DPDP Act penalties: what "₹250 crore per instance" actually means
Penalties under the DPDP Act are imposed by the Data Protection Board of India and top out at ₹250 crore per instance — reserved for failing to take reasonable security safeguards against a personal data breach. Other failures carry their own scheduled maximums, one incident can stack several of them, and the Board weighs gravity, duration and your mitigation efforts. For most SMEs, the nearer-term cost is losing enterprise customers who now demand DPDP compliance in vendor contracts.
"₹250 crore" is the number every headline quotes, but it's widely misunderstood — both by businesses who assume it could never apply to them, and by those who panic that any slip means a company-ending fine. Here's how the penalty regime actually works.
Who imposes penalties — and how
The Act creates the Data Protection Board of India, a digital-first adjudicating body. It doesn't roam around auditing companies; it acts on complaints from data principals (who must first exhaust your grievance process), on breach notifications you are required to file, and on references from the government. After an inquiry where you're heard, it can direct remediation and impose monetary penalties.
When deciding the amount, the Board must consider factors including the nature, gravity and duration of the breach, the type and volume of personal data affected, whether the breach was repetitive, whether you gained from it, and — importantly — the mitigation steps you took and how quickly. Your paper trail is your defence.
The penalty schedule in plain English
The Act's schedule sets a maximum for each category of failure (all figures are upper limits per instance, not fixed amounts):
| Failure | Maximum penalty |
|---|---|
| Not taking reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Failing to notify the Board and affected individuals of a breach | ₹200 crore |
| Breaching obligations relating to children's data | ₹200 crore |
| A Significant Data Fiduciary failing its additional obligations (DPO, audits, impact assessments) | ₹150 crore |
| Breaching any other provision of the Act or its rules | ₹50 crore |
| A data principal breaching their own duties (e.g. filing false complaints) | ₹10,000 |
Notice the design: the two heaviest penalties both attach to breach handling — preventing one, and owning up to one. The law cares most about whether you protected the data and whether you told people when you failed.
What "per instance" means in practice
Each distinct violation can attract its own penalty. Consider one bad week: a marketing database with no access controls is leaked (security safeguards — up to ₹250 crore), the company sits on it for a month without informing anyone (notification failure — up to ₹200 crore), and the database included school-student records collected without parental consent (children's data — up to ₹200 crore). That is one incident, three instances. Sloppy data practices don't add risk linearly — they multiply it.
Will the Board really fine an SME ₹250 crore?
The maximums are just that — maximums, applied with proportionality. A small business with an honest process that suffers a sophisticated attack and responds well is in a very different position from one that never bothered with basic safeguards. But treating that as comfort misses the two costs that arrive before any regulator does:
- Contractual: enterprise customers are already adding DPDP warranties and audit rights to vendor agreements. Non-compliance now loses deals, quietly, in procurement.
- Reputational: breach notification is mandatory — meaning your customers will find out. The days of quietly absorbing a leak are over.
How to shrink your exposure
- Know where your data is. You can't safeguard data you can't locate — start with data discovery.
- Minimise what you hold. Every duplicate, stale or purposeless record is penalty surface. Cleanse and de-duplicate so there is less to breach.
- Apply basic safeguards — access controls, encryption, least privilege, and logs that prove it.
- Write a breach playbook — detect, contain, notify the Board and affected people. Speed of response is a statutory mitigating factor.
- Document everything. Records of processing, consent, and grievance handling are what stand between "negligent" and "unlucky" in front of the Board.
Not sure where you stand?
Take our free, 2-minute DPDP Readiness Scorecard — answer 12 questions and get a per-area gap report showing exactly what to fix first.
How Ronin Works helps
Penalty exposure is mostly a data-hygiene problem: unknown copies, unowned systems, records kept long past their purpose. We map where personal data lives, cleanse and minimise it, then build the safeguards, breach playbook and records on top — so if the Board ever asks, you have answers, not excuses.
Keep reading
- DPDP Act 2023: a practical compliance checklist for Indian businesses
- Grievance officer under the DPDP Act: who needs one, and how to appoint them
- What happens when a company ignores a deletion request — Saaph's side, escalating exactly the failure mode that leads here
The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.
Scan your exposure at Saaph.in →Worried about your DPDP exposure?
Send us a note — we reply within one working day.
This article is general information, not legal advice. Penalty amounts are statutory maximums under the DPDP Act's schedule; actual outcomes are determined by the Data Protection Board of India case by case, and rules may change. For a formal assessment, consult a qualified professional or talk to Ronin Works.