The Digital Personal Data Protection Act 2023 (DPDPA) is India's first comprehensive data privacy law, enforceable from 2024–2025 as rules are phased in by MeitY. For clinics — who collect health data, Aadhaar numbers, contact information, and genetic data — the law creates eight binding obligations, four categories of patient rights, and penalties that reach ₹250 crore for serious violations. Every clinic with patients on a digital system is a data fiduciary under DPDPA and must comply.
The Digital Personal Data Protection Act 2023 governs how organisations collect, store, process, and share personal data of Indian citizens. A clinic is a "data fiduciary" — an entity that determines the purpose and means of processing personal data. Patients are "data principals." Health data is classified as sensitive personal data, which attracts stricter rules. The Act applies to any clinic processing digital personal data, regardless of size.
| Patient Right | What it Means for the Clinic | Response Window |
|---|---|---|
| Right to Access | Patient can request a summary of all personal data held about them | 30 days |
| Right to Correction | Patient can request correction of inaccurate or outdated data | 30 days |
| Right to Erasure | Patient can withdraw consent and request deletion (subject to legal retention requirements) | 30 days |
| Right to Nominate | Patient can nominate a person to exercise rights on their behalf | At registration |
| Right to Grievance Redressal | Patient can file a complaint and escalate to the Data Protection Board | 30 days to respond |
| Violation | Maximum Penalty |
|---|---|
| Failure to protect personal data (breach due to inadequate security) | ₹250 crore |
| Failure to notify a breach to the Data Protection Board and patients | ₹200 crore |
| Processing children's data without parental consent or age verification | ₹200 crore |
| Violation of obligations by significant data fiduciaries | ₹150 crore |
| Other violations (purpose limitation, data quality, grievance redressal) | ₹50 crore |
Source: Digital Personal Data Protection Act 2023, Schedule. Penalties are per violation and can compound across multiple violations arising from the same incident.
Yes. DPDPA applies to any entity that processes digital personal data of Indian citizens, regardless of size. A solo GP using a digital EMR, an online appointment system, or even a WhatsApp-based booking system is a data fiduciary under DPDPA. However, smaller clinics are unlikely to be classified as "significant data fiduciaries" and will have a lighter obligation set.
Personal data includes any data that identifies or can identify a patient — name, phone number, address, email, Aadhaar number, health records, prescription history, and genetic or biometric data. Health data is classified as sensitive personal data and attracts stricter protection requirements.
The DPDPA received Presidential assent in August 2023. Rules are being notified in phases by MeitY from 2024. Clinics should treat the obligations as active now — particularly consent, notice, and breach notification — and use the phased rollout as time to implement security controls and data mapping.
Significant data fiduciaries must appoint a Data Protection Officer based in India. Ordinary data fiduciaries (most smaller clinics) are not required to have a DPO but must appoint a Grievance Officer with published contact details and respond to grievances within 30 days.
The IT Act 2000 and SPDI Rules 2011 already required reasonable security practices for sensitive personal data including health records. DPDPA goes further: it codifies explicit consent requirements, patient rights (access, correction, erasure), breach notification timelines, and an enforcement body (Data Protection Board). DPDPA supersedes the SPDI Rules for data protection obligations.
Yes, but with restrictions. Research purposes can qualify as "public interest" processing under DPDPA but typically require anonymisation of the data, patient consent where identifiable data is used, and ethical committee approval for clinical research. Blanket "research" claims without anonymisation will not satisfy the purpose limitation requirement.
Answer 12 questions about your data practices. Get a personalised report with your compliance gaps and a prioritised action list — free, no sign-up required.