Guide · 9 August 2026
DPDP penalties explained: what ₹250 crore actually attaches to
The short answer: the DPDP Act's Schedule caps penalties at ₹250 crore per instance for failing security safeguards, ₹200 crore for breach-notification and children's-data violations, and ₹50 crore for everything else — including everyday failures like invalid consent or an ignored erasure request. Penalties are imposed by the Data Protection Board after inquiry, and what you can prove is the main mitigating factor the Act tells the Board to weigh.
The penalty schedule
The headline number. 'Reasonable safeguards' is judged after the breach — your evidence of controls is the defence.
The clock starts at awareness. Notification duties bite even when the breach itself wasn't your fault.
Processing a child's data without verifiable parental consent, tracking or targeted advertising at children.
Applies once notified as an SDF: DPO in India, independent audits, impact assessments.
The catch-all: invalid consent, ignored withdrawal, unanswered DSRs, missing notices — the everyday failures.
"Per instance" matters: a systemic failure affecting many users over time is not automatically one violation.
How the Board decides the amount
Section 33 directs the Board to weigh: the nature, gravity and duration of the breach; the type of data affected; whether the violation is repetitive; whether you gained from it; and — critically — the mitigating actions you took, and how promptly. Every factor on that list is an evidence question. A company that can produce a verified consent trail, a handled-on-time DSR register, and a breach-response timeline argues gravity and mitigation from records; a company with none argues from memory.
The penalty nobody prices in: blocking
Beyond fines, the Act empowers the government (on the Board's reference, after repeated penalties) to block public access to your service in India. For a foreign company, that is market exit; for an Indian one, it is existential. See DPDP for global companies — Section 3 makes this reach extraterritorial.
What actually protects you
- Provable consent — purpose-wise records stamped with the notice version each user saw. This is what makes the ₹50-crore catch-all defensible.
- A working DSR process — statutory-deadline tracking with an audit trail, so no request can silently expire into a violation.
- Tamper-evident records — evidence the Board can verify independently outweighs evidence you merely assert. (ProofKosh's chain is publicly verifiable.)
- Documented security safeguards — the ₹250-crore tier is judged on what you can show you had in place before the breach.
Know your exposure in 3 minutes
The free Readiness Score maps your gaps against exactly these penalty triggers.