The Schedule, monetary penalties

What non-compliance costs

The Act is passed and phasing in through May 2027 — the businesses most at risk are the ones who assume it doesn't apply to them.

Get a free compliance review

FREE · 30-MIN CALL · NO OBLIGATION

SCHEDULE — PENALTIES4 of the Act's liability entries
Failing to take reasonable security safeguards against a breachSCHEDULE — MAX PENALTY₹250 crore
Ignoring a data-principal's deletion or grievance request§ 13 — GRIEVANCE REDRESSALper instance
Mishandling a child's personal dataFOURTH SCHEDULE — CHILDREN'S DATAper instance
Not reporting a breach in timeRULE 7 — BREACHper instance
Tax forms and a calculator on a desk
THE SCHEDULE IS PER-INSTANCE. EVERY UNANSWERED REQUEST COUNTS
Per instance, not per year

The cap is per breach, not per business

₹250 crore is the maximum penalty, for failing to take reasonable safeguards against a breach. Other failures carry their own penalties, per instance.

SCHEDULE — max penalty for a security-safeguards failure: ₹250 croreCERT-IN DIR. 20(3) — cyber-incident report window: 6 hoursDPDP RULE 7(2) — breach report to the DPBI: 72 hoursDPDP § 6(6) — consent withdrawal, processing stops: without delay
RULE 7 — BREACHClocks that start without you

A breach, an unsubscribe, a deletion request: each starts a statutory deadline the instant it happens. "We didn't realise" is not a defence.

§ 8 — FIDUCIARY DUTIESContinuing exposure

Your CRM, your payment gateway, your mailing tool: each is a Processor. When a customer asks to be deleted, you're responsible for them too. A leaked spreadsheet or a compromised login can carry a CERT-In reporting window as short as 6h, running from the moment you became aware, not once you've finished investigating. DPDP's own notice to the Board runs on a separate clock: 72h to the Board.

Data-center server racks

SECURITY SAFEGUARDS — §8(5) — WHERE THE LARGEST PENALTY LIVES

Pramaan — breach obligations, clocked
FIG. — BREACH OBLIGATIONS, CLOCKED
Pramaan

See where you stand.

Find out, with no obligation, where your business stands under DPDP, and what it would take to stay compliant. A short call with our team.

  • A plain-language read on your actual exposure
  • The specific obligations that apply to your business
  • No jargon, no pressure, just a clear picture

We reply within one business day

Book your review

We'll get back to you within one business day.

By submitting you agree to be contacted about your review. We don't share your details.