DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · Penalties

Is the ₹10,000 crore DPDP penalty real?

No. The highest penalty in the DPDP Act is ₹250 crore, for failing to take reasonable security safeguards.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

Short answer

No. The DPDP Act does not contain a ₹10,000 crore penalty. The Schedule caps the highest fine at ₹250 crore, and penalties only become enforceable on 13 May 2027.

The real penalty tiers

Section 33 read with the Schedule sets these ceilings for the obligations that carry penalties. They apply from 13 May 2027.

Up to ₹250 croreFailure to take reasonable security safeguards
Up to ₹200 croreFailure to notify a personal data breach
Up to ₹200 croreFailure of the extra duties around children's data
Up to ₹150 croreFailure of the extra duties of a Significant Data Fiduciary
Up to ₹10,000Breach of a Data Principal's own duties
capped at the original breachBreaking a voluntary undertaking accepted by the Board
Up to ₹50 croreBreaking any other part of the Act or Rules

Where the confusion comes from

The Act's maximum is ₹250 crore. The ₹10,000 crore figure appears to come from misreporting or conflation with other regimes. The DPDP Act's Schedule is explicit: the top tier is for failing to take reasonable security safeguards, and it is capped at ₹250 crore.

The lowest tier — up to ₹10,000 — applies to Data Principals who breach their own duties under section 15, such as making false claims or suppressing material information. That is thousands, not thousands of crores.

What this means for you

Founders

Budget for security and breach-response readiness, not a mythical ₹10,000 crore headline. The ceilings run from ₹10,000 up to ₹250 crore, depending on what went wrong.

Freelancers

If you process personal data for clients, your contracts should require reasonable safeguards. The ₹200 crore breach-notification tier is the one most service providers need to watch.

Creators

Your audience data is covered. The risk is not a giant fine for ordinary creators — it is the ₹50 crore tier for missing notice, consent, or retention obligations.

Status

EnforceablePenalties under the Schedule are enforceable from 13 May 2027. The body that imposes them — the Data Protection Board — is constituted in law but is not yet hearing complaints.

Read next

Primary sources

Source
MeitY — DPDP Act (Gazette PDF)

Gazette of India, Extraordinary, Part II, Section 1, 11 August 2023 (Act 22 of 2023). Section 33 and the Schedule set the penalty ceilings.

Status unverified — no status check recorded

Source
MeitY — DPDP Rules, 2025 (Gazette PDF)

G.S.R. 846(E), 13 November 2025 (Gazette ID CG-DL-E-14112025-267650) — sets the phased commencement dates.

Status unverified — no status check recorded

Citation

Kokate, S. (2026). Is the ₹10,000 crore DPDP penalty real? India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/dpdp-penalty-myth. Educational content, not legal advice.

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.