AMLEGALS — Strategic Lawyering

DPDPA Penalties Explained: Up to ₹250 Crore and How the Board Decides

DPDPA Penalties Explained: Up to ₹250 Crore and How the Board Decides

The ceiling is the law. The number is your conduct.

The scene

The CFO asked for the exposure figure. The team added up every ceiling and produced a number larger than the company. It was not wrong, only useless. The real question was which heads were engaged, and what the Board would see when it looked at how they behaved.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Penalties are theoretical.

The Board is a quasi-judicial body with power to inquire and impose penalties.

Plan for adjudication, not negotiation.

The maximum will never apply to us.

Section 33 factors reward mitigation and punish repetition; conduct moves the number.

Build the record that argues for you.

We'll settle if it comes to that.

Voluntary undertakings under Section 32 exist, but breaching one carries its own penalty.

Only undertake what you can already do.

The Schedule

Failure to take reasonable security safeguards: up to ₹250 crore. Failure to intimate a breach: up to ₹200 crore. Breach of obligations for children: up to ₹200 crore. Breach of Significant Data Fiduciary obligations: up to ₹150 crore. Breach of Data Principal duties: up to ₹10,000. Any other breach of the Act or Rules: up to ₹50 crore.

What the Board weighs

Section 33(2): nature, gravity and duration of the breach; type and nature of personal data; repetitive nature; gain made or loss avoided; mitigation and its timeliness; proportionality and effectiveness; and likely impact on the person penalised.

Monday morning

01 Map each system to the Schedule head it could engage.

02 Document mitigation as it happens. Records made later persuade less.

03 Report exposure to the board by head, not as one sum.

Questions, answered plainly

What is the maximum penalty under DPDPA? +

The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.

How does the Data Protection Board decide the penalty amount? +

Under Section 33(2) the Board considers the nature, gravity and duration of the breach, the type of personal data, whether it is repetitive, any gain or loss avoided, mitigation and its timeliness, proportionality, and the likely impact of the penalty.

Argument 01 Implementation ends on a date. Resilience begins on it. Read →

Argument 02 Before data leaks, clarity leaks. Read →

Argument 03 You cannot protect what you have not named. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).