AMLEGALS — Strategic Lawyering
DPDPA enforcement · Defence

DPDPA penalty defence: Board inquiry representation, mitigating factors and the appeal route

When the Data Protection Board initiates an inquiry under Section 28, the Data Fiduciary has the right to be heard. The outcome depends on the evidence of compliance steps already taken, the factors the Board must consider under Section 33(2), and the quality of the representations. This guide maps the process from complaint to appeal.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 5 min read

A gavel beside a legal brief and a compliance evidence folder with a gold accent, representing DPDPA enforcement defence
Short answer

Under the Digital Personal Data Protection Act, 2023, the Data Protection Board may initiate an inquiry upon receiving a complaint from a Data Principal or a reference from the Central Government or State Government (Section 28). The Board must give the Data Fiduciary a reasonable opportunity of being heard (Section 28(4)). In determining the penalty, the Board considers the factors in Section 33(2): the nature, gravity and duration of the breach, the type and nature of personal data affected, the repetitive nature of the breach, whether the person gained financially from the breach, whether the person took steps to mitigate the effects, and the timeliness and effectiveness of the mitigation. Penalties are subject to the ceilings in the Schedule. An appeal against a Board order lies to the Appellate Tribunal under Section 29, and further to the High Court under Section 30. Rule 22 prescribes the appeal procedure.

  • Penalty defence
  • Board inquiry
  • Section 28
  • Section 33
  • Appellate Tribunal
  • Rule 22
  • DPDP Rules 2025
  • Enforcement
Inquiry trigger
Complaint by Data Principal or reference by Central/State Government (Section 28)
Right to be heard
The Board must give a reasonable opportunity of being heard (Section 28(4))
Penalty factors
Six factors under Section 33(2), including mitigation steps taken
Appeal route
Appellate Tribunal (Section 29, Rule 22), then High Court (Section 30)

How the Board conducts an inquiry

Section 27 establishes the Data Protection Board of India. Section 28 gives the Board power to inquire into breaches of the Act. An inquiry may be initiated upon receiving a complaint from a Data Principal (after the Data Fiduciary’s grievance mechanism has been exhausted) or upon a reference by the Central Government or a State Government.

The Board must give the person against whom the inquiry is conducted a reasonable opportunity of being heard (Section 28(4)). Rules 17 to 21 prescribe the procedure for inquiries conducted by the Board.

The inquiry is conducted on the basis of evidence. The Board may direct the production of information and documents (Section 28(3)). The Board is not bound by the procedure of the Code of Civil Procedure, 1908 but must follow the principles of natural justice (Section 28(5)).

The factors the Board considers in determining the penalty

Section 33(2) lists the factors the Board must have regard to when determining the penalty:

  • The nature, gravity and duration of the breach.
  • The type and nature of the personal data affected by the breach.
  • The repetitive nature of the breach.
  • Whether the person gained or avoided any loss as a result of the breach.
  • Whether the person took any action to mitigate the effects of the breach and the timeliness and effectiveness of such action.
  • Whether the penalty is proportionate and effective, having regard to the need to ensure compliance with the provisions of the Act.

Penalty defence centres on the fifth factor: demonstrating the steps the organisation took to comply, the timing of those steps, and their effectiveness. This is where the evidence from audits, DPIAs, breach exercises, training records and remediation plans becomes relevant.

Penalty ceilings under the Schedule

The Schedule to the Act prescribes the maximum penalty for each category of breach:

DPDPA penalty ceilings by breach category
Breach categorySchedule referenceMaximum penalty
Failure to take reasonable security safeguardsSection 8(5)Up to ₹250 crore
Failure to notify the Board and affected Data Principals of a breachSection 8(6)Up to ₹200 crore
Breach of duties relating to childrenSection 9Up to ₹200 crore
Breach of additional obligations of Significant Data FiduciarySection 10Up to ₹150 crore
Breach of any other provision of the Act or RulesResidualUp to ₹50 crore
Breach of duties of Data PrincipalSection 15Up to ₹10,000

These are ceilings, not fixed amounts. The Board determines the actual penalty based on the Section 33(2) factors after giving the person a reasonable opportunity of being heard.

The appeal route: Appellate Tribunal and High Court

Section 29 provides that any person aggrieved by an order of the Board may prefer an appeal to the Appellate Tribunal. Rule 22 prescribes the appeal procedure, including the time limit and the form of appeal.

Section 30 provides for a further appeal from the Appellate Tribunal to the High Court on any question of law. The High Court’s decision is final.

An appeal does not automatically stay the penalty. The Appellate Tribunal may grant a stay on such conditions as it considers fit.

What effective penalty defence looks like

Defence is not about the moment of the inquiry. It is about the evidence that exists by the time the inquiry happens. The Section 33(2) factors reward organisations that took steps to comply and to mitigate, and that can show when they took them.

  • Audit trail: dated records of the compliance programme—the data map, notices, consent logs, vendor register, breach plan, training records, DPIA reports, audit reports, retention schedules and erasure records.
  • Breach response: evidence that the breach plan was current, that notification was timely, and that steps were taken to limit harm.
  • Remediation: evidence that identified gaps were closed and that changes were made after an incident or an audit finding.
  • Governance: board-level awareness of the compliance programme, resource allocation, and escalation protocols.

An organisation that can produce dated evidence of each duty it performs is better positioned under every Section 33(2) factor than one that cannot.

How AMLEGALS represents organisations before the Board

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

The firm assists with pre-inquiry preparation (assembling the evidence file), written representations to the Board, oral submissions during the hearing, and appeals before the Appellate Tribunal under Rule 22.

Questions and answers

DPDPA Penalty Defence: common questions

Can the Data Protection Board impose a penalty without a hearing?

No. Section 28(4) requires the Board to give the person a reasonable opportunity of being heard before determining any penalty.

What factors reduce the penalty under DPDPA?

Section 33(2) lists the factors: the nature and gravity of the breach, the type of data, the repetitive nature, financial gain, and—critically—whether the person took steps to mitigate and the timeliness and effectiveness of those steps.

Can the Board order more than the Schedule ceiling?

No. Section 33(1) says the penalty shall not exceed the amount specified in the Schedule for the relevant breach.

What is the appeal process against a Board order?

An appeal lies to the Appellate Tribunal under Section 29. Rule 22 prescribes the procedure and time limit. A further appeal on a question of law lies to the High Court under Section 30.

Does an appeal stay the penalty?

Not automatically. The Appellate Tribunal may grant a stay on such conditions as it considers fit.

How should an organisation prepare for a Board inquiry?

By maintaining dated records of every compliance step: audit reports, DPIA reports, breach exercises, training records, consent logs, vendor contracts and remediation evidence. These records are the basis for showing mitigation under Section 33(2).

Contact

Discuss Board inquiry preparation or penalty defence

Share the nature of the inquiry or the complaint received. The AMLEGALS data privacy team will advise on evidence preparation, written representations and hearing strategy.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPDPA Penalty Defence: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Penalty Defence?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Penalty Defence under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Penalty Defence under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Penalty Defence?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Penalty Defence rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Penalty Defence?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Penalty Defence · DPDPA Exposure Assessment