/Tools
Penalty lookup: maximum penalties under the DPDP Act
The Schedule (see section 33) lists 7 kinds of breach. The Board decides the actual amount after an inquiry, considering the factors in section 33(2).
/Item 1
May extend to two hundred and fifty crore rupees.
Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8.
/Item 2
May extend to two hundred crore rupees.
Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8.
/Item 3
May extend to two hundred crore rupees.
Breach in observance of additional obligations in relation to children under section 9.
/Item 4
May extend to one hundred and fifty crore rupees.
Breach in observance of additional obligations of Significant Data Fiduciary under section 10.
/Item 6
Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted.
Breach of any term of voluntary undertaking accepted by the Board under section 32.
/Item 7
May extend to fifty crore rupees.
Breach of any other provision of this Act or the rules made thereunder.
/MYND · DPDP practice
Want to know where your exposure actually sits?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.