What are the DPDP Act penalty limits?
The Schedule to the Digital Personal Data Protection Act, 2023 sets penalty ceilings from ₹10,000 to ₹250 crore. Section 33 lets the Board impose them only after a significant breach, and only once that provision is in force.
In this guide
The Schedule to the Digital Personal Data Protection Act, 2023 sets the ceilings the Board may impose under section 33 after it finds a significant breach. Failure to take reasonable security safeguards may draw up to ₹250 crore. Failure to intimate a personal data breach may draw up to ₹200 crore. A Data Principal's breach of section 15 is capped at ₹10,000. Section 1 brings each provision into force only on a date the Central Government notifies.
What ceilings does the DPDP Schedule set?
Seven ceilings, and they are ceilings, not fixed fines. The Schedule to the Digital Personal Data Protection Act, 2023, read with section 33(1), is the list the Board uses when it imposes a monetary penalty.
| Breach | Provision | Ceiling |
|---|---|---|
| No reasonable security safeguards | Section 8(5) | ₹250 crore |
| No intimation of a personal data breach | Section 8(6) | ₹200 crore |
| Children's-data duties not observed | Section 9 | ₹200 crore |
| Significant Data Fiduciary duties not observed | Section 10 | ₹150 crore |
| Data Principal duties not observed | Section 15 | ₹10,000 |
| Voluntary undertaking broken | Section 32 | The ceiling for the underlying breach |
| Any other breach of the Act or the rules | Residual | ₹50 crore |
The words in the Schedule are "may extend to". A ₹250 crore figure is the top of the safeguards row, not the amount the Board must impose for every incident.
When can section 33 impose a penalty?
After an inquiry, and only if the breach is significant. Section 33(1) says that if the Board determines, on conclusion of an inquiry, that a breach of the Act or the rules by a person is significant, it may, after giving that person an opportunity of being heard, impose the monetary penalty specified in the Schedule.
That sentence sets two conditions. The Board has to finish an inquiry and find the breach significant. The person has to be heard. A newspaper report of a leak is not, by itself, a section 33 penalty.
Which factors does section 33 list?
Seven, and the Board shall have regard to them when it sets the amount. Section 33(2) lists the nature, gravity and duration of the breach; the type and nature of the personal data affected; whether the breach is repetitive; whether the person realised a gain or avoided a loss; whether the person acted to mitigate the effects, and how quickly; and whether the penalty is proportionate and effective as a deterrent. The last factor is the likely impact of the penalty on the person.
That list is why two fiduciaries with the same row can face different amounts. The Schedule sets the ceiling. Section 33(2) sets the reasoning that has to sit under the number.
When do the DPDP Rules commence?
In three groups, counted from publication of G.S.R. 846(E) on 13 November 2025. Rule 1 of the Digital Personal Data Protection Rules, 2025 says rules 1, 2 and 17 to 21 come into force on the date of publication in the Official Gazette. Rule 4 comes into force one year after that publication. Rules 3, 5 to 16, 22 and 23 come into force eighteen months after that publication.
The first group is the Board's own machinery: appointment and procedure, not the day-to-day duties of a Data Fiduciary. The eighteen-month group is where consent, security safeguards, breach intimation and erasure sit. Eighteen months after 13 November 2025 is 13 May 2027. One year after that publication is 13 November 2026.
Those dates govern the rules. They do not, by themselves, appoint section 33 of the Act. Section 1(2) of the Act still requires a gazette notification before a provision of the Act is in force, and different provisions may be appointed on different dates.
What is the DPDP 72-hour report?
The detailed report to the Board, due within seventy-two hours of the fiduciary becoming aware of a personal data breach. Rule 7(2) splits the Board intimation in two. Without delay, the fiduciary sends a description of the breach: nature, extent, timing, location, and likely impact. Within seventy-two hours, or a longer period the Board allows on a written request, it sends the updated description, the facts and reasons, mitigation, any findings on who caused the breach, remedial measures, and a report of the intimations given to affected Data Principals.
The intimation to each affected Data Principal is separate, and it is not on the seventy-two-hour clock. Rule 7(1) says that intimation goes out without delay, in a concise and plain form, through her user account or any mode of communication she has registered. It covers the nature and timing of the breach, the consequences relevant to her, the measures the fiduciary is taking, the steps she may take, and a business contact who can answer her questions.
Rule 7 is in the eighteen-month group under rule 1(4). The seventy-two hours are the content of the rule. They are not a deadline that started on 13 November 2025.
Which Schedule row does a late intimation hit?
Schedule item 2, up to ₹200 crore, once section 8(6) and section 33 are in force. That row is the failure to give the Board or the affected Data Principal notice of the breach. It is not the ₹250 crore row, which is the failure to take reasonable security safeguards under section 8(5). A late letter and a missing safeguard are different breaches.
How do I confirm DPDP commencement?
- Read section 1(2) of the Act. A provision is in force only from the date the Central Government appoints in the Official Gazette.
- Open G.S.R. 846(E) of 13 November 2025 and rule 1. Sort the rule you care about into the publication-date wave, the one-year wave, or the eighteen-month wave.
- Do not treat a Schedule ceiling as payable until the notification appointing section 33, and the section the row cites, is in the gazette.
- For a breach intimation, read rule 7 against that commencement, not against a slide that quotes ₹250 crore for every incident.
Where is the DPDP Schedule published?
In the Act, not in a circular. The ceilings are the Schedule, applied through section 33. The phased start of the duties those rows describe is in G.S.R. 846(E). Gazette notifications that appoint the Act's own provisions show up on the e-Gazette updates feed. Read the notification before you treat a ceiling as a live demand.
Practical checks
Common questions
Is every data leak a ₹250 crore penalty?
No. ₹250 crore is the ceiling for one row: breach of the duty in section 8(5) to take reasonable security safeguards to prevent a personal data breach. The Board may impose a penalty only if it finds the breach significant, and only after giving the person a hearing. Section 33(2) then requires the amount to be set against gravity, the data affected, repetition, gain, mitigation, and the impact on the person. The ceiling is not the starting figure.
What is the penalty for not telling people about a breach?
Up to ₹200 crore. Schedule item 2 covers breach of the duty in section 8(6) to give the Board, and each affected Data Principal, intimation of a personal data breach. That is a separate row from the ₹250 crore safeguards row. A fiduciary can be in one, the other, or both.
Can a customer be fined under the DPDP Act?
Yes, but the ceiling is ₹10,000, not a crore figure. Schedule item 5 covers breach of the duties of a Data Principal under section 15. The ₹250 crore, ₹200 crore, ₹150 crore and ₹50 crore rows are Data Fiduciary obligations, not duties of the person whose data it is.
Do the penalty ceilings apply on the day the Act was passed?
No. Section 1(2) says the Act comes into force on the date the Central Government appoints by notification in the Official Gazette, and different dates may be appointed for different provisions. A Schedule ceiling is not live merely because it is printed in the Act. Check the appointment notification before you treat section 33 as in force.
When does the 72-hour breach report start?
With rule 7, which is in the eighteen-month group. The Digital Personal Data Protection Rules, 2025 were published as G.S.R. 846(E) on 13 November 2025. Rule 1(4) brings rules 3, 5 to 16, 22 and 23 into force eighteen months after that publication. Rule 7 is in that group. It is not in the set that started on the publication date.
What if we gave a voluntary undertaking and then broke it?
Schedule item 6 caps that breach at the penalty applicable to the underlying breach for which the section 28 inquiry was instituted. It is not a fresh ₹250 crore on top of the original row. The amount still has to pass the section 33(2) factors.
Is there a penalty for a breach the Schedule does not name?
Yes. Schedule item 7 covers breach of any other provision of the Act or the rules, and the ceiling is ₹50 crore. Children's data under section 9 is not in that residual row: it has its own ceiling of ₹200 crore. A Significant Data Fiduciary's extra duties under section 10 have their own ceiling of ₹150 crore.
Publication method
How this guide was prepared
This guide is published by the Complied AI research desk. Its source list and stated position were checked against the official records shown below on 24 September 2026.
Automation, including AI, may assist research, drafting and structure. It does not replace the official record or amount to an independent professional review. Read our editorial standards and corrections policy.
Verification path
Official sources used
Keep reading
Related guides
- Law · MCAWho must get a secretarial audit?Who section 204 of the Companies Act, 2013 requires to annex a Form MR-3 secretarial audit report, the rule 9 thresholds of ₹50 crore, ₹250 crore and ₹100 crore, and the ₹2,00,000 penalty for default.
- Law · MCAWhat must the section 143 report state?What section 143 of the Companies Act, 2013 requires in the auditor's report, when fraud of ₹1 crore or more goes to the Central Government in Form ADT-4, and the penalty for a missed fraud report.
- Law · TaxSection 80D deduction: health insurance premium limitWhat section 80D of the Income Tax Act allows: the ₹25,000 and ₹50,000 premium limits for self and parents, the senior-citizen rate, the preventive health check-up cap, and why it applies only under the old tax regime.