CHAPTER VIII - PENALTIES AND ADJUDICATION

Section 33 - Penalties

Official text

(1)If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.

(2)While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:—

(a)the nature, gravity and duration of the breach;

(b)the type and nature of the personal data affected by the breach;

(c)repetitive nature of the breach;

(d)whether the person, as a result of the breach, has realised a gain or avoided any loss;

(e)whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;

(f)whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and

(g)the likely impact of the imposition of the monetary penalty on the person.

Cross-references

Section 33

Commentary

1.1 Detailed commentary on significant breach, monetary penalties, hearing, statutory ceilings and penalty-determination factors

Section 33 establishes the DPDPA’s monetary penalty framework. The Data Protection Board of India may impose a penalty only after completing an inquiry, determining that a person has breached the Act or Rules, and finding that the breach is significant. The person must then receive an opportunity of being heard before any monetary penalty is imposed.

The Schedule determines the maximum penalty available for each category of breach. Section 33(2) determines how the Board should select the appropriate amount within that ceiling.

Commencement position: Section 33 is scheduled to come into force on13 May 2027, eighteen months after publication of the commencement notification dated 13 November 2025. As of 17 August 2026, the provision is enacted but not yet operational.

2. Structure of the penalty mechanism

A monetary penalty under Section 33 ordinarily requires the following sequence:

  1. a proceeding is initiated and an inquiry is conducted under Section 28;

  2. the Board determines that a person breached the Act or Rules;

  3. the Board determines that the breach is significant;

  4. the Board identifies the relevant entry in the Schedule;

  5. the person receives an opportunity of being heard;

  6. the Board considers every relevant factor listed in Section 33(2);

  7. the Board selects a proportionate and effective penalty within the applicable ceiling; and

  8. the resulting order may be challenged through the appellate mechanism under Section 29.

A complaint, personal data breach or compliance deficiency does not itself automatically result in the maximum penalty. Section 33 requires adjudicatory determination and an assessment of seriousness.

Equally, the occurrence of a security incident does not by itself establish every element of a Section 8(5) security violation. The Board must examine whether the Data Fiduciary failed to take reasonable security safeguards and whether that failure constitutes a significant breach.

3. “If the Board determines on conclusion of an inquiry”

The Board must reach its penalty decision on conclusion of an inquiry.

This prevents monetary penalties from being imposed solely on the basis of:

  • an allegation;

  • a complaint;

  • a media report;

  • an unverified breach notification;

  • a preliminary suspicion;

  • a processor’s accusation;

  • an internal audit finding; or

  • an initial technical alert.

The Board may use such information to begin or support an inquiry, but the penalty decision must follow the statutory process.

3.1 What the inquiry should establish

Depending on the alleged breach, the inquiry may need to determine:

  • which person was responsible;

  • the person’s statutory role;

  • what personal data was processed;

  • which provision or Rule applied;

  • what conduct or omission occurred;

  • when the breach began and ended;

  • the number and categories of Data Principals affected;

  • whether a Data Processor was involved;

  • whether the conduct was authorised;

  • which safeguards existed;

  • what harm or risk arose;

  • what mitigation occurred;

  • whether the breach was repeated; and

  • whether the breach was significant.

3.2 Illustration: Cloud exposure

A cloud database containing customer records becomes publicly accessible.

The inquiry should not assume that the cloud provider alone is responsible. It may need to determine:

  • whether the Data Fiduciary or provider configured access;

  • whether safe defaults existed;

  • whether public-access alerts were enabled;

  • whether encryption was used;

  • whether logs were maintained;

  • whether the Data Fiduciary monitored configuration;

  • whether the provider followed contractual instructions;

  • how long the exposure lasted;

  • whether anyone accessed or downloaded the records; and

  • how quickly the parties responded.

The factual location of the database does not determine legal accountability.

4. Breach “by a person”

Section 33 applies to a breach by a person, not only by a Data Fiduciary.

Depending on the provision involved, the person may be:

  • a Data Fiduciary;

  • a Significant Data Fiduciary;

  • a Consent Manager;

  • the State or one of its instrumentalities;

  • a company;

  • a firm;

  • an association;

  • an individual;

  • a Data Principal in relation to Section 15 duties; or

  • another person upon whom the Act or Rules impose a duty.

The applicable penalty depends on:

  1. the statutory obligation;

  2. the person upon whom that obligation falls; and

  3. the corresponding Schedule entry.

A Data Processor does not automatically become liable under every obligation imposed on the Data Fiduciary merely because it caused an operational failure. The Board must identify the Processor’s own statutory role and conduct. The Data Fiduciary remains accountable under Section 8(1) for processing undertaken on its behalf, while contractual liability between the Data Fiduciary and Processor is a separate matter.

5. Meaning of “significant”

Section 33 does not permit monetary penalty for every technical or trivial departure. The Board must determine that the breach is significant.

The Act does not separately define “significant” for Section 33. Its meaning must therefore be assessed from:

  • the ordinary meaning of the word;

  • the nature of the violated obligation;

  • the facts established in the inquiry;

  • the factors listed in Section 33(2); and

  • the protective and deterrent purposes of the Act.

A breach may be significant because of one dominant feature or because several features combine.

Relevant indicators may include:

  • a large number of affected Data Principals;

  • sensitive or consequential personal data;

  • prolonged processing without a recognised ground;

  • serious security deficiencies;

  • repeated non-compliance;

  • deliberate concealment;

  • disregard of earlier warnings;

  • processing of children’s data;

  • material financial or reputational consequences;

  • inability to correct or erase data;

  • widespread disclosure;

  • systematic profiling;

  • substantial commercial gain;

  • ineffective mitigation; or

  • failure to notify affected persons.

Conversely, a technical error that:

  • is isolated;

  • concerns limited data;

  • is detected immediately;

  • produces no continuing exposure;

  • is corrected promptly;

  • does not affect a decision or disclosure;

  • is not repeated; and

  • reveals no material governance failure may be less likely to justify a monetary penalty, although the final conclusion remains for the Board.

5.1 Significant does not necessarily mean large-scale

A breach affecting one person can still be significant.

5.2 Illustration: One employee’s medical record

An HR manager deliberately sends one employee’s psychiatric assessment to the employee’s entire department to humiliate her.

Only one Data Principal is directly affected. Nevertheless, the conduct may be significant because:

  • the information is highly consequential;

  • the disclosure is deliberate;

  • the audience is extensive;

  • the breach may cause serious employment and reputational consequences; and

  • the conduct represents a grave abuse of authorised access.

The number of affected persons is relevant, but not decisive.

5.3 Large scale does not automatically settle the amount

A configuration error may briefly expose a large dataset but be detected before external access occurs. The scale remains serious, but duration, actual access, mitigation and safeguards are also relevant to the penalty amount.

6. “It may impose”

Even after finding a significant breach, Section 33 says the Board may impose a monetary penalty.

This gives the Board discretion, but not arbitrary discretion. The decision should reflect:

  • the seriousness of the breach;

  • the statutory factors;

  • the need to secure compliance;

  • deterrence;

  • proportionality;

  • corrective action;

  • the applicable ceiling; and

  • the likely impact on the person.

The word “may” indicates that a finding of significant breach does not mechanically require the maximum penalty. It does not allow the Board to disregard equivalent cases without reason.

A reasoned order should identify:

  • the breach found;

  • why it is significant;

  • the Schedule entry applied;

  • aggravating and mitigating factors;

  • the person’s submissions;

  • the selected amount; and

  • why that amount is proportionate and effective.

7. Opportunity of being heard

Before imposing a monetary penalty, the Board must give the person an opportunity of being heard.

This is an important procedural safeguard. The person should be able to address:

  • whether a breach occurred;

  • whether it was attributable to that person;

  • whether the relevant provision applied;

  • whether the breach was significant;

  • the appropriate Schedule entry;

  • the factual extent of the incident;

  • the number of affected Data Principals;

  • the nature of the data;

  • duration;

  • mitigation;

  • repetition;

  • gain or avoided loss;

  • impact of the proposed penalty; and

  • proportionality.

The hearing should be meaningful. It should not be treated as a formality after the Board has irreversibly fixed the amount.

7.1 Evidence that may be relevant

The person may rely on:

  • system logs;

  • incident reports;

  • processor contracts;

  • audit records;

  • access reviews;

  • security certifications;

  • forensic reports;

  • communications to Data Principals;

  • Board notifications;

  • employee training records;

  • mitigation evidence;

  • deletion certificates;

  • legal-retention registers;

  • remedial-action reports;

  • financial information; and

  • evidence concerning prior compliance.

The Board may distinguish between evidence created contemporaneously and documents prepared only after the inquiry began.

7.2 Illustration: Disputed breach timing

A company is alleged to have left a customer database exposed for six months. The company produces logs showing:

  • the misconfiguration existed for six months;

  • external access was technically possible;

  • no external IP address accessed the exposed endpoint;

  • the issue was detected during an internal review;

  • the endpoint was disabled within one hour; and

  • credentials were rotated immediately.

The existence of the misconfiguration remains relevant. The logs may nevertheless affect the Board’s findings on actual extent, likely consequences, gravity and mitigation.

8. Penalty ceilings under the Schedule

The Schedule specifies maximum monetary penalties for different breaches. These are ceilings, not fixed amounts.

BreachMaximum penalty
Failure to take reasonable security safeguards under Section 8(5)₹250 crore
Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6)₹200 crore
Breach of obligations relating to children under Section 9₹200 crore
Breach of additional obligations of a Significant Data Fiduciary under Section 10₹150 crore
Breach of a Data Principal’s duties under Section 15₹10,000
Breach of a voluntary undertaking accepted under Section 32Up to the amount applicable to the underlying breach for which proceedings were instituted
Breach of any other provision of the Act or Rules₹50 crore

8.1 Fixed ceilings, not turnover percentages

Unlike the GDPR, the DPDPA Schedule prescribes rupee-denominated maximum amounts rather than penalties calculated as a percentage of annual worldwide turnover.

Therefore:

  • the same statutory ceiling may apply to a startup and a large multinational;

  • the actual amount must be adjusted through Section 33(2);

  • financial size remains relevant through proportionality and the likely impact of the penalty;

  • the Board should not automatically impose the ceiling merely because it is available.

8.2 The maximum is not the default

The phrase “may extend to” means that the Board may impose an amount below the ceiling.

Example

For example, a significant Section 8(5) security failure does not automatically produce a ₹250 crore penalty. The Board must consider all relevant circumstances under Section 33(2).

9. Security safeguards: maximum ₹250 crore

The highest ceiling applies to failure to take reasonable security safeguards under Section 8(5).

The existence of a personal data breach does not necessarily prove that safeguards were unreasonable. Even a well-secured organisation may suffer a sophisticated attack.

The inquiry should examine whether the Data Fiduciary had appropriate measures such as:

  • encryption;

  • access control;

  • multifactor authentication;

  • logging;

  • monitoring;

  • vulnerability remediation;

  • backups;

  • incident response;

  • processor security provisions;

  • testing; and

  • organisational governance.

9.1 Case study: Payroll database without basic controls

Employer E uses Payroll Provider P. The payroll portal contains employee names, PAN details, bank accounts, salaries and addresses.

The system has:

  • shared administrator credentials;

  • no multifactor authentication;

  • no encryption for downloaded files;

  • no administrator-access logs;

  • former employees’ active accounts;

  • no security review;

  • no breach escalation clause; and

  • internet exposure.

An attacker downloads 80,000 employee records.

The Board may regard this as a serious Section 8(5) failure because the breach was enabled by multiple basic control deficiencies affecting highly consequential financial and identity data.

Relevant aggravating factors include:

  • scale;

  • foreseeable risk;

  • absence of elementary controls;

  • lack of logs;

  • continuing access by former personnel; and

  • substantial identity and financial risk.

If the employer had received prior audit warnings and failed to act, the repetitive or knowing character would further aggravate the matter.

10. Breach-notification failure: maximum ₹200 crore

A separate ceiling applies to failure to notify:

  • the Board; or

  • affected Data Principals under Section 8(6).

Security failure and notification failure are legally distinct.

An organisation may:

  • violate Section 8(5) by failing to prevent the breach;

  • violate Section 8(6) by not notifying;

  • violate both; or

  • suffer a breach despite reasonable security but still violate Section 8(6) by failing to notify.

10.1 Case study: Deliberately delayed notification

A hospital discovers that a processor exposed patient records, including diagnoses, prescriptions and contact details.

Senior management delays notification for six weeks because it is negotiating an acquisition and fears adverse publicity. During that period:

  • no patients are warned;

  • phishing messages impersonating the hospital begin;

  • patients cannot take protective steps;

  • the Board is not informed; and

  • the hospital issues only a vague statement after the incident becomes public.

The delayed notification may attract significant treatment because:

  • the delay was deliberate;

  • health information was involved;

  • affected persons lost the opportunity to protect themselves;

  • the organisation prioritised a commercial transaction over statutory duties; and

  • the delay increased the practical consequences.

Prompt notification after media exposure would not erase the earlier failure, though later cooperation may still be considered.

11. Children’s-data obligations: maximum ₹200 crore

The Schedule provides a maximum penalty of ₹200 crore for breach of Section 9 obligations relating to children.

Relevant conduct may include:

  • processing without verifiable parental consent where required;

  • causing a detrimental effect on a child’s well-being;

  • tracking or behavioural monitoring contrary to Section 9;

  • targeted advertising directed at children; or

  • failing to satisfy conditions attached to an exemption.

11.1 Case study: Child-directed gaming application

A gaming application is designed for users aged 12 to 17 but records every user as an adult based only on a self-declared checkbox.

The application:

  • tracks play behaviour;

  • creates vulnerability profiles;

  • predicts when a child is likely to make a purchase;

  • sends targeted prompts;

  • uses location and device identifiers;

  • shares advertising segments; and

  • does not obtain verifiable parental consent.

Relevant factors may include:

  • the platform’s actual child audience;

  • deliberate avoidance of age verification;

  • duration;

  • behavioural tracking;

  • commercial gain;

  • number of children;

  • whether the design exploited vulnerability;

  • prior complaints; and

  • whether the practices continued after internal warnings.

A platform should not be treated as compliant merely because its terms state that users must be adults when its design and audience show substantial use by children.

12. Significant Data Fiduciary obligations: maximum ₹150 crore

A formally notified Significant Data Fiduciary faces additional obligations under Section 10 and Rule 13, including requirements concerning:

  • appointment of a Data Protection Officer;

  • appointment of an independent data auditor;

  • periodic DPIAs;

  • audits;

  • algorithmic due diligence; and

  • specified localisation restrictions where applicable.

12.1 Case study: SDF ignores algorithmic risks

A notified SDF uses an algorithm to suspend customer accounts for suspected fraud.

Internal testing shows that the model:

  • produces a high false-positive rate;

  • disproportionately misclassifies certain regional users;

  • relies on outdated location indicators;

  • provides no meaningful review pathway; and

  • automatically shares fraud labels with another group entity.

The SDF does not conduct the required due diligence, does not include the system meaningfully in its DPIA, and continues using it after internal warnings.

The breach may be aggravated by:

  • the consequential effect on customers;

  • repeated use;

  • known model deficiencies;

  • disclosure of inaccurate fraud labels;

  • absence of effective review; and

  • failure to perform enhanced SDF duties.

13. Data Principal duties: maximum ₹10,000

The DPDPA also imposes duties on Data Principals under Section 15. The Schedule provides a substantially lower maximum penalty of ₹10,000 for breach of those duties.

Potential examples include:

  • impersonating another person while providing personal data;

  • suppressing material information while seeking correction or erasure;

  • registering a false or frivolous grievance or complaint; or

  • providing false particulars when exercising rights.

The existence of this penalty should not be used by Data Fiduciaries to intimidate individuals who raise genuine concerns.

A complaint is not “false or frivolous” merely because:

  • the Data Fiduciary disagrees;

  • the complaint is ultimately rejected;

  • the Data Principal cannot prove every allegation;

  • the issue results from a misunderstanding;

  • the individual uses strong language; or

  • no penalty is imposed on the Data Fiduciary.

13.1 Case study: Deliberate impersonation

Person A seeks access to Person B’s account records. A supplies:

  • B’s name;

  • a fabricated authorisation;

  • misleading contact information; and

  • false identity particulars.

If the conduct is established, Section 15 and the corresponding Schedule entry may apply.

By contrast, if a customer mistakenly identifies the wrong transaction date while making a genuine complaint, that ordinary error should not automatically be treated as a breach deserving penalty.

14. Breach of voluntary undertaking

If a person fails to comply with a voluntary undertaking accepted under Section 32, the maximum penalty corresponds to the amount applicable to the breach for which the original proceedings were instituted.

This ensures that an undertaking is not used to obtain closure and then ignored.

14.1 Case study: Unfulfilled deletion undertaking

A recruitment platform gives an undertaking to:

  • delete unlawfully retained applicant profiles within sixty days;

  • stop using them for AI training;

  • cause subprocessors to delete copies;

  • submit an independent deletion report; and

  • refrain from restarting the processing.

The platform deletes visible profiles but:

  • retains embeddings;

  • continues model training;

  • leaves copies with a subprocessor;

  • submits an incomplete report; and

  • misses the deadline.

The failure constitutes a deemed breach under Section 32(5). The Schedule ceiling is linked to the underlying matter covered by the original proceeding.

Partial or cosmetic compliance does not necessarily satisfy the undertaking.

15. Catch-all penalty: maximum ₹50 crore

The Schedule provides a residual ceiling for breach of any other provision of the Act or Rules.

This may cover significant breaches concerning matters such as:

  • notice;

  • consent;

  • consent withdrawal;

  • certain legitimate uses;

  • processor contracts;

  • data quality;

  • erasure;

  • contact information;

  • grievance redressal;

  • rights handling;

  • cross-border processing restrictions;

  • Consent Manager obligations; and

  • other prescribed requirements not assigned a specific penalty entry.

15.1 Case study: Applicant data retained indefinitely

A company collects applications for one vacancy. Its notice states that information will be used for the current recruitment exercise.

After the vacancy closes, the company:

  • retains all CVs indefinitely;

  • keeps background reports;

  • uses unsuccessful applicants for unrelated AI training;

  • allows recruiters to export profiles;

  • ignores erasure requests;

  • fails to cause processor deletion; and

  • provides no functioning privacy contact.

The Board may need to identify each breached provision and determine which Schedule entry applies. Where no more specific entry governs the relevant significant breach, the residual ceiling may apply.

16. Section 33(2)(a): Nature, gravity and duration

This factor examines what happened, how serious it was and how long it continued.

16.1 Nature

The nature of a breach concerns its character.

Example

Examples include:

  • accidental disclosure;

  • deliberate sale;

  • failure to erase;

  • unlawful profiling;

  • security failure;

  • inaccurate decision-making;

  • children’s tracking;

  • suppression of breach information; or

  • failure to comply with an undertaking.

A deliberate commercial misuse is different from an isolated administrative error.

16.2 Gravity

Gravity concerns seriousness and consequences.

Relevant considerations may include:

  • number of Data Principals;

  • likelihood of identity theft;

  • financial consequences;

  • employment effects;

  • denial of services;

  • reputational consequences;

  • discrimination;

  • inability to correct data;

  • vulnerability of affected persons;

  • breadth of disclosure; and

  • reversibility.

16.3 Duration

Duration concerns how long the breach continued.

A breach may be:

  • instantaneous;

  • repeated daily;

  • continuous for months;

  • discovered and immediately stopped; or

  • knowingly continued after warning.

16.4 Detailed case study: Exposed customer portal

A customer portal exposes addresses and order histories because of a coding defect.

16.5 Scenario A: Short duration

The defect exists for twelve minutes, is detected automatically, and logs confirm that no unauthorised user accessed the records.

16.6 Scenario B: Long duration

The defect exists for fourteen months, search engines index the pages, the company receives customer complaints, and no corrective action is taken.

Both scenarios concern the same types of data. The second is substantially more serious because of:

  • long duration;

  • actual dissemination;

  • ignored warnings;

  • greater scale; and

  • ineffective governance.

17. Section 33(2)(b): Type and nature of personal data

The Board must consider the type and nature of affected personal data.

The DPDPA does not create a statutory category called “sensitive personal data.” Nevertheless, the character of the data matters directly under Section 33(2)(b).

Higher-impact data may include:

  • financial information;

  • banking details;

  • health records;

  • biometric templates;

  • identity documents;

  • precise location;

  • children’s data;

  • employment assessments;

  • family details;

  • communications;

  • allegations;

  • authentication credentials; and

  • legal or disciplinary records.

The inquiry should consider not only the field name but also context.

A mobile number in a business directory differs from the same number associated with:

  • a domestic-violence shelter;

  • psychiatric treatment;

  • a political complaint;

  • a whistle-blower report; or

  • a child’s location.

17.1 Case study: Two email disclosures

17.2 Scenario A

A company accidentally discloses a public professional email address.

17.3 Scenario B

A company discloses an email address specifically used by an employee to report workplace harassment, together with the complaint and supporting material.

The same general identifier appears in both situations. The context and connected data make the second substantially more consequential.

18. Section 33(2)(c): Repetitive nature

The Board must consider whether the breach is repetitive.

Repetition may include:

  • the same breach occurring multiple times;

  • continued failure across several systems;

  • recurring complaints;

  • repeated incidents involving the same weakness;

  • failure to implement an earlier corrective measure;

  • similar violations across business units;

  • prior Board findings;

  • breach of an undertaking; or

  • continuation after internal audit warnings.

The Board should distinguish between:

  • one incident affecting many records; and

  • repeated separate failures arising from an unresolved cause.

Both may be serious, but they are analytically different.

18.1 Case study: Repeated marketing after withdrawal

A retailer receives complaints for twelve months that customers continue receiving messages after withdrawal.

Each time, customer service manually removes the complainant from one mailing list. The retailer never fixes the underlying problem that:

  • the email processor, SMS provider and advertising platform maintain different suppression lists;

  • processor updates are not reconciled;

  • withdrawn customers are reimported during campaign uploads; and

  • no central control exists.

The repetitive nature may aggravate the penalty because the organisation:

  • knew of the failure;

  • treated each complaint as isolated;

  • failed to correct the systemic cause; and

  • permitted the same breach to recur.

19. Section 33(2)(d): Gain realised or loss avoided

The Board must consider whether the person obtained a gain or avoided a loss as a result of the breach.

Under Section 2, “gain” and “loss” are broad and can include:

  • property;

  • services;

  • opportunities to earn remuneration;

  • greater remuneration; and

  • financial advantage.

This factor prevents non-compliance from becoming economically attractive.

19.1 Gain realised

Example

Examples include:

  • revenue from unlawful profiling;

  • sale of personal data;

  • increased advertising income;

  • subscription growth through manipulative tracking;

  • commercial use of unlawfully retained records; and

  • model development using personal data without incurring lawful acquisition costs.

19.2 Loss avoided

Example

Examples include:

  • avoiding the cost of encryption;

  • avoiding security upgrades;

  • avoiding deletion engineering;

  • failing to appoint required personnel;

  • avoiding an audit;

  • not building a consent-withdrawal system;

  • retaining data to avoid reacquisition costs; and

  • not notifying a breach to avoid reputational damage.

19.3 Case study: Avoided security expenditure

A financial platform receives repeated recommendations to implement multifactor authentication and privileged-access monitoring. Management rejects the controls because they would cost ₹3 crore and delay launch.

An administrator account is compromised, exposing customer financial records.

The Board may consider that the organisation avoided a known security cost and accepted the corresponding risk. The avoided expenditure does not mechanically determine the final penalty, but it is an aggravating consideration.

19.4 Case study: Unlawful advertising revenue

A platform continues tracking users who withdrew consent because removing them would reduce advertising revenue.

The platform earns substantial income from the continued profiles.

The gain is directly connected to the breach and supports a stronger deterrent penalty.

20. Section 33(2)(e): Mitigation, timeliness and effectiveness

The Board must consider:

  • whether any mitigation occurred;

  • how quickly it occurred; and

  • whether it was effective.

Mitigation is not measured by announcements or intentions. It concerns actual reduction of effects and consequences.

Effective steps may include:

  • isolating affected systems;

  • blocking unauthorised access;

  • rotating credentials;

  • restoring accurate data;

  • notifying affected persons promptly;

  • assisting with protective measures;

  • deleting unauthorised copies;

  • correcting recipients’ records;

  • stopping disputed processing;

  • re-evaluating adverse decisions;

  • repairing processor controls;

  • preserving evidence;

  • appointing independent experts; and

  • testing recurrence prevention.

20.1 Case study: Two ransomware responses

20.2 Organisation A

Within hours, it:

  • isolates affected systems;

  • activates tested backups;

  • preserves logs;

  • informs the Board;

  • informs affected persons;

  • gives practical protective instructions;

  • obtains processor cooperation;

  • restores services;

  • conducts independent testing; and

  • publishes a reliable update.

20.3 Organisation B

It:

  • conceals the incident;

  • deletes logs;

  • pays the attacker without investigation;

  • delays notification;

  • tells customers nothing;

  • blames the processor without evidence; and

  • leaves the same vulnerability open.

The underlying attacks may be similar, but the mitigation factor strongly distinguishes the appropriate penalty.

20.4 Later remediation does not erase the breach

Prompt mitigation can reduce consequences and influence penalty. It does not retrospectively make the original breach lawful.

An organisation should not assume:

“We corrected the problem, so no penalty can be imposed.”

Correction is relevant, but the Board may still need a penalty for observance and deterrence.

21. Section 33(2)(f): Proportionate and effective penalty

The Board must ensure that the amount is:

  • proportionate to the breach;

  • effective in securing observance; and

  • sufficient to deter future breach.

These requirements operate together.

21.1 Proportionate

A penalty should reflect:

  • seriousness;

  • culpability;

  • duration;

  • affected data;

  • scale;

  • repetition;

  • gain;

  • mitigation;

  • consequences; and

  • the person’s circumstances.

A minor isolated failure should not ordinarily attract the same amount as a deliberate, prolonged and profitable misuse.

21.2 Effective

The amount should be capable of securing compliance. A purely nominal penalty may be ineffective where the violator earned far more through the unlawful activity.

21.3 Deterrent

The penalty should discourage:

  • the same person from repeating the breach; and

  • other similarly placed persons from treating non-compliance as an acceptable business cost.

21.4 Case study: Profitable unlawful profiling

A large platform earns ₹75 crore from an unlawful profiling programme. A penalty of ₹1 lakh would be unlikely to remove the commercial incentive or deter repetition.

By contrast, imposing the maximum available amount on a small entity for an isolated and promptly corrected administrative error may be disproportionate and unnecessarily destructive.

The Board must select an amount that is neither merely symbolic nor excessive.

22. Section 33(2)(g): Likely impact on the person

The Board must consider the likely impact of the monetary penalty on the person against whom it is imposed.

Relevant considerations may include:

  • turnover;

  • assets;

  • financial condition;

  • business size;

  • liquidity;

  • number of employees;

  • ability to continue essential services;

  • dependency of users on the service;

  • public functions;

  • insolvency risk;

  • remedial expenditure already incurred; and

  • effect on ongoing compliance investment.

This factor does not create immunity for small businesses. Nor does it mean that a large company should automatically receive the maximum penalty.

Its purpose is to ensure that the penalty remains proportionate and effective in the actual circumstances.

22.1 Case study: Same breach, different entities

A small healthcare startup and a major national hospital network commit comparable access-control failures.

The statutory ceiling may be the same. However, the same absolute penalty may:

  • close the startup entirely;

  • be insignificant to the national network; or

  • undermine patient services disproportionately.

The Board should consider financial impact while still ensuring meaningful deterrence.

A person should not be able to avoid an effective penalty merely by claiming financial hardship without reliable evidence.

23. Interaction among the seven factors

The factors do not operate in isolation.

A single case may involve:

23.1 Aggravating considerations

  • prolonged breach;

  • children’s or health data;

  • repeated warnings;

  • commercial gain;

  • concealment;

  • ineffective response;

  • failure to cooperate;

  • weak governance; and

  • continued processing after discovery.

23.2 Mitigating considerations

  • isolated occurrence;

  • strong prior controls;

  • immediate containment;

  • prompt and complete notification;

  • effective support for affected persons;

  • independent investigation;

  • processor correction;

  • voluntary disclosure;

  • full cooperation;

  • remediation before inquiry; and

  • no gain or avoided loss.

The Board should explain how these considerations affect the final amount rather than merely listing them.

24. Consolidated case study: E-commerce data breach

E-Commerce Company E stores:

  • customer names;

  • addresses;

  • phone numbers;

  • order histories;

  • password hashes;

  • payment tokens; and

  • customer-support records.

A processor leaves an administrative interface exposed. An attacker accesses two million customer records.

24.1 Security breach

The Board examines whether E:

  • conducted processor due diligence;

  • required contractual safeguards;

  • maintained access controls;

  • reviewed privileged access;

  • enabled multifactor authentication;

  • monitored logs;

  • tested the interface; and

  • acted on earlier security findings.

If elementary safeguards were absent, Section 8(5) and the ₹250 crore ceiling may become relevant.

24.2 Notification breach

E discovers the incident but waits three weeks to notify customers and the Board.

Section 8(6) and the separate ₹200 crore ceiling may become relevant.

24.3 Nature, gravity and duration

The interface was exposed for nine months and accessed repeatedly. This aggravates the matter.

24.4 Type of data

Addresses, order histories, credentials and payment-related tokens increase the practical risk.

24.5 Repetition

A previous audit had identified the same administrative-interface weakness. Management deferred remediation. This aggravates culpability.

24.6 Gain or avoided loss

E avoided the cost and delay of implementing the recommended security changes.

24.7 Mitigation

After discovery, E:

  • isolates the interface;

  • rotates credentials;

  • forces password resets;

  • assists affected users;

  • appoints forensic experts;

  • revises processor access; and

  • conducts independent testing.

These steps may mitigate the amount, but they do not erase the preceding failures or notification delay.

24.8 Proportionality and impact

The Board must choose amounts that reflect the seriousness and deter repetition while considering E’s financial condition and the operational impact.

25. Monetary penalty is not compensation

A penalty under Section 33 is a public-law enforcement measure. It is not automatically compensation payable to the affected Data Principal.

Section 34 provides for sums realised through penalties to be credited to the Consolidated Fund of India. An affected individual should therefore not assume that a Board penalty will be paid to her as damages.

Corrective outcomes may still arise through:

  • grievance redressal;

  • mediation under Section 31;

  • a voluntary undertaking under Section 32;

  • correction or erasure;

  • account restoration;

  • processor remediation; or

  • another remedy available under applicable law.

The functions of penalty and individual relief should not be conflated.

26. Multiple breaches arising from one incident

One factual incident may implicate several statutory obligations.

Example

For example, a breach involving children may also involve:

  • failure to implement reasonable security;

  • failure to notify;

  • breach of children’s-data obligations;

  • failure to comply with a voluntary undertaking; and

  • another contravention under the Rules.

The Board must identify each legally distinct breach and the applicable Schedule entry. The Act does not justify counting the same conduct repeatedly under different labels without analysing whether the obligations and failures are genuinely distinct.

Equally, an organisation should not assume that one penalty ceiling automatically covers every separate violation connected with the incident.

The penalty order should explain:

  • each breach found;

  • the facts supporting it;

  • the applicable Schedule entry;

  • whether conduct overlaps;

  • the amount attributed to each breach; and

  • overall proportionality.

27. Common mistakes in understanding Section 33

27.1 Mistake 1: “Every breach automatically attracts the maximum penalty”

The Schedule provides ceilings. The Board must find significance, provide a hearing and consider Section 33(2).

27.2 Mistake 2: “A security incident proves inadequate security”

A breach may occur despite reasonable safeguards. The Board must examine the actual controls and circumstances.

27.3 Mistake 3: “Only Data Fiduciaries can be penalised”

Section 33 refers to breach by a person. The relevant obligation determines who may be liable.

27.4 Mistake 4: “Prompt remediation eliminates the violation”

Remediation is relevant to the amount but does not automatically erase the original breach.

27.5 Mistake 5: “A processor contract transfers all penalty exposure”

Section 8(1) prevents the Data Fiduciary from contracting away statutory accountability.

27.6 Mistake 6: “The DPDPA fine is based on worldwide turnover”

The DPDPA uses rupee-denominated ceilings, not GDPR-style turnover percentages.

27.7 Mistake 7: “An individual receives the penalty amount”

Penalties are credited to the Consolidated Fund of India, not automatically paid as compensation.

27.8 Mistake 8: “A rejected complaint is necessarily frivolous”

A Data Principal’s complaint does not become false or frivolous merely because it is unsuccessful.

27.9 Mistake 9: “Large scale is the only measure of significance”

A deliberate disclosure of one person’s medical or biometric information may still be significant.

27.10 Mistake 10: “Once an undertaking is accepted, the entire matter disappears”

The bar applies only to the contents of the undertaking and depends on compliance with every accepted term.

27.11 Final interpretation

Section 33 does not create an automatic fine for every technical non-compliance. It establishes a structured adjudicatory process in which the Board must:

  1. complete an inquiry;

  2. identify a breach by a person;

  3. determine that the breach is significant;

  4. provide an opportunity of being heard;

  5. identify the applicable Schedule ceiling;

  6. consider every relevant statutory factor; and

  7. impose an amount that is proportionate, effective and deterrent.

The Schedule provides the outer limits. Section 33(2) provides the calibration mechanism.

A serious penalty becomes more likely where the breach is:

  • prolonged;

  • deliberate;

  • repeated;

  • profitable;

  • harmful;

  • concealed;

  • poorly mitigated;

  • connected with consequential personal data; or

  • committed despite prior knowledge.

A lower penalty, or potentially a different enforcement response, may be appropriate where the breach is isolated, promptly detected, effectively contained, fully reported, non-repetitive and supported by credible evidence of prior compliance and substantial remediation.

The controlling principle is:

Key point

The penalty must fit both the breach and the person: serious enough to secure compliance and deter repetition, but no greater than is proportionate to the established facts and statutory purpose.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.