DPDP Act 2023 for Doctors: What Patient Data Rules Require

DPDP Act 2023 for Doctors: What Patient Data Rules Require

The DPDP Act 2023 for Doctors: What Patient Data Rules Actually Require

India’s Digital Personal Data Protection Act, 2023, together with the Digital Personal Data Protection Rules, 2025, has created the country’s first comprehensive, enforceable framework for how personal data — including patient health data — must be collected, used, stored, and protected. For a profession that has always treated patient confidentiality as an ethical duty, the DPDP Act adds something new: legal obligations, a regulator, and real financial penalties. Here is what it actually requires in practice.

Does the DPDP Act Apply to Individual Doctors and Small Clinics?

Yes, in principle. The Act applies to any entity that processes digital personal data and determines the purpose and means of that processing — a definition broad enough to cover hospitals, clinics, diagnostic labs, and individual practitioners who maintain digital patient records, appointment systems, or billing software. Larger hospital chains and health-tech platforms are more likely to be formally designated as Significant Data Fiduciaries, which carries extra obligations, but the baseline consent, notice, and security requirements are not limited to large organisations.

Under the DPDP Act, consent is the primary lawful basis for processing personal data, including health data. Consent must be free, specific, informed, unconditional, and given through a clear affirmative action — pre-ticked boxes or buried consent clauses do not meet the standard. A separate notice, given before or at the time consent is sought, must explain in plain, accessible language what data is being collected, why, how long it will be kept, and how the patient can withdraw consent or raise a grievance. Importantly, giving notice is not the same as obtaining consent — both steps are required.

A Specific Carve-Out That Matters for Healthcare

The DPDP Rules include a Fourth Schedule that exempts certain categories of data fiduciaries — including clinical establishments, mental health establishments, registered medical practitioners, and allied healthcare professionals — from the specific requirement to obtain verifiable parental consent when processing a child’s personal data for defined healthcare-related purposes, subject to conditions set out in the Rules. This is a narrow, purpose-specific exemption designed to avoid situations where a strict parental-consent requirement could delay urgent care for a minor; it does not remove the general obligation to give notice and handle data lawfully.

Telemedicine Consultations Need Their Own Attention

The 2020 Telemedicine Practice Guidelines already distinguish between patient-initiated consultations, where consent is treated as implied by the patient’s own action of starting the consultation, and doctor-initiated outreach, where explicit consent is required. DPDP compliance layers on top of this: even for a patient-initiated teleconsultation, the notice about data use should be presented before the consultation begins, so that the patient’s decision to proceed can reasonably count as the clear affirmative action the Act requires.

What Counts as a Data Breach, and What Happens Next

A data breach under the Act covers any unauthorised processing, or loss of access, integrity, or confidentiality of personal data — this could be anything from a hacked clinic database to a misdirected email containing patient reports. Data fiduciaries are required to notify both the Data Protection Board of India and the affected patients, in plain language explaining what happened, what data was involved, what the patient can do to protect themselves, and how to contact the organisation. Failing to notify a breach can attract a substantial penalty — reported at up to ₹200 crore per incident under the Act’s schedule of penalties — underscoring that this is not a box-ticking exercise.

Patient Rights Your Clinic Needs to Be Ready For

  • Right to access: patients can ask what personal data a clinic holds about them and how it is being used.
  • Right to correction and erasure: patients can request correction of inaccurate data, and erasure once the purpose for which it was collected no longer applies — clinics generally have 90 days to act on a valid erasure request.
  • Right to withdraw consent: patients can withdraw consent at any time, and withdrawal should be as easy as giving it was.
  • Right to grievance redressal: clinics need a clear, accessible way for patients to raise a data-related complaint before it escalates to the Data Protection Board.

Purpose Limitation: The Rule Most Clinics Overlook

Data collected for treating a patient cannot automatically be reused for marketing, research, or any other secondary purpose without separate, explicit consent. A clinic that collects a patient’s phone number for appointment reminders, for example, cannot use the same number for promotional WhatsApp messages without a distinct consent for that purpose — this connects directly to the advertising and solicitation restrictions covered elsewhere in NMC ethics rules.

What Larger Hospitals Face as Significant Data Fiduciaries

Hospitals or hospital chains that the Central Government designates as Significant Data Fiduciaries take on additional obligations: appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, undergoing independent data audits, and maintaining more detailed compliance records. Given how sensitive health data is treated across most data protection regimes globally, larger hospital groups and health-tech platforms should expect close scrutiny even before a formal designation is made.

A Practical Starting Checklist for Clinics

  1. Map what patient data you collect, where it is stored, who can access it, and who it is shared with (labs, billing partners, insurers, software vendors).
  2. Rewrite patient-facing consent language in plain, simple terms, available in the languages your patients actually use.
  3. Separate consent for treatment-related data use from any consent for marketing or promotional communication.
  4. Put a basic breach-response plan in place: who is notified internally, how patients are informed, and how a report reaches the Data Protection Board if needed.
  5. Review contracts with any third party that processes patient data on your behalf (billing software, cloud storage, diagnostic partners) to confirm they meet DPDP obligations too.

Frequently Asked Questions

Does the DPDP Act replace medical confidentiality obligations under the NMC ethics code?

No. It sits alongside them. The ethics code has always treated patient confidentiality as a professional duty; the DPDP Act adds a separate, legally enforceable data protection framework with its own regulator and penalties.

Is a small, single-doctor clinic exempt from the DPDP Act?

There is no blanket size-based exemption for the core consent and notice obligations, though smaller entities are less likely to be designated Significant Data Fiduciaries, which carries the heaviest additional obligations.

Retention should be tied to a genuine purpose — including applicable medical record-keeping laws — rather than indefinite default storage; once the purpose is served and no other legal obligation requires retention, data should be erased.

Do I need a Data Protection Officer for a small clinic?

A dedicated Data Protection Officer is specifically required for entities designated as Significant Data Fiduciaries; most small and mid-size clinics are unlikely to fall into that category, though someone in the practice should still be responsible for data compliance.

What is the single most common compliance gap in clinics right now?

Using patient contact details collected for treatment purposes (appointment reminders, reports) for unrelated promotional messaging without separate consent is one of the most frequent and easily fixed gaps.

Research Sources

  1. Digital Personal Data Protection Act, 2023, and Digital Personal Data Protection Rules, 2025 (meity.gov.in)
  2. KSandK — Data Privacy Compliance for Healthcare and Healthtech in India
  3. AMLEGALS — Health Data and the DPDP Act: A Practical Guide, including telemedicine-specific consent analysis
  4. Cyril Shroff / official DPDP Act FAQs — Fourth Schedule exemptions for clinical establishments and healthcare professionals
  5. Seclore — Digital Personal Data Protection Rules 2025 compliance guide, breach notification and erasure framework

Disclaimer

This article is for general informational and educational purposes and reflects the DPDP Act and Rules as understood at the time of writing. It is not legal advice; clinics and hospitals should consult a qualified data protection lawyer to assess their specific obligations and build a compliant data-handling programme.

Vivek Chaudhary is a Technical Content Developer specializing in healthcare, health technology, and digital healthcare business solutions. He creates research-driven, SEO-focused content for doctors, clinics, hospitals, healthcare professionals, and patients, covering topics such as healthcare technology, patient engagement, clinic management, digital communication, and online visibility.

Vivek Chaudhary

<strong>Vivek Chaudhary</strong> is a Technical Content Developer specializing in<strong> healthcare, health technology, and digital healthcare business solutions</strong>. He creates research-driven, SEO-focused content for doctors, clinics, hospitals, healthcare professionals, and patients, covering topics such as healthcare technology, patient engagement, clinic management, digital communication, and online visibility.

0 comments

Top