The number that gets quoted most about the DPDP Act is its top penalty. Here’s that figure in context, alongside the rest of the scale.
Failure
- Inadequate security safeguards, leading to a breach
- Failing to notify a breach
- Non-compliance on children's data
- Significant Data Fiduciary duties not met
- Other contraventions of the Act or Rules
- A Data Principal breaching their own duties
Maximum penalty
- Up to ₹250 crore
- Up to ₹200 crore
- Up to ₹200 crore
- Up to ₹150 crore
- Up to ₹50 crore
- Up to ₹10,000
These are ceilings, not fixed fines. The Data Protection Board weighs the nature and duration of the breach, the sensitivity of the data involved, whether it was repeated, and how the organisation responded, before landing on an actual figure — and penalties for separate violations in one incident can stack. There are no criminal penalties under the Act; every consequence here is financial and administrative.
Common misconception — That these are automatic, ticket-style fines. They’re not — the Board conducts an inquiry and weighs several factors before setting the amount, and prompt, transparent remediation genuinely helps.
₹250 crore is the ceiling, not the going rate — but it exists to make security safeguards a board-level priority, not an afterthought.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf  ·  India’s New Digital Privacy Law: The DPDP Act and Rules Explained — Lexology — https://www.lexology.com/library/detail.aspx?g=f4b2877e-a81b-4286-bdbf-77c4d9fd0807Â