CHAPTER VIII - PENALTIES AND ADJUDICATION

Section 34 - Crediting sums realised by way of penalties to Consolidated Fund of India

Official text

All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India.

Commentary

Section 34 provides that every sum actually recovered from a monetary penalty imposed by the Data Protection Board of India under the DPDPA must be credited to the Consolidated Fund of India. It confirms that penalties under the Act are public regulatory sanctions intended to secure compliance and deter violations, not compensation payable to affected Data Principals.

Commencement position: Section 34 is scheduled to come into force on13 May 2027, eighteen months after publication of the commencement notification dated 13 November 2025. As of 17 August 2026, it is enacted but not yet operational.

1. Relationship between Sections 33 and 34

Sections 33 and 34 perform different but connected functions.

Section 33 determines:

  • when the Board may impose a monetary penalty;

  • whether the established breach is significant;

  • which penalty ceiling in the Schedule applies;

  • what factors must be considered when fixing the amount; and

  • what opportunity of hearing must be given to the person concerned.

Section 34 determines only what happens to the penalty amount after it is recovered.

The statutory sequence is therefore:

  1. the Board conducts an inquiry;

  2. it determines that a significant breach occurred;

  3. it gives the person an opportunity of being heard;

  4. it imposes a monetary penalty under Section 33;

  5. the person may pursue the statutory appeal;

  6. the amount that remains legally payable is recovered; and

  7. the amount realised is credited to the Consolidated Fund of India.

Section 34 does not independently authorise a penalty, calculate its amount or determine whether the breach was significant.

2. “All sums realised”

The expression “all sums” makes the provision comprehensive. It applies to every amount recovered from a penalty imposed by the Board under the Act, irrespective of:

  • the amount;

  • the identity of the person penalised;

  • the number of Data Principals affected;

  • the provision breached;

  • whether the matter arose from a complaint or another statutory process; or

  • whether the penalty involved a Data Fiduciary, Significant Data Fiduciary, Consent Manager, Data Principal or another person subject to an obligation under the Act.

It therefore covers penalties relating to:

  • failure to maintain reasonable security safeguards;

  • failure to notify the Board or affected Data Principals of a personal data breach;

  • violation of children’s-data obligations;

  • violation of Significant Data Fiduciary obligations;

  • breach of Data Principal duties;

  • breach of an accepted voluntary undertaking; and

  • significant breach of any other provision of the Act or Rules.

2.1 “Realised” is different from “imposed”

A penalty is imposed when the Board passes the penalty order. It isrealised when the amount is actually paid or recovered.

This distinction matters where:

  • the payment period has not expired;

  • an appeal is pending;

  • a stay has been granted;

  • the penalty is reduced on appeal;

  • the amount is recovered in instalments;

  • only part of the penalty has been recovered; or

  • the order is set aside.

Section 34 operates on the amount actually realised, not merely the amount originally mentioned in the Board’s order.

2.2 Illustration 1: Penalty reduced on appeal

The Board imposes a penalty of ₹60 crore. The Appellate Tribunal reduces the penalty to ₹35 crore. The person then pays ₹35 crore.

The amount realised is ₹35 crore. That amount must be credited to the Consolidated Fund of India.

The original ₹60 crore does not become public revenue because the final legally payable amount was reduced before recovery.

2.3 Illustration 2: Partial recovery

The Board imposes a penalty of ₹10 crore. The Government initially recovers ₹4 crore while proceedings for recovery of the balance continue.

The ₹4 crore already realised must be credited to the Consolidated Fund. The remaining ₹6 crore becomes subject to Section 34 when it is recovered.

2.4 Illustration 3: Penalty set aside before payment

The Board imposes a penalty, but the Appellate Tribunal sets aside the order before any amount is recovered.

No penalty amount has been realised. Section 34 does not create an independent payment obligation after the underlying penalty has been set aside.

3. Penalties are regulatory and not compensatory

Section 34 confirms the legal character of a DPDPA monetary penalty. It is a regulatory enforcement measure imposed in response to a significant breach of the Act or Rules.

The penalty serves purposes such as:

  • securing observance of the Act;

  • deterring repetition;

  • responding to significant non-compliance;

  • reinforcing accountability; and

  • discouraging organisations from treating non-compliance as an acceptable business cost.

It is not calculated or distributed as damages for the losses suffered by individual Data Principals.

An affected Data Principal therefore does not acquire a right to the penalty amount merely because:

  • her complaint initiated the proceeding;

  • her personal data was involved;

  • she suffered financial loss;

  • she suffered anxiety or reputational harm;

  • the Board found a serious violation; or

  • a substantial penalty was imposed.

The entire amount realised goes to the Consolidated Fund.

4. Penalty and compensation must be distinguished

The distinction between a public penalty and individual compensation is central to understanding Section 34.

4.1 Monetary penalty

A monetary penalty under the DPDPA:

  • is imposed by the Board under Section 33;

  • requires a significant breach;

  • is subject to the ceiling in the Schedule;

  • is calibrated through the factors in Section 33(2);

  • promotes compliance and deterrence; and

  • is credited to the Consolidated Fund under Section 34.

4.2 Compensation

Compensation ordinarily seeks to place an affected person, so far as money can do so, in a position addressing the harm caused to her.

Such harm may include:

  • fraudulent transactions;

  • identity theft;

  • expenses incurred in protecting accounts;

  • loss of employment;

  • loss of business opportunity;

  • reputational damage;

  • emotional distress;

  • anxiety;

  • loss of control over private information; or

  • other material or non-material consequences.

The DPDPA does not contain an express standalone compensation provision equivalent to Article 82 GDPR. Sections 33 and 34 create a public penalty mechanism, not a damages action before the Board.

Consequently, the Board cannot ordinarily take part of a penalty and direct that it be paid to the affected Data Principal as compensation.

5. Financial loss following a data breach

5.1 Facts

An e-commerce company fails to secure a customer database. The exposed records include:

  • names;

  • addresses;

  • phone numbers;

  • purchase histories;

  • payment-related information; and

  • account identifiers.

One customer later suffers fraudulent transactions amounting to ₹75,000.

The Board completes an inquiry and determines that the company failed to take reasonable security safeguards. It imposes a penalty of ₹90 crore, which the company pays.

The ₹90 crore must be credited to the Consolidated Fund.

The customer does not receive:

  • ₹75,000 from the penalty;

  • a proportionate share of the ₹90 crore;

  • priority over the penalty proceeds; or

  • an automatic monetary award from the Board.

The Board’s penalty and the customer’s loss are legally distinct.

The customer may obtain regulatory and corrective protection through:

  • breach notification;

  • assistance with account security;

  • correction of inaccurate information;

  • cessation of unauthorised processing;

  • grievance redressal;

  • mediation under Section 31;

  • commitments contained in a voluntary undertaking; or

  • another remedy available under applicable law.

However, the penalty itself remains public revenue.

6. Non-material harm following a privacy breach

The distinction is equally important where the Data Principal suffers serious non-financial harm.

6.1 Facts

A mental-health application suffers a personal data breach. The exposed information includes:

  • diagnoses;

  • therapy notes;

  • information concerning depression;

  • details of suicidal ideation;

  • family information; and

  • private communications with therapists.

The affected individual does not suffer an immediately measurable financial loss. She nevertheless experiences:

  • anxiety;

  • loss of sleep;

  • fear that her employer or family may obtain the information;

  • withdrawal from social interaction; and

  • loss of control over intensely private information.

The nature of the information and the likely consequences may make the breach particularly grave for penalty purposes. They may influence the Board’s assessment under Section 33 concerning:

  • the nature and gravity of the breach;

  • the type and nature of the personal data;

  • the effectiveness of mitigation; and

  • the amount needed for deterrence.

However, any penalty realised must still be credited to the Consolidated Fund.

The penalty does not become compensation for the individual’s anxiety, distress or loss of control. Section 34 does not empower the Board to award the penalty proceeds to her.

7. Individual harm may affect penalty severity without becoming compensation

It would be incorrect to conclude that harm to Data Principals is entirely irrelevant under Section 33 merely because Section 34 sends the penalty to the Consolidated Fund.

The Board must consider the nature and gravity of the breach and thetype and nature of the personal data affected. The practical consequences for individuals may therefore help demonstrate the gravity of the violation.

Example

For example:

  • fraudulent transactions may show the gravity of exposure of banking data;

  • denial of employment may show the consequences of inaccurate background information;

  • exposure of medical records may aggravate the seriousness of a breach;

  • disclosure of a person’s home address may create a physical-safety risk;

  • disclosure of a child’s precise location may be especially serious;

  • public circulation of disciplinary allegations may cause substantial reputational consequences.

These circumstances may support a higher regulatory penalty.

But there remains a fundamental distinction:

7.1 Considering individual consequences when fixing a public penalty is not the same as awarding compensation for those consequences.

Even if a person’s harm increases the penalty amount, Section 34 requires the resulting penalty to be credited to the Consolidated Fund.

8. The Board cannot distribute penalty proceeds among affected Data Principals

Section 34 uses mandatory language. All sums realised from Board-imposed penalties shall be credited to the Consolidated Fund.

The Board therefore cannot ordinarily direct that:

  • a percentage of the penalty be paid to the complainant;

  • the penalty be divided among affected users;

  • the penalty be used to reimburse individual financial losses;

  • a portion be reserved for persons who suffered identity theft;

  • the penalty fund counselling or monitoring for affected individuals;

  • the penalty be transferred to a representative action fund; or

  • the penalty finance a class-wide settlement.

These may be desirable forms of remediation in particular circumstances, but they cannot be created by redirecting the statutory penalty contrary to Section 34.

If a Data Fiduciary provides money, services or reimbursement to affected Data Principals, that must arise through a distinct legal basis, such as:

  • a mediated settlement;

  • a private settlement;

  • a contractual obligation;

  • an insurance arrangement;

  • a consumer remedy;

  • a court order under another law; or

  • a separately structured remedial commitment.

9. Different categories of payment

Not every payment arising from a data-protection incident is a penalty under Section 34.

PaymentLegal characterDestination
Board-imposed monetary penaltyPublic regulatory sanctionConsolidated Fund of India
Reimbursement agreed in mediationSettlement paymentAffected Data Principal, as agreed
Refund of service chargesCommercial or consumer remedyCustomer
Contractual indemnity from ProcessorPrivate contractual paymentData Fiduciary or other indemnified party
Insurance proceedsPayment under insurance contractInsured or beneficiary
Damages awarded under another lawCompensatory judicial remedySuccessful claimant
Payment under a private settlementContractual settlementAs agreed by the parties
Penalty imposed by another regulatorRegulatory sanctionAs provided by that regulator’s governing law
Penalty for breach of a Section 32 undertakingDPDPA regulatory penaltyConsolidated Fund once realised

9.1 Case study: Processor indemnity

A bank appoints a data-analytics provider as its Data Processor. A security failure at the provider leads to a significant breach.

The Board penalises the bank under the DPDPA. The bank pays the penalty, which is credited to the Consolidated Fund.

The bank then recovers part of its loss from the Processor under a contractual indemnity.

The two payments remain separate:

  • the Board-imposed penalty is public revenue;

  • the indemnity is a private contractual payment to the bank.

The indemnity does not alter Section 34 or convert the Processor into the direct payer of compensation to affected Data Principals.

10. Mediation under Section 31

Section 31 mediation may produce an individual monetary or non-monetary settlement.

10.1 Facts

A hospital discloses a patient’s report to the wrong person. The patient incurs expenses in obtaining legal and technical assistance and seeks correction, deletion and reimbursement.

Through mediation, the hospital agrees to:

  • obtain deletion from the unintended recipient;

  • correct its communication procedures;

  • reimburse documented expenses;

  • provide a written explanation; and

  • implement additional recipient-verification controls.

10.2 Effect of Section 34

The reimbursement paid under the settlement is not a penalty imposed by the Board. It is therefore not credited to the Consolidated Fund.

If the Board separately imposes a penalty for a significant statutory breach, that penalty is credited to the Consolidated Fund.

A mediated payment and a Board-imposed penalty can therefore coexist because they perform different functions.

11. Voluntary undertakings under Section 32

A voluntary undertaking may require a person to:

  • correct records;

  • delete personal data;

  • stop specified processing;

  • strengthen security;

  • notify affected individuals;

  • conduct an audit;

  • refrain from AI training;

  • revise processor contracts; or

  • publicise corrective action.

If the undertaking is accepted and fully complied with, proceedings concerning its contents are barred. No monetary penalty may arise in relation to those covered matters, and Section 34 has no sum upon which to operate.

If the person breaches the undertaking:

  1. the breach is deemed to be a breach of the Act;

  2. the Board gives the person an opportunity of being heard;

  3. the Board may proceed under Section 33;

  4. a monetary penalty may be imposed; and

  5. the amount realised must be credited to the Consolidated Fund.

Illustration

A recruitment platform undertakes to delete unlawfully retained applicant profiles, stop using them for AI training and obtain processor-deletion confirmation.

The platform fails to comply. The Board imposes a penalty under Section 33.

That penalty is public revenue under Section 34. It is not divided among the applicants whose profiles were retained.

12. Meaning of the Consolidated Fund of India

The Consolidated Fund of India is the principal constitutional fund of the Union. Article 266 provides the broader constitutional framework and requires that money may be appropriated from the Fund only in accordance with law and the constitutional budgetary process.

Once a DPDPA penalty is credited to the Consolidated Fund:

  • it becomes part of the Union’s public finances;

  • it is subject to constitutional financial control;

  • the Board cannot treat it as its own income;

  • a ministry cannot independently spend it;

  • it is not reserved for the complainant;

  • it is not automatically earmarked for privacy enforcement; and

  • expenditure from it requires lawful appropriation.

Section 34 therefore does not establish a dedicated:

  • privacy compensation fund;

  • cybersecurity remediation fund;

  • Data Principal assistance fund;

  • Board enforcement fund; or

  • digital-rights awareness fund.

Parliament may separately establish or finance such measures through law and appropriation, but Section 34 itself does not do so.

13. Institutional independence of the Board

Section 34 separates the Board’s enforcement role from the financial benefit of penalties.

The Board may:

  • conduct inquiries;

  • determine significant breaches;

  • give persons an opportunity of being heard;

  • impose proportionate monetary penalties; and

  • supervise compliance within its statutory powers.

It cannot retain the amount to fund:

  • its salaries;

  • office costs;

  • investigations;

  • technical systems;

  • enforcement teams;

  • public-awareness programmes;

  • mediation;

  • grants; or

  • compensation payments.

This separation reduces the concern that the Board might have a direct institutional revenue incentive to impose larger or more frequent penalties.

The amount of a penalty must be determined through Section 33’s statutory criteria, not by reference to:

  • the Board’s budget;

  • government revenue needs;

  • the cost of operating the Board; or

  • the desirability of funding unrelated public programmes.

14. No earmarking for data-protection purposes

Section 34 does not require the Government to use DPDPA penalty proceeds for:

  • privacy awareness;

  • cybersecurity improvements;

  • assistance to breach victims;

  • legal aid;

  • independent audits;

  • funding Consent Managers;

  • supporting Data Protection Officers;

  • Board infrastructure; or

  • research into data protection.

The amount enters the general constitutional fund. Its later expenditure is governed by the ordinary public-finance and appropriation process.

Accordingly, it would be incorrect to state that a penalty:

“will be used by the Board to compensate affected users” or “will automatically finance privacy enforcement.”

Neither result follows from Section 34.

15. Effect of the omission of Section 43A of the Information Technology Act

Section 43A of the Information Technology Act, 2000 historically created a limited compensation route where a body corporate negligently failed to maintain reasonable security practices in relation to sensitive personal data or information and caused wrongful loss or wrongful gain.

Section 44(2) of the DPDPA omits Section 43A when that amendment becomes operational. The commencement notification places Section 44(2) on the same eighteen-month track as Sections 28 to 34, with commencement scheduled for 13 May 2027.

The resulting structure is important:

  • the DPDPA creates a broad regulatory penalty framework;

  • Section 34 directs those penalty amounts to the Consolidated Fund;

  • Section 43A is scheduled to be omitted;

  • the DPDPA does not replace Section 43A with an express standalone right to compensation; and

  • a Data Principal seeking monetary redress must examine legal routes outside Sections 33 and 34.

This does not mean that no other remedy can ever exist. It means that the DPDPA penalty mechanism itself does not provide the compensation.

16. Other possible remedial routes

Section 34 neither creates nor excludes every claim available under other laws.

Depending on the facts, an affected person may examine:

  • consumer law;

  • contractual remedies;

  • civil claims;

  • insurance;

  • banking or payment remedies;

  • employment remedies;

  • sector-specific regulation;

  • constitutional remedies in an appropriate case involving State action; or

  • settlement through mediation.

Each route has its own legal elements.

16.1 Consumer-law illustration

A paying customer argues that failure to secure personal data constituted a deficiency in the digital or financial service supplied to her.

She may need to establish:

  • consumer status;

  • the service obtained;

  • the deficiency;

  • causation;

  • resulting loss or injury;

  • territorial and pecuniary jurisdiction; and

  • limitation.

Section 34 does not decide whether that consumer claim succeeds. It only establishes that the Board’s penalty cannot be paid to her as compensation.

16.2 Civil-claim illustration

A customer claims that negligent security caused identity theft and measurable financial loss.

A civil claim may require proof of:

  • duty;

  • breach;

  • causation;

  • legally recognised damage; and

  • quantum.

Again, the existence of a Board penalty may be relevant evidence depending on the proceeding, but Section 34 does not automatically convert the Board’s finding or penalty into a damages award.

17. Comparison with the GDPR

The GDPR maintains a clear separation between administrative fines and compensation:

  • Article 83 permits supervisory authorities to impose administrative fines; and

  • Article 82 creates a distinct right to compensation for material or non-material damage caused by an infringement.

The DPDPA adopts the first component but does not contain an express equivalent of the second.

IssueDPDPAGDPR
Regulatory monetary sanctionSection 33Article 83
Destination of sanctionConsolidated Fund under Section 34Applicable public fiscal framework
Direct statutory compensation rightNo express equivalentArticle 82
Material damageNot compensated through Sections 33 and 34Potentially compensable under Article 82
Non-material damageNot compensated through Sections 33 and 34Potentially compensable under Article 82
Relationship between fine and compensationPenalty remains public revenueFine and compensation operate separately

The comparison should not be misunderstood. GDPR administrative fines are also not ordinarily distributed to affected individuals. The difference is that the GDPR separately creates a compensation right under Article 82, whereas the DPDPA does not contain a corresponding express provision.

18. Policy significance

Section 34 creates a penalty-only public enforcement structure without a corresponding compensation mechanism within the DPDPA.

This has practical consequences.

A Data Principal may:

  • establish that a serious breach occurred;

  • trigger a Board inquiry;

  • receive confirmation that the Data Fiduciary violated the Act;

  • see a substantial monetary penalty imposed; and

  • still receive no monetary redress through the DPDPA for her own loss.

The result is especially significant where the harm consists of:

  • anxiety;

  • loss of control over personal data;

  • reputational consequences;

  • fear of future misuse;

  • exposure of medical or family information; or

  • other non-financial consequences that are difficult to pursue through traditional legal claims.

Section 34 is not itself responsible for the absence of a compensation provision. Its function is narrower. But by routing all realised penalties to the Consolidated Fund, it makes clear that penalty amounts cannot be used to fill that remedial gap through Board discretion.

19. Common misconceptions

19.1 “The complainant receives the penalty”

Incorrect. All realised penalty amounts are credited to the Consolidated Fund.

19.2 “The Board may award part of the penalty as compensation”

Incorrect. Section 34 does not give the Board that power.

19.3 “If the Board imposes a large penalty, affected individuals are fully remedied”

Incorrect. Regulatory deterrence and individual redress are separate.

19.4 “All payments made in a DPDPA matter go to the Consolidated Fund”

Incorrect. Section 34 applies only to penalties imposed by the Board under the Act. Private settlements, reimbursements, refunds, indemnities and damages under other laws are distinct.

19.5 “The Board may retain the money for enforcement”

Incorrect. The Board does not directly retain realised penalties as institutional revenue.

19.6 “Section 34 calculates the penalty amount”

Incorrect. Section 33 and the Schedule govern the imposition and amount. Section 34 governs destination.

19.7 “The amount enters the Fund as soon as the order is signed”

Not necessarily. Section 34 refers to amounts realised, meaning actually paid or recovered.

19.8 “The penalty is automatically earmarked for privacy programmes”

Incorrect. Section 34 creates no dedicated privacy fund.

19.9 “Payment of the penalty ends all compliance obligations”

Incorrect. The person may still need to:

  • correct data;

  • stop unlawful processing;

  • strengthen security;

  • notify affected persons;

  • comply with an undertaking;

  • erase processor copies; or

  • remedy continuing violations.

19.10 Concluding interpretation

Section 34 completes the DPDPA’s monetary enforcement framework by directing all penalty proceeds into the Consolidated Fund of India.

Its legal consequences are clear:

  1. penalties are public regulatory sanctions;

  2. Section 33 determines the penalty, while Section 34 determines its destination;

  3. only amounts actually realised are covered;

  4. the Board cannot retain the proceeds;

  5. the complainant does not receive the penalty;

  6. individual harm may affect the gravity of the breach without converting the penalty into compensation;

  7. settlements, reimbursements, indemnities and damages under other laws remain separate;

  8. the DPDPA contains no express compensation right equivalent to GDPR Article 82; and

  9. penalty payment does not replace corrective compliance.

The controlling principle is:

Key point

A monetary penalty under the DPDPA punishes and deters a significant statutory breach. It does not compensate the affected Data Principal. Once realised, the entire amount belongs to the public fiscal framework through the Consolidated Fund of India.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.