On this page
A clinic or hospital holds patient data, and the DPDP Act treats it as personal data like any other. The Act and the Rules do not set up a separate category for health data, and they have no separate rules for medical records. What they do give you are a few uses that need no consent, a limited exemption for children’s data, and the same duties on vendors, retention and breaches that other Data Fiduciaries carry from 13 May 2027.
What the Act covers in a clinic
Personal data is any data about an individual who can be identified by or in relation to that data. The Act applies to digital personal data, which includes data collected on paper and digitised afterwards. A register that is written by hand and never entered into a computer is outside it. Appointment systems, billing software, scanned reports, WhatsApp messages and cloud storage are inside it.
The Act’s list of exemptions names no clinic or hospital, and its definitions set no size threshold. A single-doctor practice and a hospital company can each be a Data Fiduciary, because the Act’s word person covers individuals, firms and companies, and a Data Fiduciary is any person who decides why and how personal data is processed.
What the video shows
- How Sample Hospital fills in its DPDPA documents.
- Patient records, vendors, retention and a breach. Made-up names and data.
- RoPA tracker
- Each way Sample Hospital uses patient data gets one row.
- Pick the legal basis from the Act's own list.
- Responding to a medical emergency that threatens life, or is an immediate threat to health, is one of the uses the Act lists.
- sheet rows: Send appointment reminders by SMS / Consent (S.6) / Name, phone number, appointment date; Send the receipt the patient asked for / Legitimate Use - S.7(a) voluntary purpose / Name, phone number, bill amount; Admit a patient in a life-threatening emergency / Legitimate Use - S.7(f) medical emergency / Name, vitals, allergies
- Vendor risk assessment
- The lab and the pharmacy supplier both handle patient data. List each one.
- Mark how sensitive the data is.
- A processor serving your patients needs a valid contract. You stay responsible.
- Data retention schedule
- Keep data and processing logs at least a year, for uses by the State that the Rules list. Then erase, unless another law requires longer.
- If another law requires longer, the Act lets you keep the data for that long.
- Breach register
- A lab report is emailed to the wrong patient. Log it when you become aware.
- Each affected patient and the Board are told without delay.
- The detailed report to the Board is due within 72 hours of becoming aware.
Which ground fits which activity
A Data Fiduciary may process personal data only with the person’s consent or for one of the certain legitimate uses the Act lists. The table sets the uses that matter most in healthcare beside what the text says.
| Situation | What the Act says |
|---|---|
| A patient gives her details to book a visit or collect medicine | You may use them for the specified purpose for which she voluntarily provided them, unless she has told you she does not consent to that use. The Act’s own example is a pharmacy that, at the customer’s request, sends a payment receipt to her mobile phone. |
| A patient arrives in a medical emergency | You may process personal data to respond to a medical emergency involving a threat to the life or immediate threat to the health of the patient or any other individual. |
| An epidemic or outbreak | You may process personal data to take measures to provide medical treatment or health services during an epidemic, outbreak of disease or any other threat to public health. |
| Any use that is not on the Act’s list | You need her consent. Every request for consent must be accompanied or preceded by a notice that describes the data and the purpose, how she can withdraw consent and use her rights, and how she can complain to the Board. |
The emergency use covers responding to a medical emergency that threatens life or immediately threatens health. The list has no separate entry for routine treatment, so ask counsel which ground your own front-desk and consulting-room activities rest on. A consent request must be limited to the data that is necessary for its purpose. The Act’s telemedicine example makes the point: an app may ask for the person’s data to provide the service, but her phone contact list is not necessary for it, so her consent is limited to the data needed for the service.
A use that needs no consent still sits inside the Act. Security safeguards and breach reporting apply to this data too.
Lab, pharmacy and other vendors
A Data Processor is a person who processes personal data on behalf of a Data Fiduciary. Whether an outside lab, pharmacy, billing company or software supplier is your processor depends on who decides why and how the data is used. In the Act’s own example, a company that emails a telecom provider’s bills to its customers is the Data Processor, and the telecom provider is the Data Fiduciary.

- You stay responsible for processing done on your behalf, whatever the contract says.
- You may engage a processor for offering goods or services only under a valid contract.
- Your security safeguards must include an appropriate contract provision with the processor, wherever applicable.
- A patient who gave you her data, with consent or voluntarily for a purpose, can ask for the identities of the other Data Fiduciaries and Data Processors you shared it with, and a description of what was shared. Sharing with another Data Fiduciary authorised by law to obtain the data, on its written request to prevent, detect or investigate offences or cyber incidents, or to prosecute or punish offences, is excluded. Keep a list of who receives patient data.
See processors and vendors for what goes into the contract.
Children as patients
A child is anyone under eighteen, and the Act asks for a parent’s verifiable consent before any processing of a child’s personal data. The Rules lift that duty, and the ban on tracking children, for clinical establishments, mental health establishments and healthcare professionals, but only where processing is restricted to providing health services to the child, to the extent necessary for the protection of her health. Allied healthcare professionals have the same relief where processing is restricted to supporting implementation of a healthcare treatment and referral plan recommended by that professional for the child, to the extent necessary for the protection of her health.
The duty not to process a child’s data in a way likely to harm her well-being is not lifted by these exemptions. Read the children’s data article for the full list of exemptions.
Keeping and erasing records
You must erase personal data when the patient withdraws consent, or when it is reasonable to assume the purpose is no longer served, whichever is earlier, unless retention is necessary for compliance with a law. Neither the Act nor the Rules names a retention period for medical records, so check whether another law that applies to you requires you to keep them.
Separately, the Rules require you to keep personal data, associated traffic data and logs of the processing for at least one year from the date of the processing, for the purposes the Rules list, then erase them unless another law requires longer. The three-year inactivity limit applies only to large e-commerce, online gaming and social media platforms. See how long you can keep data.
If patient data leaks
The Rules set minimum safeguards for a Data Fiduciary: encryption, masking or tokens; access controls; logs and monitoring; backups; and, wherever applicable, a contract provision with each processor. After a breach you must tell each affected person without delay, and tell the Board without delay, with a detailed report to the Board within 72 hours of becoming aware of the breach. The Act sets ceilings of up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify. See the breach article.
Before 13 May 2027
- List every system that holds patient data and every vendor that receives it.
- Decide the ground for each activity, and write a consent notice for the others. What a notice must contain.
- Publish a contact for questions and a grievance period of no more than 90 days.
- Put a contract in place with each processor, and prepare the breach notices in advance.
Common questions
Does the DPDP Act apply to clinics and hospitals?
Yes. The Act applies to digital personal data, which includes data collected on paper and digitised afterwards. Its own exemptions name no clinic or hospital. The Rules give clinical establishments and healthcare professionals a limited exemption for children’s data only. The duties start on 13 May 2027.
Can a clinic treat a patient in an emergency without asking for consent?
The Act lists responding to a medical emergency involving a threat to the life or immediate threat to the health of the person or any other individual as a use that needs no consent. It also lists measures to provide medical treatment or health services during an epidemic, outbreak of disease or other threat to public health. The list has no separate entry for routine treatment.
Is my lab or pharmacy a Data Processor?
It depends on who decides why and how the data is processed. A Data Processor processes personal data on behalf of a Data Fiduciary. You stay responsible for processing done on your behalf, and you may engage a processor for offering goods or services only under a valid contract.
How long must a clinic keep patient records?
Neither the Act nor the Rules names a retention period for medical records. You must erase personal data when the person withdraws consent or the purpose is no longer served, unless retention is necessary for compliance with a law. Separately, you must keep personal data, traffic data and logs of the processing for at least one year from the date of the processing, for the purposes the Rules list, then erase them unless another law requires longer.
What must a clinic do after a patient data breach?
Tell each affected person without delay, in a concise, clear and plain way. Tell the Data Protection Board without delay, then send a detailed report within 72 hours of becoming aware of the breach. Failing to notify carries a penalty ceiling of up to ₹200 crore.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 09: Control your vendors, in the toolkit
- How-to 03: Know your data, in the toolkit
- How-to 11: When something goes wrong, in the toolkit
- The free duties list, every duty in plain words
In the news
- From trust to tech: protecting India’s health data
Newspaper piece on protecting health data amid cyber threats and the new rules.
- Cross-Border Transfer Of Healthcare Data: Reconciling India's DPDPA With GDPR
Practitioner view on healthcare data crossing borders, relevant if a clinic uses overseas cloud tools.
- Connected Healthcare and the Right to Privacy — Impact of DPDPA on Med-Tech
Legal analysis of the Act’s effect on connected medical technology, for clinics using such devices.
Sources
Every section, rule and date above was checked against the official text on 6 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 2(i)Data Fiduciary
- Section 2(k)Data Processor
- Section 2(s)Person includes an individual, a firm and a company
- Section 2(t)Personal data
- Section 3Digital personal data, including data collected on paper and digitised afterwards; personal or domestic use excluded
- Section 4(1)Processing only with consent or for a certain legitimate use
- Section 5(1)Notice with or before every consent request
- Section 6(1)Consent limited to the data necessary for the purpose; telemedicine illustration
- Section 6(6)Illustration: a telecom provider and the Data Processor that emails its bills
- Section 7(a), (f) and (g)Certain legitimate uses: voluntary provision (a), medical emergency (f), epidemic, outbreak or other public health threat (g)
- Section 8(1)Responsible for processing by a Data Processor, whatever the agreement
- Section 8(2)Processor engaged for offering goods or services: only under a valid contract
- Section 8(5)Reasonable security safeguards, including for processing by a processor
- Section 8(6)Intimation of a personal data breach to the Board and each affected person
- Section 8(7)Erase on withdrawal of consent or when the purpose is no longer served, unless a law requires retention; the bank illustration
- Section 9Verifiable parental consent, no harm to well-being, no tracking or targeted advertising for children
- Section 11(1) and (2)Right to the identities of other Data Fiduciaries and Data Processors the data was shared with; sharing with a body authorised by law, on its written request for offences or cyber incidents, is excluded
- Section 17Exemptions
- The Schedule, items 1 and 2Up to ₹250 crore (security safeguards); up to ₹200 crore (breach notice)
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(4)Rules 3, 5 to 16 in force eighteen months from publication
- Rule 6Reasonable security safeguards, including a contract provision with each processor
- Rule 7Breach: tell each affected person; tell the Board without delay and in detail within 72 hours of becoming aware
- Rule 8Three-year inactivity limit for three classes; one-year minimum for personal data, traffic data and logs
- Rule 12Exemptions from the child duties for the classes and purposes in the Fourth Schedule
- Fourth Schedule, Part A items 1 and 2Clinical establishment, mental health establishment, healthcare professional, allied healthcare professional: limited exemption for a child's data
- Third ScheduleThree-year inactivity limit: e-commerce entity, online gaming intermediary, social media intermediary
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17 in force eighteen months from 13 November 2025
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


