Penalty Schedule
What each type of failure can cost — and the smaller penalty that applies to individuals filing false complaints.
Every figure here is a ceiling, not a fine. The Act says each penalty "may extend to" the amount shown. The Board decides what to actually impose in a given case. A ₹250 crore maximum does not mean a ₹250 crore penalty.
- Failing to take reasonable security safeguards to prevent a data breach — s.8(5)₹250 crore
- Failing to notify the Board or affected people of a data breach — s.8(6)₹200 crore
- Failing the extra duties around children's data — s.9₹200 crore
- Failing the extra duties of a Significant Data Fiduciary — s.10₹150 crore
- A Data Principal breaching their own duties — s.15₹10,000
- Breaking a voluntary undertaking you gave the Board — s.32capped at the original breachno fixed amount
- Breaking any other part of the Act or Rules₹50 crore
If you give the Board an undertaking and then break it, the ceiling is whatever the breach you were being investigated for carried — not a new amount.
Note the last two rows. If you give the Board a voluntary undertaking and then break it, the penalty is capped at whatever the original breach carried — not at a new amount. And section 15 is the one people miss: it applies to individuals, not companies. If you file false or frivolous complaints, or impersonate someone else to make a data request, you can be fined up to ₹10,000.
For how the Board applies these ceilings in practice, consult qualified counsel and the text of the Schedule linked below.
Penalty tiers read directly from the Schedule to the Act.
Notified — checked 2026-10-06. Opened the DPDP Act, 2023 (Gazette PDF). Partly in force: most duties start 13 May 2027 (G.S.R. 843(E)).
Am I a Data Fiduciary?
Reading about DPDP obligations? Run the 2-minute self-check to see exactly what applies to your product.
Run it now