DPDP Act 2023 Penalty Schedule & Section 33(2) Exposure Caps
The Digital Personal Data Protection Act 2023 specifies severe statutory maximum penalties per instance in its Schedule: up to ₹250 crore for failing to implement security safeguards, ₹200 crore for failing to notify breaches, and ₹200 crore for violating children's data obligations. Under Section 33(2), the Data Protection Board of India determines actual penalty amounts based on gravity, duration, gain/loss, and mitigation actions taken. Estimate your exposure using our Free DPDP Penalty Calculator.
The Statutory Penalty Schedule
| Violation Type | Statutory Cap |
|---|---|
| Failure to take reasonable security safeguards to prevent data breach | ₹250 Crore |
| Failure to notify Data Protection Board or users of a breach | ₹200 Crore |
| Breach of obligations in relation to children's data | ₹200 Crore |
| Breach of Significant Data Fiduciary (SDF) obligations | ₹150 Crore |
| Breach of any other provision or statutory duty | ₹50 Crore |
Business Risk & Consumer Protection: Ronin Works ↔ Saaph.in
Failure to respond to consumer privacy requests submitted via platforms like Saaph.in exposes businesses to complaints before the Data Protection Board.
Use our Free DPDP Penalty Calculator to weigh Section 33(2) factors and model your statutory risk exposure.
Want a Comprehensive DPDP Exposure Assessment?
Ronin Works conducts full compliance posture audits, risk quantification, and executive board reviews for Indian companies.