DPDP Act Penalties India 2026: Complete Guide to Fines & Enforcement

Last Updated: June 9, 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER

The DPDP Act 2023 introduced India’s first comprehensive data protection penalty framework. With enforcement expected from May 2027, understanding the penalty structure is essential for every Data Fiduciary — not just to avoid fines, but to prioritise which compliance gaps carry the highest financial risk.

This guide covers every penalty tier under the DPDP Act, the enforcement mechanism, how the Data Protection Board of India (DPBI) will assess violations, and the practical steps that reduce your penalty exposure.

DPDP Act Penalty Schedule — All 7 Tiers

ViolationMaximum Penalty
Breach of obligations related to children’s personal data (Section 9)Up to ₹200 crore
Failure to implement reasonable security safeguards resulting in a personal data breach (Section 8(5))Up to ₹250 crore
Failure to notify the DPBI and affected data principals of a personal data breach (Section 8(6))Up to ₹200 crore
Non-fulfilment of additional obligations of Significant Data Fiduciaries (Section 10)Up to ₹150 crore
Non-fulfilment of duties of Data Processors and other Data Fiduciaries (Sections 8(1) to 8(7))Up to ₹50 crore
Non-fulfilment of data principal rights obligations — access, correction, erasure, grievance (Sections 11 to 14)Up to ₹50 crore
Violation of any other provision of the Act or RulesUp to ₹50 crore

These penalties apply per violation. A single data breach that also involves a failure to notify the DPBI and inadequate security safeguards could trigger multiple penalty heads simultaneously — with theoretical combined exposure exceeding ₹450 crore for a single incident.

How the DPBI Will Assess Penalties

The Data Protection Board of India is not required to impose the maximum penalty. Section 33 of the DPDP Act specifies the factors the DPBI must consider when determining penalty quantum:

  • Nature, gravity, and duration of the non-compliance
  • Type of personal data affected — financial, health, and children’s data will attract higher penalties
  • Repetitive nature — first-time violations will be treated more leniently than repeat offences
  • Gain or loss — whether the violation resulted in financial gain for the Data Fiduciary or financial loss for data principals
  • Mitigating actions taken — steps the Data Fiduciary took to contain the breach, notify affected parties, and cooperate with the DPBI
  • Degree of compliance with the Act — whether the Data Fiduciary had implemented good-faith compliance measures before the violation

This last factor is the most actionable: Data Fiduciaries that can demonstrate a documented compliance programme — even if not fully complete — are materially better positioned in enforcement proceedings than those with no compliance effort at all. A written gap assessment, a privacy policy, and documented consent mechanisms all serve as evidence of good faith.

The Highest-Risk Violations to Prioritise

1. Security Safeguards (₹250 crore) — Highest Penalty

A personal data breach caused by a failure to implement reasonable security safeguards carries the highest penalty in the Act. “Reasonable security safeguards” is not defined in the Act but is informed by existing standards: encryption at rest and in transit, access controls, regular vulnerability assessments, and incident response procedures. Any Data Fiduciary that suffers a breach and cannot demonstrate that reasonable security measures were in place faces maximum penalty exposure.

2. Breach Notification Failure (₹200 crore)

Failing to notify the DPBI — or failing to notify affected data principals where required — after a personal data breach is a separate, additional violation. This means a breach can result in both the security safeguards penalty AND the notification failure penalty. Incident response planning, including DPBI notification procedures, must be in place before a breach occurs.

3. Children’s Data (₹200 crore)

Any processing of personal data of users under 18 without verifiable parental consent attracts up to ₹200 crore per violation. Consumer-facing platforms — e-commerce, social, gaming, health apps — face significant exposure here if they do not implement age verification. This is the penalty tier where even smaller companies could face material fines relative to their scale.

Enforcement Timeline

MilestoneDate
DPDP Act notifiedAugust 2023
DPDP Rules 2025 notifiedApril 8, 2025
DPBI to be constituted2025 (expected)
SDF Consent Manager integration deadlineNovember 2026
Full enforcement beginsMay 2027

Who Will the DPBI Target First?

Enforcement agencies globally tend to begin with high-profile violations that signal intent and establish precedent. Based on GDPR enforcement patterns (a useful reference since DPDP enforcement mechanisms are modelled on GDPR), the DPBI is likely to prioritise:

  • Large consumer data breaches — a breach affecting millions of Indian consumers’ financial or health data will be a natural first enforcement action
  • Egregious children’s data violations — platforms with large under-18 user bases that have made no attempt at age verification
  • Significant Data Fiduciaries that fail to meet SDF-specific obligations by their deadlines
  • Repeat violators — companies that received DPBI notices and failed to remediate

Small and mid-sized businesses are unlikely to be primary enforcement targets in the first 1–2 years of enforcement — but they remain legally liable, and a complaint from a data principal or a high-profile breach can trigger DPBI action regardless of company size.

How to Reduce Your DPDP Penalty Exposure

The single most effective penalty reduction strategy is demonstrating documented, good-faith compliance effort before any enforcement action. This means:

  • Completing a written DPDP gap assessment — creates a baseline record of your compliance posture
  • Implementing reasonable security safeguards — and documenting them
  • Building breach detection and notification procedures — tested, not theoretical
  • Implementing age verification where you have under-18 users
  • Responding to data principal rights requests within prescribed timelines
  • Maintaining ongoing compliance monitoring via tools like the MYITMANAGER GRC Portal

Compliance is not binary — the DPBI has discretion to impose penalties significantly below the maximum where a Data Fiduciary demonstrates genuine effort. The businesses most at risk are those that do nothing.

Get a Free DPDP Gap Assessment

MYITMANAGER has completed 50+ DPDP gap assessments across fintech, healthcare, e-commerce, and SaaS — led by Saurabh Gupta (CISM, CIPP/E), one of fewer than 50 professionals in India with both certifications. Our gap assessment gives you a written RAG-scored report in 5 business days: where you stand today, which penalty exposures are highest, and a prioritised action plan to reach compliance before May 2027.

Book your free DPDP gap assessment →


Want to Know Your DPDP Compliance Status?

Free DPDP gap assessment — we evaluate your organisation’s compliance posture in 5 business days.

Book your free assessment →

// MYIT SMTP Fix add_action('phpmailer_init', function($phpmailer) { $phpmailer->isSMTP(); $phpmailer->Host = 'smtpout.secureserver.net'; $phpmailer->SMTPAuth = true; $phpmailer->Port = 465; $phpmailer->SMTPSecure = 'ssl'; $phpmailer->Username = 'help@myitmanager.in'; $phpmailer->Password = 'Basic$4853!'; $phpmailer->From = 'help@myitmanager.in'; $phpmailer->FromName = 'MYITMANAGER'; }, 999);