Infosek
INFOSEK

DPDP Penalties Explained: What Each Breach Actually Costs

The headline number is two hundred and fifty crore rupees. It attaches to one specific failure, not to DPDP generally, and the Schedule to the Act sets out six other heads alongside it.

DPDP Penalties Explained: What Each Breach Actually Costs

The short answer

The Schedule to the DPDP Act, read with section 33(1), sets seven heads of penalty. These are maximums, not fixed fines:

Security is the most expensive thing to get wrong

The top two heads, totalling ₹450 crore of exposure, both concern a personal data breach: failing to prevent one, and failing to report one properly. The obligations behind them are now specific rather than open-ended.

Rule 6 sets out what reasonable security safeguards must include at minimum: encryption, obfuscation, masking or virtual tokens; access control on computer resources; logs and monitoring for detecting unauthorised access; backups for continuity; contractual provisions binding Data Processors; and retention of logs and personal data for one year to support detection and investigation.

Rule 7 sets out the reporting. Because it is a list, a gap assessment against Rule 6 is concrete: you either have logging that meets 6(1)(c) and 6(1)(e) or you do not.

When does enforcement actually begin?

This is where most planning goes wrong. The Board was constituted on 14 November 2025 by sections 18 to 26, read with Rules 17 to 21. But under G.S.R. 843(E), section 27 — the Board’s power to inquire into a breach or complaint and impose a penalty — commences on 14 May 2027.

The penalty provisions themselves, sections 28 to 34, also commence on 14 May 2027, as do the duties in sections 3 to 17. So there is no penalty exposure under the Act before that date. The urgency is not enforcement risk in the meantime; it is that the obligations arriving in May 2027 are engineering work that cannot be completed in a quarter.

A maximum is not a forecast. The Board assesses each case on its facts, and an organisation that reported promptly and had documented controls is in a very different position from one that could not say what had been accessed.

Infosek Team

What actually reduces the number

Section 33(2) requires the Board to have regard to matters including the nature, gravity and duration of the breach, the type of personal data affected, whether the breach was repetitive, whether any gain or loss resulted, what mitigating action was taken and how promptly, and whether the penalty is proportionate and effective.

Almost every item on that list is something you influence before an incident rather than during one. Documented controls, working logs, a tested response procedure and a prompt, complete intimation are the difference between demonstrating diligence and being unable to describe what happened.

The practical reading

Common questions

What is the maximum penalty under the DPDP Act?

Two hundred and fifty crore rupees. Under the Schedule to the Digital Personal Data Protection Act 2023, read with section 33(1), that is the maximum for a breach of the obligation to take reasonable security safeguards to prevent a personal data breach under section 8(5).

Who imposes DPDP penalties?

The Data Protection Board of India. The Board was constituted by sections 18 to 26, which commenced on 14 November 2025. Its powers and functions under section 27, including inquiring into complaints and imposing penalties, commence on 14 May 2027, apart from section 27(1)(d) which commences on 14 November 2026.

Want to know which of these you are exposed to?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment