The DPDP Act
The Schedule
Financial Penalties
Penalty ceilings the Data Protection Board of India may impose per instance of significant non-compliance, as set out in the Schedule to the Act.
| Non-compliance | Provision | Maximum Penalty |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | Section 8(5) | Up to ₹250 crore |
| Failure to notify the Board and affected Data Principals of a breach | Section 8(6) | Up to ₹200 crore |
| Non-compliance with additional obligations regarding children's data | Section 9 | Up to ₹200 crore |
| Non-compliance with additional obligations of a Significant Data Fiduciary | Section 10 | Up to ₹150 crore |
| Breach of duties by a Data Principal (e.g. false information, frivolous complaints) | Section 15 | Up to ₹10,000 |
| Non-compliance with any other provision of the Act or Rules | General | Up to ₹50 crore |
Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact figures against the official Gazette of India before relying on this for legal or compliance decisions.