---
title: "Section 33: Penalties"
url: https://dpdp.myndsolution.com/wiki/act/section-33-penalties/
description: "Section 33 of the Digital Personal Data Protection Act, 2023 (Penalties). Official text verbatim, comes into force on 13 may 2027, with plain-English…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-33-penalties/
---
# Section 33: Penalties

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter VIII: PENALTIES AND ADJUDICATION. Comes into force on 13 May 2027.*

## Official text

- **(1)** If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.

- **(2)** While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:—
  - **(a)** the nature, gravity and duration of the breach;
  - **(b)** the type and nature of the personal data affected by the breach;
  - **(c)** repetitive nature of the breach;
  - **(d)** whether the person, as a result of the breach, has realised a gain or avoided any loss;
  - **(e)** whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;
  - **(f)** whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and
  - **(g)** the likely impact of the imposition of the monetary penalty on the person.



## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Section 33 gives the Board the power to impose financial penalties when someone breaks the rules of the Act. If the Board finishes an inquiry and decides that a breach is significant, it can issue a monetary penalty. The amounts for these penalties are listed in a separate Schedule. Before imposing any penalty, the Board must give the person a chance to be heard. The law does not set a fixed fine for every violation. Instead, the Board must look at several specific factors to decide the exact amount. These include how serious the breach was, how long it lasted, and what kind of personal data was involved. The Board also checks if the person has broken the rules before, or if they made money or avoided losing money because of the breach. Furthermore, the Board will consider how the person reacted after the breach happened. If the person took quick and effective steps to fix the problem and reduce the harm, the Board must take that into account. Finally, the Board must ensure the penalty is proportionate, acts as a strong deterrent, and considers the financial impact the fine will have on the person paying it.

### Key points

- The Board can impose a monetary penalty if it determines after an inquiry that a breach of the Act or rules is significant (1).
- The person accused of the breach must be given an opportunity to be heard before a penalty is imposed (1).
- The Board must consider the nature, gravity, duration, and repetitive nature of the breach when setting the penalty amount (2)(a), (2)(c).
- The Board must look at whether the person gained an advantage or avoided a loss due to the breach (2)(d).
- The timeliness and effectiveness of any actions taken to mitigate the breach must be factored into the penalty amount (2)(e).
- The penalty must be proportionate, effective for deterrence, and consider the likely impact on the person (2)(f), (2)(g).

### Common misreadings

- People might think penalties are automatic, but the Board must first conclude an inquiry and give the person a chance to be heard.
- People might assume all breaches get the same fine, but the Board must adjust the amount based on specific factors like mitigation efforts and the nature of the data.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 33. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
