Skip to content
DPDP Insurance IndiaNoida · DPDP · Cyber · Privacy
Home/ Insights/Regulation
Regulation

₹250 crore, per violation: how DPDP penalties actually work

Published 12 August 2026 · 7 min read · DPDP Insurance India

Every conference slide about India's data protection law shows the same figure: ₹250 crore. It is accurate and almost useless on its own, because it describes a ceiling for one specific failure, not a tariff. If you are trying to work out what your business is actually exposed to, the useful reading is the structure underneath the headline.

What the Schedule actually says

The Digital Personal Data Protection Act, 2023 sets out its penalties in a Schedule, with a separate maximum for each category of failure. The five that matter to most businesses:

FailureMaximum penalty
Failure to take reasonable security safeguards to prevent a personal data breachUp to ₹250 crore
Failure to notify the Board or affected data principals of a breachUp to ₹200 crore
Failure to meet additional obligations relating to children's dataUp to ₹200 crore
Failure to meet the additional duties of a Significant Data FiduciaryUp to ₹150 crore
Breach of any other provision of the Act or RulesUp to ₹50 crore

Read the first row again. The largest penalty in the Act is not for the breach itself. It is for not having built reasonable safeguards in the first place. That is a judgement about your controls on the day before the incident, which is why underwriters ask about backups and MFA rather than about your firewall brand.

Why penalties stack

The maximums are stated per violation, and one incident routinely produces more than one violation. A ransomware event at a company with weak access controls that then misses the notification window has crossed two heads at once: safeguards and notification. If children's data was in the affected set, that is a third.

The practical exposure is not ₹250 crore. It is the sum of several heads, moderated heavily by what the Board thinks of your conduct.

How the Board decides the number

The Data Protection Board of India is a digital-first body: complaints are filed online, proceedings run online, and appeals go to the Telecom Disputes Settlement and Appellate Tribunal. When it fixes a penalty it weighs factors including the nature and gravity of the breach, the type of personal data involved, how many people were affected, whether the failure was repetitive, whether you gained anything from it, and what you did to mitigate once you knew.

That last factor is the one you can still influence after an incident, and it is the one most businesses handle badly under pressure. A company that notified quickly, retained forensics, told affected individuals plainly what to do and fixed the underlying control is arguing from a very different position than one that waited three weeks and issued a press release.

The dates that matter

  • 13 November 2025 — the DPDP Rules were notified. The Board, its procedures and its digital functioning took effect immediately.
  • November 2026 — the consent manager provisions came into force, one year after notification.
  • 13 May 2027 — eighteen months after notification, the substantive obligations apply in full: notices, security safeguards, breach reporting, erasure, data principal contact details and Significant Data Fiduciary duties.

Eighteen months sounds generous until you price the work. A data inventory across a mid-sized company takes a quarter on its own, and rewriting processor contracts takes longer, because it depends on other people's legal teams.

What insurance can and cannot fund

This is where the market gets loose with language, so be precise about three buckets.

  • Defence and representation costs. Squarely insurable, and the core of what a well-written regulatory section delivers. If the Board opens an inquiry, someone has to answer it, and privacy counsel is not cheap.
  • Civil regulatory penalties. Insurable to the extent Indian law and the specific wording permit. Wordings differ materially here. Read the definition of "penalty" and any carve-out for "fines and penalties uninsurable at law" before you rely on it.
  • Criminal fines. Not insurable by anyone, anywhere in India. If a broker implies otherwise, ask them to show you the clause.

Alongside those sits the operational cost of compliance failure, which is where most of the money actually goes: forensic work to establish what personal data was affected, drafting and issuing notifications, and running the support load that follows. Those are ordinary insured expenses under a decent DPDP section, and they arrive long before any penalty is assessed.

What to do in the next quarter

  1. Build the data inventory. You cannot evidence safeguards over data you cannot list.
  2. Fix the two controls that carry the most weight with both the Board and underwriters: enforced MFA everywhere, and backups that an attacker cannot delete.
  3. Write the notification runbook now, while nobody is shouting. Who decides it is reportable, who drafts, who signs, who staffs the inbox.
  4. Pull your processor contracts and check whether security and breach-notification obligations actually pass down.
  5. Then price the residual risk. That is the part insurance is for.

Questions people ask

Is the ₹250 crore penalty per company or per incident?

It is a maximum per violation. A single incident can produce several violations, and the Board fixes each amount after weighing the gravity of the breach, the number of people affected, your compliance history and your remediation.

Can a startup be penalised under the DPDP Act?

Yes. There is no revenue or size threshold for the core obligations. Only the Significant Data Fiduciary tier adds extra duties, and that classification is notified by the government based on factors including data volume and sensitivity.

Want this applied to your business? Send us your record count and your largest customer contract. We will come back with a sized limit and a market quote. Call +91 63070 73633 or use the enquiry form.

Keep reading

More insights

WhatsApp us Call +91 63070 73633