What factors does the Board have to consider while imposing penalties for non-compliance?

As per section 33(2) while determining the amount of monetary penalties, the Board shall consider the following factors:

  1. The nature, gravity and duration of the breach
  2. The type and nature of the personal data affected by the breach
  3. Repetitive nature of the breach;
  4. Whether the person, as a result of the breach, has realized a gain or avoided any loss;
  5. Whether any action was taken to mitigate the effects and consequences of the breach and timeliness and effectiveness of the such action
  6. Whether monetary to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions
  7. The likely impact of the imposition of the penalty on the person
For more information please contact us at : info@ssrana.com