How liability arises under the DPDP Act
Who carries the liability, at which point in the life of personal data it arises, what the Schedule says it can cost, and what the Board weighs when it decides. Our reading, in plain terms.
The fiduciary carries it, including for its processors
Data fiduciary
Whoever decides the purpose and means of processing. Responsible for compliance, including processing done on its behalf by a processor (s.8(1)).
Data processor
Processes on the fiduciary's behalf under a valid contract (s.8(2)). The fiduciary answers to the Board for the processor's failures.
Significant Data Fiduciary
Notified by the government on volume, sensitivity and risk. Adds a DPO in India, an independent auditor and periodic impact assessments (s.10).
Data principal
The person whose data it is. Has duties too, such as not filing frivolous complaints (s.15), with a penalty of up to ₹10,000.
Seven points in the life of personal data where liability is created
No valid notice or consent
Consent bundled, pre-ticked, or given without an itemised notice.
Beyond the purpose
Data used for a purpose the person never agreed to, or kept after withdrawal.
Processors without control
Vendors with no contract, or reaching more data than their purpose needs.
Past its purpose
Retained after the purpose is served, with no law requiring it.
Safeguards that fail
Reasonable safeguards to prevent a breach not taken.
Silence after the event
The Board and affected people not told.
Rights ignored
Access, correction, erasure or grievance not answered in time.
DPDP Act penalties: what each failure can cost
| Breach of | What it covers | Penalty, up to |
|---|---|---|
| Security safeguards · s.8(5) | Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Breach intimation · s.8(6) | Failure to inform the Board or affected data principals of a personal data breach | ₹200 crore |
| Children · s.9 | Additional obligations for the personal data of children | ₹200 crore |
| Significant Data Fiduciary · s.10 | Additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Voluntary undertaking · s.32 | Breach of an undertaking accepted by the Board | Up to the amount for the breach it covered |
| Any other provision | Notice, consent, withdrawal, retention, rights, grievance and the rest of the Act and Rules | ₹50 crore |
| Data principal duties · s.15 | Duties of the person whose data it is | ₹10,000 |
The Board weighs what you did, and how promptly
Section 33 asks the Board to consider these factors before it sets an amount. Most of them are decided by evidence you either have on the day, or do not.
- The nature, gravity and duration of the breach
- The type and nature of the personal data affected
- Whether the breach was repetitive
- Whether a gain was made or a loss avoided as a result
- Action taken to mitigate the effects, and how timely it was
- Whether the penalty is proportionate and effective in securing compliance
- The likely impact of the penalty on the person
Show what you did
A dated record of notices, consents, withdrawals relayed and requests answered.
Show how promptly
Incident timelines from awareness, with each notification and filing timestamped.
Settle where you can
The Board may accept a voluntary undertaking at any stage of a proceeding (s.32). A good record makes one credible.
Where software keeps that record:Consent management software →Data discovery software →
Twenty questions. Ten minutes. Your exposure, by obligation.
No sign-up. Your answers stay in your browser. You see where liability sits and what would reduce it, including where software is not the answer.
Know which of these applies to you, before someone else asks.
Wekalp is software for data fiduciaries and is not a Consent Manager registered with the Data Protection Board under section 6(9) of the Act. Nothing on this site is legal advice.