Sector guide

DPDP Compliance for Healthcare and Hospitals

Healthcare processes some of the most sensitive personal data there is, usually across the least consolidated systems. Hospital information systems, laboratory systems, PACS imaging, pharmacy, insurance desks and increasingly ABDM-linked records each hold part of a patient's record, and very few providers can say precisely where all of it sits.

Priya Gupta

What makes healthcare harder than most sectors

The obligations are the same as anyone else's. The estate is what differs.

  • Data is fragmented across HIS, LIS, PACS, pharmacy and billing, often from different vendors and eras, frequently on-premise.
  • Consent is taken at the point of care, sometimes on paper, sometimes by a person who is unwell or accompanied by a relative — so proving consent was free, informed and unambiguous is genuinely difficult.
  • Children's data appears routinely in paediatrics, and the Act treats it with additional care obligations.
  • Third parties are everywhere: insurers, TPAs, referring doctors, diagnostic partners and increasingly ABDM participants.

Consent at the point of care

The realistic answer is to separate clinical care from everything else. Treatment records generally do not rest on consent as their lawful basis; marketing, research participation, feedback campaigns and data sharing with partners usually do. Bundling all of it into one admission form is the common failure — it makes the whole bundle challengeable.

Notices must be available in a language the patient can read, which in most Indian hospitals means more than English.

What to do first

Inventory the systems before touching consent forms. In healthcare the inventory itself is usually the revelation, because imaging archives and legacy lab systems tend to hold far more identifiable data, for far longer, than anyone assumes.

Then split the consent model: care, versus everything else.

Frequently asked questions

Does the DPDP Act apply to hospitals?

Yes. A hospital determining the purpose and means of processing patients' digital personal data is a Data Fiduciary under the Act.

Is patient consent required for treatment under the DPDP Act?

Clinical care generally does not rest on consent as its lawful basis. Marketing, research, feedback campaigns and sharing with partners usually do — which is why bundling all of it into one admission form is a weak position.

How does the DPDP Act treat children's health data?

Data relating to children carries additional obligations, including verifiable parental consent and restrictions on tracking and targeted advertising. Paediatric records need to be identifiable as such in your inventory.

Priya GuptaPriya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →