Under India's DPDP Act 2023, the Data Protection Board can levy penalties up to ₹250 Crore per violation for inadequate security safeguards, ₹200 Crore for breach-notification and children's-data failures, and ₹150 Crore for not honouring Data Principal rights. Penalties are per-incident and can accumulate — making prevention far cheaper than cure.
The penalty tiers
The highest tier — up to ₹250 Crore — applies to inadequate security safeguards. Breach-notification and children's-data failures sit at up to ₹200 Crore, and failing Data Principal rights at up to ₹150 Crore.
Per-incident and cumulative
Because penalties apply per violation, a single breach affecting many Data Principals — or several distinct lapses — can stack into very large liability.
How to reduce exposure
Strong security, valid consent, accurate RoPA, tested breach response and documented assessments reduce both the likelihood and the assessed severity of violations.
FAQ
Up to ₹250 Crore per violation for inadequate security safeguards, with other tiers at ₹200 Crore and ₹150 Crore; penalties are per-incident and can accumulate.