Almost every DPDP explainer leads with "penalties of up to ₹250 crore" as if it's a flat ceiling for any violation. It isn't. It's one line in a seven-tier schedule, and it's tied to one specific failure — not the one most people assume.
DPDP §33 doesn't set a single number. It says that if the Data Protection Board concludes, after an inquiry and a hearing, that a breach is significant, it "may impose such monetary penalty specified in the Schedule" — and the Schedule is where every actual figure lives, each one attached to a specific kind of breach, not a general "violated the Act" catch-all.
Seven line items. The ₹250 crore ceiling is the first one — and it's specifically for failing to take reasonable security safeguards, not for a consent or notice defect.
| Breach | Section | Penalty may extend to |
|---|---|---|
| Failing to take reasonable security safeguards to prevent a personal data breach | §8(5) | ₹250 crore |
| Failing to notify the Board or affected Data Principals of a personal data breach | §8(6) | ₹200 crore |
| Breaching the additional obligations for children's data | §9 | ₹200 crore |
| Breaching the additional obligations of a Significant Data Fiduciary | §10 | ₹150 crore |
| Breach of any other provision of the Act or Rules | — | ₹50 crore |
| Breach of a voluntary undertaking accepted by the Board | §32 | Up to the original proceeding's cap |
| A Data Principal breaching their own duties | §15 | ₹10,000 |
Most of the Schedule is about what a Data Fiduciary owes. One line is about what a Data Principal owes — furnishing genuine information and not filing frivolous complaints, among other duties under §15 — and it's priced four orders of magnitude below anything else on the list. The Act clearly isn't treating those two kinds of breach as remotely comparable, which is worth knowing if you've only ever heard the crore-scale numbers.
Every figure in the Schedule is a maximum — "may extend to," not "is." §33(2) requires the Board to weigh seven things before landing on an actual number: the nature, gravity and duration of the breach; the type and sensitivity of the data involved; whether it was repeated; whether the fiduciary gained or avoided a loss from it; whether they acted to mitigate it, and how quickly; whether the penalty is actually proportionate to deterring the breach, rather than just maximal; and the likely impact of the penalty on the fiduciary itself.
A first-time, promptly-disclosed, quickly-mitigated incident and a repeated, concealed one sit on the same Schedule line and are not supposed to land on the same number.
Not to the Board, and not to whoever was affected. §34 sends every rupee the Board collects in penalties to the Consolidated Fund of India. There's no separate compensation mechanism for a Data Principal built into this section — the penalty is a deterrent against the fiduciary, not a payout to the person whose data was mishandled.
This covers the penalty Schedule specifically — it doesn't cover how an inquiry under the Act actually proceeds, what counts as "significant," or the appeal process. The Act and Schedule are the actual source; this is a map to them, not a substitute for reading them, and it isn't legal advice.