Section 33 as published in the Gazette of India
(1) If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule.
(2) While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:—
(a) the nature, gravity and duration of the breach;
(b) the type and nature of the personal data affected by the breach;
(c) repetitive nature of the breach;
(d) whether the person, as a result of the breach, has realised a gain or avoided any loss;
(e) whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action;
(f) whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and
(g) the likely impact of the imposition of the monetary penalty on the person.
The Schedule
[See section 33(1)]
| Sl. No. | Breach of provisions of this Act or rules made thereunder | Penalty |
|---|---|---|
| 1 | Breach in observing the obligation of Data Fiduciary to take reasonable security safeguards to prevent personal data breach under sub-section (5) of section 8. | May extend to two hundred and fifty crore rupees. |
| 2 | Breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8. | May extend to two hundred crore rupees. |
| 3 | Breach in observance of additional obligations in relation to children under section 9. | May extend to two hundred crore rupees. |
| 4 | Breach in observance of additional obligations of Significant Data Fiduciary under section 10. | May extend to one hundred and fifty crore rupees. |
| 5 | Breach in observance of the duties under section 15. | May extend to ten thousand rupees. |
| 6 | Breach of any term of voluntary undertaking accepted by the Board under section 32. | Up to the extent applicable for the breach in respect of which the proceedings under section 28 were instituted. |
| 7 | Breach of any other provision of this Act or the rules made thereunder. | May extend to fifty crore rupees. |
Source. Digital Personal Data Protection Act, 2023 (Act 22 of 2023, assented 11 August 2023), published in the Gazette of India, Extraordinary, Part II — Section 1. Reproduced verbatim. This page is a reference, not legal advice, and no advisor–client relationship arises from reading it.