₹250 crore is a number capable of making almost any management team pay attention.

Under India's DPDP framework, the schedule to the Act provides for penalties that can reach ₹250 crore for a failure to take reasonable security safeguards to prevent a personal-data breach.

But beginning the data-protection conversation with the maximum penalty can obscure the more useful question.

What would have to fail inside the organisation before a penalty ever became the issue?

The problem begins much earlier.

It may begin with excessive access to a production database. An unpatched vulnerability. Credentials that were never revoked. An external processor nobody remembered was still receiving data. A backup exposed through an incorrect configuration.

None of those starts as a legal headline.

They start as technology and operating-control problems.

Reasonable safeguards need evidence.

Security programmes often look impressive when described at policy level. The assurance question is whether the organisation can demonstrate the controls beneath those statements.

That can include identity and access management, encryption, network security, vulnerability management, security testing, logging, monitoring, incident response and resilient backups.

DON'T ASK ONLY “Do we have a security policy?”

Also ask: “What evidence demonstrates that the controls described by that policy are operating?”

A breach is also an operational test.

When something goes wrong, organisations need more than technology. Teams need to know who assesses the incident, who escalates it, where evidence is obtained and how decisions are coordinated.

A beautifully written incident-response document that nobody has exercised is very different from an operating capability.

The objective isn't fear. It's readiness.

Penalty figures are useful because they make boards pay attention. They should not become the entire DPDP strategy.

The better outcome is to use that attention to understand the data environment, strengthen safeguards, close operational gaps and create evidence that controls are working.

Because by the time ₹250 crore is the conversation, a much earlier conversation has probably already been missed.

HOW READY ARE YOU? Take Tricona's 4-minute DPDP Readiness Assessment.

15 questions · instant readiness score · executive report.

ASSESS YOUR READINESS →