August 3, 2026 · Alastor InfoSec Team
DPDPA Penalties Decoded: What Triggers ₹250 Crore Fines and How Indian Businesses Can Avoid Them in 2026
India's Digital Personal Data Protection Act is no longer a future obligation. With the Data Protection Board of India (DPBI) now being actively staffed and the Phase 2 Consent Manager framework activating on November 13, 2026, the penalty clauses buried in Schedule II of the DPDP Act are about to become real line items in boardroom risk registers. The fines are significant — up to ₹250 crore per breach incident — and the law is written broadly enough that a single misconfigured system or a missed notification can trigger them.
This post decodes each penalty tier, explains exactly what behaviour attracts the highest penalties, and provides the specific technical and operational controls that demonstrate compliance under DPBI scrutiny.
How the DPDPA Penalty Structure Works
The DPDPA does not impose a flat fine for non-compliance. Instead, Schedule II structures penalties around specific failure categories, each with its own ceiling. The DPBI has adjudicatory authority to investigate, issue notices, and impose penalties after conducting proceedings that mirror a regulatory tribunal — not a court. That matters because the standard of proof is lower than criminal proceedings and the burden of demonstrating reasonable security safeguards falls on the Data Fiduciary, not the regulator.
The penalty tiers break down as follows. The most severe penalty — ₹250 crore — applies to failure to implement adequate security safeguards leading to a personal data breach. The second-highest tier — ₹200 crore — applies to failure to notify the DPBI and affected data principals of a breach within the prescribed timeline. ₹150 crore applies to failure to erase data upon withdrawal of consent or upon request. ₹50 crore applies to breaches involving children's data — defined as anyone under 18. ₹10,000 applies per instance of failure to properly implement a Grievance Officer mechanism.
What "Adequate Security Safeguards" Actually Means Under DPBI Scrutiny
The ₹250 crore penalty is the one that concerns security teams the most, and for good reason: it is the broadest. Rule 8 of the DPDP Rules 2025 requires Data Fiduciaries to implement "reasonable security safeguards" to prevent personal data breaches. The Rules do not prescribe a specific standard — which means the DPBI will adjudicate based on whether the organisation took security seriously relative to its size, data volume, and risk profile.
In practice, the DPBI is expected to look at three things. First, whether the organisation had a documented vulnerability assessment and penetration testing programme — not a one-time audit but a continuous programme that could detect exploited weaknesses before attackers did. Second, whether access controls on personal data systems were role-based, audited, and enforced. Third, whether the organisation could demonstrate evidence of its security posture over time — not just a point-in-time certificate.
This is why the link between VAPT and DPDPA compliance is not theoretical. An organisation that cannot produce VAPT reports, remediation records, or continuous monitoring evidence will struggle to show the DPBI that its security safeguards were "reasonable." Alastor Pulse — our PTaaS dashboard — generates exactly this audit trail: timestamped findings, CVSS-scored severity classifications, and remediation verification, all exportable for regulatory submissions.
The 72-Hour Breach Notification Rule — and Why Most Businesses Will Miss It
The ₹200 crore penalty for failure to notify is where most organisations will be caught out in the first wave of enforcement. DPDPA Rule 7 requires notification to the DPBI "as soon as possible" — and the DPBI has indicated in guidance that "as soon as possible" means no later than 72 hours after the Data Fiduciary becomes aware of a breach. For organisations also subject to CERT-In directions, the 6-hour mandatory incident report to CERT-In must go out first, followed by the DPBI notification within 72 hours and individual notifications to affected data principals promptly thereafter.
The operational challenge is detection latency. The IBM Cost of a Data Breach 2025 report found the average time to identify a breach was 194 days. If your security team takes six months to detect an intrusion, you have missed the notification window by five and a half months and are exposed to the full ₹200 crore penalty regardless of the underlying severity. The answer is continuous monitoring — real-time alerting on anomalous data access, exfiltration patterns, and login anomalies that shortens detection time from months to hours.
Alastor Shield maps your monitoring controls directly to DPDPA Rule 7, generating the notification templates and evidence packages the DPBI expects to receive. It also integrates with SIEM and endpoint detection tools so that breach triggers surface automatically rather than depending on someone checking a dashboard.
Children's Data: A Separate and Overlooked Liability
The ₹50 crore penalty for violations involving children's data is one that many businesses underestimate because they assume they do not collect children's data. Under the DPDPA, a minor is anyone under 18, and the Act applies to any platform that is "likely to be accessed" by minors — not just those explicitly targeting them. An e-commerce platform, an ed-tech app, or a consumer SaaS product used by families falls under this obligation without any age-gate explicitly in place.
Rule 10 of the DPDP Rules 2025 requires Data Fiduciaries to obtain verifiable parental consent before processing any personal data of a child. The Consent Manager integration required under Phase 2 must support a separate consent flow for children that captures parental approval. Organisations that have not mapped their user demographics or implemented a children's data identification process are running a ₹50 crore risk they do not know about.
Data Erasure: The Technical Requirement Everyone Ignores
Section 17 of the DPDPA gives every Data Principal the right to erasure — the deletion of their personal data — upon withdrawal of consent or upon the fulfilment of the purpose for which the data was collected. Failure to honour erasure requests within a reasonable timeframe attracts up to ₹150 crore in penalties.
The technical challenge is that personal data in enterprise environments does not live in one database. It lives in the CRM, the data warehouse, the email archive, the backup system, the third-party analytics tool, and the logs. A meaningful erasure implementation requires a data inventory (knowing where personal data lives), an automated erasure workflow that propagates deletion across all systems, and a vendor contract clause that obligates processors to honour erasure requests within a defined window.
Most Indian businesses have none of these three things fully implemented today. Building them requires a data mapping exercise first, then technical implementation, then documentation for the DPBI. We work with clients to conduct this exercise under Alastor Shield's compliance automation module — if you need to start, reach us at [email protected].
What the DPBI Enforcement Process Actually Looks Like
Understanding the penalty structure is only half the picture. The DPBI will not randomly audit organisations — it will investigate on receipt of complaints from Data Principals, referrals from CERT-In after breach notifications, or suo motu if it detects patterns of non-compliance through public reporting. The investigation process involves issuing a show-cause notice, conducting hearings, and then issuing a reasoned order imposing a penalty.
Critically, the DPDPA's safe harbour provision — Section 11(5) — provides a penalty reduction path for organisations that can demonstrate that they took prompt corrective action upon discovering the breach, cooperated with the DPBI's investigation, and had reasonable security measures in place before the incident. This means organisations with documented VAPT programmes, continuous monitoring logs, and incident response procedures have a credible mitigation defence. Those without any of these face the full penalty ceiling with no mitigation on the table.
The Compliance Controls That Matter Most Right Now
With Phase 2 activating on November 13, 2026, organisations have approximately 15 weeks to get the highest-risk controls in place. The three highest-priority actions are: first, implement continuous security monitoring and vulnerability management to demonstrate "reasonable security safeguards"; second, build and test your breach detection and notification workflow against both the 6-hour CERT-In and 72-hour DPBI timelines; third, complete your data mapping and erasure workflow before the first erasure request arrives.
Secondary priorities — children's data identification, Consent Manager integration, Grievance Officer appointment — are important but unlikely to attract the largest penalties in the first enforcement wave. Start with what the DPBI will look at first: your security posture and your breach response capability.
The DPDPA's penalty structure is designed to make data security failures expensive — and the DPBI has been constituted specifically to enforce it. The organisations that build their compliance around genuine security controls, not checkbox documentation, are the ones that will survive the first enforcement cycle intact.
To understand where your DPDPA exposure sits today, contact Alastor InfoSec at [email protected] or explore our compliance automation platform at /products/alastor-shield.