The DPDP Act 2023 fines companies that mishandle personal data. Fines run from Rs 10,000 to Rs 250 crore for each mistake. The Data Protection Board of India decides the penalty, and fines add up, so one breach can cross Rs 250 crore.
The Act sets the rules for how companies handle personal data in India, like names, phone numbers, Aadhaar, and bank details. If your business collects any personal data, non-compliance is now a real cost. Here is what you need to know.
Does Every Business Need to Worry About DPDP Penalties?
Yes, many people think the DPDP Act only affects large technology companies. In reality, any organization that processes digital personal data may have responsibilities under the law.
This includes:
- Startups
- E-commerce businesses
- Banks and NBFCs
- Healthcare providers
- Educational institutions
- HR platforms
- SaaS companies
- Insurance companies
- Fintech companies
- Enterprises of all sizes
The amount of personal data you process and the risks involved may affect your compliance obligations, but no business should ignore the Act.

What are the penalties for Non Compliance Under DPDP Act?
The DPDP Act does not have a fixed fine for every violation. Instead, the Data Protection Board of India can impose penalties depending on the nature and seriousness of the violation.
DPDP ACT Penalty List
| Violation | Maximum Penalty |
| Failure to implement reasonable security safeguards leading to a personal data breach | Up to ₹250 crore |
| Failure to notify the Data Protection Board and affected individuals about a reportable personal data breach | Up to ₹200 crore |
| Failure to fulfill obligations related to children’s personal data | Up to ₹200 crore |
| Failure to comply with additional obligations applicable to Significant Data Fiduciaries | Up to ₹150 crore |
| Failure to follow the Data Protection Board’s directions | Up to ₹50 crore |
| Failure to meet other obligations under the Act | Up to ₹50 crore |
These are the maximum penalties. The actual amount depends on the facts of each case.
Simplify Your Compliance & Stay Audit-Ready
Help your team manage controls, risks, and audits with ease
What Can Lead to a DPDP Act Penalty?
These are the key factors that may bring penalties:
Weak Security Measures
If customer data is exposed because the company failed to implement reasonable security safeguards, the business may face one of the highest penalties under the Act.
Examples include:
- Weak password policies
- Unencrypted databases
- Lack of access controls
- Ignoring known security vulnerabilities
- Poor cloud security
Not Reporting a Data Breach
If a reportable personal data breach occurs, businesses must notify the authorities and affected individuals as required. Trying to hide a breach or delaying notification can increase regulatory action.
Collecting More Data Than Necessary
Businesses should collect only the information needed for a specific purpose. For example, asking for identity documents when only an email address is required may create unnecessary compliance risk.
Using Personal Data Without Proper Consent
Consent is a key part of the DPDP Act in many situations.
Businesses should clearly explain:
- Why data is being collected
- How it will be used
- How long it will be retained
- How individuals can withdraw consent
Using personal data beyond the stated purpose may lead to regulatory scrutiny.
Ignoring User Requests
Individuals have rights under the DPDP Act, including requesting corrections, updates, or erasure of personal data in certain circumstances. Ignoring these requests without a valid reason may amount to non-compliance.
How Does the Government Decide the Penalty Amount?
The DPI Board may consider factors such as:
- The seriousness of the violation
- The number of people affected
- Whether the breach could have been prevented
- Whether the business cooperated during the investigation
- Whether the company repeatedly violated the law
- Steps taken to reduce harm after the incident
This means two businesses committing similar violations may receive different penalties depending on the circumstances.

How to Reduce Your DPDP Penalty Risk?
You have time until May 2027. But the work takes months. So start now.
- Know your data: list what personal data you collect, why, and who you share it with.
- Get consent right: ask users clearly and save the proof. A consent manager makes this simple.
- Be ready for leaks: have a plan to tell the Board and your users fast.
- Lock down security: use encryption, access limits, and alerts. This is your shield against the Rs 250 crore fine.
- Check your partners: if a vendor leaks your data, you pay. So put the rules in their contract too.
Conclusion
The DPDP Act is here, and the fines are real. But you do not need to panic. Start early, know what data you hold, take consent the right way, and keep your security tight. Small steps now save you from big fines later. You should make and follow the DPDP Compliance checklist to avoid fines. The deadline is May 2027, so there is time to get ready. Do not wait for a breach to take it seriously. A dedicated compliance platform like SureGrid makes staying ready much easier.
FAQs
Ques: What is the maximum penalty for non-compliance under the DPDP Act 5 crore 250 crore, 100 crore, 50 crore?
Ans: Rs 250 crore for one mistake if weak security causes a data leak. Many mistakes in one check can add up to even more.
Ques: Do vendors get fined under the DPDP Act?
Ans: No, the Board fines your company, not your vendor. But if your vendor leaks the data, you still pay. So choose vendors with care.
Ques: What is the penalty for Section 15 of the DPDP Act?
Ans: Section 15 of the DPDP Act covers the duties of a Data Principal. Breaking these duties, such as filing false complaints or submitting fake documents, carries a penalty of up to Rs 10,000.
Ques: When does DPDP enforcement start?
Ans: The rules came out in November 2025. The main duties apply from 14 May 2027. But the Board is already active, so people can complain now.
Ques: Can you appeal a DPDP fine?
Ans: Yes, you get 60 days to appeal to the tribunal. After that, you can go up to the Supreme Court.