What non-compliance
actually costs.
The DPDP Act's penalty schedule, obligation by obligation, with what triggers each one and what the Board weighs when deciding the amount.
The schedule
The Act attaches penalties to specific failures rather than to a general standard. The figures below are maximums, and the Board sets the actual amount after inquiry.
| Failure | Maximum penalty | What triggers it |
|---|---|---|
| Reasonable security safeguards | ₹250 crore | Failing to take reasonable security safeguards to prevent a personal data breach. The largest penalty in the Act, and the one most likely to be reached by an ordinary security incident. |
| Breach notification | ₹200 crore | Failing to notify the Board and affected Data Principals of a personal data breach. |
| Children's data | ₹200 crore | Failing to meet the Section 9 obligations: verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising directed at children. |
| Significant Data Fiduciary duties | ₹150 crore | Failing the additional Section 10 obligations once designated: DPO in India, independent auditor, periodic impact assessments. |
| Any other provision | ₹50 crore | The catch-all, which covers notice and consent failures. Most consent-related exposure sits here. |
| Data Principal duties | ₹10,000 | On the individual, for false or frivolous complaints and impersonation. |
Figures are the maximums in the Schedule to the Act. Confirm against the current text before you quote them anywhere that matters.
How the Board decides the number
The maximum is not the expected outcome. Section 33 directs the Board to consider the nature and gravity of the breach, the type and volume of data affected, whether it was repetitive, whether you gained anything by it, what you did to mitigate and how quickly, whether the penalty is proportionate and effective, and the likely impact on you.
Read that list as an instruction. Almost every factor rewards two behaviours: detecting quickly and being able to show what you had in place beforehand. A company that can produce timestamped evidence of its controls on the day of the incident is in a materially different position from one reconstructing it afterwards.
Where the realistic exposure is
For most companies the ₹250 crore figure is not the live risk. Two smaller ones are.
Consent you cannot prove. It falls under the ₹50 crore catch-all, and it is the failure most likely to be discovered, because any user can trigger it by asking a question you cannot answer.
Breach notification you missed. The Act does not set a materiality threshold, so the instinct to wait until an incident is 'confirmed material' is the wrong instinct. The exposure for late notification is ₹200 crore, and the mitigation is a rehearsed process rather than a policy document.
Both are evidence problems before they are legal problems. Provable consent and a register that shows what was in place and when are the two controls that change the conversation.
The things people ask us
Are these fines per breach or per affected person?
The Schedule sets a maximum per instance of non-compliance, not per affected individual. The Board decides the actual amount after an inquiry, weighing the nature and gravity of the breach, the type of data involved, whether it was repetitive, what you did to mitigate it, and whether the penalty is proportionate.
Can directors be personally liable?
The Act's penalties are financial and fall on the entity. There is no imprisonment provision. That is a meaningful difference from some other Indian statutes, and it is why the practical risk is balance-sheet risk rather than personal criminal exposure.
What happens between a complaint and a penalty?
The Board can inquire on a complaint or on reference. It has civil-court powers for the inquiry, and can accept a voluntary undertaking instead of proceeding, which ends the proceedings for that breach unless the undertaking is itself breached.
Is there a penalty on individuals who misuse the complaint process?
Yes. Data Principals have duties under Section 15, including not filing false or frivolous complaints, with a penalty of up to ₹10,000. It is small, but it exists to discourage nuisance complaints.
Find the exposure before the Board does.
The free scan shows what fires on your site before consent is given, which is the most common and most discoverable failure under the Act.