KryptoMindz Technologies

KryptoMindz Insight · DPDP Act

DPDP Act Penalties Explained

The DPDP Act deters with money, not jail: up to ₹250 crore for security safeguard failures, up to ₹200 crore for breach-notification and children's-data violations. Here is the full picture.

By 10 min read Reviewed August 7, 2026

Key takeaways

  • The DPDP Act relies on financial penalties and does not create criminal offences or jail terms.
  • The highest tiers — ₹250 crore for safeguard failure leading to a breach and ₹200 crore for breach-notification failure or children's-data violations — target negligence in security and transparency.
  • Penalties are applied by the Data Protection Board of India through digital-first, evidence-driven proceedings.

How the penalty regime works

Penalties under the DPDP Act are set out in the Schedule and applied by the Data Protection Board of India. They are administrative financial penalties, not criminal sanctions — an important difference from earlier bill drafts and from jurisdictions that criminalize certain data practices.

Penalty tiers at a glance

ViolationMaximum penalty
Failure to take reasonable security safeguards leading to a personal data breach₹250 crore
Failure to notify the Board and affected users of a breach₹200 crore
Violation of children's data obligations (verifiable parental consent, no tracking or targeted ads)₹200 crore
Other specified violations under the Schedule₹50 crore per the current Schedule (verify current edition)
Data Principal duty violations (false complaints, impersonation, suppression of information)Up to ₹10,000

Why the top tiers matter for planning

Two violations dominate the top of the Schedule: failing to protect data that then leaks, and failing to tell people when it leaks. That pairing is a signal about where regulators expect organizations to invest — security safeguards and breach transparency.

The children's-data tier is equally notable: violations of verifiable parental consent, tracking, behavioral monitoring or targeted advertising directed at children carry the same ₹200 crore ceiling as breach-notification failure. Products that touch users under 18 should treat this as a first-class design constraint.

How the Board applies penalties

The Data Protection Board of India is an adjudicatory body. It directs investigations into personal data breaches, inquires into complaints and can impose penalties, direct remediation or allow compounding. Under the DPDP Rules, 2025, its proceedings are digital-first: electronic filings, virtual hearings and digital evidence.

The practical consequence for compliance teams: the record you keep — breach detection timelines, notification attempts, notice versions, consent records, retention decisions — is the same record the Board will examine. Evidence quality is not an audit afterthought; it is the substance of the proceeding.

Managing penalty risk

Reduce your DPDP penalty exposure

KryptoMindz helps teams build security safeguards, breach response playbooks and evidence architecture that survive Board scrutiny.

Discuss Your Risk Program

Go deeper