₹250 Crore Penalties Under DPDPA: What Triggers Them and How to Avoid Them

    ₹250 crore. Per violation. The DPDPA's penalty schedule is not a deterrent buried in legal fine print — it is an existential financial risk for any business that handles Indian customer data carelessly.

    OneConsentBlog
    6 min read
    Saturday, 20 June 2026
    ₹250 crore penalties under DPDPA explained, including key compliance triggers and how Indian businesses can reduce penalty risk.

    This Is Not a Compliance Formality

    Let's be direct about what ₹250 crore actually means for most Indian businesses.

    For a mid-sized company with a few hundred crore in annual revenue, a single maximum penalty under the DPDPA isn't a regulatory setback. It's a company-ending event. And unlike some regulatory frameworks that impose annual caps or aggregate limits, the DPDPA's Schedule prescribes per-incident maximums — assessed by the Data Protection Board of India following investigation and adjudication. One significant breach, one systemic failure, one category of repeated non-compliance.

    That's all it takes.

    The DPDPA introduces penalty amounts that are significant enough to move data protection from a legal discussion into a boardroom priority. That's not hyperbole — it's the considered design of legislators who watched GDPR's relatively toothless early enforcement and deliberately chose a different path.

    What the Penalty Schedule Actually Says

    The Act's Schedule maps specific violations to specific penalty ceilings. These are maximums, not guaranteed outcomes, but they define the outer boundary of your exposure:

    1. Failure to implement security safeguards to prevent data breaches: Up to ₹250 crore

    2. Failure to notify the Data Protection Board and affected individuals of a breach: Up to ₹200 crore

    3. Failure to comply with children's data obligations: Up to ₹200 crore

    4. Breach of Significant Data Fiduciary obligations: Up to ₹150 crore

    5. Breach of duties by a Data Principal (filing false complaints): Up to ₹10,000

    Read that list carefully. The top three violations — security failure, non-notification, and children's data, collectively cover scenarios that apply to virtually every consumer-facing business operating in India. This isn't a niche compliance risk. It's core operational exposure.

    One more thing the schedule makes clear: a data breach doesn't generate one penalty. Inadequate security is one violation. Failing to notify is a second, separate violation. A single incident can trigger multiple penalty proceedings simultaneously.

    What the Board Actually Looks At

    The Data Protection Board doesn't automatically impose maximum penalties. What it considers in assessment is worth understanding, because it tells you exactly where your compliance investment needs to go.

    The Board weighs the gravity and nature of non-compliance, how many Data Principals were affected, the sensitivity of the personal data involved, whether the violation was a one-time failure or a systemic pattern, what steps the organisation took to mitigate harm after discovering the issue, and whether the organisation cooperated with the investigation or obstructed it.

    That last factor matters more than most compliance teams realise. Organisations that can demonstrate a functioning compliance programme — even an imperfect one — consistently receive more favourable treatment than those who show up to an investigation with nothing but excuses. The Board is looking for good faith effort, and the evidence of that effort is your audit trail.

    The Five Scenarios Where Exposure Is Highest

    Not all violations carry equal real-world risk. Based on the penalty schedule and the types of data practices most common in Indian businesses, five scenarios stand out.

    1. A data breach from inadequate security. This is the double-penalty scenario — inadequate safeguards plus failure to notify can stack into ₹450 crore of combined maximum exposure from a single incident. Companies that haven't invested in basic access controls, encryption, or breach detection are sitting on enormous unhedged risk.

    2. Marketing campaigns running on non-compliant consent. Millions of Indian businesses have been collecting customer data and running campaigns for years using consent mechanisms that don't meet DPDPA's standard — no per-purpose granularity, bundled opt-ins, pre-ticked boxes. Every campaign sent to those contacts is a potential violation.

    3. Collecting children's data without verification. Section 9 is unambiguous. If your platform can be accessed by anyone under 18 — even if children aren't your intended audience — you need verifiable parental consent before collecting their data, and you cannot track or profile them. Many platforms have not even begun thinking about this.

    4. Ignoring withdrawal and erasure requests. When a Data Principal withdraws consent or requests deletion, processing must stop and data must be deleted unless a legal retention obligation exists. Systems that can't execute this in real time are creating ongoing violations with every day that passes after the request.

    5. No functioning grievance mechanism. Appointing a Grievance Officer isn't a checkbox — it requires a named individual with published contact details, an intake mechanism, a 48-hour acknowledgement process, and a documented resolution workflow. Many companies have none of this. Every unresolved complaint is a potential Board escalation.

    How the Board's Enforcement Process Works

    The Data Protection Board has real investigatory teeth. It can summon witnesses, require production of documents and electronic records, conduct hearings digitally, and engage independent technical experts to assess your systems.

    Critically — and this is the part that keeps CIOs up at night — the Board can direct organisations to stop processing data entirely while an investigation is ongoing. For a data-driven business, a processing suspension is often more damaging than the eventual fine. Imagine a loyalty programme, a lending platform, or a marketing automation business being told it cannot process customer data while the Board investigates a complaint. The operational damage compounds daily.

    Appeals from Board orders go to the Appellate Tribunal, whose orders are executable as civil court decrees. This is a serious legal mechanism, not an administrative body that can be waited out.

    Where to Focus Your Risk Reduction

    The good news is that the Board's own assessment criteria essentially tell you what to build. Organisations that can demonstrate security safeguards, compliant consent infrastructure, functioning breach response procedures, and cooperative documentation will face materially lower penalty exposure than those that can't.

    Practically, that means: implement per-purpose consent management before a violation occurs, not after. Maintain tamper-proof, append-only audit logs that can show the Board exactly what consent was obtained, when, and under what Notice version. Build breach notification workflows with tested timelines — know, right now, who gets notified first internally, what the Board notification template looks like, and how affected individuals will be reached. And when the Board does come — cooperate. Document everything. The posture of an organisation that takes compliance seriously is itself a mitigating factor in penalty assessment.

    The Math Is Not Complicated

    The DPDPA's penalty structure was deliberately designed to make non-compliance more expensive than compliance. For most businesses, building proper consent management infrastructure, security safeguards, and breach response capability costs a small fraction of the maximum exposure from a single significant violation.

    The question isn't whether your organisation can afford to invest in compliance. It's whether it can absorb the consequences of not doing so. Because the Data Protection Board is operational, enforcement is coming, and the penalty schedule is exactly as serious as it reads.

    OneConsent gives you the consent audit trail, real-time enforcement infrastructure, and documented compliance evidence your legal team needs to demonstrate DPDPA compliance before a violation occurs, not after.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack