DPDP penalties, mapped to the control that prevents each one
The Schedule to the DPDP Act sets penalties up to ₹250 crore. Each band points at a specific duty, and each duty has a specific control. A working map from fine to fix.
By Promiz · Published · 5 min read · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice
What are the penalty bands?
The Schedule to the DPDP Act, 2023 sets maximum penalties by breach type: up to ₹250 crore for failing to take reasonable security safeguards (Section 8(5)); up to ₹200 crore for failing to notify a personal data breach (Section 8(6)) and for breaching the duties around children’s data (Section 9); and up to ₹50 crore for most other obligations, including notice, consent, withdrawal, erasure and rights requests.
The Board decides the amount within those ceilings, and the Act lists factors such as the nature and duration of the breach and the steps taken to mitigate it. Being able to show the control existed, and ran, is part of that mitigation.
Which control answers the ₹250 crore band?
Security safeguards under Section 8(5) and Rule 6 cover encryption, masking or tokenisation, access control, and logs of who accessed personal data kept for at least one year. For consent data specifically, the control is encryption at rest, one-way identifiers, masked display with logged reveals, and a tamper-evident audit trail of every administrative action.
Your own systems still need their own safeguards. A consent platform reduces the surface area - it does not cover the CRM or the data warehouse.
Which controls answer the ₹200 crore band?
Breach notification (Section 8(6), Rule 7) requires telling the Board and affected people without delay, and sending a detailed report within 72 hours. The control is a breach log that starts the clock the moment a breach is recorded, tracks each notice, and assembles the structured report from what was logged.
Children’s data (Section 9, Rule 10) requires verifiable consent from a parent or guardian and bars tracking and targeted advertising. The control is a guardian check through DigiLocker recorded on the consent, with child-restriction flags applied per purpose and the Fourth Schedule exemptions (Rule 12) recorded for the organisation.
Which controls answer the ₹50 crore band?
Everything else: an itemised notice in a language the person reads (Section 5, Rule 3); free, specific consent per purpose (Section 6); withdrawal as easy as consent and processing that stops afterwards (Sections 6(4) and 6(6)); erasure when the purpose ends (Section 8(7), Rule 8); and the five rights with their deadlines (Sections 11–14, Rule 14).
These are the duties most likely to be tested first, because they are visible to every customer. The controls are versioned notices with snapshots, one choice per purpose, stop-processing tasks, retention clocks with confirmed deletion, and a rights queue with a clock on each request.