Digital Personal Data Protection Act, 2023
THE SCHEDULE
Penalties
[See section 33 (1)]
| Sl. No. | Breach of Provisions | Penalty |
|---|---|---|
| (1) | Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8. | May extend to two hundred and fifty crore rupees. |
| (2) | Breach in observing the obligation to give notice of a personal data breach under sub-section (6) of section 8. | May extend to two hundred crore rupees. |
| (3) | Breach in observing additional obligations in relation to children under section 9. | May extend to two hundred crore rupees. |
| (4) | Breach in observing additional obligations of Significant Data Fiduciary under section 10. | May extend to one hundred and fifty crore rupees. |
| (5) | Breach in observing the duties under section 15. | May extend to ten thousand rupees. |
| (6) | Breach of any term of voluntary undertaking accepted by the Board under section 32. | Up to the extent of the applicable maximum penalty. |
| (7) | Breach of any other provision of this Act or the rules made thereunder. | May extend to fifty crore rupees. |
Important Interpretation
Unlike the GDPR which uses a percentage of global turnover, the DPDPA relies on fixed maximum financial penalties. The penalties are determined based on the severity, nature, and duration of the breach as outlined in Section 33.