India's Digital Personal Data Protection Act, 2023 (DPDPA) received Presidential assent on 11 August 2023 and was published in the Official Gazette the same day. As of the time of writing, most provisions are not yet in force — the Central Government must notify the date(s) of commencement and release the Rules before obligations formally attach. But the healthcare sector cannot afford to wait. Every hospital, clinic, diagnostics centre, and doctor who collects, stores, or processes patient information in digital form will be subject to this law, and the compliance window is narrow.
This article explains what the DPDP Act means for healthcare providers in India: who is covered, what the obligations are, what patients can now demand, and what happens when a hospital gets it wrong.
"Patient data is among the most sensitive personal data that exists. The DPDP Act brings Indian healthcare into the modern data-protection era — but hospitals that treat it as just another regulatory box-tick will be caught off guard when the Rules are notified and enforcement begins."
— Dr. Namit Gupta, Senior Medico-Legal Expert, Medico Legal Services, New Delhi
Overview of the DPDP Act 2023 — What Is New?
India has attempted data-protection legislation before — draft bills in 2018 and 2021 were withdrawn. The 2023 Act is the first to pass Parliament. It draws heavily from the GDPR framework but is tailored to India's context: it applies to digital personal data only (not paper records), and it creates a domestic enforcement authority called the Data Protection Board of India.
Key features relevant to healthcare:
- Applies to personal data processed within India in digital form, and to digital data collected outside India if it is used to offer goods or services to individuals in India
- Does not distinguish "sensitive" personal data from other personal data as a separate category (unlike the GDPR's Article 9 or India's earlier Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011)
- Establishes consent as the primary legal basis for processing, with limited legitimate-use exceptions
- Creates enforceable rights for Data Principals (patients)
- Introduces financial penalties through an adjudicatory process before the Data Protection Board
Key Definitions: Who Is What in the Healthcare Context?
Data Principal — the Patient
The individual to whom personal data relates. In healthcare, this is ordinarily the patient. Where the patient is a minor (under 18) or a person with disability requiring a guardian, the consent of the guardian is required. The Act requires that Data Fiduciaries not process children's data in a manner that is detrimental to the child's well-being — a provision that affects paediatric hospitals in particular.
Data Fiduciary — the Hospital or Doctor
Any person (individual or entity) who alone or in conjunction with others determines the purpose and means of processing personal data. In healthcare, hospitals, nursing homes, clinics, and individual doctors who collect and manage patient records are Data Fiduciaries. They bear the primary legal obligation under the Act.
Data Processor — EMR Vendors and Cloud Providers
Any person who processes personal data on behalf of a Data Fiduciary. If your hospital uses a cloud-based Electronic Medical Records (EMR) platform or stores patient data on a third-party server, that vendor is your Data Processor. The hospital (Data Fiduciary) remains responsible for ensuring the processor follows the Act — this must be addressed through a data processing agreement.
Significant Data Fiduciary
The Central Government may designate certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data they process, the potential risk to the rights of Data Principals, national security concerns, or public order implications. Large multi-specialty hospitals, hospital chains, and health-tech platforms are the most likely candidates in healthcare. Significant Data Fiduciaries face additional obligations including mandatory appointment of a Data Protection Officer (DPO) resident in India and mandatory Data Protection Impact Assessments.
What Is "Personal Data" in the Healthcare Context?
The Act defines personal data as "any data about an individual who is identifiable by or in relation to such data." In healthcare, this is extremely broad:
- A patient's name and UHID (Unique Hospital ID) together constitute personal data
- A diagnosis, prescription, lab result, imaging report, or discharge summary — attached to an identifiable patient — is personal data
- An IP address or device ID that can be linked to an identified patient is personal data
- A photograph from a clinical record is personal data
De-identified data is excluded — if data is truly anonymised so that no individual can be identified from it (directly or in combination with other data), it falls outside the Act's scope. Hospitals that use patient data for research or analytics must genuinely anonymise it to claim this exclusion; pseudonymisation alone (using coded identifiers) generally does not suffice.
| Data Type | Personal Data? | Notes |
|---|---|---|
| Name + Diagnosis | Yes | Clearly identifiable — core personal data |
| Anonymised aggregate statistics | No | Excluded if truly de-identified |
| Lab result with patient ID | Yes | Identifiable via hospital record |
| CCTV footage of hospital | Yes (if faces visible) | Biometric data; identifiable individuals |
Obligations on Hospitals as Data Fiduciaries
1. Purpose Limitation
A hospital may process a patient's personal data only for the specific purpose for which consent was obtained, or for a permitted legitimate use. A hospital that collects a patient's contact number for appointment reminders cannot use it to send promotional messages without fresh, specific consent. This is a common gap in hospital practice today.
2. Data Minimisation
Collect only what is necessary for the stated purpose. Requiring a patient to submit their Aadhaar number, marital status, or income details merely to register for an outpatient consultation — when these are not clinically required — is likely to be inconsistent with this principle.
3. Accuracy
Data Fiduciaries must make reasonable efforts to ensure that personal data is accurate and updated. Incorrect entries in patient records — a wrong drug allergy, an incorrect date of birth, a wrong diagnosis code — are not just clinical risks; they are now potential compliance issues.
4. Storage Limitation
Personal data must not be retained beyond the period necessary for the purpose for which it was collected, unless retention is required by law. Hospitals must map their data categories against applicable retention rules (see below) and delete or anonymise data that no longer needs to be retained.
5. Security Safeguards
Data Fiduciaries must implement appropriate technical and organisational measures to prevent personal data breaches. In the hospital context this means: encrypted storage and transmission of EHRs, role-based access controls (not all staff should be able to view all records), audit trails, endpoint security, and periodic security assessments. The minimum security standard for healthcare is not yet defined by rule but must be "reasonable" — which courts and the Board will benchmark against sector norms.
6. Accountability and Breach Notification
When a personal data breach occurs — a hacker accessing the EMR, an employee emailing the wrong patient's records to a third party, a server left unencrypted — the Data Fiduciary must notify the Data Protection Board and each affected Data Principal. The notification must be prompt, though the Rules will specify the exact timeline. Failure to notify is the single act that carries the highest penalty: up to ₹250 crore.
Consent Under the DPDP Act: What Hospitals Must Change
Consent must be free, specific, informed, unconditional, and unambiguous. The hospital must provide a notice — before or at the time of collecting data — that sets out:
- What personal data is being collected
- The purpose of the processing
- The rights of the Data Principal and how to exercise them
- The manner in which a complaint may be made to the Data Protection Board
The notice must be in clear, plain language. Where a patient has limited English literacy, the notice should be available in the patient's preferred language (the government may specify languages). The consent must be separate from any terms-and-conditions agreement — buried consent clauses in registration paperwork will not satisfy the Act.
Consent may be withdrawn at any time, and withdrawal must be as easy as giving it. A patient who withdraws consent does not thereby require the hospital to delete records required by law, but the hospital must stop further processing beyond the legally mandated retention.
Sensitive Health Data: How DPDP Differs from GDPR
One important structural difference between the DPDP Act and the GDPR: the Indian law does not create a separate "special category" for sensitive personal data (health, genetic, biometric, religious, political data). Under GDPR Article 9, health data is subject to a higher threshold — explicit consent and specific legal bases. Under the DPDP Act, health data is personal data, subject to the same rules. There is no statutory heightened standard for it — though it is very likely that the Rules and the Significant Data Fiduciary designation process will create sector-specific obligations for healthcare.
The Information Technology (Reasonable Security Practices) Rules 2011 did list health information as "sensitive personal data" requiring heightened safeguards. Those Rules continue to apply to body corporates until the government specifies otherwise, creating an overlapping compliance obligation for hospitals in the interim period.
Cross-Border Data Transfer Restrictions
The DPDP Act permits the Central Government to restrict the transfer of personal data to countries or territories outside India. A whitelist approach is expected: transfers will be permitted to notified countries; transfers to non-notified countries will require specific justification or approval. For hospitals using cloud EMR systems where data may be stored on servers outside India, this is critical — contracts with international cloud vendors must be reviewed for data residency provisions. The Indian health sector may eventually be required to store patient data on servers located in India.
Data Retention and the Interaction with Existing Medical Records Rules
The DPDP Act introduces a storage limitation principle, but it also recognises that legal retention obligations override that principle. India's existing rules on medical records retention include:
- Clinical Establishments (Central Government) Rules, 2012: Maintain medical records for a minimum of 3 years from the date of treatment
- Maharashtra Medical Council: 7 years for patient records
- Karnataka: Minimum 5 years
- Consumer Protection Act, 2019: Limitation period for complaints is 2 years from the cause of action, so records supporting a potential dispute should be retained for at least this period beyond the date of treatment
- Minor patients: Records should be retained until the patient reaches 18 + 3 years (or until local limitation periods expire for any potential claim by the minor on reaching majority)
- ICU and surgical records: Many hospital policies specify 10 years; given litigation risk, this is prudent
The DPDP Act does not override these retention requirements. What it adds is an obligation to delete or anonymise data that is no longer required to be retained under any applicable law or for the stated purpose. In practice, hospitals must map their data categories, apply the longest applicable retention period, and build a data deletion process for records that have passed that period.
Rights of Patients as Data Principals
Right to Information
Patients may request a summary of the personal data a hospital holds about them and information on its processing — including the identities of other Data Fiduciaries and Data Processors with whom it has been shared.
Right to Correction and Erasure
Patients may request correction of inaccurate or misleading personal data, completion of incomplete data, and erasure of data that is no longer necessary for the purpose it was collected for, or where the patient has withdrawn consent and no legal retention obligation applies.
Right to Grievance Redressal
Every Data Fiduciary must have a published grievance mechanism. If the grievance is not resolved satisfactorily, the patient may approach the Data Protection Board.
Right of Nomination
A Data Principal may nominate another individual to exercise their rights in the event of death or incapacity — relevant in the clinical context where a patient's next-of-kin may need to access or act on the patient's data.
The Data Protection Board and Penalties
The Data Protection Board of India is the adjudicatory body. It will hear complaints from Data Principals and can impose financial penalties. Key penalties under Schedule I of the Act:
- Failure to notify a personal data breach: Up to ₹250 crore
- Failure to implement adequate security safeguards: Up to ₹200 crore
- Breach of obligations regarding children's data: Up to ₹200 crore
- Breach of additional obligations by Significant Data Fiduciaries: Up to ₹150 crore
- Other violations of the Act or Rules: Up to ₹50 crore
The Board proceeds in a civil, quasi-judicial process. Penalties are not criminal. However, the amounts are significant enough to be existential for small and mid-sized hospitals. A single ransomware attack on a hospital's EMR that is reported poorly — or not reported at all — could lead to the maximum ₹250 crore penalty.
Practical Compliance Checklist for Hospitals
Large Hospitals and Hospital Chains
- Conduct a data mapping exercise: What patient data do you collect, from where, for what purpose, stored where, shared with whom?
- Review and update patient consent forms and registration documents to meet the DPDP Act's consent standard
- Draft a clear, multilingual Privacy Notice to be displayed at reception and on your hospital website
- Audit your EMR vendor and all other Data Processors — enter into formal data processing agreements that bind them to Act compliance
- Implement breach detection and notification protocols (internal escalation, Board notification, patient notification)
- Prepare for possible designation as a Significant Data Fiduciary — identify a potential DPO candidate and conduct a Data Protection Impact Assessment
- Review cloud and cross-border data transfer arrangements
- Train clinical and administrative staff on data-handling obligations
Small Clinics and Solo Practitioners
If you use a digital system at all — an appointment app, a messaging service to share prescriptions, a WhatsApp group for patient follow-ups, an online booking system — you are a Data Fiduciary. Your obligations under the Act are the same in principle, even if the scale is different. At a minimum, small practices should: obtain valid consent before collecting patient data digitally, use password-protected devices and encrypted storage, not share patient data over unsecured channels, and have a basic mechanism to respond to patient access requests.
Conclusion
The DPDP Act 2023 is not yet fully in force, but its direction is clear and its applicability to healthcare is beyond doubt. Hospitals and doctors who move now — mapping data flows, updating consent processes, locking down EMR security, reviewing vendor contracts — will be in a far better position than those who wait for enforcement to begin. Patient data privacy is both a legal obligation and a clinical duty; the two have never been more aligned than under this framework.
If your hospital or practice needs a compliance review, data breach response plan, or patient consent framework for digital health records, contact our medico-legal team for expert guidance.