Erasure

Blog

Written by the Erasure product and engineering team

DPDP Penalties: What the ₹250 Crore Cap Means for Startups

India's DPDP Act caps penalties at ₹250 crore per violation, with enforcement expected from May 2027. Here is how the penalty regime actually works and what it means for product companies.

India's DPDP Act carries a penalty regime with a headline number that scares everyone: up to ₹250 crore per violation under Section 33. The rules were notified in November 2025, and enforcement is expected to begin around May 2027. For startups the number feels abstract, so let's make it concrete: what triggers penalties, how the Board decides, and what the realistic exposure is for a product company that does nothing.

This is not legal advice. It is an operational read of the penalty framework, written for founders and engineers who need to price the risk.

The structure of the penalty regime

The DPDP Act does not have a flat fine schedule like a traffic ticket. Section 33 sets a maximum of ₹250 crore for violations of specified provisions, and the Data Protection Board determines the actual amount based on the nature, gravity, and duration of the breach, plus whether the fiduciary cooperated.

What that means in practice: the ₹250 crore figure is a ceiling, not a default. But the ceiling matters because it changes the conversation. Under the old IT Act regime, the effective maximum for most violations was ₹5 crore. The DPDP Act raises the stakes by two orders of magnitude, and it also removes the criminal penalty that existed for certain violations under Section 72A, replacing it with this civil regime.

What triggers the big numbers

The provisions that carry the highest penalty exposure are the ones that sit closest to product teams:

  • Failure to take reasonable security safeguards to prevent a breach
  • Failure to notify the Data Protection Board of a breach within the prescribed timeline (72 hours under the Rules)
  • Non-compliance with orders of the Board
  • Processing personal data without consent where consent is required

Notice what is missing from that list: there is no penalty for having a weak privacy policy. The penalties attach to operational failure, to not securing data, not reporting breaches, and processing without a lawful basis. That is an important reframe for anyone who thought compliance was a documents exercise.

The consent penalty is the startup-relevant one

For most Indian product companies, the most likely penalty trigger is not a mega-breach. It is consent failure: collecting and processing personal data without valid consent, or failing to honour withdrawal, or failing to provide the notice the Act requires.

The good news is that consent failure is the most fixable category, because it is an engineering problem. You need consent collection that meets the five Section 6 conditions (free, specific, informed, unconditional, unambiguous), a withdrawal path as easy as the consent path, and receipts that prove what the user saw and chose.

Enforcement timing: the May 2027 expectation

The timeline matters more than the numbers. The DPDP Rules were notified November 13, 2025. The Data Protection Board was constituted as part of that. The Consent Manager registration window opens November 2026. Full penalty enforcement is expected to begin around May 2027.

That is the window. Companies that treat 2026 as a planning year are making a bet that enforcement will slip. It might, but the history of GDPR tells you what happens to that bet: the first few years saw headline fines land on companies that treated the transition period as optional.

What GDPR's experience suggests

Europe's GDPR is the closest analogue, and its enforcement history is instructive even though the regimes differ. GDPR fines have run into the hundreds of millions of euros, and the early enforcement years showed two patterns:

  • Regulators started with the highest-profile, highest-volume offenders, not the small fry
  • The fines that made headlines were for systemic failure (poor security, unlawful processing at scale), not for paperwork gaps

Translated to India: the Board is likely to start with significant data fiduciaries, large consumer platforms, and breaches involving sensitive data. But the mechanism, once built, applies to everyone. The cost of building consent and deletion machinery is the same whether you are a two-person startup or a unicorn; the penalty exposure is not.

The realistic risk calculus for a startup

Let's be honest about the range of outcomes:

| Scenario | Likely consequence | |----------|-------------------| | You do nothing until enforcement begins | Highest exposure; remediation under a regulator's gaze is expensive and slow | | You build notice + consent + deletion basics this year | Most operational risk retired; residual risk is mostly around scale and edge cases | | You build the full loop including evidence and audit | Defensible position; you can show what happened, which changes how any inquiry goes |

The middle path is the pragmatic one for most startups: build the operational machinery now, while the enforcement clock is still running, and treat the remaining exposure as insurance against scale.

Where the work actually is

The penalty regime rewards one thing above all: being able to show what happened. A breach notification with a clear account of scope, affected systems, and remediation is a different conversation than a breach discovered by the Board. A consent record that reconstructs what a user saw in July 2025 is a different conversation than "we don't have that anymore."

That is why Erasure exists. The platform operationalizes the loop: consent with immutable receipts in Accord, deletion requests with verification and durable jobs in Rights, data inventory in Data Maps, fulfilment across Postgres, MySQL, HTTP, and Webhook systems, and exportable evidence throughout. It is invite-only in beta, with pricing that starts at ₹0 and a Starter tier at ₹999/month.

The bottom line

The ₹250 crore cap is real, but the way to read it is not as a threat. It is a signal that operational privacy work now has legal teeth, and that the cheapest time to build the machinery is before enforcement starts. The penalties are priced for the worst cases; your job is to not be one.

Start with the work that reduces the most risk per hour: consent with proof, a deletion workflow, and a data inventory. Our compliance checklist is the itemized version, and the DPDP Rules explainer covers what the Rules require in detail.

About this post

Written by the Erasure product and engineering team

Published 24 July 2026

This article is grounded in Erasure's product documentation and explains engineering and operational implications. Where it discusses regulation, it is not legal advice. See our editorial policy.

← All posts · Docs