Readiness assessment
Share this section

Chapter VIII · Penalties and Adjudication

Section 33: Penalties

Section 33 is where the money lives: after an inquiry, if the Board finds a significant breach and hears you out, it can impose the Schedule penalty, up to Rs 250 crore, set case by case using seven factors.

Official text
Section 33Penalties & Schedule
Chapter
Chapter VIII · Penalties and Adjudication
Status
Enacted · phased commencement
Full compliance
13 May 2027
Maximum penalty
Rs 250 crore (s.8(5))
Applies to
Any person in breach
Official citation
DPDP Act, 2023, s.33 + Schedule
Reading time
8 min
Updated
August 2026

At a glance

Section 33 lets the Data Protection Board impose a monetary penalty from the Schedule, but only on conclusion of an inquiry, only where it determines the breach of the Act or Rules is significant, and only after giving the person an opportunity of being heard [33(1)]. The amount is set case by case using seven mandatory factors: the nature, gravity and duration of the breach; the type and nature of the personal data affected; whether it was repetitive; whether the person gained or avoided a loss; the mitigation taken and its timeliness and effectiveness; whether the penalty is proportionate and deterrent; and the likely impact on the person [33(2)]. The Schedule sets maximums, not fixed or minimum fines: up to Rs 250 crore for a security-safeguard breach [s.8(5)], Rs 200 crore for a breach-notification failure [s.8(6)], Rs 200 crore for children's-data breaches [s.9], Rs 150 crore for SDF breaches [s.10], Rs 10,000 for Data Principal duties [s.15], the underlying-breach ceiling for breaking a voluntary undertaking [s.32], and Rs 50 crore for any other breach. Section 33 and the Schedule take effect on 13 May 2027.

Applies to Any person in breachChapter Chapter VIIIMax penalty Rs 250 croreRead time 8 min

Key takeaways

  • A penalty is never automatic: it needs a completed inquiry, a finding that the breach is significant, and an opportunity to be heard [33(1)].
  • The Board sets the amount case by case using seven factors [33(2)], not a formula: gravity, data type, repetition, gain or loss, mitigation, proportionality and impact.
  • The Schedule gives maximums, not minimums: the top figure is Rs 250 crore, for failing to take reasonable security safeguards [s.8(5)].
  • A breach-notification failure [s.8(6)] is a separate Rs 200 crore ceiling, even if your security was reasonable.
  • There is no minimum: a small breach is not guaranteed a small fine, and a large firm is not guaranteed the maximum. Evidence and the factors decide.
  • Penalties go to the Consolidated Fund of India, and the Government can raise Schedule figures only up to twice the enacted amount under Section 42.

Who should read this

Read this if you want to understand your real financial exposure under the DPDP Act: what triggers a penalty, how big it can get, and which of your everyday records actually move the number down.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Section 33 is the Act's penalty engine, and the Schedule is its price list. The headline number everyone quotes, Rs 250 crore, is the ceiling for one specific failure: not taking reasonable security safeguards. It is a maximum, not a flat fine.

Getting there is not automatic. The Board must finish an inquiry, decide your breach is significant, and hear you first. Only then can it impose a penalty, and it must set the amount using seven factors, from how bad and how long the breach was to whether you gained from it and how quickly you fixed it.

There is no minimum and no formula. That cuts both ways: a small firm can still be penalised, and a large one is not automatically hit with the maximum. What you can show, prompt mitigation, no gain, real remediation, genuinely changes the number.

The text of the law

Section 33: Penalties

33(1) On conclusion of an inquiry, if the Board determines a person's breach of the Act or Rules is significant, it may, after giving the person an opportunity of being heard, impose the monetary penalty specified in the Schedule.

33(2) In determining the amount, the Board must have regard to: (a) the nature, gravity and duration of the breach; (b) the type and nature of the personal data affected; (c) the repetitive nature of the breach; (d) whether the person realised a gain or avoided a loss; (e) the mitigating action taken and its timeliness and effectiveness; (f) whether the penalty is proportionate and effective for deterrence; and (g) the likely impact of the penalty on the person.

Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

The Schedule: penalties at a glance

#Nature of non-complianceMaximum penalty
1Failure to take reasonable security safeguards to prevent a personal data breach (s.8(5))Up to ₹250 crore
2Failure to notify the Board or affected Data Principals of a personal data breach (s.8(6))Up to ₹200 crore
3Breach of additional obligations for children's data (s.9)Up to ₹200 crore
4Breach of Significant Data Fiduciary obligations (s.10)Up to ₹150 crore
5Breach of a Data Principal's duties (s.15)Up to ₹10,000
6Breach of a term of an accepted voluntary undertaking (s.32)Tracks the underlying breach
7Breach of any other provision of the Act or Rules (residual)Up to ₹50 crore

Every figure is a maximum ("may extend to"), not a fixed or minimum fine; the Board sets the actual amount using the seven Section 33(2) factors. Under Section 42 the Government may amend these figures but cannot raise any penalty beyond twice the amount originally enacted.

What this means for you

  • Build your mitigation evidence during normal operations, not after a Board notice: incident timelines, containment logs, patch records, notification proof and post-incident testing all map straight to factor (e).
  • Be able to show no gain and no avoided cost [factor (d)]: keep the decision records and business cases that demonstrate a breach did not make you money or save a spend you were obliged to make.
  • Keep a clean prior-incident register [factor (c)]: evidence that past issues were found, fixed and closed is what stops "repetitive" from inflating the number.
  • Invest in the controls behind the biggest ceilings: reasonable security safeguards under Section 8(5) (Rs 250 cr) and breach-notification readiness under Section 8(6) (Rs 200 cr) are where the exposure is largest.
  • Remember cooperation is not a named factor, but effective, timely remediation is: do not assume being helpful alone removes a penalty. Want a clear read on your exposure? Take the readiness assessment or find a specialist.

Frequently asked questions

Is Rs 250 crore the automatic fine for any breach?
No. It is the maximum for failing to take reasonable security safeguards under Section 8(5). A penalty needs a completed inquiry, a significant-breach finding, a hearing, and the Section 33(2) factors applied.
Is there a minimum penalty?
No. The Schedule sets only maximums ("may extend to"). The Board can impose less, guided by the seven factors.
Can we be fined for a notification failure even if our security was fine?
Yes. Failing to notify the Board or affected Data Principals under Section 8(6) is a separate ceiling of up to Rs 200 crore.
Can we be fined for something not named in the Schedule?
Potentially. The residual row covers any other provision of the Act or Rules, up to Rs 50 crore.
Can the Government raise these penalties?
Only within a limit. Under Section 42 it may amend the Schedule by notification, but cannot raise any penalty to more than twice the amount originally enacted.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment