Chapter VIII · Penalties and Adjudication
Section 33: Penalties
Section 33 is where the money lives: after an inquiry, if the Board finds a significant breach and hears you out, it can impose the Schedule penalty, up to Rs 250 crore, set case by case using seven factors.
- Chapter
- Chapter VIII · Penalties and Adjudication
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Maximum penalty
- Rs 250 crore (s.8(5))
- Applies to
- Any person in breach
- Official citation
- DPDP Act, 2023, s.33 + Schedule
- Reading time
- 8 min
- Updated
- August 2026
At a glance
Section 33 lets the Data Protection Board impose a monetary penalty from the Schedule, but only on conclusion of an inquiry, only where it determines the breach of the Act or Rules is significant, and only after giving the person an opportunity of being heard [33(1)]. The amount is set case by case using seven mandatory factors: the nature, gravity and duration of the breach; the type and nature of the personal data affected; whether it was repetitive; whether the person gained or avoided a loss; the mitigation taken and its timeliness and effectiveness; whether the penalty is proportionate and deterrent; and the likely impact on the person [33(2)]. The Schedule sets maximums, not fixed or minimum fines: up to Rs 250 crore for a security-safeguard breach [s.8(5)], Rs 200 crore for a breach-notification failure [s.8(6)], Rs 200 crore for children's-data breaches [s.9], Rs 150 crore for SDF breaches [s.10], Rs 10,000 for Data Principal duties [s.15], the underlying-breach ceiling for breaking a voluntary undertaking [s.32], and Rs 50 crore for any other breach. Section 33 and the Schedule take effect on 13 May 2027.
Key takeaways
- A penalty is never automatic: it needs a completed inquiry, a finding that the breach is significant, and an opportunity to be heard [33(1)].
- The Board sets the amount case by case using seven factors [33(2)], not a formula: gravity, data type, repetition, gain or loss, mitigation, proportionality and impact.
- The Schedule gives maximums, not minimums: the top figure is Rs 250 crore, for failing to take reasonable security safeguards [s.8(5)].
- A breach-notification failure [s.8(6)] is a separate Rs 200 crore ceiling, even if your security was reasonable.
- There is no minimum: a small breach is not guaranteed a small fine, and a large firm is not guaranteed the maximum. Evidence and the factors decide.
- Penalties go to the Consolidated Fund of India, and the Government can raise Schedule figures only up to twice the enacted amount under Section 42.
Who should read this
Read this if you want to understand your real financial exposure under the DPDP Act: what triggers a penalty, how big it can get, and which of your everyday records actually move the number down.
In plain language
Section 33 is the Act's penalty engine, and the Schedule is its price list. The headline number everyone quotes, Rs 250 crore, is the ceiling for one specific failure: not taking reasonable security safeguards. It is a maximum, not a flat fine.
Getting there is not automatic. The Board must finish an inquiry, decide your breach is significant, and hear you first. Only then can it impose a penalty, and it must set the amount using seven factors, from how bad and how long the breach was to whether you gained from it and how quickly you fixed it.
There is no minimum and no formula. That cuts both ways: a small firm can still be penalised, and a large one is not automatically hit with the maximum. What you can show, prompt mitigation, no gain, real remediation, genuinely changes the number.
The text of the law
Section 33: Penalties
33(1) On conclusion of an inquiry, if the Board determines a person's breach of the Act or Rules is significant, it may, after giving the person an opportunity of being heard, impose the monetary penalty specified in the Schedule.
33(2) In determining the amount, the Board must have regard to: (a) the nature, gravity and duration of the breach; (b) the type and nature of the personal data affected; (c) the repetitive nature of the breach; (d) whether the person realised a gain or avoided a loss; (e) the mitigating action taken and its timeliness and effectiveness; (f) whether the penalty is proportionate and effective for deterrence; and (g) the likely impact of the penalty on the person.
Wording summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
The Schedule: penalties at a glance
| # | Nature of non-compliance | Maximum penalty |
|---|---|---|
| 1 | Failure to take reasonable security safeguards to prevent a personal data breach (s.8(5)) | Up to ₹250 crore |
| 2 | Failure to notify the Board or affected Data Principals of a personal data breach (s.8(6)) | Up to ₹200 crore |
| 3 | Breach of additional obligations for children's data (s.9) | Up to ₹200 crore |
| 4 | Breach of Significant Data Fiduciary obligations (s.10) | Up to ₹150 crore |
| 5 | Breach of a Data Principal's duties (s.15) | Up to ₹10,000 |
| 6 | Breach of a term of an accepted voluntary undertaking (s.32) | Tracks the underlying breach |
| 7 | Breach of any other provision of the Act or Rules (residual) | Up to ₹50 crore |
Every figure is a maximum ("may extend to"), not a fixed or minimum fine; the Board sets the actual amount using the seven Section 33(2) factors. Under Section 42 the Government may amend these figures but cannot raise any penalty beyond twice the amount originally enacted.
What this means for you
- Build your mitigation evidence during normal operations, not after a Board notice: incident timelines, containment logs, patch records, notification proof and post-incident testing all map straight to factor (e).
- Be able to show no gain and no avoided cost [factor (d)]: keep the decision records and business cases that demonstrate a breach did not make you money or save a spend you were obliged to make.
- Keep a clean prior-incident register [factor (c)]: evidence that past issues were found, fixed and closed is what stops "repetitive" from inflating the number.
- Invest in the controls behind the biggest ceilings: reasonable security safeguards under Section 8(5) (Rs 250 cr) and breach-notification readiness under Section 8(6) (Rs 200 cr) are where the exposure is largest.
- Remember cooperation is not a named factor, but effective, timely remediation is: do not assume being helpful alone removes a penalty. Want a clear read on your exposure? Take the readiness assessment or find a specialist.
Frequently asked questions
Is Rs 250 crore the automatic fine for any breach?
Is there a minimum penalty?
Can we be fined for a notification failure even if our security was fine?
Can we be fined for something not named in the Schedule?
Can the Government raise these penalties?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.