What the DPDP Act Means for Doctors and Clinics in India
-
By Mimansa Ambastha | Managing Partner, Starlex Consultants LLP - August 4, 2026
Dr. Sharma’s general practice in Bengaluru has been running for eleven years. It is busy, well-regarded, and digitally active: the clinic has a website with an online appointment form, an active WhatsApp Business account used to send reminders and follow-up messages, and a practice manager who regularly messages the clinic’s patient list about new services. Last year, the practice partnered with a digital marketing agency to run Google Ads. The agency was given access to the clinic’s patient contact list to help build a “retargeting” audience. Nobody thought much about it.
Under India’s Digital Personal Data Protection Act, 2023 (the DPDP Act), almost everything described above is a potential violation. The appointment form collects personal data without a DPDP-compliant consent mechanism. The WhatsApp messages are sent to numbers that were not collected with explicit consent for marketing communication. The patient list shared with the agency was transferred without a Data Processing Agreement. And none of this would have required malicious intent or negligence to qualify as non-compliance. It is simply how most clinics in India currently operate.
The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection legislation. Passed by Parliament in August 2023, with Rules notified in 2025, and enforceable starting May 2027, the Act establishes a framework for how personal data of individuals in India must be collected, stored, processed, and protected. It is structured around the concept of the “Data Principal” (the individual whose data is being processed) and the “Data Fiduciary” (any person or entity that determines the purpose and means of processing). Clinics, hospitals, and individual practitioners are Data Fiduciaries.
Healthcare is more exposed than most sectors for reasons that are structural, not incidental. Every clinical encounter generates personal data. More importantly, it generates sensitive personal data – information about a person’s health, diagnoses, medications, and medical history. Unlike a retail transaction, where a data breach might expose a purchase history, a healthcare breach can expose conditions that affect employment, insurance, marriage, and social standing. The DPDP Act does not carve out healthcare as a separate category, but its general framework – requiring lawful consent, limiting use to stated purposes, mandating security safeguards, and imposing breach notification obligations – applies with particular force wherever sensitive personal data is involved.
The Act’s implementing rules are being finalised, but the statutory obligations of Data Fiduciaries are already in force. Clinics that wait for rules to be notified before beginning compliance review are taking a measurable legal risk.
Under Section 6 of the DPDP Act, personal data may be processed only on the basis of ‘free, specific, informed, unconditional and unambiguous’ consent of the Data Principal, or a legitimate use recognised under the Act. For most clinical contexts, consent is the operative basis. The critical word is ‘specific’: a patient who consents to their data being used for appointment reminders has not thereby consented to receiving promotional WhatsApp messages about a new service, or to their contact details being included in an audience list for digital advertising. Each distinct purpose requires a separate, specific consent.
In practice, this means every touchpoint at which a clinic collects patient data – the website appointment form, the reception intake form, the WhatsApp onboarding message – must be accompanied by a clear, purpose-specific consent mechanism. The consent notice must be in plain language (the Act specifically requires it to be “clear and plain”), and patients must have a genuine ability to withdraw consent without facing any disadvantage in the clinical care they receive. A pre-ticked box or an implied consent from registration is not sufficient.
When a clinic engages a third party to handle patient data – a digital marketing agency, a CRM platform, an SMS gateway, an email marketing service – that third party is a “Data Processor” under the Act, and the clinic remains the “Data Fiduciary.” Section 8(2) of the DPDP Act requires the Data Fiduciary to ensure that the Data Processor processes personal data only in accordance with the Fiduciary’s instructions and in a manner consistent with the Act’s requirements.
This obligation cannot be met without a Data Processing Agreement (DPA) – a formal written contract specifying what personal data is shared, for what purpose, the security standards required, and the consequences of a breach. Almost no clinic in India currently has such agreements with its marketing or technology vendors. The gap matters because the clinic is liable for the processor’s violations. If your marketing agency misuses patient data, you – not the agency – are the Data Fiduciary facing the Data Protection Board.
The DPDP Act holds the Data Fiduciary responsible for personal data breaches regardless of whether the breach was caused by an external attacker or an employee’s careless act. A receptionist who saves a patient’s file to her personal phone, a billing assistant who forwards a patient list over personal email, or a nurse who adds patients to an informal WhatsApp broadcast group without consent – each of these is a compliance failure attributable to the clinic. Section 8(5) of the Act specifically requires Data Fiduciaries to protect personal data in their possession “by taking reasonable security safeguards to prevent personal data breach.”
Reasonable security safeguards include – at a minimum – a documented data-handling policy for clinical staff, restrictions on accessing patient records from personal devices, and regular training on what constitutes a data breach and how to report it. This is not complex to implement, but it must be deliberately done. Ad hoc instruction is not sufficient; documented training – with records of who was trained and when – provides both compliance and evidence of compliance if the clinic is ever investigated.
The DPDP Act establishes a tiered penalty structure enforced by the Data Protection Board of India. Under the Act, failure to implement adequate security safeguards that results in a personal data breach attracts a penalty of up to ₹250 crore. Failure to notify the Data Protection Board of a breach carries a penalty of up to ₹200 crore. Non-fulfilment of obligations relating to children’s data attracts a penalty of up to ₹200 crore. Lesser violations – such as failure to provide a required notice or to honour a Data Principal’s rights request – attract penalties up to ₹50 crore.
The Board has the power to investigate suo motu (on its own initiative) or on receipt of a complaint. Importantly, the Act does not require a complainant to have suffered financial loss – a violation of the consent framework alone is sufficient. For healthcare practices, the risk is compounded by the reputational dimension: a publicly reported data investigation involving a clinic’s patient records is not a recoverable event for most practices. Patient trust, once lost at this scale, rarely returns.
DPDP compliance is not a single project with a finish line. It is an ongoing discipline. But there are concrete first steps that any clinic or hospital can take in the next 30 to 90 days to begin building a defensible compliance position.
The questions your clinic will face from regulators, patients, and vendors in the coming years will increasingly turn on personal data. The practices that prepare now will be positioned not just to avoid penalties, but to build the kind of institutional trust that distinguishes a modern, responsible healthcare provider from one still operating on assumptions formed before data became central to clinical life.