Legal Register
Visual Infographic
I-04 Sanctions & Liability ๐Ÿ‘ค Executive Board & General Counsel

The Penalty Schedule & Ceilings

Seven Statutory Sanction Tiers: Maximum Monetary Ceilings under Section 33(1)

Section 33 and the Schedule to the DPDP Act establish a tiered penalty structure with massive monetary ceilings. Unlike GDPR which ties fines to global turnover percentages (e.g. 4%), DPDP specifies absolute INR rupee ceilings per breach occurrence up to โ‚น250 Crores (~$30M USD). The schedule contains 7 distinct tiers ranging from failure to take reasonable security safeguards to breach of Data Principal duties.

Statutory Source: Ch. 6, Appendix A.4, Act Schedule
Archetype: penalty matrix
I-04 DiagramArchetype: PENALTY MATRIX

The Penalty Schedule & Ceilings

Statutory Penalty Schedule (Section 33 & Act Schedule)
Tier 1 (Maximum)s.8(5)
โ‚น250 Crore

Failure to take reasonable security safeguards to prevent personal data breach

Tier 2s.8(6)
โ‚น200 Crore

Failure to give the Board or affected Data Principals intimation of personal data breach

Tier 3s.9
โ‚น200 Crore

Breach of obligations in relation to children or persons with disabilities (tracking/ads/harm)

Tier 4s.10
โ‚น150 Crore

Breach of additional obligations of Significant Data Fiduciaries (DPO/Audit/DPIA)

Tier 5Residual
โ‚น50 Crore

Breach of any other provision of the Act or Rules for which no specific penalty is provided

Tier 6s.15
โ‚น10,000

Breach of duties by Data Principals (frivolous complaints, false impersonation)

Tier 7s.32
Modified Ceilings

Breach of terms of Voluntary Undertaking accepted by the Board

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ Penalties are statutory maximum ceilings per adjudication, not standard fixed penalties.
โœฆ The Board has no criminal imprisonment powers; all sanctions are civil monetary penalties.
โœฆ Security safeguard failure (โ‚น250 Cr) and breach notification failure (โ‚น200 Cr) are cumulative.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 33(1)Schedule (Act)Section 8(5)Section 8(6)Section 9Section 10Section 15Section 32

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Present the penalty exposure matrix to the Board Risk Committee.
  2. Calibrate cyber insurance coverage to cover DPDP statutory penalty ceilings.
  3. Implement multi-layered encryption, access controls, and immutable telemetry for SYS-002 and SYS-004.

Enterprise Traps & Failure Modes

  • โš ๏ธ Assuming small enterprises are exempt from the โ‚น250 Cr maximum ceiling.
  • โš ๏ธ Failing to report a breach within time limits, triggering an independent โ‚น200 Cr penalty.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ Enterprise Risk Assessment & Sanction Exposure Model
๐Ÿ“„ Board Presentation on DPDP Liabilities
๐Ÿ“„ Incident Escalation Protocol