How the Schedule of Penalties Actually Gets Applied in Practice
The penalty amounts everyone quotes are ceilings, not fixed fines. Understanding how the Board is expected to calibrate within them matters more than memorising the numbers.
Ceilings, not tariffs
The Schedule to the DPDP Act sets maximum monetary penalties for defined categories of non-compliance, commonly reported as up to approximately 250 crore for failing to implement reasonable security safeguards under Section 8(5), up to roughly 200 crore for failing to notify a personal data breach under Section 8(6) or for non-compliance with children's data obligations under Section 9, up to about 150 crore for a Significant Data Fiduciary's failure to meet its additional obligations under Section 10, and a general ceiling of up to around 50 crore for other contraventions by a Data Fiduciary or Processor. A much smaller ceiling, reported at up to 10,000, applies to a Data Principal's breach of their own duties under Section 15.
It is important to read these as maximums the Board may impose after an inquiry, not as fixed fines that automatically attach to every violation. The Act directs the Board to have regard to factors such as the nature, gravity, and duration of the breach, the type and volume of personal data affected, whether the breach was repeated, and the mitigating steps taken by the fiduciary, in arriving at an actual penalty figure within the ceiling.
Why the same failure could attract very different penalties
Two organisations experiencing what looks like the same category of failure, say, a delayed breach notification, could see very different outcomes depending on how quickly they acted once the issue was discovered, whether they had documented safeguards that simply failed despite reasonable diligence, and whether the affected data involved children or a large volume of Data Principals. A single, contained incident handled transparently is likely to be treated differently from a pattern of neglect uncovered only through a complaint.
This calibration approach is broadly consistent with how many statutory penalty regimes work internationally, though the DPDP Act's fixed rupee ceilings, rather than a turnover-linked formula, mean the ceiling itself does not scale automatically with the size of the organisation involved.
Multiple contraventions and cumulative exposure
A single incident can potentially implicate more than one category in the Schedule, for instance a security lapse (Section 8(5)) that leads to a breach that is then not notified in time (Section 8(6)), and separately involves children's data (Section 9). How the Board would approach layering or combining penalties across categories arising from one underlying incident is not fully spelled out in the Act and is likely to become clearer only through actual Board decisions and possibly through the Rules.
Organisations should not assume the categories are mutually exclusive safety nets; a poorly handled incident touching several obligations at once could plausibly expose the organisation to scrutiny under multiple heads rather than just the single largest one.
Where to go next
The Timeline Explorer sets out which obligations, and therefore which penalty categories, become live at each stage of the Act's phased implementation. Pair that with the Readiness Assessment to see which of your current gaps map to the higher-ceiling categories, security safeguards and breach notification chief among them.