CHAPTER IX - MISCELLANEOUS

Section 44 - Amendment to certain Acts

Official text

(1)In section 14 of the Telecom Regulatory Authority of India Act, 1997, in clause (c), for sub-clauses (i) and (ii), the following sub-clauses shall be substituted, namely:— “(i) the Appellate Tribunal under the Information Technology Act, 2000;

(ii)the Appellate Tribunal under the Airports Economic Regulatory Authority of India Act, 2008; and

(iii)the Appellate Tribunal under the Digital Personal Data Protection Act, 2023.”.

(2)The Information Technology Act, 2000 shall be amended in the following manner, namely:—

(a)section 43A shall be omitted;

(b)in section 81, in the proviso, after the words and figures “the Patents Act, 1970”, the words and figures “or the Digital Personal Data Protection Act, 2023” shall be inserted; and

(c)in section 87, in sub-section (2), clause (ob) shall be omitted.

(3)In section 8 of the Right to Information Act, 2005, in sub-section (1), for clause (j), the following clause shall be substituted, namely:— “(j) information which relates to personal information;”.

Commentary

Section 44 restructures the surrounding legal framework so that the DPDPA can operate alongside India’s existing telecommunications, information-technology and transparency laws. It makes three major changes: it formally designates the Telecom Disputes Settlement and Appellate Tribunal as the appellate forum under the DPDPA, removes the older compensation and security framework under Section 43A of the Information Technology Act, 2000, and substantially broadens the personal-information exemption under the Right to Information Act, 2005.

The three amendments do not have the same commencement date:

  • amendments to the TRAI Act and RTI Act came into force on 13 November 2025; and

  • amendments to the Information Technology Act are scheduled to come into force on 13 May 2027.

This staggered commencement is legally important. The RTI amendment is already operative, while Section 43A of the IT Act and the SPDI framework have not yet been displaced by Section 44(2) as of 18 August 2026.

1.1 Amendment to the TRAI Act: TDSAT as the DPDPA appellate forum

The amendment to Section 14 of the Telecom Regulatory Authority of India Act, 1997 recognises the Telecom Disputes Settlement and Appellate Tribunal as the Appellate Tribunal under the DPDPA.

This must be read with Section 2(a) of the DPDPA, which defines the “Appellate Tribunal” as TDSAT, and Section 29, which provides the right of appeal against an order or direction of the Data Protection Board.

The practical appellate chain is:

  1. the Data Protection Board conducts the relevant proceeding;

  2. it issues an order or direction under the DPDPA;

  3. an aggrieved person may appeal to TDSAT under Section 29;

  4. TDSAT examines the appeal according to the DPDPA and applicable procedural rules; and

  5. a further appeal lies to the Supreme Court under the framework incorporated through Section 29.

The amendment avoids creating a separate appellate tribunal solely for data-protection matters. TDSAT already performs appellate functions under the Information Technology Act and the Airports Economic Regulatory Authority of India Act. Section 44(1) adds the DPDPA to that statutory appellate portfolio.

The Data Protection Board and TDSAT perform different functions. The Board is the first-instance regulatory and adjudicatory body under the DPDPA. TDSAT is the appellate body that reviews appealable Board decisions. A party cannot ordinarily bypass the Board and initiate the underlying DPDPA proceeding directly before TDSAT.

The amendment also supports Section 39, which bars civil courts from entertaining matters assigned to the Board. Challenges to Board orders are channelled through the specialised appellate mechanism rather than ordinary civil suits.

Although Section 44(1) is already in force, the substantive appeal provision in Section 29 is scheduled to commence on 13 May 2027. The TRAI Act amendment therefore presently establishes the institutional basis for the appellate forum, while the operational right of appeal will commence with Section 29.

1.2 Amendment to the Information Technology Act, 2000

Section 44(2) makes three connected changes to the IT Act:

  • omission of Section 43A;

  • amendment of the overriding clause in Section 81; and

  • omission of the rule-making power in Section 87(2)(ob).

These changes are scheduled to take effect on 13 May 2027. Until then, the IT Act’s presently operative text must be applied, including Section 43A and the rules made under it.

1.3 Omission of Section 43A

Section 43A currently provides a limited statutory compensation mechanism where a body corporate:

  • possesses, deals with or handles sensitive personal data or information;

  • is negligent in implementing and maintaining reasonable security practices and procedures; and

  • thereby causes wrongful loss or wrongful gain.

The provision is compensatory rather than purely regulatory. Its focus is on liability arising from negligent security and resulting wrongful loss or gain.

Once Section 44(2) takes effect, Section 43A will be omitted. This means that claims arising after the operative date will no longer be capable of being founded on Section 43A. The precise treatment of causes of action, liabilities and proceedings arising before the omission will depend on applicable principles governing repeal, accrued rights and pending proceedings and should not be resolved solely by stating that Section 43A has been removed.

The omission is significant because the DPDPA does not replace Section 43A with an equivalent individual compensation right. The DPDPA instead creates:

  • regulatory obligations;

  • Data Principal rights;

  • grievance and complaint mechanisms;

  • Board inquiries;

  • voluntary undertakings; and

  • monetary penalties for significant breaches.

Those monetary penalties are credited to the Consolidated Fund of India under Section 34. They are not paid to affected Data Principals as compensation. The removal of Section 43A therefore leaves an important distinction between regulatory enforcement and individual monetary redress.

An affected person may still examine whether another independent cause of action exists under consumer law, contract, tort, banking law, employment law or another applicable framework. Section 44 does not determine the availability or success of those claims. It removes the specific statutory compensation route previously contained in Section 43A.

1.4 Effect on the SPDI Rules, 2011

The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 were made under Section 43A read with Section 87(2)(ob). They regulate matters including:

  • sensitive personal data or information;

  • privacy policies;

  • collection;

  • consent;

  • purpose limitation;

  • disclosure;

  • transfer;

  • grievance handling; and

  • reasonable security practices.

Section 44(2) removes both:

  • the principal statutory provision, Section 43A; and

  • the specific rule-making clause, Section 87(2)(ob).

This legislative design indicates that the DPDPA and DPDP Rules are intended to replace the Section 43A and SPDI regime for digital personal data within the DPDPA’s scope. However, the legal status and residual application of the SPDI Rules after 13 May 2027 should be assessed against the final operative statutory text, any repeal or savings notifications, and general principles relating to subordinate legislation made under an omitted enabling provision.

As of 18 August 2026, it would be incorrect to state that Section 43A and the SPDI Rules have already ceased to operate. Their omission is scheduled for 13 May 2027.

1.5 Difference between the Section 43A and DPDPA frameworks

The two frameworks are materially different.

IssueSection 43A and SPDI RulesDPDPA framework
Protected informationSensitive personal data or information defined by the SPDI RulesDigital personal data generally
Regulated personPrimarily a body corporateData Fiduciaries, and other persons as specified
Security failureNegligence in reasonable security practicesFailure to take reasonable security safeguards
Individual monetary remedyCompensation for wrongful loss or gainNo express standalone compensation right
Regulatory sanctionNot the central Section 43A remedyBoard-imposed monetary penalties
Destination of penaltyNot applicable to compensationConsolidated Fund of India
Operational detailsSPDI Rules, 2011DPDP Rules, 2025

The DPDPA is broader in its general coverage of digital personal data, but its enforcement model is regulatory rather than compensatory. The omission of Section 43A should therefore not be described merely as a technical transfer of the same remedy from one statute to another. The nature of the remedy changes.

1.6 Amendment to Section 81 of the IT Act

Section 81 gives the IT Act overriding effect where it conflicts with another law, while its existing proviso preserves rights under the Copyright Act, 1957 and Patents Act, 1970.

Section 44(2)(b) adds the DPDPA to that proviso. The result is that the IT Act’s overriding clause cannot be used to restrict a person from exercising rights conferred by the DPDPA.

This amendment aligns with Section 38 of the DPDPA, under which the DPDPA operates in addition to other laws and prevails to the extent of an irreconcilable conflict.

The practical effect is that an entity cannot rely on the IT Act’s general overriding clause to defeat:

  • a Data Principal right;

  • a Data Fiduciary obligation;

  • a Board power;

  • a breach-notification requirement;

  • a security obligation; or

  • another right or obligation conferred by the DPDPA.

The statutes should first be interpreted harmoniously. The protective effect of the Section 81 proviso becomes relevant where such harmonious application is not possible.

1.7 Amendment to the Right to Information Act, 2005

Section 44(3) replaces the former Section 8(1)(j) of the RTI Act with the much shorter exemption:

“information which relates to personal information.”

This amendment came into force on 13 November 2025 and is already operative.

1.8 Position before the amendment

Before substitution, Section 8(1)(j) exempted personal information where disclosure:

  • had no relationship to a public activity or interest; or

  • would cause an unwarranted invasion of the individual’s privacy, unless the Public Information Officer or appellate authority was satisfied that the larger public interest justified disclosure.

The original provision also stated that information which could not be denied to Parliament or a State Legislature should not be denied to a citizen.

The earlier clause therefore required a contextual balance. Personal character alone did not always end the inquiry. The authority considered:

  • the nature of the information;

  • its connection with a public activity;

  • the privacy intrusion;

  • the public interest in disclosure; and

  • the legislative-access proviso.

The Supreme Court’s 2019 Constitution Bench decision in Central Public Information Officer, Supreme Court of India v. Subhash Chandra Agarwal treated privacy and transparency as rights requiring contextual balancing and proportionality. The Court held that the office of the Chief Justice of India is a public authority and examined disclosure through the RTI Act’s privacy and public-interest framework.

1.9 Effect of the substituted clause

The amended clause exempts information that relates to personal information without retaining within Section 8(1)(j):

  • the public-activity or public-interest connection;

  • the unwarranted-invasion test;

  • the clause-specific larger-public-interest exception; or

  • the proviso concerning information that cannot be denied to Parliament or a State Legislature.

On its face, the new text therefore creates a broader exemption than the former clause.

The practical consequences may extend to RTI requests involving personal information about:

  • public officials;

  • beneficiaries of public schemes;

  • public appointments;

  • disciplinary proceedings;

  • educational qualifications;

  • asset declarations;

  • conflict-of-interest material;

  • attendance or service records;

  • public expenditure involving identifiable persons;

  • welfare disbursements;

  • muster rolls;

  • electoral or licensing records; and

  • information appearing in government accountability portals.

This does not mean that every record containing a name must necessarily be withheld in full. RTI authorities must still examine the entire Act, including the nature of the requested record, severability under Section 10, proactive disclosure obligations under Section 4, third-party procedure under Section 11, and the public-interest override in Section 8(2). But the direct balancing language previously embedded in Section 8(1)(j) has been removed.

1.10 Continuing relevance of Section 8(2) of the RTI Act

Section 8(2) states that a public authority may allow access to information notwithstanding the exemptions in Section 8(1) if the public interest in disclosure outweighs the harm to the protected interests.

The Central Government’s publicly reported position is that the RTI Act retains a sufficient public-interest override through Section 8(2), even after the amendment to Section 8(1)(j). It has therefore argued that the DPDPA amendment does not eliminate public-interest disclosure altogether.

Critics dispute that position. They argue that the previous Section 8(1)(j) contained a specific and mandatory balancing framework tailored to personal information, whereas Section 8(2) is framed more generally and uses the language that a public authority “may” allow access. They also point to the deletion of the Parliament or State Legislature proviso and argue that the amendment makes denial easier whenever a record can be characterised as personal information.

The proper legal relationship between the amended Section 8(1)(j), Section 8(2), Section 10 severability and constitutional transparency principles is now a live interpretive and constitutional question.

1.11 Current constitutional challenge to the RTI amendment

As of August 2026, the constitutional validity of Section 44(3), together with other parts of the DPDPA framework, is under consideration before the Supreme Court.

Petitions have challenged the amendment on grounds including Articles 14, 19(1)(a) and 21, arguing that it creates an excessively broad exemption for personal information and removes the earlier statutory proportionality mechanism. The proceedings include petitions by RTI advocates, journalists and civil-society organisations.

The Supreme Court has identified the distinction between public data and personal data, and the need to harmonise privacy with access to information, as issues requiring examination. The amendment remains operative because there is no reported final judgment invalidating it or general stay suspending its effect as of 18 August 2026.

The legal position should therefore be stated carefully:

  • Section 44(3) is currently in force;

  • its constitutionality is under judicial consideration;

  • the challenge has not yet produced a final determination; and

  • RTI authorities must apply the operative statutory text while remaining subject to binding court orders and eventual Supreme Court interpretation.

1.12 Broader significance of Section 44

Section 44 does more than make technical consequential amendments. It redistributes jurisdiction, remedies and statutory priorities across three separate legal regimes.

1.13 Appellate jurisdiction

TDSAT becomes the specialist appellate forum for DPDPA decisions, avoiding creation of a new appellate institution.

1.14 Data-security compensation

The older Section 43A compensation framework is scheduled to be removed and replaced by a DPDPA framework centred on regulatory obligations and public monetary penalties rather than an express individual damages remedy.

1.15 Interaction between the IT Act and DPDPA

The amendment to Section 81 prevents the IT Act’s overriding clause from defeating rights conferred by the DPDPA.

1.16 Transparency and privacy

The RTI amendment changes the statutory balance between privacy and public access by broadening the personal-information exemption, while leaving debate over the continuing effect of Section 8(2), severability and constitutional proportionality.

These are legally distinct consequences and should not be treated as one general “harmonisation” amendment.

1.17 Commencement summary

AmendmentEffectCommencement
Section 44(1)Recognises TDSAT as the DPDPA Appellate Tribunal13 November 2025
Section 44(2)(a)Omits IT Act Section 43A13 May 2027
Section 44(2)(b)Adds the DPDPA to the IT Act Section 81 proviso13 May 2027
Section 44(2)(c)Omits IT Act Section 87(2)(ob)13 May 2027
Section 44(3)Replaces RTI Act Section 8(1)(j)13 November 2025

,

1.18 Concluding interpretation

Section 44 integrates the DPDPA into the wider Indian legal system through three major institutional and substantive changes.

First, it establishes TDSAT as the appellate forum for DPDPA matters. Second, it schedules the removal of Section 43A and its associated rule-making basis, replacing the older sensitive-data compensation framework with the DPDPA’s broader but predominantly regulatory enforcement model. Third, it substantially expands the RTI exemption for personal information by removing the earlier clause-specific tests concerning public activity, unwarranted privacy invasion and larger public interest.

The TRAI and RTI amendments are already in force. The IT Act amendments will take effect on 13 May 2027. The RTI amendment is presently under constitutional scrutiny, but remains operative pending a final judicial determination.

1.19 The Schedule: Monetary Penalties under the DPDPA ([See section 33 (1)]

The Schedule, read with Section 33(1), specifies the maximum monetary penalties that the Data Protection Board of India may impose for significant breaches of the DPDPA or the Rules. It does not prescribe automatic or fixed fines. The Board must first complete an inquiry, determine that a breach has occurred, find that the breach is significant, give the person an opportunity of being heard and then determine an appropriate amount under the factors listed in Section 33(2).

Commencement position: Section 33, through which the Schedule’s penalties are imposed, is scheduled to come into force on13 May 2027. Accordingly, the Schedule does not presently operate as an independent penalty mechanism before Section 33 becomes operational. As of 1 September 2026, no official Section 42 notification amending the originally enacted penalty amounts was identified.

1.20 Nature of the penalty framework

The Schedule creates different penalty ceilings for different categories of non-compliance. The maximum amount depends on the obligation breached and the importance the legislation assigns to that obligation.

The structure places the greatest financial exposure on:

  • failure to maintain reasonable security safeguards;

  • failure to notify personal data breaches;

  • violation of children’s-data obligations; and

  • non-compliance by Significant Data Fiduciaries.

Lower ceilings apply to other statutory breaches and to breaches of the duties imposed on Data Principals.

The expression “may extend to” means that the stated amount is the maximum available penalty, not the amount that must be imposed in every case. The Board may impose a lower amount after considering the seriousness and circumstances of the breach. It may impose a penalty only where the breach is found to be significant.

Summary of penalty ceilings

Category of breachMaximum monetary penalty
Failure to take reasonable security safeguards under Section 8(5)₹250 crore
Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6)₹200 crore
Breach of additional obligations concerning children under Section 9₹200 crore
Breach of additional obligations of a Significant Data Fiduciary under Section 10₹150 crore
Breach of Data Principal duties under Section 15₹10,000
Breach of an accepted voluntary undertaking under Section 32Up to the ceiling applicable to the underlying breach
Significant breach of any other provision of the Act or Rules₹50 crore

These are fixed rupee-denominated ceilings. Unlike the GDPR, the DPDPA does not calculate the maximum penalty as a percentage of the organisation’s worldwide annual turnover.

1.21 Failure to take reasonable security safeguards

The highest penalty ceiling, ₹250 crore, applies where a Data Fiduciary fails to comply with its obligation under Section 8(5) to take reasonable security safeguards to prevent a personal data breach.

This category is directed at deficiencies in the Data Fiduciary’s security arrangements, including the security of processing undertaken on its behalf by a Data Processor. Once the corresponding provisions become operational, Section 8(5) must be read with Rule 6 of the DPDP Rules, 2025, which specifies minimum categories of safeguards relating to:

  • encryption, masking, tokenisation or similar protection;

  • access controls;

  • logging and monitoring;

  • detection and investigation of unauthorised access;

  • remediation;

  • continuity and backups;

  • retention of relevant logs;

  • security obligations in processor contracts; and

  • appropriate technical and organisational measures.

A personal data breach does not automatically prove a failure to maintain reasonable security safeguards. Even an organisation with substantial and properly implemented security controls may suffer a sophisticated cyberattack. The Board must examine whether the safeguards were reasonable in the circumstances and whether the established security failure was significant.

The higher end of the penalty range may become relevant where the Data Fiduciary:

  • failed to implement basic security measures;

  • used shared or default passwords;

  • allowed former employees to retain access;

  • ignored known vulnerabilities;

  • failed to encrypt highly consequential data;

  • appointed an unsuitable Processor;

  • had no meaningful logging or monitoring;

  • continued processing after repeated warnings; or

  • exposed a large volume of personal data for a prolonged period.

Prompt detection, strong existing safeguards, effective containment and complete remediation may reduce the appropriate penalty, but do not automatically eliminate liability where a significant statutory failure is established.

1.22 Failure to notify a personal data breach

A maximum penalty of ₹200 crore applies to failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6).

This is a separate obligation from the duty to prevent a breach. The same incident may therefore involve:

  1. failure to maintain reasonable security safeguards; and

  2. failure to provide the required breach notifications.

An organisation may have maintained reasonable security and still breach Section 8(6) by failing to notify. Conversely, it may notify properly but remain liable for the underlying security failure.

Once operational, Rule 7 will prescribe the content, recipients and timing of breach notifications. The seriousness of a notification failure may increase where the Data Fiduciary:

  • knowingly conceals the breach;

  • delays notification for commercial or reputational reasons;

  • gives incomplete or misleading information;

  • fails to identify relevant consequences;

  • does not provide practical protective steps;

  • omits affected groups from notification; or

  • prevents Data Principals from taking timely action against identity theft, fraud or misuse.

The maximum under this entry should not be treated as a combined ceiling for both security and notification failures. They are identified as separate breaches in the Schedule.

1.23 Breach of children’s-data obligations

A maximum penalty of ₹200 crore applies to breach of the additional obligations concerning processing of children’s personal data under Section 9.

Depending on the applicable provisions and exemptions, this may include failures concerning:

  • verifiable consent of a parent or lawful guardian;

  • processing likely to cause a detrimental effect on a child’s well-being;

  • tracking or behavioural monitoring of children;

  • targeted advertising directed at children; and

  • compliance with conditions attached to prescribed exemptions.

The substantial ceiling reflects the vulnerability of children and the potentially serious consequences of profiling, manipulation, tracking and commercial exploitation involving their personal data.

The Board’s assessment should consider the actual processing and audience rather than relying exclusively on contractual declarations. A service extensively used by children should not necessarily escape scrutiny merely because its terms state that every user is over eighteen.

1.24 Breach by a Significant Data Fiduciary

A maximum penalty of ₹150 crore applies to breach of the additional obligations imposed on a Data Fiduciary formally notified as a Significant Data Fiduciary under Section 10.

These additional obligations include requirements relating to:

  • appointment of a Data Protection Officer;

  • appointment of an independent data auditor;

  • periodic Data Protection Impact Assessments;

  • periodic audits;

  • additional measures prescribed through the Rules;

  • algorithmic due diligence; and

  • specified restrictions concerning transfer of notified personal data and related traffic data.

This penalty category applies only where the entity has been formally notified as a Significant Data Fiduciary or falls within a notified class. An organisation does not become subject to this entry merely because it is large, processes substantial data or considers itself systemically important.

A failure may be treated more seriously where an SDF ignores known high-risk processing, omits a material system from its DPIA, fails to conduct an effective audit or continues deploying an algorithm after identifying serious risks to Data Principal rights.

1.25 Breach of Data Principal duties

The Schedule provides a significantly lower maximum penalty of ₹10,000 for breach of the duties imposed on Data Principals under Section 15.

Those duties include requirements not to:

  • impersonate another person while providing personal data;

  • suppress material information while seeking correction or erasure;

  • register a false or frivolous grievance or complaint; or

  • furnish false particulars while exercising statutory rights.

This penalty should not be used to discourage genuine complaints. A grievance is not false or frivolous merely because:

  • it is ultimately rejected;

  • the Data Principal misunderstood the processing;

  • she cannot prove every allegation;

  • no penalty is imposed on the Data Fiduciary;

  • the complaint contains an ordinary factual error; or

  • the Data Fiduciary disagrees with her interpretation.

The provision is directed at misuse of the statutory process, such as deliberate impersonation, knowingly false particulars or complaints brought without a genuine basis for an improper purpose.

1.26 Breach of a voluntary undertaking

Where a person breaches a voluntary undertaking accepted by the Board under Section 32, the applicable maximum is linked to the breach for which the original proceeding under Section 28 was instituted.

The ceiling is therefore not a single fixed amount. It depends on the underlying matter.

Example

For example:

  • if the undertaking resolved proceedings concerning inadequate security safeguards, the relevant maximum may extend to ₹250 crore;

  • if it concerned a breach of children’s-data duties, the maximum may extend to ₹200 crore;

  • if it concerned another provision governed by the residual entry, the maximum may extend to ₹50 crore.

This structure prevents a person from using a voluntary undertaking to secure closure of a proceeding and then treating non-compliance with the undertaking as a minor violation.

Under Section 32(5), breach of an accepted undertaking is deemed to be a breach of the Act. The Board must still give the person an opportunity of being heard before proceeding under Section 33.

1.27 Residual penalty for other breaches

The Schedule provides a maximum penalty of ₹50 crore for a significant breach of any other provision of the DPDPA or Rules where no more specific penalty entry applies.

This residual category may cover significant failures relating to:

  • notice;

  • consent;

  • withdrawal of consent;

  • processing without an applicable ground;

  • processor engagement without a valid contract;

  • completeness, accuracy and consistency;

  • erasure and retention;

  • publication of privacy contact information;

  • grievance redressal;

  • Data Principal rights;

  • nomination;

  • Consent Manager obligations;

  • cross-border processing restrictions; and

  • other operative requirements under the Act or Rules.

The residual entry should not displace a more specific Schedule entry. If the conduct clearly concerns failure to maintain reasonable security safeguards, the specific ₹250 crore entry applies rather than the general ₹50 crore entry.

1.28 Determination of the actual penalty

The Board cannot select a penalty amount solely by referring to the maximum in the Schedule. Section 33(2) requires consideration of:

  • the nature, gravity and duration of the breach;

  • the type and nature of the personal data affected;

  • whether the breach was repetitive;

  • whether the person obtained a gain or avoided a loss;

  • the timeliness and effectiveness of mitigation;

  • whether the amount is proportionate and effective for securing compliance and deterring future breaches; and

  • the likely impact of the penalty on the person.

These factors allow the Board to distinguish between:

  • an isolated error and a systemic failure;

  • inadvertent conduct and deliberate misuse;

  • immediate containment and prolonged concealment;

  • a first occurrence and repeated non-compliance;

  • low-impact information and highly consequential financial, biometric, health or children’s data;

  • a breach corrected voluntarily and one continued despite warnings; and

  • a penalty that meaningfully deters a large enterprise and one that would be disproportionate for a smaller organisation.

The Schedule provides the outer limit. Section 33 provides the method for determining the amount within that limit.

1.29 Multiple breaches arising from one incident

A single factual incident may involve more than one statutory breach.

Example

For example, a cybersecurity incident may involve:

  • failure to maintain reasonable security safeguards;

  • failure to notify the Board;

  • failure to notify affected Data Principals;

  • non-compliance with children’s-data requirements;

  • breach of an accepted voluntary undertaking; and

  • another failure under the Rules.

The Board must identify each legally distinct obligation and determine whether the established facts support separate breaches. It should also avoid penalising identical conduct repeatedly under different labels without accounting for overlap and overall proportionality.

The Act does not state that ₹250 crore is an aggregate lifetime ceiling for an organisation. The Schedule attaches penalty ceilings to categories of breach. The treatment of several breaches, continuing conduct or multiple proceedings will therefore depend on the facts, the number of legally distinct violations and the Board’s application of Section 33.

1.30 Penalties are not compensation

Monetary penalties imposed under Section 33 are public regulatory sanctions. Under Section 34, every amount realised from those penalties must be credited to the Consolidated Fund of India.

Affected Data Principals do not automatically receive:

  • the penalty;

  • a proportionate share of it;

  • damages from the Board; or

  • reimbursement from the penalty proceeds.

The penalty may reflect the seriousness of the consequences for individuals, but it remains distinct from compensation. Individual correction, erasure, cessation of processing, account restoration, mediation or another remedy available under a separate law may operate alongside regulatory enforcement.

1.31 Power to amend the Schedule

Section 42 permits the Central Government to amend the Schedule through notification. However, no penalty may be increased to more than twice the amount specified when the DPDPA was originally enacted.

The theoretical maximum ceilings under that power are therefore:

Originally enacted ceilingMaximum permissible ceiling under Section 42
₹250 crore₹500 crore
₹200 crore₹400 crore
₹150 crore₹300 crore
₹50 crore₹100 crore
₹10,000₹20,000

The doubling limit is measured from the original statutory amount. It does not permit successive compounding by repeatedly doubling previously amended figures.

Any Section 42 amendment takes effect from the date of the notification and operates as if enacted in the DPDPA. It must also be laid before both Houses of Parliament under Section 41.

As of 1 September 2026, no official notification amending the originally enacted Schedule was identified. The penalty amounts reproduced above therefore remain the notified statutory ceilings, subject to the commencement of Section 33 on 13 May 2027.

1.32 Concluding commentary

The Schedule creates a graded penalty system in which the highest exposure is reserved for security failures, breach-notification failures and violations involving children. It separately addresses enhanced obligations of Significant Data Fiduciaries, misuse of statutory rights by Data Principals, breach of voluntary undertakings and all other significant contraventions.

The amounts stated are maximum ceilings, not standard fines. A penalty may be imposed only after the Board completes an inquiry, determines that the breach is significant, gives the person an opportunity of being heard and applies the statutory factors in Section 33(2).

Key point

The Schedule determines the maximum financial exposure for each category of breach. It does not remove the Board’s duty to establish significance, observe procedural fairness and impose a penalty that is proportionate, effective and deterrent in the circumstances.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.