
DPDPA Section 42: Government Power to Amend the Schedule and Penalty Caps
Under DPDPA Section 42, the government can issue immediate DPDP Act schedule amendments. Prepare your compliance team for changing penalty caps and rules.
Written by
Priyanka Choudhury
Date
Read time
6 min

We like to think of laws as slow-moving glaciers. Parliament debates, committees review, and eventually, a statute is carved into stone. DPDPA Section 42 shatters that illusion.
It authorizes the Central Government to amend the Act’s Schedule by issuing a simple notification. It sets a ceiling on the DPDPA penalty cap, and crucially, makes those amendments effective immediately.
This is not a minor administrative tool. The Schedule holds the operational details that dictate how you actually build compliance. Understanding how Section 42 works,and how fast it moves,is the difference between predictable execution and a Tuesday morning panic.
What Section 42 Authorizes
The mechanics are straightforward, but the implications are heavy:
- The Central Government may amend the Schedule by notification.
- Any amendment cannot increase a penalty in the Schedule to more than twice what it was when the Act was originally enacted.
- An amendment takes effect as if it were enacted in the Act and becomes operative on the exact date of the notification.
In short: the executive branch can update the Schedule without dragging it back through a full legislative amendment. The changes bite immediately.
Why the Schedule Matters
The main text of a law provides the architecture. The Schedule provides the plumbing.
It contains the granular details,categories, thresholds, classifications, procedures, and exemptions,that are too volatile to hard-code into the main statute.
Section 42 focuses entirely on this terrain. It allows the government to issue DPDP Act schedule amendments to keep the law aligned with evolving technology and practice, without reopening the core statute.
Scope and Boundaries of the Power
This is a power of agility, not reinvention.
It is limited to the Schedule. The government cannot use Section 42 to rewrite the main body of the DPDPA.
It must respect the statute. Any amendment must stay within the objects and scheme of the Act. A change that undermines fundamental rights or core duties risks being struck down as ultra vires.
It requires public visibility. The form is by notification in the Official Gazette.
If a notified change conflicts with the Act’s constitutional principles, it is open to judicial review. But until a court says otherwise, it is the law.
Immediate Effect and Operational Risk

Section 42 states that a notified amendment has the same force as if enacted and takes effect on the date of notification. There is no mandatory transition window. There is no built-in grace period.
The operational takeaway is brutal but simple: You must treat Schedule notifications as live law on day one.
Waiting for rules, FAQs, or gentle clarifications is not a safe assumption unless expressly provided elsewhere. Standing processes for regulatory scanning and rapid implementation are no longer optional. They are survival tools.
The Penalty Cap Rule

Section 42 prohibits any notification from increasing a penalty specified in the Schedule to more than twice the amounts that existed at enactment.
This DPDPA penalty cap applies strictly to penalties contained within the Schedule. The government can reduce or recalibrate these fines, but they cannot exceed that 2x ceiling. This sets an outer boundary for executive amendments and gives organizations a worst-case exposure limit for Schedule changes.
But make no mistake: this cap does not change enforcement intensity or interpretive discretion. It only limits the mathematical magnitude of a penalty increase by notification.
How This Power Will Likely Be Used
The purpose of Section 42 is responsiveness. When technical or market conditions shift, the government can refine the Schedule to keep protections current without reopening Parliament.
Typical use cases include updating categories of personal data that warrant higher protection, adjusting thresholds that determine which entities face heightened obligations, or tuning exemptions to correct unintended consequences.
These are not theoretical levers. They are necessary instruments to prevent the rules from becoming stale or misaligned with real risk.
Illustrations
What does this look like in practice?
- New sensitive data categories. If brain-computer interface outputs create novel privacy risks, the Schedule could be updated overnight to add such neuro data to a sensitive category.
- Thresholds for Significant Data Fiduciaries. If a threshold measured in the number of data principals becomes outdated, the Schedule could revise that number upward or downward to keep the designation meaningful.
- Exemptions for research or non-profits. If conditions for de-identified data processing prove too lax or too strict, the Schedule could be tuned to recalibrate the required safeguards or process steps.
Each of these moves would directly alter your operational controls, documentation, and governance,in a very short window.
Checks and Balances
The Act does not require notifications under this section to be placed before Parliament. However, standard administrative law controls still apply.
A notification can be challenged if it is arbitrary, contradicts the DPDPA’s scheme, exceeds the delegated power, or violates constitutional principles.
This is a real safeguard, but a narrow one. It does not slow down the initial effect. Organizations still need to comply while any challenge is pending, unless a court explicitly stays the notification.
Practical Implications for Organizations
Do not wait for a grace period that does not exist in the text. Your only safeguard is preparation.
- Regulatory watch: Set up monitoring for Gazette notifications tied to the DPDPA Schedule. Assign a named owner and a backup. Use escalation rules for same-day triage.
- Fast impact assessment: Create a short-form assessment template for Schedule changes covering scope, systems, vendors, notices, training, and penalties.
- Change control: Predefine playbooks for rapid updates to privacy notices, consent flows, retention rules, or DPIA triggers if the Schedule shifts.
- Contracts and vendor oversight: Map Schedule elements to contract clauses. Build a standard rider you can deploy if a category or threshold changes overnight.
- Documentation hygiene: Keep a register that links each Schedule item to internal policies, SOPs, and controls. This reduces rework when a single field moves.
- Training and comms: Maintain micro-learning modules for high-impact changes. Brief frontline teams early when the amendment is effective on day one.
- Board and risk governance: Include Schedule-amendment risk in your risk register. Define decision thresholds for budget, tooling, or headcount when exposure changes.
Interpretation Boundaries to Respect
There are lines the government cannot cross.
Section 42 cannot be used to dilute or rewrite substantive duties in the main Act. Amendments must remain coherent with the DPDPA’s core objectives, including the protection of personal data and individual privacy.
And while the penalty cap places a hard ceiling on penalty increases by notification, it does not constrain other forms of policy tightening inside the Schedule.
If a notification appears to go beyond these lines, plan for parallel tracks: immediate compliance steps on one side, and legal review to assess challenge options on the other.
Closing
Section 42 is a precision tool with real operational consequences. It keeps the DPDPA responsive, but it shifts the entire burden of agility onto you.
The law can change by notification and take effect the same day. The only rational response is disciplined monitoring, fast analysis, and repeatable change execution.
Most teams struggle not with understanding the rule, but with turning it into action across policies, systems, contracts, and training. At Regodit, we provide a structured way to track these legal changes, map them directly to your controls, and drive consistent updates with clear ownership.
Because when the Schedule changes on a Tuesday, your compliance posture needs to be ready by Wednesday.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
