Skip to main content
Section 33 DPDP Act: Penalties | AIZZENTEC — page loaded
DPDP Act, 2023 · Chapter VIII

Section 33Penalties

The text of Section 33 of the Digital Personal Data Protection Act, 2023, as published in the Gazette of India, Extraordinary, Part II — Section 1, under the chapter on penalties and adjudication.

Bare Act

Section 33 as published in the Gazette of India

(1) If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.

(2) While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:—

(a) the nature, gravity and duration of the breach;

(b) the type and nature of the personal data affected by the breach;

(c) repetitive nature of the breach;

(d) whether the person, as a result of the breach, has realised a gain or avoided any loss;

(e) whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;

(f) whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and

(g) the likely impact of the imposition of the monetary penalty on the person.

The Schedule

[See section 33(1)]

Sl. No.Breach of provisions of this Act or rules made thereunderPenalty
1Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8.May extend to two hundred and fifty crore rupees.
2Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8.May extend to two hundred crore rupees.
3Breach in observance of additional obligations in relation to children under section 9.May extend to two hundred crore rupees.
4Breach in observance of additional obligations of Significant Data Fiduciary under section 10.May extend to one hundred and fifty crore rupees.
5Breach in observance of the duties under section 15.May extend to ten thousand rupees.
6Breach of any term of voluntary undertaking accepted by the Board under section 32.Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted.
7Breach of any other provision of this Act or the rules made thereunder.May extend to fifty crore rupees.

Source. Digital Personal Data Protection Act, 2023 (Act 22 of 2023, assented 11 August 2023), published in the Gazette of India, Extraordinary, Part II — Section 1. Reproduced verbatim. This page is a reference, not legal advice, and no advisor–client relationship arises from reading it.

Our practitioner note on what Section 33 asks of an organisation is on the Act & Rules reader, alongside the provisions it works with.
All sections, rules and schedules

Need to know what this means for your organisation?

The authoritative text is the one published in the Gazette of India.