DPDP Act Penalties and Fines: What Indian Companies Must Know
India's Digital Personal Data Protection (DPDP) Act, 2023 is now the most consequential data regulation for Indian businesses — and its penalty structure is designed to hurt. A single significant data breach can cost a company up to ₹250 crore. For startups and MSMEs, that is not a fine, it is an extinction event.
This guide breaks down every penalty slab, who it applies to, and exactly what your company must do to stay compliant — without paying a law firm's retainer to figure it out.
DPDP Act Penalty Structure (All Slabs)
The DPDP Act specifies monetary penalties under Section 33, determined by the Data Protection Board of India after an inquiry. The ceilings are:
- ₹250 crore — for failure to take reasonable security safeguards to prevent personal data breaches
- ₹200 crore — for failure to notify the Board and affected Data Principals of a breach
- ₹150 crore — for failure to fulfil additional obligations for significant data fiduciaries
- ₹50 crore — for processing children's data without verifiable parental consent
- ₹25 crore — for violation of consent, notice, or purpose-limitation obligations
- ₹10 crore — for non-compliance with Data Principal rights (access, correction, erasure)
The Board is not limited to these categories — it can impose up to these amounts for related breaches, and repeat offenders face higher multipliers. Crucially, penalties are determined by an inquiry process, so your compliance documentation and breach response directly influence the final number.
Who Must Comply? Data Fiduciaries in India
Under the DPDP Act, compliance applies to every Data Fiduciary — any entity that determines the purpose and means of processing digital personal data. This includes:
- Startups and SaaS companies collecting user emails, phone numbers, or payment data
- E-commerce and D2C brands processing customer orders
- Hospitals, clinics, and ed-tech platforms handling sensitive personal data
- Employers processing employee records
- Law firms and legal tech platforms (including AI legal tools like Lexacore) handling client documents
There is no MSME exemption from the obligations — only consideration of size during penalty determination. If you collect an Indian resident's phone number for OTP login, the DPDP Act applies to you.
Core Obligations: The Consent Rule
The DPDP Act's foundation is consent. Before processing any personal data, you must:
- Obtain explicit consent — clear, affirmative, informed, specific, and freely given. Pre-ticked boxes are illegal.
- Provide a notice — in plain language, stating what data is collected, why, and how it will be used.
- Limit purpose — data can only be used for the purpose stated in the consent notice.
- Honour withdrawal — users can withdraw consent, and you must stop processing and delete data within a reasonable period.
- Facilitate rights — access, correction, erasure, grievance redressal, and nomination mechanisms.
Consent management is where most Indian companies currently fail. A privacy policy page alone is not compliance — you need recorded, retrievable consent for every data subject, with timestamps and purpose mapping.
Data Breach Notification: The 72-Hour Reality
India has not adopted the EU's 72-hour rule verbatim, but the obligation is similar in effect: the moment a breach is detected, the Data Fiduciary must notify the Data Protection Board and every affected Data Principal. Failure to notify attracts penalties up to ₹200 crore — even if the breach itself was minor.
Practical steps: maintain an incident response runbook, log access to personal data, and run quarterly breach drills so your team knows who informs whom, and how.
How Lexacore Helps You Stay DPDP-Compliant
Lexacore was built DPDP-first. Our ComplianceRadar monitors DPDP Act amendments and notification obligations in real time, LexCounsel AI answers DPDP compliance questions with verified statutory citations, and the Legal Vault stores sensitive documents with zero-knowledge, 256-bit AES encryption — so client data is unreadable even to us. See our complete DPDP guide and compliance statement.
DPDP Compliance Checklist for 2026
- Map all personal data you collect, process, and store
- Deploy a consent capture and withdrawal mechanism with audit logs
- Draft plain-language privacy notices (English + Hindi)
- Implement breach detection and notification runbooks
- Review vendor and contract DPDP clauses — see our contract review guide
- Appoint a Data Protection Officer if you are a significant data fiduciary
- Run an annual compliance audit with tools like ComplianceRadar
The DPDP Act is not a one-time project. Rules evolve, penalties scale, and enforcement is beginning. Companies that treat it as a continuous compliance function — not a legal document on a shelf — are the ones that survive the first wave of inquiries.
Want a live view of your compliance exposure? Start with the NDA generator, review a contract with ContractIQ, or try the interactive demo — no signup needed.