Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 33 of the Digital Personal Data Protection Act, 2023: Monetary penalty and the factors to consider

Section 33(1): if the Board determines on conclusion of an inquiry that a breach of the Act or the Rules by a person is significant, it may, after an opportunity of being heard...

Published
Updated
Reading time
7 min
Views
10
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 10, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 33 is where an inquiry turns into money. It allows the Board to impose a penalty from the Schedule only if, at the end of an inquiry, it determines the breach is significant and after giving the person a hearing. It then lists seven matters the Board must weigh in fixing the amount. If you face a penalty proceeding, our legal dispute resolution team can help you prepare.

Section 33(1): three gates before a penalty

GateTextMeaning
Inquiry"on conclusion of an inquiry"No penalty without a completed inquiry under section 28
Significant breach"breach ... by a person is significant"The Board must determine significance; the Act does not define it
Hearing"after giving the person an opportunity of being heard"A hearing before penalty, in addition to the natural justice in section 28(6)

If all three are met, the Board "may" impose "such monetary penalty specified in the Schedule". Note the discretion: "may", not "shall". Note also that the penalty is that "specified in the Schedule": the Board cannot invent a new head or exceed the Schedule's ceiling. The Central Government can amend the Schedule under section 42, but not to more than twice the original amount.

The section applies to "a person", a breach "of the provisions of this Act or the rules made thereunder". It is not confined to Data Fiduciaries: a Consent Manager, a Data Processor, an intermediary or a Data Principal in breach of section 15 can be in scope, because the Schedule has heads for each (item 5 for Data Principal duties).

What "significant" means

The Act does not define it and gives no threshold. The factors in 33(2) are the natural tools for deciding significance, although the text puts them at the stage of fixing the amount. Expect the Board to look at how many people were affected, what data it was, how long it lasted and what the fiduciary did. Do not assume that a small incident escapes: the test is the Board's determination on the facts.

Section 33(2): the seven matters

ClauseMatterWhat to prepare
(a)Nature, gravity and duration of the breachA timeline with start, detection and end dates; root cause
(b)Type and nature of the personal data affectedData inventory showing categories; flags for sensitive or children's data
(c)Repetitive nature of the breachHistory of earlier incidents and complaints and what changed
(d)Whether the person, as a result of the breach, realised a gain or avoided any lossEvidence of whether any benefit flowed or cost was saved
(e)Whether the person took action to mitigate the effects and consequences, and the timeliness and effectiveness of that actionDated records of containment, notices, remedies
(f)Whether the penalty is proportionate and effective, having regard to the need to secure observance of and deter breach of the ActSubmissions on proportionality
(g)Likely impact of the penalty on the personFinancial and operational information, supplied honestly

The words "shall have regard to" make the list mandatory considerations. The Act does not give weights, nor say that one factor outweighs another, nor say that the list is exhaustive.

How to use the factors

  • (a), (b): Facts you cannot change, so the focus is accuracy. Do not minimise.
  • (c): If there was a prior incident, show the corrective action that followed and why this one is different.
  • (d): Noting "gain realised or loss avoided" points at cases where a fiduciary saved on safeguards or profited from data use.
  • (e): The most controllable factor. Quick, documented containment and communication is directly relevant. Note that the duty to intimate a breach to the Board and to affected Data Principals is in section 8(6); failing to do so is itself a separate breach under item 2 of the Schedule.
  • (f), (g): An appeal to fairness and to proportion. The Board is directed to consider deterrence as well, so an argument based only on inability to pay may not carry the whole case.

Link to the Schedule

The amounts are in the Schedule, which section 33(1) refers to. In short, the ceilings range from ten thousand rupees for a Data Principal's duties up to two hundred and fifty crore rupees for a failure of reasonable security safeguards. See the Schedule for each item. Nothing in section 33 says that the ceiling is the usual penalty; the Board fixes the amount up to the ceiling using the section 33(2) factors.

What happens to the money

Section 34: all sums realised by way of penalties are credited to the Consolidated Fund of India. They do not go to the complainant. See sections 34 to 36.

Challenging a penalty order

A penalty order is an order of the Board; any person aggrieved may appeal to the Appellate Tribunal within sixty days of receipt under section 29. Section 39 bars civil courts. See section 29.

Related routes that can reduce exposure

  • Voluntary undertaking (section 32): can bar proceedings on its contents; breach returns exposure up to the original ceiling.
  • Mediation (section 31): the Board may direct it.
  • Closure (section 28(11)): the Board may close the proceedings at the end of an inquiry instead of moving to section 33.

Common mistakes

  1. Assuming the maximum is automatic, or assuming no penalty for small incidents.
  2. Leaving mitigation records to memory; clause (e) looks at timeliness.
  3. Skipping the hearing stage or answering only in writing without evidence.
  4. Forgetting that repeated breaches count against you under clause (c).
  5. Ignoring the Rules, which carry detail on the matters the Act leaves to be prescribed.

Example

A company suffers a breach caused by weak access controls. It detected the incident quickly, contained it, informed those affected and fixed the controls. The Board finds the breach significant. In fixing the amount it weighs the data involved, the duration, the absence of repetition, the company's mitigation and its capacity to pay. The figure is below the ceiling of item 1.

Need help facing a penalty proceeding?

The record you build before and during an inquiry shapes the factors the Board weighs. Our legal dispute resolution team can help you assemble the evidence on mitigation and proportionality and plan for appeal.

Key takeaways

  • A penalty needs a concluded inquiry, a finding of significant breach and a hearing.
  • The Board imposes the penalty specified in the Schedule; amounts are ceilings.
  • Seven factors in section 33(2) must be considered.
  • Mitigation and its timeliness are within your control.
  • Penalties go to the Consolidated Fund of India; appeals lie to the Appellate Tribunal.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 33

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does every breach attract a penalty?

No. The Board must determine that the breach is significant, after an inquiry and a hearing.

Who decides the amount?

The Board, up to the Schedule's ceiling, having regard to the factors in section 33(2).

Keep your documents in an order a stranger could follow — one day an officer or auditor will have to.

— TaxClue Compliance Desk

Section 33: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. The Board must determine that the breach is significant, after an inquiry and a hearing.

The Board, up to the Schedule's ceiling, having regard to the factors in section 33(2).

The Schedule says "may extend to", so it is a ceiling for each item.

Seven: nature, gravity and duration; type of data; repetition; gain or avoided loss; mitigation and its timeliness; proportionality and deterrence; impact on the person.

Yes, to the Appellate Tribunal within sixty days of receipt (section 29).

No. Section 34 credits it to the Consolidated Fund of India.