Back to Sectors & Impact

Healthcare

DPDPA compliance for hospitals, clinics & health-tech - patient consent, clinical research exemptions, health record retention, and Section 9 children's data rules.

8 min read

Sector Overview

Healthcare organisations in India process vast quantities of sensitive personal data including patient health records, diagnostic reports, treatment histories, insurance claims, and clinical research data. The Digital Personal Data Protection Act, 2023 (DPDPA) applies to all digital processing of personal data, making healthcare one of the most significantly impacted sectors. Unlike the EU's GDPR, the DPDPA does not create a separate category of "sensitive personal data." However, the nature of health data means that healthcare organisations face heightened compliance expectations, particularly around consent, security safeguards, and data retention. The sector must also reconcile DPDPA requirements with existing regulations from the Medical Council of India, NABH accreditation standards, and the Clinical Establishments Act.

Key DPDPA Provisions for Healthcare

Several provisions of the DPDPA are particularly relevant to healthcare organisations: Consent Framework (Section 5-6): Healthcare providers must obtain valid consent before processing patient data for purposes beyond direct treatment. This includes research, marketing of health services, sharing data with insurance companies, and analytics. The consent must be free, specific, informed, and unambiguous. Legitimate Uses (Section 7): The DPDPA recognises processing for medical emergencies and threats to life as a legitimate use that does not require explicit consent. This is critical for emergency departments and urgent care settings. Employment-related processing of healthcare worker data is also covered. Section 8 (Obligations): Healthcare organisations must implement reasonable security safeguards commensurate with the sensitivity of health data. Rule 6 prescribes specific measures including encryption, access controls, and maintenance of processing logs for at least one year. Section 9 (Children's Data): Paediatric healthcare providers are exempt from verifiable parental consent requirements under Rule 12, recognising the practical challenges of requiring parental verification for children's healthcare services. Significant Data Fiduciary (Section 10): Large hospital chains, health insurance companies, and digital health platforms processing data at scale may be designated as Significant Data Fiduciaries, triggering enhanced obligations including DPO appointment, DPIA, and independent audits.

Compliance Considerations

Healthcare organisations should address the following compliance areas: 1. Consent Management: Implement granular consent mechanisms that distinguish between consent for treatment, research, insurance processing, and marketing. Consent notices must be independent and self-sufficient per Rule 3. 2. Data Mapping: Conduct comprehensive data mapping to identify all personal data flows - from patient registration through treatment, billing, insurance claims, and research. This includes data shared with laboratories, pharmacies, and referral networks. 3. Security Safeguards: Implement encryption for electronic health records, role-based access controls limiting access to authorised personnel, audit trails for all data access, and secure communication channels for sharing patient information. 4. Breach Response: Establish two-tier breach notification procedures per Rule 7. Healthcare data breaches can have severe consequences for patients, making rapid detection and response critical. For clinical trials, organisations must also report Serious Adverse Events (SAEs) to the DCGI/CDSCO within 24 hours - a much shorter window than Rule 7's 72-hour detailed report to the Data Protection Board. 5. Data Retention: Establish clear retention policies that reconcile DPDPA requirements with medical record retention obligations under the Indian Medical Council regulations and state-specific rules. 6. Cross-Border Transfers: Telemedicine providers, clinical research organisations, and multi-national hospital chains must ensure compliance with cross-border transfer restrictions under Section 16 and Rule 15.

Interaction with Other Regulations

Healthcare organisations must navigate the DPDPA alongside several sector-specific regulations: The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the IT Act earlier classified health data as "sensitive personal data or information" (SPDI). With Section 43A of the IT Act now omitted under the DPDPA, the SPDI Rules, 2011 have ceased to operate as a parallel statutory framework. The DPDPA is the sole standard for digital personal data privacy in India. The National Digital Health Mission (NDHM) and Ayushman Bharat Digital Mission (ABDM) create digital health infrastructure including Health IDs, health records, and consent management. Healthcare organisations participating in these programmes must align DPDPA compliance with ABDM's consent framework. NABH (National Accreditation Board for Hospitals) accreditation standards include data protection requirements that organisations must continue to meet alongside DPDPA compliance. Clinical research organisations must comply with the New Drugs and Clinical Trials Rules, 2019, which have their own data protection and consent requirements. The DPDPA's research exemption under Rule 16 may apply to certain research activities, but Rule 16 only exempts research where it follows the "Standards for Processing" in the Second Schedule. Crucially, ICMR requires Re-Consent for secondary use of data unless the Ethics Committee waives it; the DPDPA does not have a "Waiver" clause. Clinical trials must therefore follow the stricter ICMR standard.

Practical Compliance Checklist

*Note: This checklist is interpretive guidance derived from the DPDPA's general provisions (Sections 5-10, Rules 3, 6-7, 12-13, 16). It should be validated by legal counsel for your specific organisational context.* Healthcare organisations should prioritise the following actions: • Appoint a data protection lead or DPO (mandatory if designated as SDF) • Conduct a comprehensive data mapping exercise covering all patient data flows • Review and update patient consent forms to meet DPDPA standards • Implement independent, itemised privacy notices per Rule 3 • Upgrade security safeguards to meet Rule 6 requirements (encryption, access controls, 1-year logs) • Establish a two-tier breach notification procedure per Rule 7, and a parallel 24-hour SAE reporting workflow to DCGI/CDSCO for clinical trials • Define data retention policies reconciling DPDPA with medical record retention requirements • Review data sharing agreements with laboratories, insurers, and research partners • Train all staff handling patient data on DPDPA obligations • Conduct a DPIA if processing health data at scale

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.