11. Multiple breaches arising from one incident
A single factual incident may involve more than one statutory breach. For example, a cybersecurity incident may involve:
-
failure to maintain reasonable security safeguards;
-
failure to notify the Board;
-
failure to notify affected Data Principals;
-
non-compliance with children’s-data requirements;
-
breach of an accepted voluntary undertaking; and
-
another failure under the Rules.
The Board must identify each legally distinct obligation and determine whether the established facts support separate breaches. It should also avoid penalising identical conduct repeatedly under different labels without accounting for overlap and overall proportionality. The Act does not state that ₹250 crore is an aggregate lifetime ceiling for an organisation. The Schedule attaches penalty ceilings to categories of breach. The treatment of several breaches, continuing conduct or multiple proceedings will therefore depend on the facts, the number of legally distinct violations and the Board’s application of Section 33.
Penalties are not compensation Monetary penalties imposed under Section 33 are public regulatory sanctions. Under Section 34, every amount realised from those penalties must be credited to the Consolidated Fund of India. Affected Data Principals do not automatically receive:
-
the penalty;
-
a proportionate share of it;
-
damages from the Board; or
-
reimbursement from the penalty proceeds.
The penalty may reflect the seriousness of the consequences for individuals, but it remains distinct from compensation. Individual correction, erasure, cessation of processing, account restoration, mediation or another remedy available under a separate law may operate alongside regulatory enforcement.
Power to amend the Schedule Section 42 permits the Central Government to amend the Schedule through notification. However, no penalty may be increased to more than twice the amount specified when the DPDPA was originally enacted. The theoretical maximum ceilings under that power are therefore:
Originally enacted ceiling
Maximum permissible ceiling under Section 42 ₹250 crore ₹500 crore ₹200 crore ₹400 crore ₹150 crore ₹300 crore ₹50 crore ₹100 crore ₹10,000 ₹20,000 The doubling limit is measured from the original statutory amount. It does not permit successive compounding by repeatedly doubling previously amended figures. Any Section 42 amendment takes effect from the date of the notification and operates as if enacted in the DPDPA. It must also be laid before both Houses of Parliament under Section 41. As of 1 September 2026, no official notification amending the originally enacted Schedule was identified. The penalty amounts reproduced above therefore remain the notified statutory ceilings, subject to the commencement of Section 33 on 13 May 2027.
Concluding commentary The Schedule creates a graded penalty system in which the highest exposure is reserved for security failures, breach-notification failures and violations involving children. It separately addresses enhanced obligations of Significant Data Fiduciaries, misuse of statutory rights by Data Principals, breach of voluntary undertakings and all other significant contraventions. The amounts stated are maximum ceilings, not standard fines. A penalty may be imposed only after the Board completes an inquiry, determines that the breach is significant, gives the person an opportunity of being heard and applies the statutory factors in Section 33(2). The Schedule determines the maximum financial exposure for each category of breach. It does not remove the Board’s duty to establish significance, observe procedural fairness and impose a penalty that is proportionate, effective and deterrent in the circumstances.