DPDP Act penalties explained

India's Digital Personal Data Protection Act sets statutory penalties up to ₹250 crores per incident. See what that means for compliance teams.

Published . Updated .

Short answer

The Digital Personal Data Protection Act governs digital personal data in India.

The statute allows penalties up to ₹250 crores per incident for serious non-compliance.

That figure is a statutory maximum, not an AUDIX customer outcome.

What the Act covers

It covers processing of digital personal data of individuals in India.

Organizations must support consent, grievance redressal, and reasonable security safeguards.

Cross-border transfers and purpose limitation also sit in the compliance scope.

Primary rules are published by MeitY as the Digital Personal Data Protection Rules, 2025.

How AUDIX supports DPDP readiness

AUDIX maps DPDP controls to continuous evidence from cloud, identity, and ticketing integrations.

It supports DPO grievance workflows with response tracking.

Residency and transfer posture stay visible in one dashboard.

Security safeguard evidence refreshes from live integrations.

Next steps

Map your stack to DPDP controls before enforcement milestones land.

Pair DPDP work with SOC 2 or ISO 27001 when you sell globally.

Read the Act on India Code, then book a 30-minute AUDIX scoping call.

More articles on the AUDIX GRC blog. Book a demo via contact.