DPDPA penalties explained: how the Data Protection Board imposes penalties under Section 33, the Schedule amounts, and how to cut your risk.
The Data Protection Board determines, after an inquiry, whether a person has committed a significant breach and imposes a monetary penalty up to the limits in the Schedule. In setting the amount it weighs the nature, gravity and duration of the breach, the type of data affected, repetition, gains or losses, and the mitigation taken.
Headline figures include up to 250 crore rupees for failure to take reasonable security safeguards leading to a breach, up to 200 crore rupees for failing to meet children's obligations and breach-notification duties, and up to 50 crore rupees for other specified failures, with smaller amounts for other breaches.
Penalties apply to data fiduciaries and, where relevant, Consent Managers; data principals can also face a small penalty for false or frivolous grievances under the duties provisions.
The largest penalties track the security-safeguards and children's duties, so the highest-leverage controls are reasonable security, pre-consent tracker blocking, a verifiable consent and notice flow, an age-gate for minors, and an incident-response plan that can notify the Board and affected people on time.
ConsentX provides the consent-side controls and tamper-evident evidence that demonstrate diligence and help mitigate exposure if the Board ever asks.
This page is a plain-English summary of the Digital Personal Data Protection Act, 2023 for general information and is not legal advice. Confirm your obligations with qualified counsel.
DPDPA-native consent, Section 9 age-gate and verifiable receipts. Start free or take the DPDPA quiz.