Last Updated: June 9, 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER
The DPDP Act 2023 introduced India’s first comprehensive data protection penalty framework. With enforcement expected from May 2027, understanding the penalty structure is essential for every Data Fiduciary — not just to avoid fines, but to prioritise which compliance gaps carry the highest financial risk.
This guide covers every penalty tier under the DPDP Act, the enforcement mechanism, how the Data Protection Board of India (DPBI) will assess violations, and the practical steps that reduce your penalty exposure.
DPDP Act Penalty Schedule — All 7 Tiers
| Violation | Maximum Penalty |
|---|---|
| Breach of obligations related to children’s personal data (Section 9) | Up to ₹200 crore |
| Failure to implement reasonable security safeguards resulting in a personal data breach (Section 8(5)) | Up to ₹250 crore |
| Failure to notify the DPBI and affected data principals of a personal data breach (Section 8(6)) | Up to ₹200 crore |
| Non-fulfilment of additional obligations of Significant Data Fiduciaries (Section 10) | Up to ₹150 crore |
| Non-fulfilment of duties of Data Processors and other Data Fiduciaries (Sections 8(1) to 8(7)) | Up to ₹50 crore |
| Non-fulfilment of data principal rights obligations — access, correction, erasure, grievance (Sections 11 to 14) | Up to ₹50 crore |
| Violation of any other provision of the Act or Rules | Up to ₹50 crore |
These penalties apply per violation. A single data breach that also involves a failure to notify the DPBI and inadequate security safeguards could trigger multiple penalty heads simultaneously — with theoretical combined exposure exceeding ₹450 crore for a single incident.
How the DPBI Will Assess Penalties
The Data Protection Board of India is not required to impose the maximum penalty. Section 33 of the DPDP Act specifies the factors the DPBI must consider when determining penalty quantum:
- Nature, gravity, and duration of the non-compliance
- Type of personal data affected — financial, health, and children’s data will attract higher penalties
- Repetitive nature — first-time violations will be treated more leniently than repeat offences
- Gain or loss — whether the violation resulted in financial gain for the Data Fiduciary or financial loss for data principals
- Mitigating actions taken — steps the Data Fiduciary took to contain the breach, notify affected parties, and cooperate with the DPBI
- Degree of compliance with the Act — whether the Data Fiduciary had implemented good-faith compliance measures before the violation
This last factor is the most actionable: Data Fiduciaries that can demonstrate a documented compliance programme — even if not fully complete — are materially better positioned in enforcement proceedings than those with no compliance effort at all. A written gap assessment, a privacy policy, and documented consent mechanisms all serve as evidence of good faith.
The Highest-Risk Violations to Prioritise
1. Security Safeguards (₹250 crore) — Highest Penalty
A personal data breach caused by a failure to implement reasonable security safeguards carries the highest penalty in the Act. “Reasonable security safeguards” is not defined in the Act but is informed by existing standards: encryption at rest and in transit, access controls, regular vulnerability assessments, and incident response procedures. Any Data Fiduciary that suffers a breach and cannot demonstrate that reasonable security measures were in place faces maximum penalty exposure.
2. Breach Notification Failure (₹200 crore)
Failing to notify the DPBI — or failing to notify affected data principals where required — after a personal data breach is a separate, additional violation. This means a breach can result in both the security safeguards penalty AND the notification failure penalty. Incident response planning, including DPBI notification procedures, must be in place before a breach occurs.
3. Children’s Data (₹200 crore)
Any processing of personal data of users under 18 without verifiable parental consent attracts up to ₹200 crore per violation. Consumer-facing platforms — e-commerce, social, gaming, health apps — face significant exposure here if they do not implement age verification. This is the penalty tier where even smaller companies could face material fines relative to their scale.
Enforcement Timeline
| Milestone | Date |
|---|---|
| DPDP Act notified | August 2023 |
| DPDP Rules 2025 notified | April 8, 2025 |
| DPBI to be constituted | 2025 (expected) |
| SDF Consent Manager integration deadline | November 2026 |
| Full enforcement begins | May 2027 |
Who Will the DPBI Target First?
Enforcement agencies globally tend to begin with high-profile violations that signal intent and establish precedent. Based on GDPR enforcement patterns (a useful reference since DPDP enforcement mechanisms are modelled on GDPR), the DPBI is likely to prioritise:
- Large consumer data breaches — a breach affecting millions of Indian consumers’ financial or health data will be a natural first enforcement action
- Egregious children’s data violations — platforms with large under-18 user bases that have made no attempt at age verification
- Significant Data Fiduciaries that fail to meet SDF-specific obligations by their deadlines
- Repeat violators — companies that received DPBI notices and failed to remediate
Small and mid-sized businesses are unlikely to be primary enforcement targets in the first 1–2 years of enforcement — but they remain legally liable, and a complaint from a data principal or a high-profile breach can trigger DPBI action regardless of company size.
How to Reduce Your DPDP Penalty Exposure
The single most effective penalty reduction strategy is demonstrating documented, good-faith compliance effort before any enforcement action. This means:
- Completing a written DPDP gap assessment — creates a baseline record of your compliance posture
- Implementing reasonable security safeguards — and documenting them
- Building breach detection and notification procedures — tested, not theoretical
- Implementing age verification where you have under-18 users
- Responding to data principal rights requests within prescribed timelines
- Maintaining ongoing compliance monitoring via tools like the MYITMANAGER GRC Portal
Compliance is not binary — the DPBI has discretion to impose penalties significantly below the maximum where a Data Fiduciary demonstrates genuine effort. The businesses most at risk are those that do nothing.
Get a Free DPDP Gap Assessment
MYITMANAGER has completed 50+ DPDP gap assessments across fintech, healthcare, e-commerce, and SaaS — led by Saurabh Gupta (CISM, CIPP/E), one of fewer than 50 professionals in India with both certifications. Our gap assessment gives you a written RAG-scored report in 5 business days: where you stand today, which penalty exposures are highest, and a prioritised action plan to reach compliance before May 2027.
Book your free DPDP gap assessment →
Want to Know Your DPDP Compliance Status?
Free DPDP gap assessment — we evaluate your organisation’s compliance posture in 5 business days.