DPDP Glossary

Penalty

A monetary penalty the Board may impose under Section 33 and the Schedule where it determines a breach is significant.

Section 33; Schedule

What it means

Section 33 empowers the Board to impose monetary penalties referenced in the Schedule where it determines that a breach is significant, having regard to factors the Act sets out. Penalties are Board outcomes after inquiry — not automatic fines triggered by a vendor dashboard. Amounts and heads live in the Schedule to the Act.

Worked example

A headline “₹250 crore fine” without tying it to the Schedule entry and Board process misleads stakeholders. Programme planning should read the Schedule categories against real failure modes (security, children’s provisions, and so on) rather than quoting a single maximum as if it applies to every mistake.

In practice

Use the Schedule for risk communication with leadership; use operational controls to prevent the underlying breaches. For narrative and schedule orientation, see the Penalties topic page.

Penalties under DPDP →

Source

Section 33; Schedule · Official text (PDF)

Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.

Further reading

← Back to glossary