Skip to content
checkDPDP

DPDP Tools · Free

DPDP Penalty Exposure Calculator

Pick the violations that apply, layer Section 33(2) aggravating and mitigating factors, and see your statutory cap plus a realistic enforcement estimate. Built from Schedule 1 of the DPDP Act 2023. Board-ready output. No signup.

Security (Section 8) · ₹250 cr cap

5 possible violations in this band

Children's Data (Section 9) · ₹200 cr cap

3 possible violations in this band

Breach Notification (Section 8(6)) · ₹200 cr cap

4 possible violations in this band

SDF Obligations (Section 10) · ₹150 cr cap

4 possible violations in this band

General Non-Compliance · ₹50 cr cap

7 possible violations in this band

Aggravating factors · Section 33(2)

Each factor selected pushes the realistic estimate toward the cap.

Mitigating factors · Section 33(2)

Each factor selected reduces the realistic estimate.

No data leaves your browser. The calculation runs locally.

How this works

The maths behind the estimate

Statutory cap (upper bound)

Each Schedule 1 entry is a cap per failure. The "statutory cap" figure adds the cap of each violation you select. This is the maximum the Data Protection Board could levy in theory if every gravity factor goes against you and every mitigation is ignored.

Realistic estimate (centre of mass)

For each violation the calculator multiplies its cap by an empirical gravity factor (30–60 % of cap depending on category), then applies the Section 33(2) aggravators and mitigators you select. The result is a more realistic "centre of mass" for an enforcement action — not legal advice, not a forecast.

Why it exists

The board conversation that this calculator is designed to support

Quantify before you prioritise

A ₹250 cr Section 8 cap moves a Board agenda differently than a ₹50 cr residual finding. Pick your remediation order from the realistic number, not the cap.

Compare to remediation cost

A ₹6 lakh banner / DPA / consent log spend that closes a ₹50 cr cap is the easiest board-approval you will ever ask for. Use the estimate as the denominator.

Drive the SDF / DPO conversation

If your selected violations cross the ₹150 cr SDF band, the case for an India-resident DPO and an independent audit writes itself.