DPDP Act penalties: up to ₹250 crore

Updated 19 Sep 2026 · 4min read · Reviewed by ConsentLo's DPDP audit team

The DPDP Act sets out a schedule of maximum penalties. The Data Protection Board decides the actual amount after an inquiry, considering the nature and impact of the breach.

Maximum penalties

Penalties apply per instance of breach of an obligation:

  • Up to ₹250 crore: failing to take reasonable security safeguards to prevent a personal data breach.
  • Up to ₹200 crore: failing to notify the Board or affected people of a breach.
  • Up to ₹200 crore: failing to meet the additional obligations for children.
  • Up to ₹150 crore: failing to meet the additional obligations of a Significant Data Fiduciary.
  • Up to ₹10,000: a Data Principal breaching their own duties, such as filing a false complaint.
  • Up to ₹50 crore: breach of any other provision of the Act or Rules.

How the amount is decided

The Board considers the nature, gravity and duration of the breach, the type of personal data affected, whether it was repeated, any gain made or loss avoided, how quickly and effectively it was mitigated, and whether the penalty is proportionate. Timely action and good records count in your favour.

Reducing your exposure

ConsentLo estimates your exposure from open issues, such as overdue requests or unreported breaches, using the Act's own factors, so you can fix the costliest gaps first. The estimate is indicative, not a prediction of any Board order.

Frequently asked questions

What is the highest penalty under the DPDP Act?

Up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach.

Can DPDP penalties be appealed?

Yes. Orders of the Data Protection Board can be appealed to the Appellate Tribunal (TDSAT), generally within 60 days.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.