DPDP Wiki Talk to us

/The Act · Chapter VIII · Penalties and Adjudication

Section 33: Penalties

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter VIII: Penalties and Adjudication
Provision
Section 33 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
None identified
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 33. Penalties

Verbatim from the Gazette of India
(1)

If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.

(2)

While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:—

(a)

the nature, gravity and duration of the breach;

(b)

the type and nature of the personal data affected by the breach;

(c)

repetitive nature of the breach;

(d)

whether the person, as a result of the breach, has realised a gain or avoided any loss;

(e)

whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;

(f)

whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and

(g)

the likely impact of the imposition of the monetary penalty on the person.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
BoardData FiduciaryData ProcessorConsent Manager

Section 33 gives the Board the power to impose financial penalties when someone breaks the rules of the Act. If the Board finishes an inquiry and decides that a breach is significant, it can issue a monetary penalty. The amounts for these penalties are listed in a separate Schedule. Before imposing any penalty, the Board must give the person a chance to be heard. The law does not set a fixed fine for every violation. Instead, the Board must look at several specific factors to decide the exact amount. These include how serious the breach was, how long it lasted, and what kind of personal data was involved. The Board also checks if the person has broken the rules before, or if they made money or avoided losing money because of the breach. Furthermore, the Board will consider how the person reacted after the breach happened. If the person took quick and effective steps to fix the problem and reduce the harm, the Board must take that into account. Finally, the Board must ensure the penalty is proportionate, acts as a strong deterrent, and considers the financial impact the fine will have on the person paying it.

Key points

  • The Board can impose a monetary penalty if it determines after an inquiry that a breach of the Act or rules is significant (1).
  • The person accused of the breach must be given an opportunity to be heard before a penalty is imposed (1).
  • The Board must consider the nature, gravity, duration, and repetitive nature of the breach when setting the penalty amount (2)(a), (2)(c).
  • The Board must look at whether the person gained an advantage or avoided a loss due to the breach (2)(d).
  • The timeliness and effectiveness of any actions taken to mitigate the breach must be factored into the penalty amount (2)(e).
  • The penalty must be proportionate, effective for deterrence, and consider the likely impact on the person (2)(f), (2)(g).

Common misreadings

  • People might think penalties are automatic, but the Board must first conclude an inquiry and give the person a chance to be heard.
  • People might assume all breaches get the same fine, but the Board must adjust the amount based on specific factors like mitigation efforts and the nature of the data.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.