Section 33 · Schedule
DPDP Penalties and Enforcement
Section 33 empowers the Data Protection Board to impose monetary penalties specified in the Schedule where it determines that a breach is significant, after giving the person an opportunity of being heard. Amounts in the Schedule are maxima (“may extend to…”), not automatic fines.
What Section 33 and the Schedule say
Where the Board determines that a non-compliance is significant, it may impose a monetary penalty as specified in the Schedule after giving the person an opportunity of being heard. Section 33(2) sets factors the Board must consider — such as the nature, gravity and duration of the breach, type and nature of personal data affected, whether the breach is repetitive, whether gain or loss was realised, whether mitigation steps were taken, and the proportionality and likely impact of the penalty — among other factors stated in the Act.
The Schedule lists categories of non-compliance with maximum penalties that may extend to the amounts below. Exact liability is fact-specific and determined by the Board after inquiry. This table is educational, not a tariff that organisations “pay by default.”
| Breach category (Schedule) | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards (Section 8(5)) | May extend to ₹250 crore |
| Failure to give notice of a personal data breach (Section 8(6)) | May extend to ₹200 crore |
| Additional obligations relating to children (Section 9) | May extend to ₹200 crore |
| Additional obligations of Significant Data Fiduciary (Section 10) | May extend to ₹150 crore |
| Duties of Data Principal (Section 15) | May extend to ₹10,000 |
| Any other provision of the Act or Rules | May extend to ₹50 crore |
What it means in practice
Use the Schedule to prioritise risk discussions — especially security safeguards, breach intimation, children’s obligations and SDF duties where designated — not as marketing scare copy. Boards and executives should fund governance, security and incident readiness because those are statutory duties, not because a vendor promises to “prevent penalties.”
Document mitigation, training and response capability; Section 33(2) factors make those facts relevant if the Board ever assesses significance and quantum. Align programmes with commencement dates so preparation matches enforceable obligations.
Penalties are an enforcement tool, not a marketing message. ConsentifyAI does not claim to prevent DPDP penalties. Organisations should build appropriate governance and seek qualified advice for their facts. For institutional context, see the Data Protection Board of India.
Common mistakes
- Reading Schedule maxima as mandatory fixed fines for every non-compliance.
- Treating penalty headlines as a substitute for reading the underlying duties (for example Rule 6 security or Rule 7 intimation).
- Claiming that any software product guarantees avoidance of Board penalties.
Official source
ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.
Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.