Direct answer: Under India's Digital Personal Data Protection Act 2023, financial penalties range up to ₹250 crore for failure to implement reasonable security safeguards, up to ₹200 crore for breach-notification failures, consent/notice violations, and children's data breaches, and up to ₹150 crore for Significant Data Fiduciary obligation breaches. The Data Protection Board of India (DPBI) imposes penalties proportionate to breach severity; full enforcement is expected from May 2027.
DPDP Act 2023 Penalties — Complete Guide for Indian Businesses
Non-compliance with the DPDP Act is not a theoretical risk. The Act establishes a schedule of financial penalties designed to be material for organisations of every size — from early-stage startups to large enterprises.
Penalty Schedule (Key Violations)
| Violation | Max Penalty | DPDP Reference |
|---|---|---|
| Failure to implement reasonable security safeguards | ₹250 Crore | Schedule Item 1 |
| Failure to notify Board and Data Principal of breach | ₹200 Crore | Schedule Item 2 |
| Children's data violations (Section 9) | ₹200 Crore | Schedule Item 3 |
| Consent / notice violations (Sections 5–7) | ₹200 Crore | Schedule Item 4 |
| Significant Data Fiduciary obligation breaches | ₹150 Crore | Schedule Item 5 |
| Failure to fulfil data principal rights (Sections 11–14) | ₹100 Crore | Schedule Item 6 |
| Grievance redressal failures (Section 13) | ₹50 Crore | Schedule Item 7 |
Enforcement Timeline
- August 2023: DPDP Act passed by Parliament
- November 2025: DPDP Rules 2025 notified; Data Protection Board established
- November 2026: Consent Manager registration opens
- May 2027: Full compliance enforcement expected — DPBI adjudicatory powers active
How Penalties Are Calculated
The DPBI considers the nature, gravity and duration of the non-compliance, whether it was intentional or negligent, prior history, and steps taken to mitigate harm. Documented compliance programmes, timely breach response, and evidence of good-faith remediation can influence outcomes even when a violation occurred.
Reduce Penalty Exposure with Complynz
- Free DPDP readiness assessment — section-by-section scoring
- Consent Management Tool — Section 6 compliant with audit trails
- Data principal rights portal — DSR and grievance automation
- Breach notification templates — DPBI Rule 7 ready
- DPDP Guide: Penalties chapter — Sections 27–33 explained