Section 33 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 33 is where an inquiry turns into money. It allows the Board to impose a penalty from the Schedule only if, at the end of an inquiry, it determines the breach is significant and after giving the person a hearing. It then lists seven matters the Board must weigh in fixing the amount. If you face a penalty proceeding, our legal dispute resolution team can help you prepare.
Section 33(1): if the Board determines on conclusion of an inquiry that a breach of the Act or the Rules by a person is significant, it may, after an opportunity of being heard, impose the monetary penalty specified in the Schedule. Section 33(2): in fixing the amount it shall have regard to seven matters: nature, gravity and duration; type and nature of data; repetition; gain or avoided loss; mitigation and its timeliness; proportionality and deterrence; and likely impact on the person. Amounts are ceilings ("may extend to") in the Schedule.
Section 33(1): three gates before a penalty
| Gate | Text | Meaning |
|---|---|---|
| Inquiry | "on conclusion of an inquiry" | No penalty without a completed inquiry under section 28 |
| Significant breach | "breach ... by a person is significant" | The Board must determine significance; the Act does not define it |
| Hearing | "after giving the person an opportunity of being heard" | A hearing before penalty, in addition to the natural justice in section 28(6) |
If all three are met, the Board "may" impose "such monetary penalty specified in the Schedule". Note the discretion: "may", not "shall". Note also that the penalty is that "specified in the Schedule": the Board cannot invent a new head or exceed the Schedule's ceiling. The Central Government can amend the Schedule under section 42, but not to more than twice the original amount.
The section applies to "a person", a breach "of the provisions of this Act or the rules made thereunder". It is not confined to Data Fiduciaries: a Consent Manager, a Data Processor, an intermediary or a Data Principal in breach of section 15 can be in scope, because the Schedule has heads for each (item 5 for Data Principal duties).
What "significant" means
The Act does not define it and gives no threshold. The factors in 33(2) are the natural tools for deciding significance, although the text puts them at the stage of fixing the amount. Expect the Board to look at how many people were affected, what data it was, how long it lasted and what the fiduciary did. Do not assume that a small incident escapes: the test is the Board's determination on the facts.
Section 33(2): the seven matters
| Clause | Matter | What to prepare |
|---|---|---|
| (a) | Nature, gravity and duration of the breach | A timeline with start, detection and end dates; root cause |
| (b) | Type and nature of the personal data affected | Data inventory showing categories; flags for sensitive or children's data |
| (c) | Repetitive nature of the breach | History of earlier incidents and complaints and what changed |
| (d) | Whether the person, as a result of the breach, realised a gain or avoided any loss | Evidence of whether any benefit flowed or cost was saved |
| (e) | Whether the person took action to mitigate the effects and consequences, and the timeliness and effectiveness of that action | Dated records of containment, notices, remedies |
| (f) | Whether the penalty is proportionate and effective, having regard to the need to secure observance of and deter breach of the Act | Submissions on proportionality |
| (g) | Likely impact of the penalty on the person | Financial and operational information, supplied honestly |
The words "shall have regard to" make the list mandatory considerations. The Act does not give weights, nor say that one factor outweighs another, nor say that the list is exhaustive.
How to use the factors
- (a), (b): Facts you cannot change, so the focus is accuracy. Do not minimise.
- (c): If there was a prior incident, show the corrective action that followed and why this one is different.
- (d): Noting "gain realised or loss avoided" points at cases where a fiduciary saved on safeguards or profited from data use.
- (e): The most controllable factor. Quick, documented containment and communication is directly relevant. Note that the duty to intimate a breach to the Board and to affected Data Principals is in section 8(6); failing to do so is itself a separate breach under item 2 of the Schedule.
- (f), (g): An appeal to fairness and to proportion. The Board is directed to consider deterrence as well, so an argument based only on inability to pay may not carry the whole case.
Link to the Schedule
The amounts are in the Schedule, which section 33(1) refers to. In short, the ceilings range from ten thousand rupees for a Data Principal's duties up to two hundred and fifty crore rupees for a failure of reasonable security safeguards. See the Schedule for each item. Nothing in section 33 says that the ceiling is the usual penalty; the Board fixes the amount up to the ceiling using the section 33(2) factors.
What happens to the money
Section 34: all sums realised by way of penalties are credited to the Consolidated Fund of India. They do not go to the complainant. See sections 34 to 36.
Challenging a penalty order
A penalty order is an order of the Board; any person aggrieved may appeal to the Appellate Tribunal within sixty days of receipt under section 29. Section 39 bars civil courts. See section 29.
Related routes that can reduce exposure
- Voluntary undertaking (section 32): can bar proceedings on its contents; breach returns exposure up to the original ceiling.
- Mediation (section 31): the Board may direct it.
- Closure (section 28(11)): the Board may close the proceedings at the end of an inquiry instead of moving to section 33.
Common mistakes
- Assuming the maximum is automatic, or assuming no penalty for small incidents.
- Leaving mitigation records to memory; clause (e) looks at timeliness.
- Skipping the hearing stage or answering only in writing without evidence.
- Forgetting that repeated breaches count against you under clause (c).
- Ignoring the Rules, which carry detail on the matters the Act leaves to be prescribed.
Example
A company suffers a breach caused by weak access controls. It detected the incident quickly, contained it, informed those affected and fixed the controls. The Board finds the breach significant. In fixing the amount it weighs the data involved, the duration, the absence of repetition, the company's mitigation and its capacity to pay. The figure is below the ceiling of item 1.
Need help facing a penalty proceeding?
The record you build before and during an inquiry shapes the factors the Board weighs. Our legal dispute resolution team can help you assemble the evidence on mitigation and proportionality and plan for appeal.
Key takeaways
- A penalty needs a concluded inquiry, a finding of significant breach and a hearing.
- The Board imposes the penalty specified in the Schedule; amounts are ceilings.
- Seven factors in section 33(2) must be considered.
- Mitigation and its timeliness are within your control.
- Penalties go to the Consolidated Fund of India; appeals lie to the Appellate Tribunal.
Read next
- Schedule to the DPDP Act, 2023: penalties
- Sections 34, 35 and 36: penalties fund, good faith and power to call for information
- Section 32 of the DPDP Act, 2023: voluntary undertaking
- Penalties under the DPDP Act
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
