DPDP Penalty Calculator: Estimate Maximum Exposure Under the Act
Contravention by contravention, with the Section 33(2) severity factors.
Methodology & assumptions
This note is published as a working draft so the reasoning is open to scrutiny. The figures and section references come from the tool itself; the interpretation around them has not yet been signed off.
How the result is calculated
Each contravention you select contributes its statutory maximum. The severity slider scales every selected maximum by the same percentage, and the figure shown is the sum. Nothing is sent anywhere: the calculation runs entirely in your browser.
Statutory basis
The five maxima are those in the Schedule to the Act: ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to notify a breach, ₹200 crore for children's-data failures, ₹150 crore for Significant Data Fiduciary failures, and ₹50 crore for breach of any other duty. The severity slider stands for Section 33(2), which requires the Board to weigh the nature, gravity and duration of a contravention before fixing an amount.
Assumptions and limitations
The tool assumes selected contraventions cumulate, and applies one severity percentage to all of them. The Schedule sets ceilings, not tariffs, and the Board has published no penalty under this Act, so there is nothing to calibrate against. Treat the result as an upper bound for planning, not a predicted fine. Information, not legal advice.