Back to Key Provisions
Penalties and Consequences
Detailed breakdown of the DPDPA's penalty framework - penalty amounts, determination factors, adjudication process, and comparison with global frameworks.
10 min read
Civil Penalty Framework
The DPDPA adopts an exclusively civil penalty regime - there is no criminal liability for data protection violations. This is a deliberate departure from the earlier Personal Data Protection Bill, 2019, which included criminal sanctions, and reflects a policy choice to encourage compliance through financial deterrents rather than criminalisation.
The Schedule to the Act prescribes maximum penalty amounts for different categories of violations, with the Data Protection Board having discretion in determining the actual quantum.
Penalty Schedule
The Act prescribes the following maximum penalties:
1. Failure to take reasonable security safeguards (Section 8(5)): Up to Rs 250 crore
2. Failure to notify the Board and Data Principals of a breach (Section 8(6)): Up to Rs 200 crore
3. Breach of obligations relating to children's data (Section 9): Up to Rs 200 crore
4. Breach of additional obligations by Significant Data Fiduciaries (Section 10): Up to Rs 150 crore
5. Non-compliance with any other provision of the Act: Up to Rs 50 crore
6. Breach of duties by a Data Principal (Section 15): Up to Rs 10,000
These are maximum amounts - the Board has discretion to impose lower penalties based on the circumstances of each case. The Rs 250 crore maximum for security failures signals the Act's emphasis on preventive security measures.
Factors in Penalty Determination
The Board considers multiple factors when determining the quantum of penalty:
• Nature, gravity, and duration of the breach
• Type and nature of personal data affected
• Repetitive nature of the breach (repeat offenders face higher penalties)
• Whether the person made any gain or avoided any loss as a result of the breach
• Whether the person took any action to mitigate the effects of the breach
• Whether the person cooperated with the Board during the inquiry
• Any other factors the Board considers relevant
This multi-factor approach provides flexibility but also introduces an element of unpredictability in penalty outcomes.
Absence of Criminal Liability
The DPDPA deliberately excludes criminal sanctions, a significant policy decision. The rationale includes:
• Encouraging compliance through proportionate civil penalties rather than fear of prosecution
• Avoiding the chilling effect of criminal liability on innovation and data-driven businesses
• Aligning with the evolving global trend toward civil enforcement in data protection
However, criminal liability for data-related offences may still arise under other laws, including the IT Act (Section 72A) and the Bharatiya Nyaya Sanhita (BNS) provisions on fraud, cheating, and identity theft. Note: Section 43A of the IT Act has been omitted by Section 44(b) of the DPDPA.
Cumulative Penalties
A single incident may trigger multiple penalty provisions. For example, a data breach could result in:
1. Penalty for failure to implement reasonable security safeguards (up to Rs 250 crore)
2. Penalty for failure to notify the Board and Data Principals (up to Rs 200 crore)
3. If children's data is involved, additional penalty (up to Rs 200 crore)
The theoretical maximum exposure for a single incident involving children's data could therefore be up to Rs 650 crore. This cumulative potential creates a strong economic incentive for compliance.
Comparison with Global Penalties
The DPDPA's penalties are significant but differ in structure from other frameworks:
• GDPR: Up to EUR 20 million or 4% of global annual turnover (whichever is higher)
• DPDPA: Fixed maximum amounts (up to Rs 250 crore, approximately EUR 28 million)
• CCPA: $2,500 per unintentional violation, $7,500 per intentional violation
The DPDPA does not link penalties to revenue, meaning the same maximum applies to both a small startup and a large multinational. This has been criticised as potentially disproportionate for smaller organisations while being insufficient deterrent for global technology companies.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
