dpdp

What happens if you ignore DPDP? Here’s a simple guide to penalties for Indian founders.

JO
Joginder Poswal
04 Jun 2026 10 min read
Share:
What happens if you ignore DPDP? Here’s a simple guide to penalties for Indian founders.

What happens if you ignore DPDP? A penalty walkthrough for Indian founders

₹250 crore.

This is the biggest penalty under the Digital Personal Data Protection Act 2023.

Pause and consider how large that number is.

If your business makes ₹5 crore a year, one fine could erase 50 years of revenue. For a SaaS founder earning ₹80 lakh ARR, the penalty hardly seems real.

For most Indian SMEs, these penalties haven’t felt real. The rules seemed far away, and the Board felt like just an idea.

But this is the situation in 2026.

The DPDP Rules were announced on 13 November 2025. The Data Protection Board of India is now active. The full compliance deadline, when all main requirements will be enforced, is 13 May 2027.

You have about a year from now.

More importantly, the Board can act before May 2027. It is already working, taking complaints, and handling cases. If a customer complains about your data practices now, the Board can start an investigation immediately.

This post explains in plain language what happens if you don’t follow DPDP. It covers penalty amounts, enforcement procedures, and what a mid-sized Indian business could face if something goes wrong.

No legal jargon. Only the facts.

How the penalty structure actually works

Most founders who know about DPDP think of the ₹250 crore number. But the Act doesn’t use a flat fine. Instead, there are different levels, each tied to a specific type of failure.

Here’s how it works.

Failure to protect children's data or process it without verifiable parental consent: up to ₹200 crore.

This penalty surprises many people. If your product has users who might be under 18, such as apps, platforms, e-commerce sites, edtech products, or games, and you haven’t added age checks or parental consent, you fall into this group. The Act is strict about protecting minors.

Failure to implement reasonable security safeguards, resulting in a data breach: up to ₹250 crore.

This is the most serious penalty. The Act does not require ISO 27001 certification, but it does require ‘reasonable’ security based on the type and amount of data you have. For example, if you store Aadhaar numbers in an unencrypted database with shared access credentials and a breach occurs, that is not reasonable. That counts as negligence.

Failure to notify the Data Protection Board and affected individuals of a breach: up to ₹200 crore.

If you have a breach and try to hide it, the Act treats this as a separate violation with its own penalty. You can be fined for the breach and fined again for failing to report it. The DPDP Rules require you to inform the Board of the breach, including what happened, which data was affected, how many people were impacted, and what you did to contain it.

Non-fulfilment of obligations related to consent, data accuracy, or erasure: up to ₹50 crore each.

These are operational failures, like not allowing people to withdraw consent, not correcting incorrect data when asked, or not deleting data when you’re supposed to.

Breach of any other provision of the Act or Rules: up to ₹50 crore.

This is the catch-all category for anything that doesn’t fit the specific types above.

These penalties can add up. Different violations in the same incident can each get a separate penalty.

Who decides the fine?

The Data Protection Board of India (DPBI) was established under the Act and is now operational.

The Board is not a court. It is an independent regulator with some legal powers. It gets complaints from Data Principals, investigates, collects evidence, and gives penalties. The Board can also act on its own if it hears about a possible violation, such as through news reports of a breach.

The Board's orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), and from there to the High Court.

This is a real enforcement process, not just a theory. The Board is set up, the rules are active, and the complaint system works.

What the Board considers when deciding the penalty amount

The Act lists specific things the Board must consider before deciding on a penalty. This matters because the Board doesn’t always give the maximum fine. Instead, it looks at the details of each case.

The factors include:

  • The nature, gravity, and duration of the breach

  • The type of personal data involved

  • Whether the violation was intentional or negligent

  • Whether the business took any steps to mitigate the damage

  • Whether this is a repeat violation

  • Whether the business gained financially from the violation

  • The impact on affected Data Principals

In practice, a business that reports a breach quickly, works with the Board, and has some security in place will get a much better result than one that hides the breach, refuses to cooperate, and has no security at all.

You don’t have to be perfect. You just need to be reasonable and responsive.

A realistic scenario: what this looks like for an actual Indian business

Here’s a made-up scenario based on how the Act and Rules actually work.

Imagine you run a D2C skincare brand. You’ve made ₹ 4- 5 crore in revenue over the last few years. You have a website, a mobile app, a WhatsApp channel, and you use a third-party logistics partner for deliveries.

Your customer database has about 80,000 records. Each record has a name, phone number, delivery address, and purchase history. Your logistics partner receives the name, phone number, and address for every order you send out.

In April 2026, your logistics partner’s system is breached. Customer data is posted on a Telegram channel and sold for ₹2 per record.

Your customers start getting scam calls. Some trace the calls back to you and file complaints with the Data Protection Board.

Here’s what happens next.

The Board receives the complaints and opens an inquiry. They send you a notice asking what happened, what data was affected, and what security measures you had in place.

The investigation begins.

The Board reviews your contract with the logistics partner and finds no data-processing clause. You gave them access to 80,000 customers’ personal data under a standard agreement that lacked data protection terms. Under the DPDP Act, this is your responsibility. As the Data Fiduciary, you are responsible for how your partners handle your customers’ data.

The Board checks your security setup. Your customer database is on a shared server. There’s no encryption at rest. Database credentials are shared with your operations team. There are no audit logs to show who accessed what.

The Board checks your breach response. You didn’t tell affected customers. You didn’t report the breach to the Data Protection Board as the Rules require.

That’s already three violations, each with its own penalty.

The Board also checks your consent process. Your 2022 privacy policy doesn’t mention the logistics partner or that you share customer data with third parties. You shared personal data without telling users in your consent notice.

Four violations.

When deciding the penalty, the Board probably won’t give the maximum amount since you’re not a big company. But a fine of ₹5-10 crore for these violations is realistic for a business this size, given the number of affected users and the lack of safeguards.

For a business earning ₹4-5 crore in revenue, a penalty like this could threaten its survival. This doesn’t even include legal costs, damage to your reputation, or loss of customer trust.

"But the full enforcement deadline is May 2027"

This is the objection I hear most often.

And yes, the full set of core compliance requirements, like consent mechanisms, breach notification, and rights management, will be enforced from 13 May 2027 in Phase 3 of the rollout.

But this way of thinking has a big flaw.

The Data Protection Board is already constituted and operational. Under Phase 1 (effective since 13 November 2025), the Board's powers are live. It is already processing complaints. It can already conduct inquiries.

The scenario above, where customers complain after a breach, doesn’t need Phase 3 to be active. The Board already has the tools to investigate.

Second, when Phase 3 starts on 13 May 2027, businesses won’t be judged solely on their state as of that day. They’ll be judged on their current practices. If your consent and security measures aren’t compliant today, they’ll still be non-compliant on 14 May 2027.

Businesses that start now have 12 months to get things right. Those who wait will be working under pressure, with the Board fully active and enforcement already happening.

The "it won't happen to us" calculation

Let’s be honest about how most Indian SMEs see this.

They’re not thinking, "We’ll definitely get fined." They’re thinking, "Enforcement will focus on Jio, Paytm, and HDFC Bank. No one’s coming after a 10-person company in Gurugram."

There’s some truth to that. Big, visible violations will probably get attention first. But a few things make this logic less safe than it seems.

One: Data Principals can directly file complaints with the Board. You don't need a regulator to decide to come after you. One customer whose data was misused can trigger an inquiry. Eighty thousand customers are a lot of potential complainants.

Second, breaches get covered in the news. If your breach is reported in the media, the Board can act on its own without waiting for complaints.

Third, your B2B customers and enterprise clients will start asking about compliance. This is already happening in BFSI and healthcare. Bigger companies will increasingly require DPDP compliance from their vendors to do business. For SaaS founders, this is a business risk, not just a regulatory one.

What actually reduces your exposure

None of this is meant to scare you. It’s to give you a clear picture so you can make good decisions.

The things the Board looks at when deciding penalties are things you can work on right now.

Security safeguards: put reasonable measures in place before you need them. Use encryption, access controls, and basic patching. None of this needs a big budget.

Vendor contracts: add data processing clauses to every agreement where a vendor handles personal data for you. This is a one-time job you can complete in a few hours using a standard template.

Breach response plan: write down what you’d do in the first 48 hours after a breach. Who gets called, what gets recorded, how the Board is notified, and how users are informed. The plan doesn’t have to be fancy; it just needs to exist.

Privacy notice: update it to accurately describe what data you collect, why, who you share it with, and how users can exercise their rights.

Consent records: start keeping them. For every consent you collect from now on, record who gave it, what it was for, and when.

You don’t need a compliance team for any of this. You just need to treat customer data as your responsibility, not someone else’s problem.

What dComply does for this

We built dComply to handle the day-to-day compliance tasks that most Indian SMEs find difficult.

Consent management with records. Data mapping. Vendor tracking with contract flags. Breach response workflows. Rights request handling. Privacy notice templates built for the DPDP Act and Rules 2025.

The compliance deadline is 13 May 2027. That might sound like plenty of time. But if you’ve never done a data audit, never written a breach response plan, and never checked your vendor contracts for data processing clauses, 12 months will go by quickly.

The Free plan is a real way to get started. No credit card needed, no sales call.

Start with dComply for free

Found this useful? Share it:

Ready to Get DPDP Compliant?

Start free and explore All 89 compliance modules

Talk to Sales