DPDP Act Penalties: ₹250 Crore Fine — Who Is at Risk?
India's Digital Personal Data Protection (DPDP) Act, 2023, has fundamentally changed how organizations must handle personal data. If you are still asking, "What is DPDP Act?", it's time to get up to speed quickly, because the cost of ignorance is exceptionally high.
Unlike previous frameworks, the DPDP Act introduces a steep penalty structure, with fines going up to ₹250 Crore for a single breach. There are no criminal provisions, but the financial repercussions are designed to ensure strict compliance from both Data Fiduciaries (organizations that determine the purpose and means of processing personal data) and Data Principals (individuals to whom the data relates).
In this article, we break down the penalty structure, explore who enforces these fines, discuss how they are calculated, and provide practical advice on how to avoid them.
The DPDP Act Penalty Breakdown Table
The Schedule to the DPDP Act outlines the maximum penalties for various contraventions. Here is a clear breakdown of the financial risks:
| Offence/Contravention | Maximum Penalty | Who is at Risk? | | :--- | :--- | :--- | | Failure to take reasonable security safeguards to prevent personal data breach | Up to ₹250 Crore | Data Fiduciary | | Failure to give the Data Protection Board or Data Principal notice of a personal data breach | Up to ₹200 Crore | Data Fiduciary | | Non-fulfilment of additional obligations in relation to processing of children's data | Up to ₹200 Crore | Data Fiduciary | | Non-fulfilment of additional obligations of Significant Data Fiduciaries | Up to ₹150 Crore | Significant Data Fiduciary | | Breach of any other provision of the Act or Rules | Up to ₹50 Crore | Data Fiduciary / Processor | | Breach of duties by a Data Principal | Up to ₹10,000 | Data Principal (Individual) |
1. The ₹250 Crore Threat: Personal Data Breaches
The most severe penalty under the Act is reserved for failing to implement reasonable security safeguards. If your organization suffers a data breach and it is proven that you lacked adequate security measures, you could face fines up to ₹250 Crore. This emphasizes the necessity of robust cybersecurity frameworks, encryption, and regular audits. For a comprehensive overview of necessary safeguards, review our DPDP Compliance Checklist.
2. The ₹200 Crore Fine: Failure to Notify
Even if a breach occurs, the Act mandates that you must promptly notify both the Data Protection Board (DPB) and the affected individuals. Attempting to cover up a breach or failing to report it within the specified timeframe can result in an additional penalty of up to ₹200 Crore. Transparency is no longer optional.
3. Protecting Children's Data
The DPDP Act places a high premium on the protection of children's data. Processing data of individuals under 18 requires verifiable parental consent. Furthermore, you cannot undertake tracking, behavioral monitoring, or targeted advertising directed at children. Violating these provisions can cost up to ₹200 Crore.
Who Enforces the Penalties?
The enforcement of the DPDP Act is the responsibility of the Data Protection Board (DPB) of India. The DPB is an independent body established by the Central Government.
The DPB has the authority to:
- Direct any person to provide information.
- Conduct inquiries into potential breaches.
- Impose financial penalties.
- Issue binding directions to ensure compliance.
If you are found in violation, the DPB will issue a notice, hear your representation, and then determine the final penalty amount.
How Are Penalties Calculated?
The figures mentioned above (e.g., ₹250 Crore) are maximum limits. The DPB will not automatically levy the maximum fine for every minor infraction. According to Section 33(2) of the Act, the Board will consider several factors when determining the quantum of the penalty:
- Nature, gravity, and duration of the breach: A temporary, minor glitch will be treated differently than a systemic, long-term failure.
- Type and nature of the personal data affected: Was it basic contact info, or sensitive financial/health data?
- Repetitive nature of the breach: Repeat offenders will face harsher penalties.
- Impact of the breach: Did the breach cause significant harm to the Data Principals?
- Mitigating actions taken: Did you act quickly to stop the breach and minimize damage? Did you assist the DPB?
- Proportionality: The fine will be proportionate to the size of the company and its revenue, ensuring it acts as a deterrent without necessarily bankrupting smaller entities.
Real-World Scenarios and Practical Advice
Let’s look at some practical scenarios and how to mitigate the risks.
Scenario A: The Accidental Deletion
A customer requests their account to be deleted. Your customer support team acknowledges the request but forgets to follow through, leaving the data on your servers. If the customer complains, you are violating their data rights. Advice: Implement automated data deletion workflows. Ensure your team understands the Right to Erasure Guide to handle these requests promptly and compliantly.
Scenario B: The Vendor Data Leak
You use a third-party marketing agency (a Data Processor) and share your customer list with them. Their database gets hacked. Advice: As the Data Fiduciary, you are ultimately responsible. You must ensure your contracts with Data Processors include strict security requirements and audit rights. If a breach happens, you must notify the DPB, not just rely on the vendor.
Scenario C: The Silent Breach
Your IT team discovers unauthorized access to a server containing customer emails. They patch the vulnerability but decide not to tell management or the customers because "no financial data was stolen." Advice: This is a critical failure. Create a mandatory internal reporting policy where all suspected breaches are immediately escalated to your Data Protection Officer (DPO). The decision to notify the DPB must be made at the highest level, prioritizing transparency to avoid the ₹200 Crore non-notification penalty.
How to Avoid Penalties: Proactive Compliance
Waiting for a breach to occur is not a strategy. To avoid these staggering penalties, you must adopt a proactive approach to compliance:
- Map Your Data: Understand what personal data you collect, why you collect it, where it is stored, and who has access to it.
- Implement Security Safeguards: Invest in encryption, access controls, and regular vulnerability assessments.
- Establish a Breach Response Plan: Have a documented plan detailing exactly who does what when a breach is suspected, ensuring the DPB and Data Principals are notified promptly.
- Train Your Employees: Your security is only as strong as your weakest link. Ensure everyone understands the principles of the DPDP Act.
- Use Purpose-Built Software: Managing consents, data rights requests, and breach notifications manually via spreadsheets is a recipe for disaster.
Automate Your DPDP Compliance with Infiverix
Navigating the complexities of the DPDP Act shouldn't require a massive legal team. Infiverix provides a comprehensive SaaS platform designed specifically for Indian businesses to manage DPDP compliance effortlessly.
From automated consent management and privacy notice generation to tracking data rights requests and logging grievance resolutions, Infiverix gives you the tools you need to avoid crippling fines.
Don't leave your compliance to chance. Protect your business and your customers' data today.
Start your compliance journey now — Go to your Infiverix Dashboard
Ready to automate your DPDP compliance?
Join Indian startups using Infiverix to manage consent and data rights effortlessly.
Start Free Pilot