---
title: "The Schedule: penalties under the DPDP Act"
url: https://dpdp.myndsolution.com/wiki/act/schedule/
description: "The Schedule to the DPDP Act, 2023 (see section 33): every breach and its maximum penalty, up to ₹250 crore, verbatim from the Gazette of India."
kind: act-schedule
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/schedule/
---
# The Schedule

*[See section 33 (1)]*


| Sl. No. | Breach of provisions of this Act or rules made thereunder | Penalty |
| --- | --- | --- |
| 1 | Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8. | May extend to two hundred and fifty crore rupees. |
| 2 | Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8. | May extend to two hundred crore rupees. |
| 3 | Breach in observance of additional obligations in relation to children under section 9. | May extend to two hundred crore rupees. |
| 4 | Breach in observance of additional obligations of Significant Data Fiduciary under section 10. | May extend to one hundred and fifty crore rupees. |
| 5 | Breach in observance of the duties under section 15. | May extend to ten thousand rupees. |
| 6 | Breach of any term of voluntary undertaking accepted by the Board under section 32. | Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted. |
| 7 | Breach of any other provision of this Act or the rules made thereunder. | May extend to fifty crore rupees. |


## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

The Schedule to the Digital Personal Data Protection Act sets out the maximum financial penalties for breaking different rules under the law. These penalties apply to Data Fiduciaries (entities determining the purpose and means of processing data), Significant Data Fiduciaries (those with higher obligations), and Data Principals (the individuals to whom the data relates).\n\nThe highest penalty is for a Data Fiduciary that fails to take reasonable security safeguards to prevent a personal data breach. This failure can result in a penalty of up to 250 crore rupees. If a Data Fiduciary fails to notify the Board or the affected Data Principal about a data breach, the penalty can reach up to 200 crore rupees. Breaking the special rules for handling children's data also carries a maximum penalty of 200 crore rupees.\n\nSignificant Data Fiduciaries face penalties of up to 150 crore rupees if they fail to meet their extra obligations. If an entity breaks a voluntary undertaking that the Board previously accepted, the penalty can be up to the maximum amount allowed for the original violation. Breaking any other provision of the Act or its rules can lead to a fine of up to 50 crore rupees. Finally, Data Principals who fail to observe their specific duties can be penalized up to 10,000 rupees.

### Key points

- Failing to implement reasonable security safeguards to prevent a data breach carries a penalty of up to 250 crore rupees [1].
- Failing to notify the Board or the affected Data Principal of a data breach can result in a penalty of up to 200 crore rupees [2].
- Breaching the additional obligations related to children carries a penalty of up to 200 crore rupees [3].
- A Significant Data Fiduciary that breaches its specific additional obligations faces a penalty of up to 150 crore rupees [4].
- A Data Principal who breaches their duties under the Act can be penalized up to 10,000 rupees [5].
- Breaching any other provision of the Act or its rules carries a penalty of up to 50 crore rupees [7].

### Common misreadings

- Readers might think the listed amounts are fixed fines, but the text states the penalties 'may extend to' these amounts, meaning they are maximum limits.
- Readers might assume only organizations face financial penalties, but Data Principals can also be penalized up to 10,000 rupees for breaching their duties.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*
