Penalties Under the DPDP Act: What Non-Compliance Costs

The number that gets quoted most about the DPDP Act is its top penalty. Here’s that figure in context, alongside the rest of the scale.

Failure

Maximum penalty

These are ceilings, not fixed fines. The Data Protection Board weighs the nature and duration of the breach, the sensitivity of the data involved, whether it was repeated, and how the organisation responded, before landing on an actual figure — and penalties for separate violations in one incident can stack. There are no criminal penalties under the Act; every consequence here is financial and administrative.
Common misconception — That these are automatic, ticket-style fines. They’re not — the Board conducts an inquiry and weighs several factors before setting the amount, and prompt, transparent remediation genuinely helps.

₹250 crore is the ceiling, not the going rate — but it exists to make security safeguards a board-level priority, not an afterthought.

SOURCES  The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf   ·   India’s New Digital Privacy Law: The DPDP Act and Rules Explained — Lexology — https://www.lexology.com/library/detail.aspx?g=f4b2877e-a81b-4286-bdbf-77c4d9fd0807 

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.