The DPDPA establishes a penalty framework under Section 33 and the Schedule with penalties reaching ₹250 Crore for security safeguard failures. Unlike the Companies Act 2013, the DPDPA does not contain an express "officer in default" clause creating automatic personal liability for directors. Penalties under the Act are imposed on the Data Fiduciary as an entity. However, the magnitude of these penalties — and the enhanced governance obligations under Section 10 for Significant Data Fiduciaries — create a governance imperative that demands active board engagement. Boards that fail to establish adequate data protection governance expose the organisation to maximum penalty exposure and undermine any defence of reasonable diligence.
Section 33 Penalty Architecture and Board Exposure
Section 33 of the DPDPA empowers the Data Protection Board to impose penalties for contraventions as specified in the Schedule. The penalty framework is structured by violation type: failure to implement reasonable security safeguards under Section 8(5) attracts up to ₹250 Crore; failure in breach notification under Section 8(6) attracts up to ₹200 Crore; non-compliance with children's data provisions under Section 9 attracts up to ₹200 Crore; and non-compliance with SDF obligations under Section 10 attracts up to ₹150 Crore. The Board considers the nature, gravity, and duration of the contravention, the type of personal data affected, and the mitigating actions taken. For boards, the governance implication is clear: the organisation's penalty exposure is a direct function of its compliance infrastructure, and the Board's assessment of adequacy will turn on documented evidence of governance engagement.
Key Points
- Penalties imposed on the Data Fiduciary entity under Section 33
- Up to ₹250 Crore for security safeguard failures
- Board considers nature, gravity, duration and mitigating actions
- Documented compliance governance is the primary institutional defence
Significant Data Fiduciary Governance Obligations
Section 10 creates enhanced governance obligations for organisations designated as Significant Data Fiduciaries by the Central Government based on volume, sensitivity, or risk of processing. These organisations must: (a) appoint a Data Protection Officer based in India; (b) appoint an independent data auditor; and (c) conduct periodic Data Protection Impact Assessments. The DPO must report directly to the board or a board-level committee — not to the IT department or Chief Information Officer. This reporting line is critical because it ensures that compliance information reaches the governance level without operational filtering. The independent data auditor provides external assurance that the organisation's processing activities comply with the Act. Together, these requirements create a governance infrastructure — DPO appointment, independent audit, and impact assessment — that establishes the minimum standard of institutional diligence.
Key Points
- Section 10 mandates DPO, independent auditor, and impact assessments
- DPO must report directly to board or board committee
- Independent audit provides external compliance assurance
- Governance infrastructure defines the minimum standard of institutional diligence
Building an Effective Board Privacy Committee
Best governance practice under the DPDPA involves constituting a dedicated Board Privacy Committee or integrating privacy governance into an existing Risk or Audit Committee with defined terms of reference. The committee should: (a) receive quarterly compliance reports from the DPO including grievance trends, breach incidents, and regulatory developments; (b) review and approve the annual data protection budget and resource allocation; (c) oversee Data Protection Impact Assessments for high-risk processing activities; (d) review and approve material changes to data processing practices, particularly those involving Significant Data Fiduciary obligations; and (e) maintain minutes that document governance decisions, risk assessments, and compliance directives. Documented governance is the organisation's primary defence in penalty proceedings: contemporaneous records of board engagement, questioning, resource allocation, and decision-making demonstrate that the organisation took reasonable measures to prevent contraventions.
Key Points
- Dedicated Board Privacy Committee or integrated Risk/Audit Committee
- Quarterly DPO reports covering grievances, breaches, and regulatory changes
- Committee oversight of impact assessments and material processing changes
- Documented governance decisions serve as primary institutional defence
Strategic Integration and Compliance Culture
Board-level privacy governance extends beyond structural compliance into organisational culture. Directors must ensure that data protection is integrated into strategic planning, product development, M&A due diligence, and vendor management. A board that approves a new product launch without considering DPDPA implications — notice requirements under Section 5, consent architecture under Section 6, processor obligations under Section 8 — weakens the organisation's defence in any subsequent penalty proceedings. Similarly, M&A transactions must include DPDPA compliance assessment as part of due diligence: acquiring an entity with significant non-compliance exposes the acquirer to inherited penalty risk. The compliance culture extends to resource allocation: organisations that underfund data protection relative to their processing scale and risk profile face maximum penalty exposure. The DPDPA, through the combined effect of Section 33 penalties and Section 10 SDF obligations, effectively requires boards to treat data protection with the same strategic seriousness as financial reporting, anti-money laundering, and securities compliance.
Key Points
- Data protection must integrate into strategic planning and product development
- M&A due diligence must include DPDPA compliance assessment
- Underfunding data protection relative to risk maximises penalty exposure
- DPDPA requires strategic equivalence with financial and securities compliance
Key Takeaways
DPDPA penalties under Section 33 are imposed on the Data Fiduciary entity, with maximum penalties reaching ₹250 Crore
The Act does not contain an express officer-in-default clause for automatic personal liability of directors
Significant Data Fiduciaries under Section 10 must appoint DPO, independent auditor, and conduct impact assessments
Board Privacy Committee with documented governance decisions is the primary institutional defence in penalty proceedings
Data protection must be integrated into strategic planning, M&A, and product development
Resource allocation for data protection is a measurable indicator of organisational diligence

