₹250 crore is not a line item.It is a balance-sheet event.

The Schedule sets ceilings. Section 33 decides where within them you land.

In one line: The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.

The estate · What the Schedule actually costsHover to inspect

The ceiling is the law. The number is your conduct.

The scene

The CFO asked for the exposure figure. The team added up every ceiling and produced a number larger than the company. It was not wrong, only useless. The real question was which heads were engaged, and what the Board would see when it looked at how they behaved.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
Penalties are theoretical. The Board is a quasi-judicial body with power to inquire and impose penalties. Plan for adjudication, not negotiation.
The maximum will never apply to us. Section 33 factors reward mitigation and punish repetition; conduct moves the number. Build the record that argues for you.
We'll settle if it comes to that. Voluntary undertakings under Section 32 exist, but breaching one carries its own penalty. Only undertake what you can already do.

The Schedule

Failure to take reasonable security safeguards: up to ₹250 crore. Failure to intimate a breach: up to ₹200 crore. Breach of obligations for children: up to ₹200 crore. Breach of Significant Data Fiduciary obligations: up to ₹150 crore. Breach of Data Principal duties: up to ₹10,000. Any other breach of the Act or Rules: up to ₹50 crore.

What the Board weighs

Section 33(2): nature, gravity and duration of the breach; type and nature of personal data; repetitive nature; gain made or loss avoided; mitigation and its timeliness; proportionality and effectiveness; and likely impact on the person penalised.

Monday morning

  1. 01Map each system to the Schedule head it could engage.
  2. 02Document mitigation as it happens. Records made later persuade less.
  3. 03Report exposure to the board by head, not as one sum.

Questions, answered plainly

What is the maximum penalty under DPDPA?

The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.

How does the Data Protection Board decide the penalty amount?

Under Section 33(2) the Board considers the nature, gravity and duration of the breach, the type of personal data, whether it is repetitive, any gain or loss avoided, mitigation and its timeliness, proportionality, and the likely impact of the penalty.

Argument 01Implementation ends on a date. Resilience begins on it.Read → Argument 02Before data leaks, clarity leaks.Read → Argument 03You cannot protect what you have not named.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner