Back to Enforcement Architecture
Penalties Schedule
Complete analysis of the DPDPA penalty schedule - maximum amounts, determination factors, and comparison with GDPR penalties.
7 min read
Penalty Structure Under the Schedule
The Schedule to the DPDPA prescribes maximum penalties for various categories of non-compliance. The penalties are civil in nature - the Act does not create criminal offences. Key penalty amounts include:
• Breach of personal data: Up to Rs 250 crore
• Failure to notify Board and affected persons of breach: Up to Rs 200 crore
• Non-compliance with obligations related to children's data: Up to Rs 200 crore
• Failure to comply with Board directions: Up to Rs 50 crore
• Non-compliance with other provisions: Up to Rs 50 crore
• Breach of duties by Data Principals: Up to Rs 10,000
Factors in Penalty Determination
The Board considers multiple factors when determining the quantum of penalty: (a) nature, gravity, and duration of the breach; (b) type and nature of personal data affected; (c) repetitive nature of the default; (d) whether any gain or advantage was derived; (e) whether the Data Fiduciary took mitigating action; and (f) any other relevant factor.
These factors provide the Board with discretion to impose proportionate penalties based on the specific circumstances of each case.
Comparison with GDPR Penalties
The GDPR imposes penalties of up to EUR 20 million or 4% of global annual turnover, whichever is higher. The DPDPA's fixed maximum amounts (without reference to turnover) mean that the penalty impact varies significantly based on the size of the organisation.
For large multinationals, the DPDPA's Rs 250 crore maximum (~EUR 28 million) may be less impactful than the GDPR's turnover-based calculation. For smaller organisations, the fixed amounts could be disproportionately burdensome. The Board's discretion in applying determination factors is intended to address this proportionality concern.
Aggregate and Multiple Penalties
The Act provides that the total penalty imposed under the provisions shall not exceed Rs 250 crore per instance. However, multiple breaches may attract separate penalties. An organisation that simultaneously breaches multiple provisions may face aggregate penalties exceeding Rs 250 crore across all breaches.
The cumulative financial exposure from multiple breaches underscores the importance of comprehensive compliance programmes rather than addressing isolated requirements.
Penalty Mitigation Strategies
Organisations can reduce penalty exposure by: (a) implementing robust compliance programmes; (b) conducting regular audits and assessments; (c) responding promptly to breaches and data subject requests; (d) maintaining comprehensive documentation of compliance efforts; and (e) cooperating fully with Board inquiries.
A strong compliance track record and prompt remedial action are likely to be significant mitigating factors in the Board's penalty assessment.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
