The penalty amounts in the Schedule
The Schedule to the Act lists the maximum penalty for each class of breach. Each figure is an upper limit that the Board may impose after an inquiry, as determined on the facts.
| Breach | Provision | Up to |
|---|---|---|
| Failure to take reasonable security safeguards | Section 8(5) | 250 crore rupees |
| Failure to notify a personal data breach | Section 8(6) | 200 crore rupees |
| Breach of children's data obligations | Section 9 | 200 crore rupees |
| Breach of Significant Data Fiduciary duties | Section 10 | 150 crore rupees |
| Breach of a Data Principal's duties | Section 15 | 10,000 rupees |
| Breach of other provisions (residual) | General | 50 crore rupees |
Each amount is a ceiling, not a fixed charge. The Board sets the actual figure, up to the ceiling, as determined after inquiry on the facts of the case.
How the Board sets a figure: Section 33(2)
Section 33(2) lists the factors the Board must consider when deciding the amount of a penalty. These keep the figure proportionate to the conduct.
- The nature, gravity and duration of the breach.
- The type and nature of the personal data affected.
- Whether the breach was repetitive.
- Any gain made or loss avoided as a result of the breach.
- Whether and how quickly the person took steps to mitigate the breach.
- Whether the penalty is proportionate and effective, having regard to the need to deter and to secure compliance.
The honest position on enforcement so far
The DPDP Rules, 2025 were notified in November 2025, and the core obligations are set to apply from May 2027 to give organisations time to prepare. That means, as of 2026, no penalty orders have been issued under the Act.
This is worth stating plainly, because some commentary implies enforcement is already live. The correct planning assumption is that the Board becomes operational and begins inquiries as the main obligations take effect, which makes the period before May 2027 the time to close gaps.
What reduces penalty exposure
Because the Board weighs mitigation and the security safeguards in place, the record an organisation can show matters. Documented safeguards, a tested breach response, and prompt notification all feed directly into the Section 33(2) factors.
The largest ceiling attaches to a failure of security safeguards, so demonstrable safeguards under Section 8(5) are the single most valuable thing to be able to prove.
How AMLEGALS advises on penalty exposure
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team assesses where your exposure sits against the Schedule, strengthens the evidence of safeguards and breach readiness that the Board weighs under Section 33(2), and represents organisations in inquiries before the Board.

