/The Act · Chapter VIII · Penalties and Adjudication
Section 33: Penalties
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 33 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- None identified
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:—
whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;
whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and
Section 33 gives the Board the power to impose financial penalties when someone breaks the rules of the Act. If the Board finishes an inquiry and decides that a breach is significant, it can issue a monetary penalty. The amounts for these penalties are listed in a separate Schedule. Before imposing any penalty, the Board must give the person a chance to be heard. The law does not set a fixed fine for every violation. Instead, the Board must look at several specific factors to decide the exact amount. These include how serious the breach was, how long it lasted, and what kind of personal data was involved. The Board also checks if the person has broken the rules before, or if they made money or avoided losing money because of the breach. Furthermore, the Board will consider how the person reacted after the breach happened. If the person took quick and effective steps to fix the problem and reduce the harm, the Board must take that into account. Finally, the Board must ensure the penalty is proportionate, acts as a strong deterrent, and considers the financial impact the fine will have on the person paying it.
Key points
- The Board can impose a monetary penalty if it determines after an inquiry that a breach of the Act or rules is significant (1).
- The person accused of the breach must be given an opportunity to be heard before a penalty is imposed (1).
- The Board must consider the nature, gravity, duration, and repetitive nature of the breach when setting the penalty amount (2)(a), (2)(c).
- The Board must look at whether the person gained an advantage or avoided a loss due to the breach (2)(d).
- The timeliness and effectiveness of any actions taken to mitigate the breach must be factored into the penalty amount (2)(e).
- The penalty must be proportionate, effective for deterrence, and consider the likely impact on the person (2)(f), (2)(g).
Common misreadings
- People might think penalties are automatic, but the Board must first conclude an inquiry and give the person a chance to be heard.
- People might assume all breaches get the same fine, but the Board must adjust the amount based on specific factors like mitigation efforts and the nature of the data.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.