DPDP Act penalties explained
India's Digital Personal Data Protection Act sets statutory penalties up to ₹250 crores per incident. See what that means for compliance teams.
Published . Updated .
Short answer
The Digital Personal Data Protection Act governs digital personal data in India.
The statute allows penalties up to ₹250 crores per incident for serious non-compliance.
That figure is a statutory maximum, not an AUDIX customer outcome.
What the Act covers
It covers processing of digital personal data of individuals in India.
Organizations must support consent, grievance redressal, and reasonable security safeguards.
Cross-border transfers and purpose limitation also sit in the compliance scope.
Primary rules are published by MeitY as the Digital Personal Data Protection Rules, 2025.
How AUDIX supports DPDP readiness
AUDIX maps DPDP controls to continuous evidence from cloud, identity, and ticketing integrations.
It supports DPO grievance workflows with response tracking.
Residency and transfer posture stay visible in one dashboard.
Security safeguard evidence refreshes from live integrations.
Next steps
Map your stack to DPDP controls before enforcement milestones land.
Pair DPDP work with SOC 2 or ISO 27001 when you sell globally.
Read the Act on India Code, then book a 30-minute AUDIX scoping call.
More articles on the AUDIX GRC blog. Book a demo via contact.