DPDP Act penalties, explained in plain English
The ₹250 crore figure gets quoted in every headline and understood by almost nobody. It is a ceiling for one specific failure, not a flat fine, and the Schedule to the Act sets out several distinct bands.
Knowing which band your likely failure falls into is the difference between panic and a prioritised plan.
Check this site free — DPDP, GDPR & CCPA score in 10 seconds
No signup for the score. Takes about 10 seconds. We only read your homepage.
The penalty bands
The Schedule to the DPDP Act sets maximum penalties per breach. These are upper limits — the Board determines actual quantum after an inquiry.
- Up to ₹250 crore — failure to take reasonable security safeguards to prevent a personal data breach
- Up to ₹200 crore — failure to notify the Board or affected Data Principals of a breach
- Up to ₹200 crore — failure to meet additional obligations regarding children's data
- Up to ₹150 crore — failure to meet additional obligations of a Significant Data Fiduciary
- Up to ₹50 crore — breach of any other provision, including consent and Data Principal rights obligations
- Up to ₹10,000 — penalty on a Data Principal who files false or frivolous complaints
How quantum is decided
Section 33(2) directs the Board to consider the nature, gravity and duration of the breach, the type of personal data affected, whether the breach was repetitive, whether the person gained or avoided loss by it, any mitigating action taken, and whether the penalty is proportionate and effective.
That list rewards documentation. A fiduciary who can show a consent log, a DSAR queue with response times, and a dated remediation record is arguing from a very different position than one who cannot.
You have to be able to prove it
The obligation that catches most teams out is evidentiary. Under Section 8, the Data Fiduciary — you — is responsible for demonstrating compliance, including that valid consent was obtained. If the Board asks and your answer is "our banner was live", that is not evidence.
A defensible consent record contains, at minimum: a stable visitor identifier, the categories accepted and rejected, a UTC timestamp, the version of the notice shown, the policy text hash, and enough network context to establish the request was genuine without storing raw personal identifiers. AssentRepo writes exactly this record for every consent event and one-way hashes the IP address with a server-side salt, so the log is useful to an auditor and useless to an attacker.
Frequently asked questions
Is the ₹250 crore penalty per violation or total?
It is a maximum per instance of the specified breach, determined by the Board after inquiry. Multiple distinct breaches can be assessed separately.
Can a small business really be fined crores?
The Board weighs proportionality, so a small business is unlikely to face a headline number. It is very likely to face an inquiry it cannot answer, and remediation under deadline, which for a small team is disruptive enough.
Get DPDP-ready in five minutes
One script tag: consent banner, audit log, DSAR queue. Free up to 1,000 consent events a month.