Back to Interaction with Other Laws

Sector-Specific Laws (Healthcare, Education)

How sector-specific laws for healthcare and education interact with the DPDPA - EHR standards, clinical data, student data, and R.12 exemptions.

7 min read

Healthcare Data Framework

India does not yet have a single comprehensive sector-specific data protection statute for healthcare. While a standalone DISHA Act remains in the draft phase, the National Digital Health Management Policy (v2.0) and the NMC Registered Medical Practitioner Regulations (2023/24) now function as 'de facto' sector-specific law alongside the Clinical Establishments Act, the Electronic Health Records (EHR) Standards published by MoHFW, the Telemedicine Practice Guidelines, and the Indian Medical Council regulations. Healthcare entities processing patient data must comply with the DPDPA alongside these sectoral requirements. Health data - while not separately categorised under the DPDPA as 'sensitive' (unlike the GDPR) - often warrants enhanced protections due to its nature.

Education Data Framework

The education sector is governed by the National Education Policy 2020, UGC regulations, and various state-level education laws. Student data processing by educational institutions and EdTech platforms is subject to the DPDPA. The UGC (Promotion of Equity) Regulations, 2026 (notified January 2026) now mandate the MANAS-SETU portal for real-time tracking of discrimination complaints, requiring institutions to process highly sensitive 'caste and gender' data, which must meet the DPDPA's Section 8(5) security safeguards. The DPDPA's children's data provisions (R.9-12) are particularly significant for educational institutions, as they process data of children (under 18) routinely. This includes academic records, behavioural data, learning analytics, and biometric attendance systems.

Rule 12 Exemptions for Healthcare and Education

Rule 12 provides specific exemptions from the requirement to obtain verifiable parental consent for certain categories of entities. These include: (a) healthcare entities processing children's data for medical treatment; (b) educational institutions processing data for teaching and student welfare; (c) childcare entities; (d) child safety organisations; and (e) entities monitoring parental oversight. These exemptions are subject to a strict purpose-limitation: a school is exempt only if the processing is for 'educational activities' or 'safety.' If a school shares data with a third-party uniform vendor, the exemption does not apply, and verifiable parental consent is required. These exemptions reduce the operational burden on healthcare and education entities while maintaining other DPDPA protections for children's data.

Practical Considerations

Healthcare entities should: ensure patient consent mechanisms comply with both medical ethics requirements and DPDPA standards; implement EHR security measures meeting R.6 requirements; and address telemedicine data flows. Educational institutions should: review student data processing for DPDPA compliance; implement age-appropriate consent mechanisms; leverage R.12 exemptions where applicable; restrict learning analytics to educational purposes; and ensure EdTech vendor contracts address DPDPA obligations.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.