people whose data was exposed. This is a common misunderstanding. The Act is an enforcement regime, not a compensation one: a penalty imposed by the Board goes to the Consolidated Fund of India, and the DPDP Act does not create a right for an individual to be paid damages for the harm.
An affected person’s route is to raise a grievance with the business and, if unresolved, complain to the Board — which can penalise the business, but won’t award them money. (Other laws may offer separate remedies, but that’s outside the DPDP Act.)
Can an individual be penalised too?
Yes — a Data Principal has duties as well, and breaching them can cost up to ₹10,000. It’s easy to read the Act as one-directional, but it places duties on individuals too: not to file false or frivolous complaints, not to impersonate someone else when giving data, and not to suppress material information. Breach of these can draw a penalty up to ₹10,000.
It’s a small figure next to the business tiers, but it’s a real reminder that the Act binds both sides — a point worth knowing before firing off a complaint.
When do these penalties start to bite?
The Board and its penalty powers exist now, but the obligations they enforce become binding on 13 May 2027 — so real exposure builds toward that date. The enforcement machinery (the Board, the penalty framework) was notified on 13 November 2025 and is operational. The substantive duties that carry these penalties — security safeguards, breach notification, children’s-data rules, Significant Data Fiduciary obligations — come into force 18 months later, on 13 May 2027.
That gap is the window. The penalties aren’t hypothetical for long, and the ₹250 crore and ₹200 crore tiers turn on things — how you secure and how you report — that take time to build. The runway is for getting them in place before the duty bites.
FAQ
What is the maximum penalty under the DPDP Act?
Up to ₹250 crore, for failing to take reasonable security safeguards to protect personal data. Other failures carry their own lower ceilings.
Is there jail time under the DPDP Act?
No. The DPDP Act’s penalties are civil and financial; it does not create criminal imprisonment for these breaches.
Will I be compensated if a company leaks my data?
Not under the DPDP Act — penalties go to the government, not to affected individuals. Your route is a grievance to the business and then a complaint to the Data Protection Board.
Are these fines being issued already?
The Board and penalty framework are in force, but the substantive obligations they enforce become binding on 13 May 2027, so that’s when exposure for those breaches begins in earnest.