What the DPDP Act Means for Doctors and Clinics in India

OPENING

Dr. Sharma’s general practice in Bengaluru has been running for eleven years. It is busy, well-regarded, and digitally active: the clinic has a website with an online appointment form, an active WhatsApp Business account used to send reminders and follow-up messages, and a practice manager who regularly messages the clinic’s patient list about new services. Last year, the practice partnered with a digital marketing agency to run Google Ads. The agency was given access to the clinic’s patient contact list to help build a “retargeting” audience. Nobody thought much about it.

Under India’s Digital Personal Data Protection Act, 2023 (the DPDP Act), almost everything described above is a potential violation. The appointment form collects personal data without a DPDP-compliant consent mechanism. The WhatsApp messages are sent to numbers that were not collected with explicit consent for marketing communication. The patient list shared with the agency was transferred without a Data Processing Agreement. And none of this would have required malicious intent or negligence to qualify as non-compliance. It is simply how most clinics in India currently operate.

What the DPDP Act Is

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive data protection legislation. Passed by Parliament in August 2023, with Rules notified in 2025, and enforceable starting May 2027, the Act establishes a framework for how personal data of individuals in India must be collected, stored, processed, and protected. It is structured around the concept of the “Data Principal” (the individual whose data is being processed) and the “Data Fiduciary” (any person or entity that determines the purpose and means of processing). Clinics, hospitals, and individual practitioners are Data Fiduciaries.

Healthcare is more exposed than most sectors for reasons that are structural, not incidental. Every clinical encounter generates personal data. More importantly, it generates sensitive personal data – information about a person’s health, diagnoses, medications, and medical history. Unlike a retail transaction, where a data breach might expose a purchase history, a healthcare breach can expose conditions that affect employment, insurance, marriage, and social standing. The DPDP Act does not carve out healthcare as a separate category, but its general framework – requiring lawful consent, limiting use to stated purposes, mandating security safeguards, and imposing breach notification obligations – applies with particular force wherever sensitive personal data is involved.

The Act’s implementing rules are being finalised, but the statutory obligations of Data Fiduciaries are already in force. Clinics that wait for rules to be notified before beginning compliance review are taking a measurable legal risk.

Three DPDP Obligations Healthcare Practices Must Address Now

1. Consent Before Collection (and It Must Be Specific)

Under Section 6 of the DPDP Act, personal data may be processed only on the basis of ‘free, specific, informed, unconditional and unambiguous’ consent of the Data Principal, or a legitimate use recognised under the Act. For most clinical contexts, consent is the operative basis. The critical word is ‘specific’: a patient who consents to their data being used for appointment reminders has not thereby consented to receiving promotional WhatsApp messages about a new service, or to their contact details being included in an audience list for digital advertising. Each distinct purpose requires a separate, specific consent.

In practice, this means every touchpoint at which a clinic collects patient data – the website appointment form, the reception intake form, the WhatsApp onboarding message – must be accompanied by a clear, purpose-specific consent mechanism. The consent notice must be in plain language (the Act specifically requires it to be “clear and plain”), and patients must have a genuine ability to withdraw consent without facing any disadvantage in the clinical care they receive. A pre-ticked box or an implied consent from registration is not sufficient.

2. Data Processor Accountability and the Missing DPA

When a clinic engages a third party to handle patient data – a digital marketing agency, a CRM platform, an SMS gateway, an email marketing service – that third party is a “Data Processor” under the Act, and the clinic remains the “Data Fiduciary.” Section 8(2) of the DPDP Act requires the Data Fiduciary to ensure that the Data Processor processes personal data only in accordance with the Fiduciary’s instructions and in a manner consistent with the Act’s requirements.

This obligation cannot be met without a Data Processing Agreement (DPA) – a formal written contract specifying what personal data is shared, for what purpose, the security standards required, and the consequences of a breach. Almost no clinic in India currently has such agreements with its marketing or technology vendors. The gap matters because the clinic is liable for the processor’s violations. If your marketing agency misuses patient data, you – not the agency – are the Data Fiduciary facing the Data Protection Board.

3. Employee Training and Internal Data Hygiene

The DPDP Act holds the Data Fiduciary responsible for personal data breaches regardless of whether the breach was caused by an external attacker or an employee’s careless act. A receptionist who saves a patient’s file to her personal phone, a billing assistant who forwards a patient list over personal email, or a nurse who adds patients to an informal WhatsApp broadcast group without consent – each of these is a compliance failure attributable to the clinic. Section 8(5) of the Act specifically requires Data Fiduciaries to protect personal data in their possession “by taking reasonable security safeguards to prevent personal data breach.”

Reasonable security safeguards include – at a minimum – a documented data-handling policy for clinical staff, restrictions on accessing patient records from personal devices, and regular training on what constitutes a data breach and how to report it. This is not complex to implement, but it must be deliberately done. Ad hoc instruction is not sufficient; documented training – with records of who was trained and when – provides both compliance and evidence of compliance if the clinic is ever investigated.

What Non-Compliance Looks Like

The DPDP Act establishes a tiered penalty structure enforced by the Data Protection Board of India. Under the Act, failure to implement adequate security safeguards that results in a personal data breach attracts a penalty of up to ₹250 crore. Failure to notify the Data Protection Board of a breach carries a penalty of up to ₹200 crore. Non-fulfilment of obligations relating to children’s data attracts a penalty of up to ₹200 crore. Lesser violations – such as failure to provide a required notice or to honour a Data Principal’s rights request – attract penalties up to ₹50 crore.

The Board has the power to investigate suo motu (on its own initiative) or on receipt of a complaint. Importantly, the Act does not require a complainant to have suffered financial loss – a violation of the consent framework alone is sufficient. For healthcare practices, the risk is compounded by the reputational dimension: a publicly reported data investigation involving a clinic’s patient records is not a recoverable event for most practices. Patient trust, once lost at this scale, rarely returns.

What Healthcare Practices Should Do in the Next 90 Days

DPDP compliance is not a single project with a finish line. It is an ongoing discipline. But there are concrete first steps that any clinic or hospital can take in the next 30 to 90 days to begin building a defensible compliance position.

  1. Conduct a data audit. Map every point at which your clinic collects personal data: your website forms, reception intake, WhatsApp, CRM, email lists, and third-party platforms. Understand what data you hold, where it lives, and who has access to it. You cannot protect what you have not mapped.
  2. Start a “Data Weight Loss Program” : identify all buckets of personal data which are redundant, not required, or have no legal basis for retention. Effectuate erasure and deletion of the same from active systems as well as backups. Stop hoarding personal data which can eventually become a liability under the Act, and shed all the extra personal data from your systems.
  3. Review your consent mechanisms. Check whether every collection point has a compliant, purpose-specific consent notice. If your website has a contact or booking form with no consent mechanism, that is your most visible and easily remedied exposure.
  4. Identify your Data Processors and issue DPAs. List every vendor or agency that accesses patient data on your behalf. Prioritise your marketing agency, CRM provider, and any SMS or email platform. Engage a data protection practitioner to prepare Data Processing Agreements for each.
  5. Train your staff. Implement a documented training session for all clinical and administrative staff on data handling obligations under the DPDP Act: what they can and cannot do with patient information, what constitutes a breach, and who to notify if something goes wrong.
  6. Prepare a breach response protocol. Draft a simple internal document establishing who is responsible for identifying a breach, how severity is assessed, and what steps are taken to notify the Data Protection Board and affected patients if required. This document does not need to be complex – but it must exist.

The questions your clinic will face from regulators, patients, and vendors in the coming years will increasingly turn on personal data. The practices that prepare now will be positioned not just to avoid penalties, but to build the kind of institutional trust that distinguishes a modern, responsible healthcare provider from one still operating on assumptions formed before data became central to clinical life.

0
Show Comments (0) Hide Comments (0)
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x