DPDP Penalties: What Non-Compliance Actually Costs
DPDP penalties can reach up to 250 crore rupees for the most serious violations, security safeguard failures, and are assessed per instance, not capped per company per year.
DPDP's penalty structure is tiered by violation type, with the most severe, failure to implement reasonable security safeguards leading to a data breach, carrying penalties up to ₹250 crore per instance. Other violations (failure to notify a breach, non-compliance with children's data provisions, failure to fulfill data principal rights requests) carry their own, generally lower, but still material penalty ranges.
Critically, these are assessed by India's Data Protection Board on a per-instance basis, not as an annual cap, meaning a company with recurring or systemic non-compliance issues faces cumulative exposure, not a single ceiling. The Board also has discretion to consider the nature and severity of the breach, which means demonstrable good-faith compliance efforts genuinely matter in how a penalty is assessed.
The practical implication is that partial or superficial compliance, a privacy notice that technically exists but consent flows that don't actually capture valid consent, doesn't meaningfully reduce risk, the security safeguards and consent mechanics need to actually work, not just be documented as existing.