On this page
₹250 crore is the largest figure in the Schedule to the Digital Personal Data Protection Act, 2023. It is a ceiling for one category of breach, not a fixed fine. The Act also sets out who can trigger an inquiry by the Data Protection Board of India and what the Board must find before it can penalise anyone. It then lists what the Board must weigh when it fixes an amount.
The Schedule: seven ceilings
Section 33(1) points to the Schedule at the end of the Act. Six of its seven rows say the penalty “may extend to” an amount. Row 6 is tied to the breach in the original proceedings.
| Sl. | Breach | Penalty may extend to |
|---|---|---|
| 1 | Failing to take reasonable security safeguards to prevent a personal data breach (Section 8(5)) | ₹250 crore |
| 2 | Failing to notify the Board or affected Data Principals of a personal data breach (Section 8(6)) | ₹200 crore |
| 3 | Breaching the additional obligations for children (Section 9) | ₹200 crore |
| 4 | Breaching the additional obligations of a Significant Data Fiduciary (Section 10) | ₹150 crore |
| 5 | Breaching the duties of a Data Principal (Section 15) | ₹10,000 |
| 6 | Breaching a voluntary undertaking accepted by the Board (Section 32) | Up to the amount applicable to the breach for which the Section 28 proceedings were started |
| 7 | Breaching any other provision of the Act or the Rules | ₹50 crore |
The Schedule sets no minimum and no aggregate cap. The Act does not say how penalties for several breaches in one inquiry combine.
What the video shows
- How big can a DPDPA penalty be?
- UP TO
- ₹250 crore
- for failing to take reasonable security safeguards
- Two more ceilings
- UP TO / ₹200 crore Not giving the Board or affected people notice of a breach
- UP TO / ₹200 crore Breaching the additional duties for children's data
- Five of the seven Schedule items, in ₹ crore
- Security safeguards: Up to 250
- Breach notice: Up to 200
- Children's data duties: Up to 200
- Significant Data Fiduciary duties: Up to 150
- Any other provision: Up to 50
- A ceiling is a maximum.
- 1 The Board holds an inquiry
- 2 It finds the breach significant
- 3 You get a chance to be heard
- 4 It may impose a penalty up to the Schedule ceiling
- Penalties can be imposed from 13 May 2027
Who can start a Board inquiry
Section 27(1) lists the Board’s powers and functions. Each one starts from a specific trigger:
- an intimation of a personal data breach under Section 8(6), on which the Board may also direct urgent remedial or mitigation measures;
- a complaint by a Data Principal about a personal data breach, or about a Data Fiduciary’s breach of its obligations to her or of her rights; or a reference from the Central Government or a State Government, or a court’s direction;
- a complaint by a Data Principal about a Consent Manager;
- an intimation that a Consent Manager has breached a condition of its registration;
- a reference from the Central Government about an intermediary breaching Section 37(2).
The list does not include the Board starting an inquiry on its own initiative. For most businesses, the realistic triggers are their own breach intimation, a complaint from a customer or employee, or a government reference.
A Data Principal must first use your grievance redressal mechanism before approaching the Board (Section 13(3)). A grievance process that works gives you the first chance to resolve a complaint.
From trigger to penalty
Section 28 sets the procedure. The Board first decides whether there are sufficient grounds to inquire; if not, it may close the proceedings, recording its reasons (Section 28(3) and (4)). If it inquires, it follows the principles of natural justice and records its reasons (Section 28(6)). It may issue interim orders after giving the person concerned an opportunity of being heard (Section 28(10)).

Rule 19(9) gives the Board six months from receiving the intimation, complaint, reference or direction to complete the inquiry. It may extend that for recorded reasons, by up to three months at a time.
At the end, after giving the person an opportunity of being heard, the Board either closes the proceedings or proceeds under Section 33 (Section 28(11)). Section 33(1) then sets the threshold: a penalty is possible only if the Board determines, on conclusion of the inquiry, that the breach is significant, and only after giving the person an opportunity of being heard.
The seven factors that set the amount
Section 33(2) lists what the Board must have regard to when it fixes the amount:
- the nature, gravity and duration of the breach;
- the type and nature of the personal data affected;
- whether the breach is repetitive;
- whether the person realised a gain or avoided a loss as a result;
- whether the person took action to mitigate the effects, and how timely and effective it was;
- whether the penalty is proportionate and effective, given the need to secure compliance and deter breaches;
- the likely impact of the penalty on the person.
Factor (e) is the one you control after something goes wrong. A breach log, a dated mitigation record and notices sent on time are the evidence the Board would look at under it.
Voluntary undertakings and appeals
At any stage of a Section 28 proceeding, the Board may accept a voluntary undertaking, such as a commitment to take or stop an action within a set time (Section 32(1) and (2)). Once accepted, it bars further proceedings on its contents (Section 32(4)). Breaking it is treated as a breach of the Act (Section 32(5)), with the ceiling in Schedule item 6.
Anyone aggrieved by a Board order or direction may appeal to the Appellate Tribunal, which Section 2(a) defines as the Telecom Disputes Settlement and Appellate Tribunal. The appeal is due within sixty days of receiving the order or direction, and the Tribunal may accept a late appeal for sufficient cause (Section 29(2) and (3)). Rule 22 requires the appeal to be filed in digital form. Penalties the Board collects go to the Consolidated Fund of India (Section 34).
When this starts
Sections 27 (except clause (d) of Section 27(1)), 28 to 34, and the duties the Schedule refers to come into force eighteen months after G.S.R. 843(E) was published on 13 November 2025, which is 13 May 2027. Rule 22 starts on the same date under Rule 1(4).
How to use the ceilings
The ceilings show where the Act allows the largest penalties. They are not a cost estimate. Security safeguards carry the highest ceiling (₹250 crore); breach notification and the children’s obligations share the next (₹200 crore). Because the amount depends on Section 33(2), the practical defence is evidence: documented safeguards, a working grievance process, and a record of what you did and when.
One further consequence sits outside the Schedule. Under Section 37(1), the Board may send the Central Government a written reference. It reports that the Board has penalised a Data Fiduciary (the person or business that decides why and how personal data is processed) in two or more instances. It advises blocking public access to information held in any computer resource that enables the Data Fiduciary to offer goods or services to people in India. After giving the Data Fiduciary an opportunity of being heard, the government may order that blocking in the interests of the general public. Section 37 also starts on 13 May 2027.
Common questions
What is the maximum penalty under the DPDP Act?
Up to ₹250 crore, for failing to take reasonable security safeguards to prevent a personal data breach. Failing to notify the Board or the affected people of a breach, and breaching the extra duties for children, each carry up to ₹200 crore.
Are the penalty amounts fixed?
No. The Schedule says a penalty may extend to an amount. The Board decides the amount after an inquiry, having regard to seven matters, including the nature, gravity and duration of the breach, whether it was repeated, and what the person did to reduce its effects.
When can the Board impose a penalty?
Only if it decides, on conclusion of an inquiry, that the breach is significant, and after giving the person an opportunity of being heard.
Can a person be penalised for a false complaint?
Yes. The Act’s duties for Data Principals include not registering a false or frivolous grievance or complaint, and breaching them can bring a penalty of up to ₹10,000. The Board can also warn a complainant or impose costs.
Can a Board order be appealed?
Yes. A person aggrieved by an order or direction of the Board can appeal to the Telecom Disputes Settlement and Appellate Tribunal within sixty days of receiving it. The Tribunal may allow a late appeal if there was sufficient cause.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 01: Start here, in the toolkit
- How-to 12: Bonus tools, in the toolkit
- The free duties list, every duty in plain words
In the news
- Companies can save up to ₹250 crore: Navigating the DPDP Act 2023
A law-firm view of how penalty exposure shapes compliance priorities.
- The Digital Gavel: Navigating Adjudication Under DPDP Act, 2023
Explains how adjudication under the Act works; compare with our trigger-to-penalty steps.
Sources
Every section, rule and date above was checked against the official text on 5 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 2(a)Appellate Tribunal: the Telecom Disputes Settlement and Appellate Tribunal
- Section 8(5)Security safeguards (item 1)
- Section 8(6)Breach intimation (item 2)
- Section 9Children (item 3)
- Section 10Significant Data Fiduciaries (item 4)
- Section 13(3)Grievance redressal to be exhausted before approaching the Board
- Section 15Duties of Data Principals (item 5)
- Section 27(1)The Board's powers and the triggers for each, clauses (a) to (e)
- Section 28Inquiry procedure, including sub-sections (3), (4), (6), (10) and (11)
- Section 29Appeal within sixty days; late appeals for sufficient cause
- Section 32Voluntary undertakings (item 6)
- Section 33(1)Penalty only for a significant breach, on conclusion of an inquiry, after giving the person an opportunity of being heard
- Section 33(2)Seven factors for the amount
- Section 34Penalties credited to the Consolidated Fund of India
- Section 37Blocking on a Board reference after penalties in two or more instances (1); intermediary duty referenced in Section 27(1)(e) (2)
- The Schedule, items 1 to 7Penalty ceilings: items 1 to 5 and 7 "may extend to" an amount; item 6 follows the original breach
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rule 22 in force eighteen months from publication
- Rule 19(9)Inquiry within six months, extendable by up to three months at a time
- Rule 22Appeal filed in digital form
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 27 (except 27(1)(d)), 28 to 34 and 37 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.



