5 min read

Section 33 Explained: Calculating Financial Exposure Under the DPDP Act

An executive guide to Section 33 of the DPDP Act, detailing how the Data Protection Board calculates monetary penalties up to Rs 250 crore and how finance teams measure contingent liability.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Section 33 of the Digital Personal Data Protection Act, 2023 controls how the Data Protection Board of India calculates monetary penalties. The statute rejects the concept of a flat fine for non-compliance. Section 33(1) establishes a strict procedural threshold before any financial penalty applies. The Board must determine that a breach of the Act or its rules is significant on the conclusion of a formal inquiry. The statute requires the Board to provide the person an opportunity of being heard before levying any fine. This structured approach forces the regulatory body to evaluate the exact operational context of a violation. For a Chief Financial Officer, the statute transforms a theoretical regulatory risk into a calculable contingent liability. The final assessment depends entirely on five specific statutory factors. During the inquiry phase, legal teams present evidence defending the operational decisions made prior to the breach. The Board evaluates this defense against the statutory text.

Section 33(2) outlines the exact parameters the Board considers during penalty determination. Under Section 33(2)(a), the Board weighs the nature, gravity, and duration of the breach. IT departments need precise logging tools that record exactly when an unauthorized access event began and ended. The Board penalizes extended breach durations heavily. Section 33(2)(b) requires the Board to examine the type and nature of the personal data affected. A breach exposing extensive financial records or health data carries higher gravity than a leak of basic contact details. Enterprises require updated data maps to prove exactly what data categories were compromised during an incident. The Board uses this classification evidence to scale the penalty appropriately. A long-duration exposure of extensive health records triggers maximum scrutiny under both clauses simultaneously. Legal teams must isolate the exact data fields compromised to prevent the Board from assuming worst-case scenarios.

The Board tracks the compliance history of every enterprise under Section 33(2)(c). A repetitive breach signals systemic negligence to the adjudicating body. First-time offenders face different penalty calculations than entities with a documented history of DPDP Act violations. Financial metrics play a direct role in the assessment through Section 33(2)(d). The Board assesses whether the person realized a gain or avoided a loss as a result of the breach. Finance teams need to document budget allocations for data security and DPDP compliance operations. Demonstrating that the enterprise did not cut compliance budgets to inflate margins removes the avoided loss aggravating factor. The primary defense artifact is a detailed, board-approved compliance budget audit trail. If a fiduciary cancels a vendor contract for encryption software and subsequently suffers a breach, the Board treats that saved expense as an avoided loss. The adjudicating body will increase the monetary penalty to neutralize any financial advantage gained by cutting corners.

Enterprise incident response speed directly impacts the final fine under Section 33(2)(e). The Board measures the timeliness and effectiveness of mitigation actions taken by the enterprise. Chief Financial Officers should provision emergency response budgets for immediate threat containment. The Board uses post-incident forensic reports to verify immediate containment spending and evaluate whether the remediation actually stopped the leak. Organizations need evidence trails proving active mitigation to adjust the penalty down from the maximum statutory ceiling. A delayed response directly increases the eventual monetary penalty assessed by the Board. Finance and legal teams must align their breach response protocols to satisfy this statutory mitigation requirement. Stopping a cyberattack within minutes of detection demonstrates high effectiveness. Failing to isolate a compromised server for days proves a lack of mitigation capability and drives the calculation upward.

The Schedule to the Act sets hard upper limits for specific violations. A failure to implement reasonable security safeguards under Section 8(5) carries a maximum penalty of Rs 250 crore. Failing to notify the Board and affected Data Principals of a personal data breach under Section 8(6) adds a separate potential liability extending to Rs 200 crore. Section 33 dictates how close the final assessment gets to these maximum limits. A failure to act immediately pushes the calculation toward the absolute ceiling. Enterprises processing high volumes of digital personal data face severe financial exposure if they ignore these statutory parameters. The Board does not combine these caps into a single limit for multiple distinct violations. A fiduciary failing both the security safeguard duty and the notification duty faces a combined theoretical maximum of Rs 450 crore. The inquiry process evaluates each failure independently against the factors in Section 33(2).

Section 33 operates alongside the enforcement powers granted in Section 27. When an enterprise submits a breach intimation under Section 8(6), Section 27(1)(a) empowers the Board to direct urgent remedial or mitigation measures. The Board then inquires into the incident and imposes a penalty as provided in the Act. Section 27(1)(b) allows the Board to initiate inquiries based on complaints from a Data Principal. The Board can also act on references from the Central Government, a State Government, or any court direction. This multi-channel reporting structure means the Board will inevitably discover unreported incidents. Ignoring a breach triggers both the Rs 200 crore notification penalty and the base penalty for failing to secure the data. Compliance teams cannot rely on internal silence to avoid regulatory scrutiny. The statutory mandate requires the Board to investigate complaints directly and apply the penalty matrix to confirmed breaches.

The penalty calculation interacts directly with the DPDP Rules, 2025. The Rules require fiduciaries to submit a detailed breach report to the Board within 72 hours of discovery. Missing this 72-hour window provides the Board with immediate grounds to classify the mitigation as ineffective under Section 33(2)(e). Documenting the exact time of discovery becomes a primary operational requirement for IT security teams. Security personnel must integrate timestamped network alerts directly into their legal notification workflows. Without synchronized incident response tools, enterprises risk failing the timeliness test during a Board inquiry. A failure here compounds the overall monetary assessment. Board investigators will request system logs to verify the exact gap between discovery and notification. Any discrepancy between internal IT logs and the official regulatory submission undermines the defense strategy during the formal hearing.

Exactly 252 days remain until the DPDP hard compliance deadline of 13 May 2027. Chief Financial Officers face pressure to finalize their compliance tooling budgets now. Delaying vendor consolidation increases the risk of fragmented reporting during a data breach. Enterprises must build automated evidence trails to prove mitigation effectiveness to the Board before an incident occurs. Finance leaders should require their teams to document specific operational metrics before the enforcement window opens. Organizations can check whether their current incident response and budgeting setup satisfies the mitigation requirements of Section 33 with a targeted gap assessment at freescan.complydp.com. Implementing these audit mechanisms requires cross-department coordination between legal, finance, and information technology. Waiting until a breach happens eliminates any opportunity to prepare a viable defense under the statutory parameters.

Sources

Frequently asked questions

What is the maximum penalty the Data Protection Board can impose?

The Schedule to the Act sets the maximum penalty at Rs 250 crore for failing to take reasonable security safeguards under Section 8(5). Failing to notify a breach under Section 8(6) carries a separate maximum penalty of Rs 200 crore. Section 33 dictates how the Board calculates the exact amount within these limits based on statutory factors.

How does the Board decide the final penalty amount under Section 33?

The Board evaluates specific operational and financial factors listed in Section 33(2). These parameters include the gravity and duration of the breach, the type of personal data involved, and whether the enterprise realized a financial gain by avoiding compliance costs. Timely mitigation directly reduces the final assessment.

Does the Board consider an enterprise's compliance history?

Yes. Section 33(2)(c) requires the Board to evaluate the repetitive nature of the breach. Entities with a documented history of DPDP Act violations face higher penalty calculations than first-time offenders.

How does the 72-hour reporting rule affect penalty calculations?

The DPDP Rules, 2025 require enterprises to report breaches to the Board within 72 hours. Missing this window negatively impacts the timeliness and effectiveness factors under Section 33(2)(e). This delay gives the Board direct statutory grounds to increase the final monetary penalty.

When do these penalty structures take effect?

Exactly 252 days remain until the DPDP hard compliance deadline of 13 May 2027. Enterprises must implement logging and breach response workflows before this date to build the evidence trails required by the Board. Delaying these deployments increases the risk of receiving maximum statutory penalties.