Home How We Work Security Assurance Resources
DPDP Act 2023 · How liability arises

How liability arises under the DPDP Act

Who carries the liability, at which point in the life of personal data it arises, what the Schedule says it can cost, and what the Board weighs when it decides. Our reading, in plain terms.

Who is liable

The fiduciary carries it, including for its processors

Data fiduciary

Whoever decides the purpose and means of processing. Responsible for compliance, including processing done on its behalf by a processor (s.8(1)).

Data processor

Processes on the fiduciary's behalf under a valid contract (s.8(2)). The fiduciary answers to the Board for the processor's failures.

Significant Data Fiduciary

Notified by the government on volume, sensitivity and risk. Adds a DPO in India, an independent auditor and periodic impact assessments (s.10).

Data principal

The person whose data it is. Has duties too, such as not filing frivolous complaints (s.15), with a penalty of up to ₹10,000.

Where it arises

Seven points in the life of personal data where liability is created

Collect

No valid notice or consent

Consent bundled, pre-ticked, or given without an itemised notice.

S.5, S.6
Use

Beyond the purpose

Data used for a purpose the person never agreed to, or kept after withdrawal.

S.6(1), S.6(6)
Share

Processors without control

Vendors with no contract, or reaching more data than their purpose needs.

S.8(1)–(2)
Keep

Past its purpose

Retained after the purpose is served, with no law requiring it.

S.8(7)
Secure

Safeguards that fail

Reasonable safeguards to prevent a breach not taken.

S.8(5)
Breach

Silence after the event

The Board and affected people not told.

S.8(6)
Respond

Rights ignored

Access, correction, erasure or grievance not answered in time.

SS.11–14
The Schedule

DPDP Act penalties: what each failure can cost

Breach ofWhat it coversPenalty, up to
Security safeguards · s.8(5)Failure to take reasonable security safeguards to prevent a personal data breach₹250 crore
Breach intimation · s.8(6)Failure to inform the Board or affected data principals of a personal data breach₹200 crore
Children · s.9Additional obligations for the personal data of children₹200 crore
Significant Data Fiduciary · s.10Additional obligations of a Significant Data Fiduciary₹150 crore
Voluntary undertaking · s.32Breach of an undertaking accepted by the BoardUp to the amount for the breach it covered
Any other provisionNotice, consent, withdrawal, retention, rights, grievance and the rest of the Act and Rules₹50 crore
Data principal duties · s.15Duties of the person whose data it is₹10,000
Each amount is a ceiling, imposed where the Board, after an inquiry and a hearing, finds a breach significant (ss.28, 33(1)). Where penalties have been imposed in two or more instances, the government may, on the Board's reference, direct that access to the fiduciary's service be blocked (s.37).
How the amount is decided

The Board weighs what you did, and how promptly

Section 33 asks the Board to consider these factors before it sets an amount. Most of them are decided by evidence you either have on the day, or do not.

  1. The nature, gravity and duration of the breach
  2. The type and nature of the personal data affected
  3. Whether the breach was repetitive
  4. Whether a gain was made or a loss avoided as a result
  5. Action taken to mitigate the effects, and how timely it was
  6. Whether the penalty is proportionate and effective in securing compliance
  7. The likely impact of the penalty on the person

Show what you did

A dated record of notices, consents, withdrawals relayed and requests answered.

Show how promptly

Incident timelines from awareness, with each notification and filing timestamped.

Settle where you can

The Board may accept a voluntary undertaking at any stage of a proceeding (s.32). A good record makes one credible.

About the Act and the Rules: the Digital Personal Data Protection Act, 2023 received assent in August 2023. The Digital Personal Data Protection Rules, 2025 were notified with commencement in phases. Check current Gazette notifications for timelines. This page is our reading of the Act for general information; it is not legal advice.
Readiness check

Twenty questions. Ten minutes. Your exposure, by obligation.

No sign-up. Your answers stay in your browser. You see where liability sits and what would reduce it, including where software is not the answer.

Know which of these applies to you, before someone else asks.

Wekalp is software for data fiduciaries and is not a Consent Manager registered with the Data Protection Board under section 6(9) of the Act. Nothing on this site is legal advice.