Introduction
When the European Union implemented the GDPR, the headlines were dominated by the sheer scale of the potential fines—up to 4% of a company's global revenue. While India’s Digital Personal Data Protection (DPDP) Act, 2023, does not tie penalties to global revenue, it introduces fixed, exorbitant fines that command immediate board-level attention.
With penalties reaching up to ₹250 Crores (approximately $30 million USD) per instance, non-compliance is no longer a manageable operational risk; it is an existential threat to businesses. This article decodes the penalty structure of the DPDP Act and explains how the regulatory body determines the size of the fine.
The Penalty Structure: Cap-Based Fines
Unlike the GDPR, which uses a percentage of revenue, the DPDP Act outlines specific maximum caps for various types of contraventions. These are maximum penalties, not minimums, meaning the actual fine levied will depend on the context of the breach.
The Schedule to the DPDP Act outlines the following major penalties:
- Failure to prevent a personal data breach: Up to ₹250 Crores. This applies if a Data Fiduciary fails to take "reasonable security safeguards" resulting in a breach.
- Failure to notify a breach: Up to ₹200 Crores. If a breach occurs and the company fails to notify the Data Protection Board of India (DPBI) and the affected Data Principals, this fine is triggered. Notably, a company could be fined ₹250 Crores for the breach itself, and an additional ₹200 Crores for covering it up.
- Failure to fulfill additional obligations for children: Up to ₹200 Crores. This includes processing children's data without verifiable parental consent, or engaging in behavioral monitoring or targeted advertising directed at children.
- Failure of Significant Data Fiduciaries (SDFs): Up to ₹150 Crores. SDFs have extra obligations like appointing a Data Protection Officer based in India and conducting Data Protection Impact Assessments. Failing to meet these specific obligations triggers this tier.
- General Contravention: Up to ₹50 Crores. For any other breach of the Act's provisions not explicitly listed above.
No Compensation for Individuals
A critical nuance of the DPDP Act is its focus on penalizing the company rather than compensating the victim. Unlike the GDPR or previous Indian iterations (like the Personal Data Protection Bill, 2019), the DPDP Act does not grant Data Principals the right to seek financial compensation through the Data Protection Board for a privacy violation.
All monetary penalties collected by the DPBI will be credited to the Consolidated Fund of India. However, affected individuals may still pursue civil remedies under common law, though this is traditionally a slower and more complex route in India.
How Does the Board Determine the Exact Fine?
If a company suffers a breach, an automatic ₹250 Crore fine is not guaranteed. The Data Protection Board of India has significant discretion. The DPDP Act outlines specific factors the Board must consider when deciding the quantum of the penalty:
- Nature, Gravity, and Duration: Was this a brief, accidental exposure of 100 emails, or a prolonged, systemic theft of thousands of highly sensitive medical records?
- Type of Data Affected: A breach involving financial details or biometrics will incur a harsher penalty than a breach of generic marketing lists.
- Repetitive Nature: Is this the company's first offense, or is there a pattern of negligence?
- Realized Gain or Loss: Did the company financially benefit from the contravention, or did the individuals suffer significant harm?
- Mitigating Actions: This is the most critical factor for businesses. Did the company act quickly to mitigate the damage? Did they notify the authorities promptly? Did they offer support to the victims? A robust incident response plan can significantly reduce the final penalty.
- Proportionality: The fine must be proportionate to the severity of the offense.
Voluntary Undertakings: A Get-Out-of-Jail Card?
The DPDP Act introduces a pragmatic mechanism to resolve disputes efficiently: Voluntary Undertakings. If a company realizes it has violated the Act, it can offer a voluntary undertaking to the DPBI.
This undertaking might include a commitment to take specific actions to correct the violation, a commitment to refrain from doing something, or even a commitment to publicize the undertaking. If the DPBI accepts this undertaking, it acts as a bar on any further regulatory proceedings for that specific contravention.
However, if the company fails to comply with the terms of the undertaking, it is treated as a breach of the Act, and the heavy penalties come crashing down.
Conclusion
The financial penalties under the DPDP Act are designed to be punitive and deterrent. For CEOs and CFOs, privacy compliance must be viewed through the lens of enterprise risk management. Investing in robust cybersecurity infrastructure, comprehensive vendor management, and employee training is no longer an IT overhead; it is essential insurance against catastrophic regulatory fines.