Penalties
DPDP Act penalties & enforcement
What it costs to get DPDP wrong — penalties up to ₹250 crore, how the Data Protection Board enforces them, and how to reduce your exposure.
The DPDP Act has teeth. Financial penalties run up to ₹250 crore, and enforcement sits with a dedicated regulator. This guide explains the penalties, who imposes them, and — more usefully — how to keep your exposure low. We do this without fear-mongering: the point isn't the scary number, it's that good engineering makes the number irrelevant.
Who enforces it: the Data Protection Board
The Data Protection Board of India is the independent regulator created by the Act. It investigates complaints from Data Principals and reports of breaches, gives organizations a chance to be heard, and can impose financial penalties for non-compliance. Its decisions are appealable.
The penalties
Penalties are graded to the nature and gravity of the failure. The headline figures (per the Act's schedule) include:
| Failure | Penalty up to |
|---|---|
| Failure to take reasonable security safeguards to prevent a breach | ₹250 crore |
| Failure to notify the Board / affected persons of a breach | ₹200 crore |
| Breach of additional obligations relating to children | ₹200 crore |
| Breach of additional obligations of Significant Data Fiduciaries | ₹150 crore |
| Breach of other provisions / duties | ₹50 crore |
| Breach of a voluntary undertaking | up to the applicable amount |
Data Principals also have duties, and there are smaller penalties for frivolous or false complaints.
How penalties are decided
The Board considers factors such as the nature and gravity of the breach, its duration, the type of data affected, whether it was repetitive, and what the organization did to mitigate. In other words: an organization that took compliance seriously and responded well is treated very differently from one that ignored its duties.
That's the key insight — demonstrable good-faith effort matters. Mapping your data, building real controls, and having a tested breach runbook aren't just risk reduction; they're evidence in your favor.
The real cost is bigger than the fine
A penalty is only part of the bill. A breach also brings:
- Reputational damage and lost customer trust,
- Lost enterprise deals (your buyers' due diligence will find the gap),
- Operational disruption while you firefight,
- and management distraction from the actual business.
How to keep your exposure low
The single biggest penalty attaches to failing to take reasonable security safeguards. So the highest-leverage work is exactly the engineering we specialize in:
- Encryption, access control, and audit logging — see Technical Implementation.
- A tested breach-notification runbook — part of Managed Compliance.
- Knowing your gaps before the Board does — a readiness audit.
- SDF duties handled if they apply — DPO-as-a-Service.
The cheapest way to avoid a ₹250 crore problem is to spend a small fraction of that, early, on getting the controls right.
See your current exposure in five minutes with the free DPDP Quick Scan.
General information, not legal advice. Penalty amounts are from the Act's schedule; confirm against the official text.
Frequently asked questions
Up to ₹250 crore for certain failures — most notably, failing to take reasonable security safeguards to prevent a personal data breach. Penalties are decided by the Data Protection Board after due process.
The Data Protection Board of India — an independent body that investigates complaints and breaches and can impose financial penalties.
See how this applies to you
The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.
Take the free Quick Scan