Penalties
DPDPA penalties: how big can one get? Up to ₹250 crore
The Schedule sets maximums. The Board fixes an amount only after an inquiry finds a significant breach, using seven factors set out in the Act.
Our article · Penalties ·
6 min read

Friday, 9 October 2026
Get the toolkitFriday, 9 October 2026Today’s edition
India’s Digital Personal Data Protection Act and Rules: dated headlines, our articles and our updates
Security safeguards
The Rules list seven minimum safeguards, from data security to keeping logs for a year. The duty starts on 13 May 2027.
Registration
Only Consent Managers register with the Board; those rules come into force on 13 November 2026. Significant Data Fiduciaries are notified by the government. Other businesses meet the duties from 13 May 2027.
Erasure
Erase on request unless keeping the data is necessary for the purpose or to comply with a law. The Act and Rules name no invoice period, so the period comes from the other law.
Vendors
Where a supplier stores or handles customer data for you, it is your Data Processor and you stay responsible. What the law asks, with Zoho, Tally, Google Workspace and WhatsApp Business as examples of where data sits.
DPDPA Support
Small business
The law has no size test. These are the duties that start on 13 May 2027, with our own first steps for a shop, an app, a coaching institute or a salon, clearly labelled.
Children’s data
Clinics and hospitals
Consent Managers
Definitions
Retention
Privacy page
Other laws
The DPDP Act adds to other laws and prevails only to the extent of a conflict. It amends the IT Act, including omitting 43A, from 13 May 2027.
5 min read
Sections of our articles that give our own opinion on what to do. The law each one relies on is cited earlier in that article.
The Act has no startup test. The government may notify startups out of five named provisions. We have seen no such notification as of 7 Oct 2026. Duties start on 13 May 2027.
Only Consent Managers register with the Board; those rules come into force on 13 November 2026. Significant Data Fiduciaries are notified by the government. Other businesses meet the duties from 13 May 2027.
The law has no size test. These are the duties that start on 13 May 2027, with our own first steps for a shop, an app, a coaching institute or a salon, clearly labelled.
The Schedule sets maximums. The Board fixes an amount only after an inquiry finds a significant breach, using seven factors set out in the Act.
The DPDP Act adds to other laws and prevails only to the extent of a conflict. It amends the IT Act, including omitting 43A, from 13 May 2027.
Two instruments dated 13 November 2025 set three dates. Most duties on businesses start on the third.
A child is anyone under 18. You need a parent’s verifiable consent first, and you may not track, behaviourally monitor or target ads at children unless an exemption applies.
The three roles in the DPDP Act on one page, with the Act’s definitions in plain words and what each role owes.
The Rules list seven minimum safeguards, from data security to keeping logs for a year. The duty starts on 13 May 2027.
The law does not use the words privacy policy. It asks for a notice, a contact, a way to make requests and a grievance period.
Registration of Consent Managers starts on 13 November 2026. Data Fiduciary duties start later, on 13 May 2027.
Every request for consent needs a notice that comes with it or before it. The Act and the Rules set the minimum contents.
Erase on request unless keeping the data is necessary for the purpose or to comply with a law. The Act and Rules name no invoice period, so the period comes from the other law.
Erase when the purpose ends unless a law says to keep it. Logs and related data are kept for at least one year for purposes the Rules list, then erased. Large platforms have a three-year limit.
A person uses your grievance process first. The Board then checks, inquires and hears you, and an order can be appealed within 60 days.
The Act gives people four rights against a Data Fiduciary. The Rules cap the grievance response period at 90 days. The 90 days covers the reply to a grievance.
Only a Significant Data Fiduciary, which the Central Government notifies, must appoint a DPO and run DPIAs. Those duties start on 13 May 2027.
Where a supplier stores or handles customer data for you, it is your Data Processor and you stay responsible. What the law asks, with Zoho, Tally, Google Workspace and WhatsApp Business as examples of where data sits.
Patient records are personal data like any other. The Act lists medical emergencies as a use that needs no consent, and the Rules give clinics a limited exemption for children’s data.
The Act keeps the duty with you whatever the contract says, and requires a valid contract for processors engaged to help you offer goods or services.
The Act allows transfers abroad unless the government restricts a country by notification. The Rules add requirements about foreign States, and stricter Indian law still applies.
Two filings to the Board and a notice to every affected person. What each must contain, and when it is due.
The Rules list seven minimum safeguards, from data security to keeping logs for a year. The duty starts on 13 May 2027.
Registration of Consent Managers starts on 13 November 2026. Data Fiduciary duties start later, on 13 May 2027.
Erase when the purpose ends unless a law says to keep it. Logs and related data are kept for at least one year for purposes the Rules list, then erased. Large platforms have a three-year limit.
The Act gives people four rights against a Data Fiduciary. The Rules cap the grievance response period at 90 days. The 90 days covers the reply to a grievance.
A person uses your grievance process first. The Board then checks, inquires and hears you, and an order can be appealed within 60 days.
The Schedule sets maximums. The Board fixes an amount only after an inquiry finds a significant breach, using seven factors set out in the Act.
Two filings to the Board and a notice to every affected person. What each must contain, and when it is due.
Erase on request unless keeping the data is necessary for the purpose or to comply with a law. The Act and Rules name no invoice period, so the period comes from the other law.
A child is anyone under 18. You need a parent’s verifiable consent first, and you may not track, behaviourally monitor or target ads at children unless an exemption applies.
The Act allows transfers abroad unless the government restricts a country by notification. The Rules add requirements about foreign States, and stricter Indian law still applies.
The Act has no startup test. The government may notify startups out of five named provisions. We have seen no such notification as of 7 Oct 2026. Duties start on 13 May 2027.
Only Consent Managers register with the Board; those rules come into force on 13 November 2026. Significant Data Fiduciaries are notified by the government. Other businesses meet the duties from 13 May 2027.
Where a supplier stores or handles customer data for you, it is your Data Processor and you stay responsible. What the law asks, with Zoho, Tally, Google Workspace and WhatsApp Business as examples of where data sits.
The law has no size test. These are the duties that start on 13 May 2027, with our own first steps for a shop, an app, a coaching institute or a salon, clearly labelled.
Tick what you collect, the tools you use and where data goes, and see the DPDP Act duties and toolkit documents that match.
The DPDPA duties in plain words, each with its section or rule.
Each date is cited in our timeline article.
Headlines are quoted as each outlet published them, and each links to that outlet’s own page. For what applies and from when, see the DPDP Act timeline. The page changes when the site is rebuilt.
A drafting aid. Get legal advice for your situation. These pages report the published text.