₹250 Crore for a Data Leak: Can a Company Really Be Fined That Much?
Understand how the DPDP Act's ₹250 crore maximum penalty works and what organisations need to do to strengthen security and breach response.
₹250 Crore Is the Headline. The Real Cost Starts Earlier.
When people hear the DPDP penalty figures, the first reaction is usually about the money. But for leadership teams, the number matters less than what it signals: security and breach response are now directly regulated, with consequences set in law.
How the Penalty Structure Works
The Act sets maximum penalties by type of failure. The highest, up to ₹250 crore, applies to failing to implement reasonable security safeguards.
Failing to notify a breach to the Data Protection Board and affected individuals, and breaching obligations on children's data, can each reach ₹200 crore. Significant Data Fiduciaries face a separate cap for their additional duties, and other violations carry lower maximums.
These are ceilings, not fixed fines. The Board looks at the nature, gravity and duration of the failure, the type of data involved, the steps taken to reduce harm and the organization's conduct. Penalties can also apply per instance.
What "Reasonable Security" Is Likely to Mean in Practice
The Rules spell out safeguards such as encryption, obfuscation or tokenization of data, access controls, monitoring and logging to detect unauthorized access, and backups to maintain continuity.
Organizations are also expected to retain relevant logs for a set period, and to build data-protection safeguards into contracts with their processors.
If something goes wrong, being able to show what controls you had matters as much as the controls themselves.
Breach Response Is Where Many Organizations Are Exposed
Notifying a breach needs a defined process: detect the incident, assess its scope, inform affected individuals without delay, and report to the Board with a detailed account within the prescribed timeline.
That requires clear ownership, decision rights and rehearsal long before an incident occurs. Check the Rules for the exact notification timelines when you build the playbook.
Timing
Most operational obligations and penalties take effect from 13 May 2027, with consent manager provisions starting on 13 November 2026. The IT minister has indicated the government may shorten the transition, so planning for the later date is a gamble.
Where to Start
-
Run a gap assessment.
Assess your current posture against the Rules' security requirements.
-
Know your data.
You can't protect what you haven't inventoried.
-
Review processor contracts.
Check security and breach-notification terms across relevant processor agreements.
-
Write and test a breach playbook.
Define who notifies whom, what information is required and how quickly action must be taken.
-
Keep evidence.
Maintain logs, policies and test results as evidence of reasonable security efforts.
The Real Cost of a Data Breach
The cost of a breach already includes downtime, legal fees and lost trust. DPDP adds a regulator to that list, so security belongs on the board's agenda, not just IT's.