What are the penalties under the DPDP Act?

The DPDP Act provides for financial penalties imposed by the Data Protection Board of India after an inquiry, with the Schedule setting a maximum for each category of breach. The highest exposure attaches to failing to take reasonable security safeguards to prevent a personal data breach, at up to ₹250 crore. Failures relating to breach notification and to obligations concerning children's data sit in the next tier, with lower maxima for the additional obligations of Significant Data Fiduciaries and for other contraventions.

Jupinder Bedi

The amounts are maxima, not tariffs. The Board determines the penalty in each case having regard to matters such as the nature, gravity and duration of the breach, the type of personal data affected, whether the person took mitigating action, and the effect of the penalty.

The practical implication is that evidence of a functioning programme is itself mitigation. An organisation that can show what it held, on what basis, and what it did when something went wrong is in a materially different position from one that cannot.

This page is general information about the Act, not legal advice on your situation.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Jupinder BediJupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →