RISKFORTIS
Enforcement092d 01h 44m

DPDP Penalty Exposure Calculator

What a DPDP failure is actually worth to the Board.

Set the facts. The statutory ceilings and the factors the Board must weigh appear as you type. Nothing is stored and nothing is sent — this runs in your browser.

Incident facts

Statutory ceiling · this failure

₹250 Cr

Schedule to the Act · failure to take reasonable security safeguards

Aggregate ceiling across 1 obligation(s)₹250 Cr
Notification duty owed to50,000 principals

Factors the Board must weigh · s.33(2)

  • Gravity and duration of the breachAggravating · significant cohort
  • Type and nature of personal data affectedOrdinary personal data
  • Repetitive nature of the breachFirst occurrence
  • Mitigating action taken, and how quicklyMitigating · prompt and documented
  • Compliance posture at the time — Rule 6 safeguardsAggravating · safeguards not evidenced

Exposure is mid-band. The ceiling is unchanged, but there is documented mitigation to argue against it.

What people get wrong

The ceiling is not the fine, and it is not turnover-linked. Boards read “₹250 crore” as a number that applies to somebody larger — but DPDP fixes its maximums in rupees rather than as a percentage of revenue, so a company with ₹40 crore of turnover faces the same ceiling as one with ₹40,000 crore.

The second error is arithmetic. Penalties attach per breach of each obligation, not per incident. One misconfigured bucket can be a security failure, a notification failure and a retention failure at once — three ceilings, weighed separately. What actually moves the number is the s.33(2) factors above, and every one of them is decided by evidence you either created before the incident or did not.

Read our note on Rule 7 breach intimation

General information, not legal advice. Ceilings are statutory maximums per instance; the Board determines the actual penalty after inquiry. Verify against the current text of the Act.