New Sales Pipeline is live — turn WhatsApp chats into tracked deals See how →
Home › Tools › DPDP penalty calculator
DPDP Act 2023 · Schedule

How exposed is your WhatsApp data under DPDP?

Up to nine questions about how you collect, keep and protect the contacts you message. Each gap is matched to the section of the Act it breaks and the most the Data Protection Board can fine for it, with the fix for each.

Statutory caps from the Schedule Runs in your browser; nothing is saved A fix for every gap
VolumeSec 33(2)

How many people do you message on WhatsApp in a month?

Each is a Data Principal under the Act. The Board weighs how many people a breach touches.

25,000
50050 lakh
Sec 5

Do you show a privacy notice before a contact opts in on WhatsApp?

It has to say what you collect, why, and how to withdraw consent or complain, in plain language.

Sec 6

Can you produce a consent record for every contact you message?

Consent must be free, specific, informed and unambiguous, and you carry the burden of proving it was given.

Sec 8(7) · Sec 12

When someone opts out, do you stop messaging them and erase their data?

Once consent is withdrawn and the purpose is served, the data has to go, from your processors too.

Sec 8(5)

Are contacts and chats protected: access control, encryption, logs, a vetted provider?

The largest single head in the Schedule. "Partly" counts: a gap you know about is still a gap.

Sec 8(6)

Is there a written plan to report a data breach to the Board and to the people affected?

The rules expect notice to the Board within 72 hours of becoming aware of it.

Sec 9

Do you message or hold data about anyone under 18?

Schools, coaching, gaming and kids' brands usually do. That brings in verifiable parental consent.

Sec 10

Could you be notified as a Significant Data Fiduciary?

The government notifies these by volume and sensitivity of data, and risk to people. Large consumer brands, lenders and health players should plan for it.

Questions people ask

How much can the Board fine a business?

The Schedule sets a cap per kind of breach, up to ₹250 crore for failing to protect personal data. The Board decides the actual amount after an inquiry, weighing things like how serious and how long the breach was, what data was involved, whether it repeated, and what you did to limit the harm.

Is this legal advice?

No. It maps common practices to the Act so you can see where to look. For a decision about your business, ask a lawyer who practises data protection law.

Why do children's data and the significant status weigh so much?

The Act gives both their own heads in the Schedule: up to ₹200 crore for breaking the duties about children, and up to ₹150 crore for breaking the extra duties of a Significant Data Fiduciary.

Do you keep my answers?

No. The calculator runs in your browser and nothing you tick is sent anywhere. Only if you ask us to send you the result do we keep your name, number and that result, to send it.

Figures are the statutory maximums in the Schedule to the Digital Personal Data Protection Act, 2023, and an illustration of ours; they are not a prediction of any penalty. The Rules and the Board's practice may change how the Act applies to you.