DPDP Act Schedule · Penalty Analysis

DPDP Act 2023 Penalty Schedule & Section 33(2) Exposure Caps

Published 30 July 2026 · 6 min read · By Ronin Works Team
Short Answer

The Digital Personal Data Protection Act 2023 specifies severe statutory maximum penalties per instance in its Schedule: up to ₹250 crore for failing to implement security safeguards, ₹200 crore for failing to notify breaches, and ₹200 crore for violating children's data obligations. Under Section 33(2), the Data Protection Board of India determines actual penalty amounts based on gravity, duration, gain/loss, and mitigation actions taken. Estimate your exposure using our Free DPDP Penalty Calculator.

The Statutory Penalty Schedule

Violation TypeStatutory Cap
Failure to take reasonable security safeguards to prevent data breach₹250 Crore
Failure to notify Data Protection Board or users of a breach₹200 Crore
Breach of obligations in relation to children's data₹200 Crore
Breach of Significant Data Fiduciary (SDF) obligations₹150 Crore
Breach of any other provision or statutory duty₹50 Crore

Business Risk & Consumer Protection: Ronin Works ↔ Saaph.in

Failure to respond to consumer privacy requests submitted via platforms like Saaph.in exposes businesses to complaints before the Data Protection Board.

Use our Free DPDP Penalty Calculator to weigh Section 33(2) factors and model your statutory risk exposure.

Legal Disclaimer: Penalty figures are statutory maximums. Actual amounts are determined case-by-case by the Data Protection Board of India.
DPDP Risk Audit

Want a Comprehensive DPDP Exposure Assessment?

Ronin Works conducts full compliance posture audits, risk quantification, and executive board reviews for Indian companies.

Something went wrong. Email contact@roninworks.in directly.
✓ Received! A Ronin Works compliance lead will respond within 1 business day.