# DPDP Penalties Explained: What ₹250 Crore Means for a Small Business

The number sounds terrifying.

₹250 crore.

That's the maximum penalty figure people often mention when talking about India's Digital Personal Data Protection (DPDP) Act.

For a small business, that number can immediately raise a question:

> "If my company makes a privacy mistake, can I really be fined ₹250 crore?"

The short answer is not automatically.

The ₹250 crore figure is a statutory maximum for a particular category of breach. It is not a flat fine that every small business receives after making a privacy mistake.

The actual process is more nuanced.

So, let's break down what DPDP Act penalties actually mean for a small business and, more importantly, what you can do to reduce your risk.

## What Is the ₹250 Crore DPDP Penalty?

The DPDP Act, 2023 includes a Schedule that specifies maximum monetary penalties for different types of breaches.

The largest amount is:

> Up to ₹250 crore

This applies to a breach of the Data Fiduciary's obligation to take reasonable security safeguards to prevent a personal data breach.

The important words here are "may extend to."

That means ₹250 crore is a maximum, not an automatic or minimum penalty.

It does not mean:

> Small business + privacy mistake = ₹250 crore fine.

The circumstances of the breach matter.

## Can a Small Business Be Fined ₹250 Crore?

In principle, the DPDP Act applies to organisations processing digital personal data within its scope.

However, the maximum penalty is not automatically imposed.

The Data Protection Board can impose a monetary penalty after an inquiry if it determines that the breach is significant and after giving the affected person an opportunity of being heard.

The Board must also consider several factors when determining the amount of the penalty.

These can include:

- The nature, gravity and duration of the breach
- The type and nature of personal data affected
- Whether the breach was repetitive
- Whether the organisation gained or avoided a loss
- What mitigation measures were taken
- How quickly and effectively the organisation responded
- Whether the penalty is proportionate and effective
- The likely impact of the penalty on the organisation

So, while the headline number is important, the actual circumstances of the breach are even more important.

## DPDP Penalties at a Glance

| Type of breach | Maximum penalty |
|---|---:|
| Failure to take reasonable security safeguards | Up to ₹250 crore |
| Failure to notify a personal data breach as required | Up to ₹200 crore |
| Breach of additional obligations relating to children | Up to ₹200 crore |
| Breach of Significant Data Fiduciary obligations | Up to ₹150 crore |
| Breach of Data Principal duties | Up to ₹10,000 |
| Breach of other provisions of the Act or Rules | Up to ₹50 crore |

These are maximum amounts, not automatic fines.

That distinction is extremely important for small-business owners.

## What Does "Reasonable Security Safeguards" Mean?

This is one of the most important areas for small businesses.

The law doesn't expect a five-person startup to have exactly the same security infrastructure as a massive technology company.

But that doesn't mean security can be ignored.

If your company stores customer information digitally, you should have reasonable safeguards appropriate to your operations.

For example:

- Strong passwords
- Multi-factor authentication
- Access controls
- Secure databases
- Encryption where appropriate
- Secure API connections
- Regular software updates
- Backup procedures
- Monitoring and logging
- Employee access controls
- Secure handling of customer information

The 2025 DPDP Rules describe security safeguards including measures such as encryption, access controls, monitoring for unauthorised access, logging, backups and other technical and organisational measures.

The goal isn't to buy every cybersecurity product available.

The goal is to avoid leaving customer data unnecessarily exposed.

## What Happens If Your Business Has a Data Breach?

Imagine a small online store.

It has:

- 20 employees
- 15,000 customers
- Customer names
- Phone numbers
- Email addresses
- Order information
- Delivery addresses

One day, an attacker gains access to the database.

That's a personal data breach.

The first reaction shouldn't be:

> "Let's hope nobody notices."

It should be:

> "Contain the breach and understand exactly what happened."

Your incident-response process should quickly answer:

1. What happened?
2. When did it happen?
3. What data was affected?
4. How many people were affected?
5. Is the attacker still inside the system?
6. What systems need to be secured?
7. What evidence needs to be preserved?
8. What notifications are required?

The DPDP framework contains obligations relating to personal-data-breach notification. The 2025 Rules provide further detail concerning notification to affected Data Principals and the Board.

## A Data Breach Does Not Automatically Mean a ₹250 Crore Fine

This distinction is worth repeating.

A breach does not automatically mean ₹250 crore penalty.

The statutory process involves an inquiry and a determination of whether the breach is significant before a monetary penalty is imposed.

The amount is then determined by considering the factors specified under the Act.

Think of ₹250 crore as the top ceiling for one category of breach, not a price tag attached to every security incident.

## What If a Small Business Makes an Honest Mistake?

This is where your compliance record matters.

Imagine two businesses experience similar security incidents.

### Business A

- Has no access controls
- Shares admin passwords
- Has no security process
- Ignores previous warnings
- Doesn't investigate quickly
- Continues the same practices after discovering problems

### Business B

- Uses access controls
- Has multi-factor authentication
- Maintains logs
- Keeps backups
- Detects the incident quickly
- Restricts access
- Investigates immediately
- Takes corrective action
- Documents what happened

These situations are not identical.

The DPDP Act specifically requires consideration of mitigation and the timeliness and effectiveness of actions taken to address the effects and consequences of a breach.

That's why preparation matters.

## Your Compliance Documentation Matters

Small businesses sometimes think:

> "We're too small to need documentation."

That's risky.

If something goes wrong, being able to demonstrate what your organisation was doing can be valuable.

Keep records of things such as:

- Privacy policies
- Data-processing activities
- Consent mechanisms
- Security reviews
- Access-control policies
- Employee training
- Vendor agreements
- Incident-response procedures
- Data-retention practices
- Security updates
- Breach investigations

You don't need a 500-page compliance manual.

You need evidence that your business actually takes data protection seriously.

## What Personal Data Are You Actually Holding?

One of the easiest ways to reduce risk is to stop collecting unnecessary information.

Ask your business:

### Customer Information

Do we really need:

- Full name?
- Phone number?
- Email address?
- Address?
- Date of birth?

### Order Information

Do we need to keep:

- Previous orders?
- Payment-related information?
- Delivery details?

### Marketing Information

Do we need to store:

- Marketing preferences?
- Campaign history?
- Communication records?

The more personal data you collect and retain, the more data you potentially need to protect.

Data minimisation is therefore both a privacy principle and a practical risk-management strategy.

## Don't Keep Customer Data Forever

Another common mistake is indefinite retention.

A customer purchased something from you five years ago.

Do you still need every piece of information associated with that transaction?

Maybe.

Maybe not.

The answer depends on your legal, contractual, operational and business requirements.

But you should know:

> "What data do we keep, and why do we still need it?"

Create retention rules for different categories of data.

For example:

```text
Customer Account Data
        ↓
Active Account
        ↓
Inactive Account
        ↓
Retention Period
        ↓
Delete / Anonymise Where Appropriate