DPDP Fine Calculator. Estimate your ₹250 Cr exposure.
Enter your company profile, the violations at risk, and any mitigation posture. The calculator returns your Schedule 1 maximum exposure, a realistic range calibrated for the DPB\'s Section 33(3) discretion, and the five actions that reduce your exposure fastest.
Directional estimator built from the exact 7-row Schedule to the DPDP Act 2023 · not legal advice
Source: DPDP Act 2023 Schedule (as read with Section 33(1)). Reviewed on 24 August 2026.
Source: DPDP Act 2023 Schedule as read with Section 33(1). Consent Manager, DSR, and invalid-consent violations fall under Row 7 residual — the Act has no dedicated cap for them.
Your DPDP exposure will appear here
Fill the form and hit Calculate. Instant Schedule 1 breakdown + realistic-range estimate + top 5 mitigation actions.
The maths behind the estimate
Every rupee amount in this calculator comes verbatim from the Schedule to the DPDP Act 2023. The Schedule has exactly 7 rows — the calculator does not invent additional penalty categories. Non-enumerated violations (invalid consent, DSR failure, Consent Manager non-compliance) all fall under Row 7 residual = ₹50 Cr per instance.
The calculator then applies three transformations to those exact caps:
- Aggregate cap — sum the Schedule maximum across every selected violation. This is the theoretical ceiling if the DPB applies the maximum for each cumulatively.
- Volume calibration — the DPB\'s Section 33(3)(a) considers "nature, gravity and duration". We calibrate on principals affected (15% for <1,000; 100% for >10 million) plus SDF/Consent Manager multipliers plus a sensitive-data uplift (health, financial, biometric, children). This part is a heuristic — Section 33(3) leaves discretion to the DPB.
- Section 33(3) mitigation discount — each mitigation posture reduces exposure by 10–20%. Aggregate discount capped at 70%. Mitigations map to the exact statutory factors the DPB must consider: nature of programme, self-reporting, cooperation, no-harm, remediation.
Sources cited: DPDP Act 2023 Schedule (verbatim); Section 33(1) statutory penalty authority; Section 33(3) adjudication factors. Cross-verified against dpdpa.com (Schedule text) and tsaaro.com (penalty framework commentary). Reviewed 24 August 2026.
What this calculator is not: a legal opinion. DPB adjudication is discretionary and case law is developing. Volume factor and mitigation percentages are conservative heuristics, not statutory. For a defensible exposure calculation on your real facts, engage a qualified DPO or advocate — dcomply\'s vDPO service starts at ₹2,499/month.
DPDP fine FAQ
How accurate is this DPDP fine calculator?
It is a directional estimator, not a legal opinion. The Schedule 1 caps are exact (from DPDP Act 2023 as read with Section 33). The volume calibration and mitigation discount are conservative heuristics based on Section 33(3) factors — the DPB has full discretion and case law is still developing. For a defensible exposure calculation on real facts, engage a DPO or advocate.
What are the DPDP Act 2023 Schedule penalty caps?
The Schedule to the DPDP Act 2023 has exactly 7 rows: (1) Sec 8(5) reasonable security safeguards — up to ₹250 Cr; (2) Sec 8(6) breach notification — up to ₹200 Cr; (3) Sec 9 children data obligations — up to ₹200 Cr; (4) Sec 10 SDF additional obligations — up to ₹150 Cr; (5) Sec 15 Data Principal duties — up to ₹10,000; (6) Sec 32 voluntary undertaking breach — as applicable to the underlying breach; (7) any other provision of the Act or Rules — up to ₹50 Cr per instance. Violations not enumerated (invalid consent under Sec 6, DSR failure under Sec 11-14, Consent Manager non-compliance) all fall under Row 7 residual = ₹50 Cr.
Are penalties per violation or per incident?
Per violation, per inquiry. A single incident touching multiple Schedule rows compounds. Example: a breach that involves both failure to secure (Row 1, up to ₹250 Cr) and failure to notify (Row 2, up to ₹200 Cr) can trigger up to ₹450 Cr in maximum aggregate exposure — before Section 33(3) mitigation is applied.
How does the DPB decide the actual penalty within the cap?
Section 33(3) mandates the DPB consider: (a) nature, gravity and duration of violation, (b) type and nature of data affected, (c) repetitive nature, (d) whether gain or loss from the breach, (e) action taken to mitigate, (f) proportionality and effectiveness of the penalty. Companies with documented compliance programmes get materially lower penalties.
Why does company type matter if the caps are the same?
Company type affects likely severity within the cap, not the cap itself. SDFs face higher expected scrutiny because they process at scale and have additional obligations under Section 10 (mandatory DPO, DPIA, independent audit, algorithmic accountability). Consent Managers face similar heightened scrutiny because they are DPB-registered intermediaries with published net-worth and technical criteria (Section 6(9) + DPDP Rules 2025 Rule 4). Their violations tend to attract penalties closer to the applicable cap.
Does having a DPO reduce my penalty exposure?
Yes, materially. A named DPO with a documented consent + DSR + breach + DPIA operating rhythm is the single strongest mitigation factor under Section 33(3)(e). dcomply's vDPO service provides this from ₹2,499/mo for non-SDFs and ₹19,999/mo (advocate-DPO) for SDFs.
What is the "no harm" mitigation factor?
Section 33(3)(d) explicitly considers whether the violation caused demonstrable harm to data principals. If a technical breach occurred but no personal data was exfiltrated, exposed, or misused, the DPB will materially reduce the penalty. Documenting the "no harm" position is a defence artefact.
Can the DPB issue a warning instead of a fine?
Yes for minor first violations, particularly during the 2026 soft-enforcement phase. From 13 May 2027 hard enforcement kicks in and the DPB is expected to apply the full Schedule 1 framework consistently.
Does this cover Consent Manager penalties too?
Yes. The DPDP Act 2023 Schedule does not have a dedicated Consent Manager row, so CM violations fall under Row 7 (any other provision) — up to ₹50 Cr per instance. Selecting "Consent Manager" as company type applies a higher volume-factor multiplier because CMs are DPB-registered intermediaries with heightened scrutiny under Section 6(9) + DPDP Rules 2025 Rule 4.
How do I reduce my exposure quickly?
The five highest-ROI actions: (1) publish a DPDP-compliant privacy notice with grievance officer, (2) stand up a DSR portal, (3) prepare a breach playbook mapped to DPBI + CERT-In, (4) run a DPIA on high-risk processing, (5) sign DPAs with every vendor. dcomply Starter (₹9,999/mo) covers all five.
What if I disagree with the DPB penalty?
Section 29 provides an appeal route to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days. Evidence quality is decisive on appeal — dcomply's EvidenceChain hash-chained log is designed exactly for this.
Is this calculator legal advice?
No. This is an educational estimator produced by Decipher Consultancy Services (dcomply). For a legal opinion on real facts, engage a qualified DPO or advocate. dcomply's vDPO Premium tier includes advocate-DPO retainer starting ₹19,999/mo.
Now you know the number. Here is how you reduce it.
Every action in the mitigation list ships in dcomply — for less than a fraction of a single Schedule 1 penalty.