Skip to main content

Free estimator

DPDP penalty exposure calculator

See which penalty heads under the DPDP Act you are exposed to, and what the ceiling looks like for your organisation.

Run it now

Answer the questions and you get the number, the working behind it and what we would do about it. The calculation itself runs in your browser, so your answers stay with you.

What you tell it

  • Categories of personal data you process, including any children's data
  • Whether you are likely to be notified as a Significant Data Fiduciary
  • Current state of consent, notice and breach response
  • Number of data principals on your books

What you get back

  • The penalty heads in the Schedule that apply to you
  • Maximum exposure per head, and the aggregate
  • Which gaps carry the largest single penalty, ranked
  • The three controls that close the most exposure for the least work

How the number is worked out

  1. 1

    Penalty heads and ceilings come straight from the Schedule to the Digital Personal Data Protection Act 2023.

  2. 2

    We map each head to the control that prevents it, so the output is a work list rather than a scare.

  3. 3

    Children's data and Significant Data Fiduciary obligations are scored separately, because they carry their own duties.

  4. 4

    No multiplier is applied for turnover. The Act sets fixed ceilings per breach type.

Where this stops being useful

The ceiling is not the expected fine. The Data Protection Board weighs the nature of the breach, whether it was repeated and what you did about it. This is a picture of exposure, not a forecast.

How the penalties are actually structured

The DPDP Act 2023 attaches financial penalties to specific failures rather than applying one figure to any breach, and the distinction matters when you are estimating exposure.

The largest penalty attaches to failing to take reasonable security safeguards to prevent a personal data breach. That is the one most organisations model, and it is worth noting the wording: the failure penalised is the absence of safeguards, not the occurrence of a breach. An organisation that can demonstrate reasonable safeguards is in a materially different position from one that cannot, even after the same incident.

Separate penalties attach to failing to notify the Board and affected data principals, to failures around children's data, to failures by Significant Data Fiduciaries in their additional obligations, and to breaching any other provision.

The Board determines the amount having regard to the nature and gravity of the breach, the type of data affected, whether it was repetitive, whether gains were made or losses avoided, what mitigation was taken and how quickly, and whether the penalty is proportionate. Several of those are within your control after an incident, which is the practical argument for having a response process.

What this calculator can and cannot tell you

It gives you an order of magnitude for board conversation. It cannot predict an enforcement outcome, and any tool claiming to is selling certainty that does not exist in a regime this new.

What it is genuinely useful for is comparison. The exposure attached to holding a category of data you do not need, against the cost of deleting it, is a decision that gets made informally and badly in most organisations. Putting a number on both sides changes the conversation.

It also exposes the cost of poor inventory. If you cannot say how many data principals' records you hold, you cannot estimate exposure, and that inability is itself the most urgent finding.

The mitigations that move the number most

  • Deleting data past its purpose, which reduces both the affected population and the gravity
  • Reducing the categories held, since sensitive categories weigh heavier in gravity
  • A documented, rehearsed breach notification process with a named decision maker
  • Demonstrable security safeguards, which addresses the largest penalty head directly
  • Processor contracts that carry the obligations forward, since you remain accountable
  • Evidence that controls operated, not merely that they existed

What to do with the output

Take it to whoever owns risk, not to whoever owns security. Penalty exposure is a business risk with a technical cause, and it is the framing that unlocks budget where a control gap discussion does not.

Then pair it with a retention decision. In most estates the fastest reduction available is deleting personal data that is past its purpose, and it costs engineering time rather than licence spend.

Then make sure the notification process exists, because it is the one obligation where the penalty attaches to your response rather than to the incident, and it is a page of writing and a named person.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.