DPDP Act 2023 · Penalties

DPDP Act penalties: what "₹250 crore per instance" actually means

Published July 2026 · ~7 min read · by Ronin Works
Short answer

Penalties under the DPDP Act are imposed by the Data Protection Board of India and top out at ₹250 crore per instance — reserved for failing to take reasonable security safeguards against a personal data breach. Other failures carry their own scheduled maximums, one incident can stack several of them, and the Board weighs gravity, duration and your mitigation efforts. For most SMEs, the nearer-term cost is losing enterprise customers who now demand DPDP compliance in vendor contracts.

"₹250 crore" is the number every headline quotes, but it's widely misunderstood — both by businesses who assume it could never apply to them, and by those who panic that any slip means a company-ending fine. Here's how the penalty regime actually works.

Who imposes penalties — and how

The Act creates the Data Protection Board of India, a digital-first adjudicating body. It doesn't roam around auditing companies; it acts on complaints from data principals (who must first exhaust your grievance process), on breach notifications you are required to file, and on references from the government. After an inquiry where you're heard, it can direct remediation and impose monetary penalties.

When deciding the amount, the Board must consider factors including the nature, gravity and duration of the breach, the type and volume of personal data affected, whether the breach was repetitive, whether you gained from it, and — importantly — the mitigation steps you took and how quickly. Your paper trail is your defence.

The penalty schedule in plain English

The Act's schedule sets a maximum for each category of failure (all figures are upper limits per instance, not fixed amounts):

FailureMaximum penalty
Not taking reasonable security safeguards to prevent a personal data breach₹250 crore
Failing to notify the Board and affected individuals of a breach₹200 crore
Breaching obligations relating to children's data₹200 crore
A Significant Data Fiduciary failing its additional obligations (DPO, audits, impact assessments)₹150 crore
Breaching any other provision of the Act or its rules₹50 crore
A data principal breaching their own duties (e.g. filing false complaints)₹10,000

Notice the design: the two heaviest penalties both attach to breach handling — preventing one, and owning up to one. The law cares most about whether you protected the data and whether you told people when you failed.

What "per instance" means in practice

Each distinct violation can attract its own penalty. Consider one bad week: a marketing database with no access controls is leaked (security safeguards — up to ₹250 crore), the company sits on it for a month without informing anyone (notification failure — up to ₹200 crore), and the database included school-student records collected without parental consent (children's data — up to ₹200 crore). That is one incident, three instances. Sloppy data practices don't add risk linearly — they multiply it.

Will the Board really fine an SME ₹250 crore?

The maximums are just that — maximums, applied with proportionality. A small business with an honest process that suffers a sophisticated attack and responds well is in a very different position from one that never bothered with basic safeguards. But treating that as comfort misses the two costs that arrive before any regulator does:

How to shrink your exposure

Not sure where you stand?

Take our free, 2-minute DPDP Readiness Scorecard — answer 12 questions and get a per-area gap report showing exactly what to fix first.

How Ronin Works helps

Penalty exposure is mostly a data-hygiene problem: unknown copies, unowned systems, records kept long past their purpose. We map where personal data lives, cleanse and minimise it, then build the safeguards, breach playbook and records on top — so if the Board ever asks, you have answers, not excuses.

Keep reading

Not a business — just you?

The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.

Scan your exposure at Saaph.in →
Enquiry

Worried about your DPDP exposure?

Send us a note — we reply within one working day.

✓ Thank you — we'll be in touch.

This article is general information, not legal advice. Penalty amounts are statutory maximums under the DPDP Act's schedule; actual outcomes are determined by the Data Protection Board of India case by case, and rules may change. For a formal assessment, consult a qualified professional or talk to Ronin Works.