Module 7 of 9 · 5 min read
Penalties, the Board and how enforcement actually works
The penalty schedule, the Board's process, appeals to TDSAT, and voluntary undertakings.
The penalty schedule
| Breach | Maximum penalty |
|---|---|
| Failure of Data Fiduciary to take reasonable security safeguards | ₹250 crore |
| Failure to notify the Board / affected Data Principals of a breach | ₹200 crore |
| Non-fulfilment of additional obligations relating to children | ₹200 crore |
| Non-fulfilment of additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of Data Principal duties | ₹10,000 |
| Breach of a voluntary undertaking accepted by the Board | Up to the penalty for the underlying breach |
| Any other provision of the Act or Rules | ₹50 crore |
Penalties are per instance. The Board must consider nature, gravity and duration; type and nature of data; repetitive nature; gain/loss avoided; mitigation actions taken and their timeliness; and proportionality.
The Data Protection Board of India
- An independent body, functioning as a digital office — filing, hearings and decisions online.
- Acts on complaints from Data Principals, references from Government, or breach intimations from Fiduciaries.
- Can direct urgent remedial measures, inquire, and impose penalties after giving a hearing.
- Can accept a voluntary undertaking (specific actions, timelines, public acknowledgement) instead of proceeding — the closest thing to a settlement.
Appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days, and from there to the Supreme Court.
What enforcement will look like in year one
- Complaint-driven cases — a Principal exhausts your grievance channel, then goes to the Board. Your grievance log is exhibit A.
- Breach-driven cases — your own 72-hour intimation opens an inquiry. Timeliness and candour are mitigation factors.
- Notified SDFs — audit reports to the Board create a paper trail; gaps are visible.
Where liability sits
- The Fiduciary is liable for Processor failures — there is no direct Processor penalty under the Act.
- No criminal liability for organisations under DPDPA itself; the IT Act 2000 offences still apply.
- Directors and officers: the Act's penalties are on the Fiduciary; governance failure exposure comes through Companies Act duties and sectoral regulators.