DPDPA Penalties Explained: 8 Violations That Can Cost Businesses

Search what the DPDPA can cost you, and you will get a different answer almost every time. ₹250 crore on one page, ₹500 crore on another, eight violation categories in one place, six somewhere else, and section numbers that do not even line up.
Some of it is wrong in ways that could get expensive if you plan around it.
So I went back to the Schedule and section 33 to see what actually applies to what. Below are the eight failures that carry a penalty for an Indian business, with the section number and maximum amount for each, plus the four that share one ceiling instead of having four separate ones.
One thing to keep in mind before you read those numbers: none of them is a fine you are automatically handed.
Every figure in the Schedule is a maximum. The amount you would actually pay is decided through a process the Act lays out in detail. That process is where the negotiation happens, so that is the place to start.
How the Data Protection Board decides what you pay
The Schedule is quoted often, usually as a list of alarming numbers. What often gets missed is the process behind those numbers, and that is where much of your exposure is decided.
The Board must find the breach significant and hear you first
Section 33(1) sets two conditions before any penalty can be imposed. After an inquiry, the Board must first decide that your breach of the Act or Rules is significant.
It must then give you an opportunity to be heard. Only after both steps can it impose the monetary penalty listed in the Schedule.
So the sequence is inquiry, a finding of significance, a hearing, and then the amount. Not every contravention reaches the penalty stage, and the ones that do create a paper trail you can respond to.
The 7 factors that set the amount
Section 33(2) tells the Board what to weigh: the nature, gravity, and duration of the breach; the type of personal data affected; whether the breach was repetitive; whether you gained or avoided a loss from it; whether you acted quickly and effectively to mitigate its effects; whether the penalty is proportionate and an effective deterrent; and the likely impact of the penalty on you.
Factor (e) is the only one you can still influence after a breach. The other six are shaped by what you did before it.
Every figure in the Schedule is a ceiling, not a fine
Each amount is only a maximum the penalty may extend to. If you have seen ₹500 crore quoted anywhere, the Act does not let the Board simply multiply a Schedule maximum.
The amounts are fixed in rupees, not linked to turnover. GDPR exposure scales with revenue; DPDPA exposure does not.
That means ₹50 crore lands very differently on a company doing ₹40 crore a year than on one doing ₹4,000 crore a year.
The 4 violations with their own penalty in the Schedule
Four Schedule heads name a specific obligation and attach a specific maximum. One incident can trigger more than one at once.
1. Failing to take reasonable security safeguards, section 8(5), up to ₹250 crore
The largest number in the Schedule sits here: the duty to take reasonable security safeguards to prevent a personal data breach.
The Board’s question is whether the controls existed, not whether the attacker was clever. The IQWorks readiness checklist puts four things under this obligation:
- Encryption at rest and in transit
- Role-based access control
- Audit logging
- Incident detection
Every Data Fiduciary carries this head, regardless of size, sector, or designation.
What this costs before the penalty arrives
The penalty is not the first bill. IBM's Cost of a Data Breach Report 2025 found:
- ₹22 crore is the average cost of a breach in India. An all-time high, up 13% year on year, against a global average of $4.44M.
- 263 days to identify and contain a breach in India. Roughly nine months of security and engineering time spent on the incident instead of the product.
- ₹1.79 crore added per incident by shadow AI, where employees put company data into unauthorized AI tools. IBM named it one of India’s leading drivers of breach costs.
2. Not notifying a breach to the Board and the people affected: Section 8(6), up to ₹200 crore
Section 8(6) requires notice of a personal data breach to the Board and to each affected Data Principal within the periods set by the Rules.
This is separate from the breach itself, so a single incident can result in two penalties.
You can have defensible security, still suffer a breach, and still face ₹200 crore for how you handled the hours after it.
Notifying the Board but not individuals, or the reverse, leaves the obligation unmet.
You can only notify if you know whose data it was
The ICMR breach in 2023 involved 815 million records with Aadhaar and passport information, phone numbers, and COVID test results. In 2024, Star Health Insurance involved 31 million people and 7.24 TB of data.
The IQWorks report says what they had in common: the volume of personal data held was greater than the organization could readily describe because it spanned systems that were never inventoried end-to-end.
That matters under section 8(6), which assumes you can identify whose data was involved without a long investigation.
RoPA and data lineage make that possible. They turn breach response into a fast lookup and keep the notification list and supporting evidence together.
3. Ignoring the additional obligations on children's data, section 9, up to ₹200 crore
Section 9 requires verifiable parental consent before processing personal data of anyone under eighteen, and bars tracking, behavioral monitoring, and targeted advertising to children.
Two things catch Indian founders out. Eighteen is higher than several other regimes, so a product that treats sixteen as an adult elsewhere does not clear the line here.
And the obligation applies even if children are not your intended audience. If under-eighteens use your product, and on most consumer platforms some do, the head is live.
What GDPR enforcement suggests about priority
Two of the larger GDPR fines focused on children’s data: Instagram at €405M in 2022, and TikTok at €345M.
The IQWorks report treats that as a reason to expect children’s data to be an Indian priority as well, while noting that the inference comes from European experience, not from stated Indian regulatory intent.
4. Missing Significant Data Fiduciary obligations, section 10, up to ₹150 crore
Significant Data Fiduciaries carry obligations that ordinary Data Fiduciaries do not, with their own ₹150 crore head.
Designation is assigned by the Central Government based on the volume and sensitivity of data you process and the risk to Data Principals.
The criteria are about your data, not revenue or headcount, which is why a company that sees itself as small can still be designated.
DPO in India, DPIAs, independent audit
- Appoint a Data Protection Officer based in India
- Conduct periodic Data Protection Impact Assessments
- Engage an independent data auditor rather than signing off your own work
The DPDP Rules 2025 add restrictions on SDFs transferring specified categories of personal data outside India.
If your stack runs on infrastructure hosted elsewhere, check that before designation arrives.
Must Read: Data Classification Best Practices
The four failures that fall under the residual head
The next four are the ones most Indian founders are most likely to run into, and none has its own entry in the Schedule.
They fall under the residual head, which covers breaches of any other provision of the Act or Rules and may extend to ₹50 crore. That single ceiling covers all four. Failing on all of them does not create four separate ₹50 crore penalties.
It is the smallest number in this article, and still the one most likely to hurt a mid-sized company.
5. Consent that does not meet the section 6 standard
Consent must be free, specific, informed, unconditional, and unambiguous. Most failures are not about failing to ask, but asking in a way that breaks one of those rules:
- Bundling unrelated purposes into one checkbox breaks specificity
- Making the service conditional on consent you do not need breaks free and unconditional
- Pre-ticked boxes and implied consent from continued use break unambiguous consent
Section 6(4) adds the part many teams miss. Consent can be withdrawn at any time, and withdrawal must be as easy as giving it.
If signing up took one tap and withdrawal needs an email to support plus a five-day wait, that is the failure.
Must Read: How ConsentIQ Proves Consent Without Storing Personal Data
6. Privacy notices that do not meet section 5
Section 5 requires a notice before or at the time you seek consent, stating what data you collect and why.
Section 5(3) is widely misreported in India, so it is worth being precise. You must give the Data Principal the option to access the notice in English or any language in the Eighth Schedule to the Constitution. That is an access obligation, met by offering the option.
It does not require publishing every notice in all twenty-two languages. Translate for the languages your data principals actually use, and make the option available.
7. Not honoring Data Principal rights and grievance redressal, sections 11 to 14
Four rights have no dedicated head, so failures land here:
- Access, section 11. A summary of the data processed, processing activities, and the identities of other Fiduciaries and Processors you shared it with.
- Correction and erasure, section 12, including cascading corrections under 12(3).
- Grievance redressal, section 13, with the Rules setting a response period not exceeding ninety days and the right to approach the Board if unresolved.
- Nomination, section 14, on death or incapacity.
Section 11 exposes weak record-keeping fastest. You cannot tell someone which processors hold their data if you never recorded it.
This is the other half of what ComplyIQ handles. Request management with audit trails means a request arrives, gets routed, gets fulfilled within the period, and leaves a record.
That record matters twice: once for the person who asked, and once for section 33(2)(e), where the Board weighs what action you took and how quickly.
8. Holding personal data past its purpose, section 8(7)
Section 8(7) requires erasure once the purpose is no longer served, and requires your processor to do the same.
Retention works silently against you. Nobody complains, no incident reveals it, and exposure grows every month you keep collecting.
The DPDP Rules 2025 add timing for certain classes of Data Fiduciary:
- Erase personal data three years after the Data Principal last approached you
- Retain the associated logs for at least one year
The second catches teams that read the first and delete everything. The log is your proof that erasure happened properly.
The two Schedule entries that are not about your business
Count the heads above, and you get eight failures against seven Schedule entries. Here is why.
Two entries in the Schedule are not Data Fiduciary failures at all.
Entry 5, duties of the Data Principal under section 15, ₹10,000
This penalty falls on the individual, not on you. It is the only figure in the Schedule stated in thousands rather than crores, and it exists to discourage frivolous or false complaints.
Entry 6, breach of a voluntary undertaking accepted by the Board under section 32
The Schedule gives this no separate figure. The penalty can extend only to the amount applicable to the underlying breach the undertaking covered.
So five entries govern your exposure, and four of my eight failures share the residual one.
Anyone quoting eight separate penalty amounts against Indian businesses is reading a Schedule the Act does not contain.
Must Read: DPDPA Compliance for Startups
One incident, four heads: how DPDPA penalties stack
Each Schedule entry sets a maximum for its own breach head. Nothing in the Act prevents one incident from triggering several at once.
A worked scenario
The IQWorks report describes a mid-sized e-commerce company that holds children’s data and has failed to honor pending erasure requests. One breach, four heads:
| Head engaged | Entry | Maximum |
| Inadequate security safeguards that enabled the breach | s.8(5) | ₹250 crore |
| No notice to the Board or affected Data Principals | s.8(6) | ₹200 crore |
| Children's data, additional obligations not observed | s.9 | ₹200 crore |
| Erasure requests not honored | Residual | ₹50 crore |
| Theoretical maximum from one incident | ₹700 crore |
Read that as statutory maxima, not an expected outcome. The Board sets each amount using the section 33(2) factors, and a company with evidence of remediation is unlikely to hit the ceiling on all four.
Where the exposure actually concentrates
The useful part of that table is not the total. It is that three of the four heads depend on capabilities that cost very little compared with the penalties they help avoid:
- Knowing where personal data sits
- Detecting a breach fast enough to notify within the prescribed period
- Identifying whether children’s data is involved
- Showing that erasure requests were actioned
Only the first line, the security safeguards themselves, is an infrastructure spend. The other three are record-keeping problems.
That is the case for keeping RoPA, data lineage, and request tracking in one system rather than four spreadsheets. ComplyIQ exists for that layer, and it is where most of the stacking risk lies.
What compliance costs against what non-compliance costs
The obvious objection to all of this is that DPDPA compliance is expensive. Published research suggests non-compliance costs more.
The Ponemon Institute, working with GlobalScape, compared both across surveyed multinational organizations:
| Average per organization | |
| Cost of non-compliance | $14.82M |
| Cost of compliance | $5.47M |
Non-compliance costs 2.71 times more. That figure includes disruption, churn, fines, legal costs, and breach response; the compliance figure covers tooling, training, audits, and program management.
Cisco’s Data Privacy Benchmark Study 2025 found that 96% of organizations saw returns above their spend, at a median of 1.6 times, and 93% planned to increase privacy budgets over the next two years.
The IQWorks report puts indicative implementation ranges at $75K to $250K for organizations with 50 to 500 people, and $250K to $1M for organizations with 500 to 5,000 people. These are planning figures, not research findings.
IBM found that organizations that use AI and automation extensively across security operations saved $1.9M per breach and reduced the breach lifecycle by 80 days. Against India’s 263-day average for identifying and containing a breach, that is about a third of the timeline.
Where to start - November before May
Two dates are ahead, and the nearer one matters more than most teams realize.
13 November 2026
Consent Manager registration opens, Consent Manager obligations take effect, and the Board gains inquiry powers over registration breaches.
13 May 2027
The broader operational requirements kick in: notices, consent systems, security safeguards, breach response, retention, children’s protections, and Data Principal rights all become enforceable.
That may sound like plenty of time, but in practice it is not.
The IQWorks report estimates that a manually run privacy program can take 12 to 18 months to move from kickoff to audit-ready, usually involving a privacy team of 3 to 5 people alongside external consultants.
Against a May 2027 enforcement deadline, a company starting now is already working with a fairly tight implementation window.
The mistake I would avoid is trying to solve every DPDPA obligation independently.
Most of them depend on the same foundation.
Build the data inventory first
Almost every obligation in this article comes back to one question:
What personal data do you hold, why do you hold it, and where does it sit?
If you cannot answer that confidently, almost everything downstream becomes harder.
You cannot set retention periods properly if you do not know where copies of personal data exist.
You cannot respond efficiently to a section 11 access request if customer data is scattered across your CRM, support platform, internal databases, spreadsheets, analytics tools, and third-party processors.
You cannot cascade a correction under section 12(3) if you do not know which systems and vendors received the original data.
You also cannot scope privacy notices properly or determine whose information was affected during a breach.
This is why, in my experience, the data inventory should come before most other compliance work.
Teams that establish the inventory and data flows first make consent, rights requests, breach response, retention, and vendor management easier to operationalize.
Teams that leave it until later usually end up revisiting work because the policies and workflows they created were based on an incomplete view of their data.
Why spreadsheets become a problem
You can technically build this inventory manually.
For a smaller organization with only a few systems, that may even work initially.
The problem appears once the environment starts changing.
New SaaS tools are added. Teams create spreadsheets. Data gets exported into internal systems. Vendors receive copies. Marketing and analytics tools collect additional identifiers.
A spreadsheet-based RoPA is only accurate for as long as someone continuously updates it.
The moment that process becomes inconsistent, the inventory starts ageing.
And once the inventory is unreliable, it affects every workflow that depends on it.
That is the operational gap ComplyIQ is designed to reduce.

ComplyIQ acts as the record-and-response layer for the privacy program, particularly across four areas.
- RoPA and data lineage automation. Instead of maintaining the processing inventory manually, teams can keep records of processing activities and data flows continuously updated. IQWorks estimates up to 90% savings in time and cost compared with running the same process manually.
- Data Principal request management. Access, correction, erasure, and grievance requests can be routed to the right owners, tracked through completion, and closed within the required timelines.
- Breach tracking and investigation. Data lineage helps teams understand which systems, datasets, vendors, and Data Principals may be affected, making section 8(6) notification less dependent on a last-minute manual investigation.
- Audit trails and evidence. Actions taken across RoPA management, Data Principal requests, and breach response are recorded so the organization can show what happened, who handled it, and when. That matters when demonstrating compliance and when the Board considers factors under section 33(2)(e).
The other parts of the compliance stack sit around this operational layer.
Discovery and classification sit upstream in DiscoverIQ and ClassifyIQ, helping teams identify and understand the personal data they hold.
Consent collection and preference management sit in ConsentIQ.
ComplyIQ then becomes the system your privacy team uses to maintain the processing record, manage requests, coordinate responses, and preserve evidence.
The order I would follow
If I were starting a DPDPA compliance program today, I would not begin by rewriting every privacy policy or deploying a consent banner across every property.
I would start by mapping the data.
First, identify the personal data you process, where it lives, why you collect it, who can access it, how long you retain it, and which processors receive it.
Then build the RoPA and assign ownership for those processing activities.
From there, connect the workflows that depend on that inventory: consent, Data Principal requests, retention, breach response, vendor management, and audit evidence.
With the November 2026 Consent Manager milestone arriving first, the practical sequence is straightforward:
Map the data now. Establish ownership and workflows next. Then use the remaining months before May 2027 to test whether those workflows actually work.
Do not wait until enforcement to find out that a consent withdrawal never reached the CRM, a deletion request cannot be traced across processors, or your breach team cannot determine which individuals were affected.
The strongest DPDPA programs will not be the ones with the most documentation.
They will be the ones that can show, in practice, where personal data sits, what happened to it, who acted on it, and whether every required workflow can be completed on time.
Our verdict
29 ratings, from Customer Success Research.
Ready to automate your compliance?
See how IQWorks helps enterprises manage data protection at scale.
Request Demo