CHAPTER S - THE SCHEDULE

The Schedule - Penalties

Official text

Text pending. The verbatim provision will be inserted from the official Gazette.

Cross-references

The Schedule (Penalties)

Commentary

The Schedule, read with Section 33(1), specifies the maximum monetary penalties that the Data Protection Board of India may impose for significant breaches of the DPDPA or the Rules. It does not prescribe automatic or fixed fines. The Board must first complete an inquiry, determine that a breach has occurred, find that the breach is significant, give the person an opportunity of being heard and then determine an appropriate amount under the factors listed in Section 33(2).

Commencement

Section 33, through which the Schedule’s penalties are imposed, is scheduled to come into force on 13 May 2027. Accordingly, the Schedule does not presently operate as an independent penalty mechanism before Section 33 becomes operational. As of 1 September 2026, no official Section 42 notification amending the originally enacted penalty amounts was identified.

1. Nature of the penalty framework

The Schedule creates different penalty ceilings for different categories of non-compliance. The maximum amount depends on the obligation breached and the importance the legislation assigns to that obligation. The structure places the greatest financial exposure on:

  • failure to maintain reasonable security safeguards;

  • failure to notify personal data breaches;

  • violation of children’s-data obligations; and

  • non-compliance by Significant Data Fiduciaries.

Lower ceilings apply to other statutory breaches and to breaches of the duties imposed on Data Principals. The expression “may extend to” means that the stated amount is the maximum available penalty, not the amount that must be imposed in every case. The Board may impose a lower amount after considering the seriousness and circumstances of the breach. It may impose a penalty only where the breach is found to be significant.

2. Summary of penalty ceilings

Category of breachMaximum monetary penalty
Failure to take reasonable security safeguards under Section 8(5)Rs. 250 crore
Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6)Rs. 200 crore
Breach of additional obligations concerning children under Section 9Rs. 200 crore
Breach of additional obligations of a Significant Data Fiduciary under Section 10Rs. 150 crore
Breach of Data Principal duties under Section 15Rs. 10,000
Breach of an accepted voluntary undertaking under Section 32Up to the ceiling applicable to the underlying breach
Significant breach of any other provision of the Act or RulesRs. 50 crore

These are fixed rupee-denominated ceilings. Unlike the GDPR, the DPDPA does not calculate the maximum penalty as a percentage of the organisation's worldwide annual turnover.

3. Failure to take reasonable security safeguards

The highest penalty ceiling, ₹250 crore, applies where a Data Fiduciary fails to comply with its obligation under Section 8(5) to take reasonable security safeguards to prevent a personal data breach. This category is directed at deficiencies in the Data Fiduciary’s security arrangements, including the security of processing undertaken on its behalf by a Data Processor. Once the corresponding provisions become operational, Section 8(5) must be read with Rule 6 of the DPDP Rules, 2025, which specifies minimum categories of safeguards relating to:

  • encryption, masking, tokenisation or similar protection;

  • access controls;

  • logging and monitoring;

  • detection and investigation of unauthorised access;

  • remediation;

  • continuity and backups;

  • retention of relevant logs;

  • security obligations in processor contracts; and

  • appropriate technical and organisational measures.

A personal data breach does not automatically prove a failure to maintain reasonable security safeguards. Even an organisation with substantial and properly implemented security controls may suffer a sophisticated cyberattack. The Board must examine whether the safeguards were reasonable in the circumstances and whether the established security failure was significant. The higher end of the penalty range may become relevant where the Data Fiduciary:

  • failed to implement basic security measures;

  • used shared or default passwords;

  • allowed former employees to retain access;

  • ignored known vulnerabilities;

  • failed to encrypt highly consequential data;

  • appointed an unsuitable Processor;

  • had no meaningful logging or monitoring;

  • continued processing after repeated warnings; or

  • exposed a large volume of personal data for a prolonged period.

Prompt detection, strong existing safeguards, effective containment and complete remediation may reduce the appropriate penalty, but do not automatically eliminate liability where a significant statutory failure is established.

4. Failure to notify a personal data breach

A maximum penalty of ₹200 crore applies to failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6). This is a separate obligation from the duty to prevent a breach. The same incident may therefore involve:

  1. failure to maintain reasonable security safeguards; and

  2. failure to provide the required breach notifications. An organisation may have maintained reasonable security and still breach Section 8(6) by failing to notify. Conversely, it may notify properly but remain liable for the underlying security failure.

Once operational, Rule 7 will prescribe the content, recipients and timing of breach notifications. The seriousness of a notification failure may increase where the Data Fiduciary:

  • knowingly conceals the breach;

  • delays notification for commercial or reputational reasons;

  • gives incomplete or misleading information;

  • fails to identify relevant consequences;

  • does not provide practical protective steps;

  • omits affected groups from notification; or

  • prevents Data Principals from taking timely action against identity theft, fraud or misuse.

The maximum under this entry should not be treated as a combined ceiling for both security and notification failures. They are identified as separate breaches in the Schedule.

5. Breach of children’s-data obligations

A maximum penalty of ₹200 crore applies to breach of the additional obligations concerning processing of children’s personal data under Section 9. Depending on the applicable provisions and exemptions, this may include failures concerning:

  • verifiable consent of a parent or lawful guardian;

  • processing likely to cause a detrimental effect on a child’s well-being;

  • tracking or behavioural monitoring of children;

  • targeted advertising directed at children; and

  • compliance with conditions attached to prescribed exemptions.

The substantial ceiling reflects the vulnerability of children and the potentially serious consequences of profiling, manipulation, tracking and commercial exploitation involving their personal data. The Board’s assessment should consider the actual processing and audience rather than relying exclusively on contractual declarations. A service extensively used by children should not necessarily escape scrutiny merely because its terms state that every user is over eighteen.

6. Breach by a Significant Data Fiduciary

A maximum penalty of ₹150 crore applies to breach of the additional obligations imposed on a Data Fiduciary formally notified as a Significant Data Fiduciary under Section 10. These additional obligations include requirements relating to:

  • appointment of a Data Protection Officer;

  • appointment of an independent data auditor;

  • periodic Data Protection Impact Assessments;

  • periodic audits;

  • additional measures prescribed through the Rules;

  • algorithmic due diligence; and

  • specified restrictions concerning transfer of notified personal data and related traffic data.

This penalty category applies only where the entity has been formally notified as a Significant Data Fiduciary or falls within a notified class. An organisation does not become subject to this entry merely because it is large, processes substantial data or considers itself systemically important. A failure may be treated more seriously where an SDF ignores known high-risk processing, omits a material system from its DPIA, fails to conduct an effective audit or continues deploying an algorithm after identifying serious risks to Data Principal rights.

7. Breach of Data Principal duties

The Schedule provides a significantly lower maximum penalty of ₹10,000 for breach of the duties imposed on Data Principals under Section 15. Those duties include requirements not to:

  • impersonate another person while providing personal data;

  • suppress material information while seeking correction or erasure;

  • register a false or frivolous grievance or complaint; or

  • furnish false particulars while exercising statutory rights.

This penalty should not be used to discourage genuine complaints. A grievance is not false or frivolous merely because:

  • it is ultimately rejected;

  • the Data Principal misunderstood the processing;

  • she cannot prove every allegation;

  • no penalty is imposed on the Data Fiduciary;

  • the complaint contains an ordinary factual error; or

  • the Data Fiduciary disagrees with her interpretation.

The provision is directed at misuse of the statutory process, such as deliberate impersonation, knowingly false particulars or complaints brought without a genuine basis for an improper purpose.

8. Breach of a voluntary undertaking

Where a person breaches a voluntary undertaking accepted by the Board under Section 32, the applicable maximum is linked to the breach for which the original proceeding under Section 28 was instituted. The ceiling is therefore not a single fixed amount. It depends on the underlying matter. For example:

  • if the undertaking resolved proceedings concerning inadequate security safeguards, the relevant maximum may extend to ₹250 crore;

  • if it concerned a breach of children’s-data duties, the maximum may extend to ₹200 crore;

  • if it concerned another provision governed by the residual entry, the maximum may extend to ₹50 crore.

This structure prevents a person from using a voluntary undertaking to secure closure of a proceeding and then treating non-compliance with the undertaking as a minor violation.

Under Section 32(5), breach of an accepted undertaking is deemed to be a breach of the Act. The Board must still give the person an opportunity of being heard before proceeding under Section 33.

9. Residual penalty for other breaches

The Schedule provides a maximum penalty of ₹50 crore for a significant breach of any other provision of the DPDPA or Rules where no more specific penalty entry applies. This residual category may cover significant failures relating to:

  • notice;

  • consent;

  • withdrawal of consent;

  • processing without an applicable ground;

  • processor engagement without a valid contract;

  • completeness, accuracy and consistency;

  • erasure and retention;

  • publication of privacy contact information;

  • grievance redressal;

  • Data Principal rights;

  • nomination;

  • Consent Manager obligations;

  • cross-border processing restrictions; and

  • other operative requirements under the Act or Rules.

The residual entry should not displace a more specific Schedule entry. If the conduct clearly concerns failure to maintain reasonable security safeguards, the specific ₹250 crore entry applies rather than the general ₹50 crore entry.

10. Determination of the actual penalty

The Board cannot select a penalty amount solely by referring to the maximum in the Schedule. Section 33(2) requires consideration of:

  • the nature, gravity and duration of the breach;

  • the type and nature of the personal data affected;

  • whether the breach was repetitive;

  • whether the person obtained a gain or avoided a loss;

  • the timeliness and effectiveness of mitigation;

  • whether the amount is proportionate and effective for securing compliance and deterring future breaches; and

  • the likely impact of the penalty on the person.

These factors allow the Board to distinguish between:

  • an isolated error and a systemic failure;

  • inadvertent conduct and deliberate misuse;

  • immediate containment and prolonged concealment;

  • a first occurrence and repeated non-compliance;

  • low-impact information and highly consequential financial, biometric, health or children’s data;

  • a breach corrected voluntarily and one continued despite warnings; and

  • a penalty that meaningfully deters a large enterprise and one that would be disproportionate for a smaller organisation.

The Schedule provides the outer limit. Section 33 provides the method for determining the amount within that limit.

11. Multiple breaches arising from one incident

A single factual incident may involve more than one statutory breach. For example, a cybersecurity incident may involve:

  • failure to maintain reasonable security safeguards;

  • failure to notify the Board;

  • failure to notify affected Data Principals;

  • non-compliance with children’s-data requirements;

  • breach of an accepted voluntary undertaking; and

  • another failure under the Rules.

The Board must identify each legally distinct obligation and determine whether the established facts support separate breaches. It should also avoid penalising identical conduct repeatedly under different labels without accounting for overlap and overall proportionality. The Act does not state that ₹250 crore is an aggregate lifetime ceiling for an organisation. The Schedule attaches penalty ceilings to categories of breach. The treatment of several breaches, continuing conduct or multiple proceedings will therefore depend on the facts, the number of legally distinct violations and the Board’s application of Section 33.

Penalties are not compensation Monetary penalties imposed under Section 33 are public regulatory sanctions. Under Section 34, every amount realised from those penalties must be credited to the Consolidated Fund of India. Affected Data Principals do not automatically receive:

  • the penalty;

  • a proportionate share of it;

  • damages from the Board; or

  • reimbursement from the penalty proceeds.

The penalty may reflect the seriousness of the consequences for individuals, but it remains distinct from compensation. Individual correction, erasure, cessation of processing, account restoration, mediation or another remedy available under a separate law may operate alongside regulatory enforcement.

Power to amend the Schedule Section 42 permits the Central Government to amend the Schedule through notification. However, no penalty may be increased to more than twice the amount specified when the DPDPA was originally enacted. The theoretical maximum ceilings under that power are therefore:

Originally enacted ceiling

Maximum permissible ceiling under Section 42 ₹250 crore ₹500 crore ₹200 crore ₹400 crore ₹150 crore ₹300 crore ₹50 crore ₹100 crore ₹10,000 ₹20,000 The doubling limit is measured from the original statutory amount. It does not permit successive compounding by repeatedly doubling previously amended figures. Any Section 42 amendment takes effect from the date of the notification and operates as if enacted in the DPDPA. It must also be laid before both Houses of Parliament under Section 41. As of 1 September 2026, no official notification amending the originally enacted Schedule was identified. The penalty amounts reproduced above therefore remain the notified statutory ceilings, subject to the commencement of Section 33 on 13 May 2027.

Concluding commentary The Schedule creates a graded penalty system in which the highest exposure is reserved for security failures, breach-notification failures and violations involving children. It separately addresses enhanced obligations of Significant Data Fiduciaries, misuse of statutory rights by Data Principals, breach of voluntary undertakings and all other significant contraventions. The amounts stated are maximum ceilings, not standard fines. A penalty may be imposed only after the Board completes an inquiry, determines that the breach is significant, gives the person an opportunity of being heard and applies the statutory factors in Section 33(2). The Schedule determines the maximum financial exposure for each category of breach. It does not remove the Board’s duty to establish significance, observe procedural fairness and impose a penalty that is proportionate, effective and deterrent in the circumstances.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.