All articles
Foundations

DPDP penalties explained

Smoketrees Digital LLP·12 Jun 2026·5 min read

The DPDP Act sets financial penalties for breaches of its obligations. The highest is up to INR 250 crore for failing to maintain reasonable security safeguards. Failure to report a breach can draw up to INR 200 crore. Penalties are imposed by the Data Protection Board of India after inquiry, and they scale with the nature and gravity of the breach.

The penalty schedule

  • Up to INR 250 crore for inadequate security safeguards. This is the duty to protect personal data with access controls, encryption, logging, and verified backups.
  • Up to INR 200 crore for failure to notify a personal data breach to the Board and affected users.
  • Up to INR 200 crore for breaches involving children's data, where the Act is stricter.
  • Up to INR 150 crore for a Significant Data Fiduciary that breaches its additional obligations.

Two points that matter more than the numbers

First, a personal data breach under the Act is broader than a hack. It covers any compromise of confidentiality, integrity, or availability, which includes leaks, tampering, accidental deletion, ransomware, and loss of access. Second, the penalty for not reporting a breach is separate from the breach itself. You can be penalised for the silence as much as the incident.

"The penalties are not the reason to act. They are the reason not to wait."

Next step

Ready to scope the work?

Book a free 30-minute call. We will map your gaps and tell you exactly what needs building.

Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.