/The Act · Schedule
The Schedule
[See section 33 (1)]. Maximum monetary penalties the Data Protection Board may impose.
| Sl. No. | Breach of provisions of this Act or rules made thereunder | Penalty |
|---|---|---|
| 1 | Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8. | May extend to two hundred and fifty crore rupees. |
| 2 | Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8. | May extend to two hundred crore rupees. |
| 3 | Breach in observance of additional obligations in relation to children under section 9. | May extend to two hundred crore rupees. |
| 4 | Breach in observance of additional obligations of Significant Data Fiduciary under section 10. | May extend to one hundred and fifty crore rupees. |
| 5 | Breach in observance of the duties under section 15. | May extend to ten thousand rupees. |
| 6 | Breach of any term of voluntary undertaking accepted by the Board under section 32. | Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted. |
| 7 | Breach of any other provision of this Act or the rules made thereunder. | May extend to fifty crore rupees. |
The Schedule to the Digital Personal Data Protection Act sets out the maximum financial penalties for breaking different rules under the law. These penalties apply to Data Fiduciaries (entities determining the purpose and means of processing data), Significant Data Fiduciaries (those with higher obligations), and Data Principals (the individuals to whom the data relates).\n\nThe highest penalty is for a Data Fiduciary that fails to take reasonable security safeguards to prevent a personal data breach. This failure can result in a penalty of up to 250 crore rupees. If a Data Fiduciary fails to notify the Board or the affected Data Principal about a data breach, the penalty can reach up to 200 crore rupees. Breaking the special rules for handling children's data also carries a maximum penalty of 200 crore rupees.\n\nSignificant Data Fiduciaries face penalties of up to 150 crore rupees if they fail to meet their extra obligations. If an entity breaks a voluntary undertaking that the Board previously accepted, the penalty can be up to the maximum amount allowed for the original violation. Breaking any other provision of the Act or its rules can lead to a fine of up to 50 crore rupees. Finally, Data Principals who fail to observe their specific duties can be penalized up to 10,000 rupees.
Key points
- Failing to implement reasonable security safeguards to prevent a data breach carries a penalty of up to 250 crore rupees [1].
- Failing to notify the Board or the affected Data Principal of a data breach can result in a penalty of up to 200 crore rupees [2].
- Breaching the additional obligations related to children carries a penalty of up to 200 crore rupees [3].
- A Significant Data Fiduciary that breaches its specific additional obligations faces a penalty of up to 150 crore rupees [4].
- A Data Principal who breaches their duties under the Act can be penalized up to 10,000 rupees [5].
- Breaching any other provision of the Act or its rules carries a penalty of up to 50 crore rupees [7].
Common misreadings
- Readers might think the listed amounts are fixed fines, but the text states the penalties 'may extend to' these amounts, meaning they are maximum limits.
- Readers might assume only organizations face financial penalties, but Data Principals can also be penalized up to 10,000 rupees for breaching their duties.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Worried about exposure to these penalties?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.