The Penalty Schedule & Ceilings
Seven Statutory Sanction Tiers: Maximum Monetary Ceilings under Section 33(1)
Section 33 and the Schedule to the DPDP Act establish a tiered penalty structure with massive monetary ceilings. Unlike GDPR which ties fines to global turnover percentages (e.g. 4%), DPDP specifies absolute INR rupee ceilings per breach occurrence up to โน250 Crores (~$30M USD). The schedule contains 7 distinct tiers ranging from failure to take reasonable security safeguards to breach of Data Principal duties.
The Penalty Schedule & Ceilings
Failure to take reasonable security safeguards to prevent personal data breach
Failure to give the Board or affected Data Principals intimation of personal data breach
Breach of obligations in relation to children or persons with disabilities (tracking/ads/harm)
Breach of additional obligations of Significant Data Fiduciaries (DPO/Audit/DPIA)
Breach of any other provision of the Act or Rules for which no specific penalty is provided
Breach of duties by Data Principals (frivolous complaints, false impersonation)
Breach of terms of Voluntary Undertaking accepted by the Board
๐ก Core Architectural Insights & Takeaways
Key technical and regulatory takeaways established by this architecture diagram.
๐ Statutory Grounding & Legal Perimeter
Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.
๐๏ธ Target Architecture & Impacted Systems
Enterprise nodes and store topologies impacted by this architectural pattern.
Public client boundary & untrusted intake surface for notices and consent capture
Cold physical and scanned document store subject to statutory retention schedules
Offshore disaster recovery replica; isolated pending cross-border transfer checks
Immutable consent event store and Policy Decision Point issuing authority tokens
โ๏ธ Associated Operational Controls
Control Master Matrix obligations enforcing the standards illustrated in this infographic.
๐ ๏ธ Implementation Guidance & Traps
Recommended technical sequencing and operational failure modes to avoid.
Recommended Implementation Sequence
- Present the penalty exposure matrix to the Board Risk Committee.
- Calibrate cyber insurance coverage to cover DPDP statutory penalty ceilings.
- Implement multi-layered encryption, access controls, and immutable telemetry for SYS-002 and SYS-004.
Enterprise Traps & Failure Modes
- โ ๏ธ Assuming small enterprises are exempt from the โน250 Cr maximum ceiling.
- โ ๏ธ Failing to report a breach within time limits, triggering an independent โน200 Cr penalty.
๐ Verifiable Evidence Artifacts Vault
Required evidentiary workpapers for regulatory inspections and SDF audits.