DPDPA 2023 — From Awareness to Compliance
Module 7 of 9 · 5 min read

Penalties, the Board and how enforcement actually works

The penalty schedule, the Board's process, appeals to TDSAT, and voluntary undertakings.

The penalty schedule

BreachMaximum penalty
Failure of Data Fiduciary to take reasonable security safeguards₹250 crore
Failure to notify the Board / affected Data Principals of a breach₹200 crore
Non-fulfilment of additional obligations relating to children₹200 crore
Non-fulfilment of additional obligations of a Significant Data Fiduciary₹150 crore
Breach of Data Principal duties₹10,000
Breach of a voluntary undertaking accepted by the BoardUp to the penalty for the underlying breach
Any other provision of the Act or Rules₹50 crore

Penalties are per instance. The Board must consider nature, gravity and duration; type and nature of data; repetitive nature; gain/loss avoided; mitigation actions taken and their timeliness; and proportionality.

The Data Protection Board of India

  • An independent body, functioning as a digital office — filing, hearings and decisions online.
  • Acts on complaints from Data Principals, references from Government, or breach intimations from Fiduciaries.
  • Can direct urgent remedial measures, inquire, and impose penalties after giving a hearing.
  • Can accept a voluntary undertaking (specific actions, timelines, public acknowledgement) instead of proceeding — the closest thing to a settlement.

Appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days, and from there to the Supreme Court.

What enforcement will look like in year one

  1. Complaint-driven cases — a Principal exhausts your grievance channel, then goes to the Board. Your grievance log is exhibit A.
  2. Breach-driven cases — your own 72-hour intimation opens an inquiry. Timeliness and candour are mitigation factors.
  3. Notified SDFs — audit reports to the Board create a paper trail; gaps are visible.

Where liability sits

  • The Fiduciary is liable for Processor failures — there is no direct Processor penalty under the Act.
  • No criminal liability for organisations under DPDPA itself; the IT Act 2000 offences still apply.
  • Directors and officers: the Act's penalties are on the Fiduciary; governance failure exposure comes through Companies Act duties and sectoral regulators.