---
title: "Penalties and the Board"
url: https://dpdp.myndsolution.com/wiki/faq/penalties-and-board/
description: "Maximum penalties in the Schedule, how the Board decides an amount, how complaints reach it, the digital office, appeals to TDSAT and voluntary undertakings."
kind: faq
updated: 2026-09-09
text_type: analysis
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/faq/penalties-and-board/
---
# Penalties and the Board

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

## What is the maximum penalty under the DPDP Act?

Two hundred and fifty crore rupees, for one specific failure. [The Schedule](/wiki/act/schedule/) sets a ceiling for each kind of breach. Failing to take reasonable security safeguards to prevent a personal data breach under section 8(5) "may extend to two hundred and fifty crore rupees". Failing to notify the Board or an affected Data Principal of a breach under section 8(6), and breaching the children's obligations in section 9, each "may extend to two hundred crore rupees". Breaching the extra obligations of a Significant Data Fiduciary under section 10 "may extend to one hundred and fifty crore rupees". Breaching the duties of a Data Principal under section 15 "may extend to ten thousand rupees". Any other breach of the Act or Rules "may extend to fifty crore rupees".

## When can the Board actually impose a penalty?

Only at the end of an inquiry, and only for a significant breach. If the Board "determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule" ([section 33(1)](/wiki/act/section-33/)). Three conditions are built into that sentence: an inquiry must have been completed, the breach must be found significant, and the person must have been heard. The Schedule figures are ceilings, not tariffs. They can move: the Central Government may amend the Schedule by notification, but no amendment may raise a penalty beyond twice what was specified when the Act was originally enacted ([section 42](/wiki/act/section-42/)).

## What does the Board weigh when deciding the amount?

Seven factors, listed in [section 33(2)](/wiki/act/section-33/). The nature, gravity and duration of the breach. The type and nature of the personal data affected. Whether the breach was repetitive. Whether the person realised a gain or avoided a loss as a result of it. Whether the person acted to mitigate the effects and consequences, and how timely and effective that action was. Whether the penalty is proportionate and effective, having regard to the need to secure observance and to deter breaches. And the likely impact of the penalty on the person. Mitigation and speed are therefore worth money, and repetition costs money.

## Where does the penalty money go?

To the Consolidated Fund of India. All sums realised by way of penalties imposed by the Board under the Act are credited there ([section 34](/wiki/act/section-34/)). Nothing in the Act routes any part of a penalty to the Data Principals affected by the breach, so this is not a compensation mechanism. What an affected person can get from the Board is action rather than money: on receiving an intimation of a personal data breach it may direct urgent remedial or mitigation measures ([section 27(1)(a)](/wiki/act/section-27/)), and it may issue directions to any person, after hearing them and recording reasons in writing, which that person is bound to comply with ([section 27(2)](/wiki/act/section-27/)).

## How does a complaint reach the Data Protection Board?

Through five doors, set out in [section 27(1)](/wiki/act/section-27/). On an intimation of a personal data breach from a Data Fiduciary, where the Board may also direct urgent remedial or mitigation measures. On a complaint from a Data Principal about a personal data breach or about a Data Fiduciary's observance of its obligations or her rights. On a complaint about a Consent Manager. On an intimation that a Consent Manager has breached a condition of registration. And on a reference from the Central Government about an intermediary under section 37(2). A Data Principal must first exhaust the company's own grievance process ([section 13(3)](/wiki/act/section-13/)). The Board may also direct the parties to mediation if it thinks the complaint can be resolved that way ([section 31](/wiki/act/section-31/)).

## Does the Board hold physical hearings?

As a rule, no. The Board "shall function as an independent body and shall, as far as practicable, function as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions in respect of the same being digital by design" ([section 28(1)](/wiki/act/section-28/)). The Rules go further: the Board shall function as a digital office and may adopt techno-legal measures to conduct proceedings "in a manner that does not require physical presence of any individual", without prejudice to its power to summon a person and examine her on oath ([rule 20](/wiki/rules/rule-20/)). A digital office is one where everything from receipt to disposal happens online ([section 2(m)](/wiki/act/section-2/)).

## How long does a Board inquiry take?

Six months, extendable. An inquiry by the Board "shall be completed within a period of six months from the date of receipt of the intimation, complaint, reference or direction under section 27 of the Act, unless such period is extended by it, for reasons to be recorded in writing, for a further period not exceeding three months at a time" ([rule 19(9)](/wiki/rules/rule-19/)). Before inquiring at all, the Board must decide whether there are sufficient grounds to proceed, and it may close the proceedings for reasons recorded in writing if there are not ([section 28(3)](/wiki/act/section-28/) and [section 28(4)](/wiki/act/section-28/)).

## Can I appeal a Board order, and how long do I have?

Sixty days. Any person aggrieved by an order or direction of the Board may appeal to the Appellate Tribunal, which is the Telecom Disputes Settlement and Appellate Tribunal ([section 2(a)](/wiki/act/section-2/) and [section 29(1)](/wiki/act/section-29/)). The appeal must be filed "within a period of sixty days from the date of receipt of the order or direction appealed against", though the Tribunal may admit a late appeal if satisfied there was sufficient cause ([section 29(2)](/wiki/act/section-29/) and [section 29(3)](/wiki/act/section-29/)). It must be filed in digital form, and the fee is the same as for an appeal under the Telecom Regulatory Authority of India Act, 1997, payable through the Unified Payments Interface or another payment system authorised by the Reserve Bank of India, unless reduced or waived by the Tribunal's Chairperson ([rule 22](/wiki/rules/rule-22/)). The Tribunal is to endeavour to dispose of an appeal within six months ([section 29(6)](/wiki/act/section-29/)).

## What is a voluntary undertaking?

A way to settle without a penalty. The Board may accept a voluntary undertaking from any person, on any matter related to observance of the Act, at any stage of a proceeding under section 28 ([section 32(1)](/wiki/act/section-32/)). It may include a commitment to take or refrain from an action within a time the Board determines, and to publicise the undertaking. Once accepted, it bars further proceedings on the matters it covers ([section 32(4)](/wiki/act/section-32/)). The catch is in the last sub-section: if the person fails to adhere to any term, that failure is deemed to be a breach of the Act, and the Board may proceed to penalty after hearing her ([section 32(5)](/wiki/act/section-32/)). That penalty runs "up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted" ([the Schedule](/wiki/act/schedule/)).

## Is the Data Protection Board functioning?

It exists, and its enforcement powers are not yet switched on. By [G.S.R. 844(E)](/wiki/notifications/gsr-844e-2025/) of 13 November 2025 the Central Government established the Data Protection Board of India with effect from the date of publication, and fixed its head office in the National Capital Region of India. By [G.S.R. 845(E)](/wiki/notifications/gsr-845e-2025/) of the same date it notified that the Board shall consist of four members. Sections 18 to 26, which cover establishment, composition, appointment, resignation, proceedings and staff, came into force on 13 November 2025 under [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/), as did the Rules on appointments, salaries, meetings, digital functioning and staff ([rules 17](/wiki/rules/rule-17/) to [21](/wiki/rules/rule-21/)). Section 27, which gives the Board its powers and functions, and section 28, which sets its procedure, are not yet in force, apart from section 27(1)(d) one year after publication.
