DPDP penalties explained — what is at stake for vendors
The DPDP Act 2023 imposes penalties of up to ₹250 crore. Here is how the penalty schedule works, what triggers enforcement, and why mid-size IT vendors face real financial exposure.
When compliance discussions come up in leadership meetings at mid-size IT firms, the penalty numbers from the DPDP Act 2023 are sometimes cited without context — and the result is either alarm or dismissal, neither of which leads to good decision-making. This post breaks down the actual penalty schedule, how the Data Protection Board adjudicates, what triggers enforcement, and what the realistic exposure looks like for a mid-size IT vendor.
If you are trying to understand whether signing a DPA is worth the legal cost, or whether DPDP compliance genuinely affects your deal pipeline, understanding the penalty framework is essential context. It also explains why your enterprise clients are pushing so hard on vendor compliance — they are trying to manage their own penalty exposure, and they are contractually attempting to pass that exposure to you.
The DPDP Act 2023 penalty schedule
The DPDP Act 2023 specifies penalties in Schedule 1, structured by category of violation. These are maximum penalties — the Data Protection Board determines the actual amount within the cap based on the facts of each case.
Up to ₹250 crore — Failure to implement security safeguards
Section 8(5) of the DPDP Act requires Data Fiduciaries to implement "appropriate technical and organisational measures" to prevent personal data breaches. Failure to do so — if it results in, or creates the conditions for, a personal data breach — carries a maximum penalty of ₹250 crore. This is the largest penalty in the schedule and applies to the most common type of enforcement scenario: a breach that results from inadequate security controls.
Up to ₹200 crore — Failure to notify a breach
Section 8(6) requires Data Fiduciaries to notify the Data Protection Board and affected data principals of a personal data breach "in such manner and within such period as may be prescribed." If a breach occurs and the Fiduciary does not notify as required — either because they did not detect it, delayed disclosure, or chose not to report — the penalty can reach ₹200 crore. The notification obligation applies even if the breach was caused by a vendor (Data Processor) — the Fiduciary cannot delegate this obligation by contract, though they can seek indemnification from the vendor.
Up to ₹10,000 — Frivolous complaints by data principals
The Act also includes a penalty for data principals (individuals) who file "frivolous or vexatious" complaints with the Data Protection Board. At ₹10,000, this is a very small amount — but its existence signals that the Board will have mechanisms for managing complaint volumes, which is relevant for estimating enforcement load.
Up to ₹50 crore — Violations of obligations for children's data
Section 9 imposes special obligations for processing personal data of children under 18 — including obtaining verifiable parental consent and not conducting behavioural monitoring of children. Violations carry a maximum penalty of ₹50 crore. For IT vendors who process consumer-facing applications, this is a relevant sub-category to understand.
Up to ₹150 crore — Breach of significant data fiduciary obligations
Significant Data Fiduciaries (SDFs) — a category the government will designate based on scale and sensitivity — face specific additional obligations including Data Protection Impact Assessments and periodic audits. Breaches of those SDF-specific obligations carry penalties up to ₹150 crore.
How the Data Protection Board adjudicates
The penalty schedule tells you the maximum. The adjudication process tells you how much exposure you actually face in practice.
The Data Protection Board of India is the enforcement body established under the DPDP Act. It is constituted by the central government and operates independently for adjudication purposes. The Board's process works as follows:
Complaint or suo motu notice: Enforcement begins either when a complaint is filed — by a data principal, a designated complainant body, or another government agency — or when the Board takes suo motu (on its own) notice of a reported breach or compliance failure. The Board will also be notified of breaches directly by Data Fiduciaries under the mandatory notification requirement.
Show-cause notice and opportunity to be heard: Before imposing any penalty, the Board must issue a show-cause notice to the accused entity and provide an opportunity to be heard. This is a quasi-judicial process — the Board is required to follow principles of natural justice, which means you can present your case, explain your controls, and demonstrate remediation steps taken.
Factors the Board considers in determining penalty quantum: The DPDP Act directs the Board to consider several factors when determining the penalty within the statutory cap: the nature, gravity, and duration of the non-compliance; the type of data involved and the number of data principals affected; whether the entity took steps to mitigate the impact; the repetitive nature of the breach (prior violations increase the penalty); and the entity's financial capacity. This is significant for mid-size vendors: a first-time breach with prompt notification, documented controls, and active remediation will be assessed very differently from a concealed, repeated, or wilful violation.
Appeal to the Appellate Tribunal: A penalty order from the Board can be appealed to the Appellate Tribunal for Information Technology (ATIT) constituted under the IT Act. This provides a further layer of review, though appeals require depositing a percentage of the penalty amount as security.
What actually triggers enforcement
Understanding the penalty schedule is less useful than understanding what triggers the Board's attention in the first place. Based on the structure of the DPDP Act and the experience of comparable frameworks globally, enforcement is likely to be triggered by:
Personal data breaches
A personal data breach that becomes publicly known — through a media report, a complaint from affected individuals, or a notification from the company itself — will almost certainly attract Board scrutiny. The Board will review whether the Fiduciary had adequate controls, whether it notified promptly, and whether it cooperated with the investigation. A breach that is self-reported quickly, with clear documentation of the controls in place and the remediation steps taken, is likely to receive significantly more lenient treatment than a breach that was concealed or discovered by others.
Complaints from data principals
Individual complaints from Indian citizens about failures to process erasure requests, respond to data access requests, or honour consent withdrawal are a direct trigger for Board attention. While individual complaints about small amounts of data are unlikely to attract large penalties, systemic complaints against a company — many individuals complaining about the same failure — can aggregate into a significant enforcement action.
Regulatory referrals
Sector regulators (RBI, IRDAI, SEBI, Ministry of Health) may refer data protection violations to the Board. This is particularly relevant for IT vendors in regulated sectors who are already subject to sector-specific audits. A finding in an RBI audit that a bank's IT vendor lacks adequate data protection controls could result in a referral to the Board that the vendor itself did not anticipate.
What mid-size vendors need to understand about their exposure
The DPDP Act does not distinguish between large corporations and mid-size vendors in its penalty schedule. A mid-size IT company with ₹50 crore in annual revenue faces the same maximum penalty as a large enterprise — ₹250 crore — for the same violation. The Board's discretion in determining quantum within that range is where scale matters, but even a fraction of the maximum penalty can be existentially significant for a mid-size company.
More practically, mid-size IT vendors face exposure in two directions. First, direct exposure for their own DPDP obligations — if they are Data Fiduciaries for their SaaS products, they carry all the Fiduciary obligations directly. Second, indirect exposure through contractual indemnification clauses in their DPAs with enterprise clients. If a breach in the vendor's systems triggers a penalty for the client, the client's DPA may require the vendor to indemnify the client for that penalty amount. This means the vendor is exposed to the client's penalty as well as any direct Board action against the vendor itself.
This is why the conversations happening in enterprise procurement around DPDP compliance are so financially significant — the indemnification clauses in new DPAs are, in effect, transferring penalty exposure from large enterprises to their smaller IT vendor supply chains.
Using the penalty framework to build your compliance case internally
The penalty schedule is useful not just for understanding external risk, but for building the internal business case for a DPDP compliance programme. When a CTO or CFO asks why they should spend ₹10–15 lakh on a DPDP compliance engagement, the answer is not abstract: it is the ratio of the compliance cost to the potential penalty exposure, adjusted by probability of enforcement.
Use the free DPDP Penalty Calculator to model the penalty exposure for your specific situation — based on the categories of personal data you handle, the scale of your processing, and the nature of any gaps in your current controls. It translates the statutory penalty schedule into a number relevant to your company, which is a far more persuasive input to a compliance budget discussion than a generic reference to "up to ₹250 crore."
Calculate your actual DPDP penalty exposure
The free DPDP Penalty Calculator models your specific risk based on the data you process, your current controls, and the penalty schedule under the DPDP Act 2023.
Calculate My Exposure — FreeFrequently Asked Questions
When will the Data Protection Board start imposing penalties?
The Data Protection Board will be constituted after the DPDP Rules are formally notified — a process expected to complete by end-2025 or early 2026, with enforcement practically beginning around 2026–2027. The government has indicated a phased approach with an initial focus on awareness and voluntary compliance. However, large breaches and wilful non-compliance are likely to be prioritised from the outset. Enterprise clients are not waiting for enforcement to begin — they are pushing vendor compliance requirements now.
Can a Data Processor (vendor) be penalised directly by the Data Protection Board?
The DPDP Act's direct penalty provisions apply primarily to Data Fiduciaries, who bear the primary legal obligations. Data Processors do not have direct statutory obligations to data principals under DPDP, so their direct penalty exposure to the Board is limited. However, vendors face significant indirect exposure through: contractual indemnification clauses in DPAs (if the vendor's breach causes a penalty for the Fiduciary client, the client may recover from the vendor); potential for the Board to investigate processing relationships and find the Fiduciary's insufficient vendor controls to be a Fiduciary violation; and, in cases of vendor negligence contributing to a breach, possible civil liability.
Does the DPDP Act have a penalty for not having a privacy policy?
There is no specific penalty for the absence of a privacy policy as such. The penalty exposure arises from the underlying obligations that a privacy policy documents — specifically, the obligation under Section 5 to provide a consent notice to data principals before collecting their personal data. Failure to provide the required consent notice falls under the general provision for breach of obligations, which carries penalties up to ₹250 crore in the most severe scenarios. In practice, the Board is likely to treat a documented, well-maintained consent notice and privacy policy as strong evidence of compliance, and their absence as an aggravating factor in any penalty determination.