DPDPA compliance, built under privilege — not bolted on after.
A standalone compliance vendor hands you a gap report and walks away. We run the same technical audit — consent architecture, data-flow mapping, breach readiness — directed by retained counsel, so the findings and the fix are backed by an attorney who can also stand in front of your board, your investors, or the Data Protection Board if it comes to that.
Getting the penalty figure right
₹250 crore is the statutory maximum. ₹500 crore is what happens when the Board enhances it.
Some DPDPA content states a flat "₹500 crore maximum fine" without the mechanism behind it. That figure is real, but it's not the base ceiling — it's what Section 33(3) permits the Data Protection Board to reach by doubling a penalty in serious or repeat cases. The Act's Schedule sets the base statutory maximum per violation category at ₹250 crore, specifically for failure to implement reasonable security safeguards leading to a personal data breach; other categories — failure to notify the Board of a breach, failure to meet children's-data obligations, non-compliance by a Significant Data Fiduciary — carry their own, generally lower, base caps.
The distinction matters because it changes what a client should actually expect. Presenting ₹500 crore as the standard exposure overstates the routine case and, just as importantly, understates the genuinely worst-case one: because penalties for separate violation categories can stack, a breach combined with a failure to notify the Board can produce combined exposure that exceeds either the ₹250 crore or the enhanced ₹500 crore figure taken alone. The honest framing is: ₹250 crore is the number that applies to a single serious lapse; the real tail risk sits in the compounding of several lapses at once, which is precisely what a properly scoped audit is built to prevent by catching the individual gaps before they combine.
None of this changes the core argument for a privileged audit: whether the eventual exposure is ₹250 crore, ₹500 crore, or a stacked combination, the finding that reveals the gap is the same document a regulator or opposing counsel would want to see in a later dispute — which is exactly why how that document is produced matters as much as what it says.
Evidence, not guesswork
The Schedule, in full — not just the headline figure
What actually triggers each penalty category, and how the enhancement mechanism works.
| Violation category | Base statutory maximum | Trigger |
|---|---|---|
| Inadequate security safeguards | ₹250 Cr | Failure to implement reasonable safeguards, resulting in a breach — no materiality threshold |
| Breach notification failure | ₹200 Cr | Failure to notify the Board and affected Data Principals of a breach |
| Children's data violations | ₹200 Cr | Failure to obtain verifiable parental consent, or prohibited tracking/targeted advertising to children |
| Significant Data Fiduciary non-compliance | ₹150 Cr | Failure to meet heightened SDF obligations — DPO appointment, impact assessments, audits |
| Data Principal rights failures | ₹50 Cr | Failure to honour access, correction, erasure, or grievance-redressal requests |
| Other Data Fiduciary obligations | ₹50 Cr | Residual category — consent failures, notice failures, purpose-limitation breaches |
Source: DPDP Act 2023, Section 33 and the Schedule; Section 33(3) permits Board enhancement up to 2x for serious or repeat violations. Figures reflect the base Schedule maximums; actual penalties are discretionary and depend on the six factors in Section 33(2). Confirm current interpretation with counsel before relying on any specific figure for a live matter.
What the numbers actually mean
Four figures that frame DPDPA compliance today
Per Schedule item — the ceiling for inadequate security safeguards leading to a breach, before any enhancement.
The Board's power to double a penalty for serious or repeat cases — the actual source of the ₹500 Cr figure.
Operative date for most substantive obligations — the anchor most compliance timelines are built backward from.
From gap assessment to board-ready certification for most mid-market organisations.
The privilege gap
Your gap report can be used against you
Most organisations buy a DPDPA compliance audit the same way they'd buy a website audit — from a consultant or a boutique GRC vendor. That approach has a structural weakness that only becomes visible after a breach or a regulatory inquiry.
Standard vendor audit
- A gap-assessment report from an independent consultant is generally not covered by legal privilege, and may be discoverable by a regulator or opposing counsel in a later dispute.
- Findings are handed over as a technical document, with no assessment of how each gap translates into regulatory or litigation exposure.
- Remediation advice addresses the technical fix only — not whether the fix is legally sufficient to satisfy the Act's requirements.
- If a breach follows, your own audit trail can become evidence of a known, unaddressed gap.
SIRI privileged model
- The technical audit is scoped, directed, and reported to retained counsel as part of a legal engagement, extending the same privilege doctrine used for legal work to the technical findings.
- One integrated report addresses both the technical gap and its regulatory consequence, in language your board and your regulator can both work with.
- An attorney — not only an engineer — signs off on your board-readiness position.
- If a matter later goes to a regulator or a court, the same team that ran the audit can represent you.
Core capabilities
What the engagement actually delivers
Provisions below are described in general terms. Specific section citations are finalised with retained counsel before any deliverable is issued to a client or regulator.
Consent & Notice Architecture
Multilingual consent flows and notice language built to the Act's consent standard, not a cookie banner retrofit. Reviewed jointly by counsel and the technical team before it ships.
Data Principal Rights Workflow
Access, correction, erasure, and grievance-redressal processes mapped end-to-end, with response-time tracking built into your existing systems rather than a separate spreadsheet.
Breach Notification Readiness
A board-approved breach response playbook aligned to your CERT-In notification window and your obligations toward the Data Protection Board, drafted before you need it.
Attorney-Directed Penetration Testing
A technical assessment of the systems that actually process personal data, scoped and reported under the legal engagement described above, not a standalone vendor report.
Significant Data Fiduciary Assessment
Evaluation against the Act's heightened obligations for high-volume or high-risk processing, including whether any additional audit, DPO, or impact-assessment requirements apply to your organisation.
Board Certification Pack
A single sign-off document for your board and investors — legal opinion and technical audit result in one file, not two reports that don't reference each other.
Engagement methodology
From first call to board certification
Privileged Scope & Discovery
The engagement opens as an attorney-client relationship. Your data flows, vendor list, and processing activities are mapped under privilege before any technical work starts.
Technical & Legal Audit
Penetration testing, data-flow mapping, and consent-architecture review run alongside legal gap analysis — one workstream, not two sequential ones.
Remediation & Drafting
Findings translate directly into fixed consent flows, updated policies, and a prioritised technical remediation roadmap, not a PDF of recommendations nobody actions.
Board Certification
A single sign-off pack — legal opinion plus technical evidence — ready for your board, your investors, or a regulator to review.
In practice
This is what the audit actually looks like
One real engagement, run the way described above.
HealthTech — DPDPA Compliance
Zero critical findings, on schedule
A Series B HealthTech company had investor due diligence eight weeks away and an unaudited DPDPA posture. The compliance review closed with zero critical findings, on schedule — a result made possible by running the technical and legal workstreams in parallel from the first week rather than sequencing a technical audit followed by a separate legal review.
Why SIRI
DPDPA compliance with legal weight behind every finding
The difference isn't just expertise — it's the legal authority behind every report and every recommendation.
Findings structured for privilege
Technical audit findings are scoped and directed by retained counsel from the outset, giving them the best available claim to attorney-client privilege protection under Section 132, BSA 2023.
Accurate exposure figures
We tell clients the difference between the ₹250 Cr base cap and the ₹500 Cr enhanced ceiling, and what actually triggers each — not a flattened headline number that overstates the routine case.
Same team, audit to defence
If a matter later goes to the Data Protection Board or a court, the same attorneys and technical specialists who ran your audit represent you — no hand-off gap, no re-briefing.
We tell you if you don't need us
For lower-risk organisations, a standard consultant audit may genuinely be sufficient. We say so during the scoping call rather than selling the larger engagement regardless.
Frequently asked
Questions we answer before every DPDPA engagement
Do we actually need a privileged audit, or is a standard consultant enough?
Depends on your risk profile. If you process sensitive personal data at scale, are heading into investor due diligence, or have any history of a security incident, the privilege question stops being theoretical — a discoverable gap report becomes evidence against you if something goes wrong later. For lower-risk organisations, a standard consultant audit may be sufficient. We tell you honestly which category you're in during the scoping call, not just sell you the bigger engagement.
What is the actual maximum penalty under the DPDPA, and is it ₹250 crore or ₹500 crore?
The base statutory maximum per Schedule item is ₹250 crore, specifically for failure to implement reasonable security safeguards leading to a personal data breach. Section 33(3) allows the Data Protection Board to enhance a penalty by up to two times in serious or repeat cases, which is where the ₹500 crore figure some content cites actually comes from — it is an enhanced outcome under aggravating circumstances, not the standard ceiling. Separately, penalties for different violation categories can stack: a breach combined with a failure to notify could attract exposure well beyond either figure alone. Both numbers are real; conflating them without the distinction overstates the routine exposure and understates the worst-case one.
What does "Significant Data Fiduciary" mean, and does it apply to us?
The Act sets a higher bar of obligations — additional audits, DPO appointment, impact assessments — for entities processing personal data at a volume or sensitivity the government designates as significant. Whether your organisation meets that threshold depends on criteria set by government notification, which we confirm as part of the initial assessment rather than assuming either way.
How long does a full DPDPA compliance programme take?
For most mid-market organisations, 8 to 12 weeks from gap assessment to board-ready certification, though this varies with the complexity of your data flows and how many vendor and cross-border transfers are involved. Legal and technical work run in parallel rather than in sequence, which is what keeps the timeline where it is.
Is our penetration test report protected if we're later investigated?
When testing is scoped and directed by retained counsel as part of a legal engagement, the resulting report can carry attorney-client privilege protection under Section 132 of the Bharatiya Sakshya Adhiniyam 2023, the provision that now governs this privilege, consolidating what was previously Section 126 of the Indian Evidence Act 1872. This is fact-dependent on how the engagement is actually structured, not automatic from hiring a law firm. Your retained counsel will confirm the specific protection that applies to your engagement.
Can you certify us for investor due diligence?
Yes — the Board Certification Pack is built for exactly this: a single document combining the legal opinion and technical audit result that your investors' counsel can review directly, rather than two disconnected reports they have to reconcile themselves.
What happens if the audit finds something serious?
It gets fixed, and how we handle disclosure — to a board, an investor, or a regulator — is a legal judgment made with you, not a default assumption. That's a large part of why the audit is attorney-directed in the first place: a standalone technical vendor has no framework for that decision. This is general information and not legal advice on your specific situation; talk to us directly about what you're facing.
Ready when you are
Every day without integrated cover is a day of open exposure.
Breach response, DPDPA compliance, or an ongoing retainer — the gap between your legal exposure and your security posture closes with one call. Not next quarter. Today.
Related services
Other ways SIRI Law LLP supports your compliance posture
Cybersecurity GRC & compliance
All nine frameworks we cover, under one privileged engagement.
Data privacy & cybersecurity law
The underlying legal practice behind DPDPA advisory and breach response.
SIRI Shield retainer
Continuous DPDPA monitoring built into a fixed monthly legal and security retainer.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

