1Executive Summary
The Digital Personal Data Protection Act 2023 (DPDPA) is not a technology regulation. It is a personal data regulation that applies to every Indian business - including every clinic, hospital, and diagnostic centre - that collects, stores, or processes digital personal data about individuals. Patient names, phone numbers, appointment records, WhatsApp messages, health histories, and photographs stored on a clinic computer all fall within its scope. The Act was passed in August 2023 and entered operational effect in 2025. As of July 2026, the Ministry of Electronics and Information Technology (MeitY) had published draft rules and was advancing the subordinate rulemaking process; several details remain to be confirmed in final subsidiary regulations. Clinics should monitor MeitY's official notifications for updates as implementation continues.
What the Act already establishes clearly: clinics are Data Fiduciaries - meaning they determine the purpose and means of processing patient data and carry direct legal obligations. Patients are Data Principals with enforceable rights to access, correct, and in some circumstances erase their data. Consent must be freely given, specific, informed, unconditional, and unambiguous - not buried in a form nobody reads. And the Data Protection Board, once constituted, can impose penalties reaching ₹250 crore for significant violations. None of this is aspirational. It is operative law.
Most Indian clinic owners and hospital administrators have not yet mapped the Act's requirements against their actual data practices. This article explains what the DPDPA requires in terms every clinician can follow, distinguishes what is currently clear from what awaits further regulatory specification, and provides a practical compliance framework - the COMPLY method - that any small clinic can begin implementing today without a dedicated compliance team.
---
2The Problem
Dr. Ananya Pillai runs a mid-sized dermatology practice in Pune. She has been in practice for eleven years. She has three staff, a WhatsApp Business account she uses to send appointment reminders and follow-up photos to patients, a third-party appointment booking software that stores patient contact details on cloud servers, a Google Drive folder where her staff save patient photographs for before-and-after comparisons, and a local computer that holds an eleven-year archive of patient records in a mix of Excel spreadsheets and scanned documents. When a pharmaceutical company approached her last year about sharing anonymised patient data for a market research study, she said yes, reasoning that the data would be anonymised. She did not think to ask whether her patients had consented to that use of their information, or whether it was covered in any form they had signed.
Dr. Pillai is not unusual. She is not negligent by the standards of how Indian medical practices have historically operated. The problem is that the legal standards governing patient data in India have changed materially, and the change has not propagated at the same speed as the obligations it creates. The DPDPA does not grandfather in legacy data practices. If a clinic today collects a patient's phone number for appointment reminders and then uses it to send promotional messages about a new aesthetic treatment, that secondary use requires either additional consent or a lawful basis that promotional messaging does not satisfy. The data was not collected for that purpose. Using it for that purpose - regardless of how common the practice is - is a violation under the Act.
The data footprint of a modern Indian clinic is larger and more complex than most clinic owners recognise. WhatsApp conversations are data. The auto-saved contacts on a staff member's phone, if those contacts include patient numbers, are data. Third-party appointment booking platforms that retain patient histories for years are data processors acting on the clinic's behalf - which means the clinic, as Data Fiduciary, is legally responsible for what those processors do with patient data. The informal Google Drive folder shared among clinic staff for convenience may have default sharing settings that expose data beyond the intended group. None of these are exotic edge cases. They are the daily operational reality of the vast majority of Indian medical practices.
The compliance problem is further complicated by awareness. A 2025 survey of Indian small and medium enterprises by industry bodies found that awareness of DPDPA obligations was substantially lower among healthcare service providers than among technology companies - even though both categories face identical statutory obligations. The Act does not carve out a special exception for small clinics or individual practitioners. It applies to all Data Fiduciaries processing digital personal data, with limited exemptions that do not cover routine patient administration. A solo-practice physician and a corporate hospital chain are both Data Fiduciaries. The obligations are the same; only the scale of implementation varies.
The consequences of non-compliance are not theoretical. The Data Protection Board, which hears complaints from Data Principals (patients) whose rights are violated, can issue penalties calibrated to the nature and severity of the breach. More immediately practical than maximum penalties is the complaint mechanism itself: a patient who believes their data was used without proper consent, or who requests access to their records and is denied, has a direct legal pathway to file a complaint with the Board. The reputational and legal costs of a formal complaint - even one that does not result in a maximum penalty - are significant for a small clinic that depends on community trust.
---
3Why It Matters - India-Specific
India's healthcare sector has a structural characteristic that makes the DPDPA's arrival particularly consequential: private providers handle the majority of clinical interactions, and their data practices have historically been governed more by habit than by formal compliance frameworks. Sharma et al. (2025), in a peer-reviewed study of 5,061 PM-JAY eligible individuals across seven Indian states published in Global Health Action (PMC11998304), found that 48.0% of respondents sought outpatient care from private providers, compared to 18.3% from public facilities, with 23.1% reporting no regular outpatient care at all. The dominance of private-sector care means that when a data protection framework applies to healthcare, its impact in India falls disproportionately on private clinics and hospitals. This is not a public-sector regulation that a government health system can absorb through centralised compliance infrastructure. It is a regulation that falls on hundreds of thousands of privately run practices, most of which have no legal or compliance function.
India crossed 800 million smartphone users in 2024, with a median national age of 29. This demographic profile has a direct bearing on DPDPA compliance for clinics, in two ways. First, the platforms through which clinics now engage patients - WhatsApp, Google Business Profile, Practo, JustDial, Instagram - are all digital channels that generate personal data at every touchpoint. A patient who books an appointment via Practo, receives a WhatsApp reminder, and leaves a Google review has created a data trail touching at least three platforms, all of which involve the clinic in some capacity as the recipient or initiator of that data flow. Second, younger patients are meaningfully more aware of their digital rights than the patient populations Indian clinics were designed around. A 35-year-old patient in 2026 is substantially more likely to ask what happens to their data than a patient of the same age in 2015. The cultural assumption that patients do not notice or care about data practices is increasingly unreliable as the population ages into a cohort that grew up with privacy awareness baked in.
The regulatory environment compounds these dynamics. The DPDPA operates alongside - not instead of - two other relevant frameworks for healthcare. ABDM (Ayushman Bharat Digital Mission) establishes ABHA (Ayushman Bharat Health Account) as a patient health ID layer and sets interoperability and data sharing standards for health records. The National Medical Commission (NMC) governs professional conduct for registered medical practitioners, including the ethical obligations around patient confidentiality that predate the DPDPA by decades. What the DPDPA adds is an enforceable legal framework with specific procedural requirements - notice, consent, rights fulfilment, breach notification - that codifies and significantly extends what professional ethics previously governed only in principle. A physician who handles patient data in a way that violates the DPDPA may face both Data Protection Board proceedings and NMC professional conduct implications. The frameworks interact; a clinic's compliance approach should account for both.
The FICCI-EY Parthenon survey of over 1,000 patients and 100 clinicians, published in October 2025, found that patients rely heavily on "informal proxies like brand reputation and word-of-mouth" when choosing healthcare providers - and that 83% of patients aspire to accessible, trustworthy health information. That aspiration increasingly includes trust in how their data is handled. While the survey did not directly measure data privacy as a selection criterion, the pattern is consistent with global evidence showing that data breaches and perceived misuse of health data damage institutional reputation disproportionately compared to other service failures. A clinic that proactively demonstrates DPDPA compliance is not merely avoiding a legal risk - it is building the kind of institutional trust that the patient population is actively seeking.
---
4Research and Evidence
On general DPDPA compliance awareness in India, the documented evidence from the 2025 period is predominantly industry-report grade rather than peer-reviewed. Multiple surveys of Indian businesses across sectors noted that awareness of specific DPDPA obligations - particularly the requirements for valid consent documentation, the data principal rights provisions, and breach notification timelines - was substantially lower than awareness of the Act's existence. The gap between knowing the law exists and understanding what it operationally requires is the central challenge. These surveys are industry reports, not peer-reviewed research, and carry inherent limitations in sampling methodology. Label: industry observational, directionally applicable; treat as characterising the awareness gap, not measuring it precisely.
The evidence on health data breach consequences comes primarily from US and international contexts, where data protection regulation has been operative for longer. A series of analyses of US Health Insurance Portability and Accountability Act (HIPAA) enforcement actions, published in academic journals including the Journal of the American Medical Informatics Association, found that the largest category of violations in small healthcare practices was not sophisticated cyberattacks but procedural failures: inadequate access controls, failure to execute formal data processing agreements with vendors, and disclosure of protected health information in communications channels (including fax, email, and messaging applications) that lacked adequate security. These procedural failure patterns are directly analogous to the operational habits observed in Indian clinics - WhatsApp use for clinical communication, informal data sharing with third parties, and absence of vendor agreements that specify data handling obligations. Label: US data, directionally applicable to India; US regulatory context differs from DPDPA but underlying procedural failure patterns are directly relevant.
On the specific question of consent in Indian healthcare, there is a meaningful evidentiary gap. No peer-reviewed study as of July 2026 has systematically assessed the validity of consent practices in Indian private clinics against the DPDPA's consent requirements. What exists is a body of medical ethics literature examining informed consent for clinical procedures - a different but related domain - which consistently finds that consent in Indian clinical settings is frequently sub-optimal: forms are signed without being read, verbal consent is not documented, and patients commonly report not understanding what they consented to. The DPDPA's consent standard is behavioural and procedural: it is not satisfied by a patient's signature on a form they did not read. Whether standard clinic consent practices in India meet the DPDPA standard is an open empirical question. Given the medical ethics literature, the answer is likely to be uncomfortable. Label: evidentiary gap; the medical ethics literature provides directional inference that existing consent practices are probably non-compliant with DPDPA standards in many settings.
On data minimisation and proportionate data collection, international evidence from GDPR-regulated European healthcare settings offers the most relevant directional benchmark. Research published following GDPR implementation consistently found that healthcare providers were collecting substantially more personal data than was necessary for the stated clinical purpose - maintaining patient contact details for administrative convenience that was not necessary for care, retaining marketing preferences data indefinitely, and storing data on individuals who had not been seen for years without a documented retention basis. The DPDPA contains analogous data minimisation principles, requiring that data collection be limited to what is necessary for the stated purpose. Indian clinics that have never conducted a data inventory have no visibility into whether they are complying with this principle, because they do not know what data they hold. Label: European GDPR data, directionally applicable to India; data minimisation findings reflect universal administrative practices not jurisdiction-specific factors.
On ABDM data localization and interoperability obligations, the available documentation is primarily regulatory and technical specification rather than independent research. MeitY and the National Health Authority have published technical standards and guidelines for ABHA-linked health data exchange. Clinics that participate in ABDM - whether by registering patient ABHA numbers or by sharing health records through ABDM-compliant infrastructure - take on additional data handling obligations that are specified in the ABDM framework and must be read alongside DPDPA compliance. The two frameworks are designed to be compatible but require separate assessment; ABDM compliance does not establish DPDPA compliance, and vice versa. Label: regulatory specification, primary source; independent evaluation of implementation practices is limited.
On penalties and enforcement trajectories, the Data Protection Board was constituted following the DPDPA and has begun its operational phase. As of July 2026, the Board's enforcement record is early-stage and the full scale of penalty application to small healthcare providers was not established in the public record. Clinics should not interpret a thin early enforcement record as suggesting low regulatory risk. The penalty framework is statutory and clear. The Board's capacity and enforcement focus typically expand over the first years of operation of a new regulatory body; early-stage low enforcement activity is historically a poor predictor of medium-term risk. Label: regulatory observation; enforcement trajectory based on analogous regulatory body patterns, not India-specific DPDPA outcomes data.
---
5Influx Health Perspective
The following section is Influx Health's interpretation and opinion, not research.
Working with more than 60 Indian healthcare organizations, we have observed a specific and consistent pattern with data compliance: clinic owners and hospital administrators consistently believe their data practices are better than they are. When we ask whether they have a valid consent mechanism in place for using patient contact details for appointment reminders, the answer is almost always yes. When we ask to see it - the specific wording in the consent form, where it discloses the purpose of collecting the phone number - it is either absent, buried in a general consent form that was never designed to meet DPDPA standards, or it exists only as a verbal practice that is not documented. The intent is there. The execution that satisfies the statute is not.
The WhatsApp situation deserves specific attention because it is the single most common data compliance exposure we see in Indian clinics, and it is widely underestimated. WhatsApp Business is used by the majority of the clinics we work with as the primary patient communication channel. This is operationally sensible - patients respond to WhatsApp, appointment confirmation rates are higher than email, and post-consultation follow-ups work well. But WhatsApp conversations are personal data. The phone numbers in a clinic's WhatsApp Business contact list are personal data. If a clinic collects a patient's number for appointment booking and then adds them to a broadcast list for health tips, seasonal promotional offers, or a new service announcement, that secondary use was not covered by the purpose for which the number was collected, and the DPDPA requires either fresh consent for that purpose or a lawful basis that does not exist for promotional communication. We are not predicting that clinics will be investigated for their WhatsApp broadcast lists tomorrow. We are noting that the legal exposure is real, that it applies to standard current practice across the sector, and that the fix is straightforward once the obligation is understood.
A third observation: the vendor agreement gap is material and underappreciated. Any third-party software that processes patient data on a clinic's behalf - appointment booking platforms, CRM tools, diagnostic report sharing systems, telemedicine platforms, cloud storage services - constitutes a Data Processor relationship under the DPDPA framework. The clinic, as Data Fiduciary, is responsible for what those processors do with patient data. In practice, most clinics have not reviewed the data handling terms of their third-party software vendors for DPDPA compliance. Several widely used appointment booking and clinic management platforms operating in India had not published updated data processing terms as of early 2026. This is not the clinic's fault in origin - the vendor should maintain compliant terms - but the legal exposure sits with the Data Fiduciary when a violation occurs. Reviewing and, where necessary, renegotiating vendor data processing terms is unsexy compliance work that most clinics have not prioritised. It needs to become a standard procurement step.
Finally, a note on proportionality. The DPDPA's ambitions are substantial, and the full subsidiary regulatory framework was still being finalised as of July 2026. It is reasonable for a small clinic without a compliance function to feel overwhelmed. But the core obligations are not operationally complex - they are primarily about building deliberate process where informal practice currently exists. A small clinic that has documented what data it holds, where it holds it, why, and under what consent; that has an updated patient intake form with proper DPDPA-compliant notice and consent language; that has reviewed the data handling terms of its three or four main software vendors; and that has a basic protocol for what to do if a data breach occurs is already substantially ahead of the current sector standard. This is achievable work. It does not require a lawyer on retainer or a compliance department. It requires dedicated attention for roughly two to three weeks of one person's time, and a commitment to updating processes as the subsidiary rules are finalised.
---
6Practical Framework: The COMPLY Method
The COMPLY method is a practical compliance sequence for small clinics navigating DPDPA obligations without a dedicated compliance team. Work through the six elements in order - each one builds on the previous.
C - Catalog your data assets Before you can manage your data obligations, you need to know what data you hold, where it lives, and why it is there. Run a systematic inventory: patient intake forms (paper and digital), appointment booking software, WhatsApp Business contacts and conversations, email correspondence, cloud storage (Google Drive, Dropbox, OneDrive), local computer files, third-party diagnostic and report platforms, and any CRM or practice management software. For each data category, note the type of data (names, phone numbers, health information, photographs, financial details), where it is stored, who has access, and when it was collected. Most clinics are surprised by how many places patient data lives once they do this exercise honestly.
O - Obtain valid, documented consent Under DPDPA Section 6, valid consent must be freely given, specific, informed, unconditional, and unambiguous - signified by a clear affirmative action, not assumed from silence or a pre-ticked box. Review every touchpoint at which you collect patient data and confirm that the consent obtained at that point covers the specific purpose for which the data will be used. Your registration form should state, in plain language, what data you collect, why, who else will access it, and how long you retain it. Consent obtained for appointment booking does not cover promotional messaging. Consent for treatment does not cover sharing data with a third-party research partner. Where you discover gaps between the consent you have obtained and the purposes you are currently using data for, either obtain fresh consent or stop the secondary use. Keep records of consent - a dated log entry noting when consent was obtained, for what purpose, and through what mechanism.
M - Map patient rights into your workflow Under DPDPA Sections 11–16, patients (Data Principals) have rights you are legally obligated to honour: the right to know what data you hold about them (access), the right to correct inaccurate data, the right to erase data in certain circumstances, the right to nominate someone to exercise those rights on their behalf, and the right to withdraw consent. These rights are not optional. You need a process for handling such requests. Designate a person in your clinic who receives and processes data rights requests. Define a maximum response time (the Act and rules specify obligations here - monitor MeitY updates for the confirmed timeframe). Create a simple log for tracking such requests and their resolution. Most small clinics will receive very few data rights requests; having a process costs almost nothing and protects you entirely.
P - Protect data with proportionate security DPDPA Section 8 requires Data Fiduciaries to implement reasonable security safeguards to prevent personal data breaches. For a small clinic, this does not mean enterprise-grade cybersecurity infrastructure. It means: password-protecting clinic computers and requiring individual logins rather than a shared password; using two-factor authentication on email and cloud storage accounts used for patient data; ensuring that WhatsApp Business account access is restricted to authorised staff; not storing patient photographs or records on personal devices without access controls; reviewing the security settings of every third-party platform that holds patient data; and having a basic protocol for what happens if a device is lost or stolen. These are standard digital hygiene measures. They are not technically complex. They are simply not implemented by default in the vast majority of clinics we work with.
L - Limit retention - define and enforce data lifecycles The DPDPA's data minimisation and storage limitation principles require that personal data be retained only as long as necessary for the purpose it was collected, and no longer. In practice, this means a clinic should have a documented retention policy - even if it is one page - that states how long different categories of patient data are kept, and what happens to them at the end of that period. Medical records retention requirements under the Clinical Establishments Act and the Indian Medical Council Regulations set minimum retention periods (commonly seven years for case records); these minimum periods are relevant to the DPDPA analysis because they constitute a lawful basis for retention during that window. Data beyond the minimum retention window - particularly marketing data, promotional contact lists, and records of patients who have not been seen in many years - needs a documented lawful basis or should be deleted.
Y - Your breach notification plan - prepare before you need it The DPDPA requires Data Fiduciaries to notify the Data Protection Board and affected Data Principals "as soon as possible" (final notification timelines will be specified in subsidiary rules - monitor MeitY) in the event of a personal data breach. A breach is not limited to a cyberattack. It includes any unauthorised access, disclosure, or loss of personal data - including a staff member sending a patient's records to the wrong number on WhatsApp, a laptop being stolen, or a third-party platform reporting a security incident. Your breach notification plan does not need to be complex. It needs to include: who in the clinic is responsible for identifying and assessing a potential breach; who is responsible for notifying the Board; a template for notifying affected patients; and a log for recording breach incidents and responses. Building this plan before an incident occurs is materially easier than building it under the time pressure of an actual breach.
---
7Action Checklist
- This week - Run your data inventory. List every place patient data is stored: computers, cloud drives, appointment software, WhatsApp Business, email, paper records that have been scanned. For each location, note what type of data, who has access, and whether access is secured by individual login and two-factor authentication. This single exercise will reveal most of your current exposure.
- This week - Review your patient intake form. Does it contain a clear notice of what data you collect, why, who else will see it, and how long you keep it? If not, draft a simple one-page DPDPA-compliant notice to include in your registration process. Ensure it obtains explicit opt-in consent for any use beyond direct clinical care - including appointment reminders, WhatsApp follow-ups, and health communications.
- This month - Audit your third-party vendor data terms. Open the privacy policy and data processing terms of your appointment booking software, any CRM or practice management tool, diagnostic report platforms, and cloud storage services you use for patient data. Confirm each has an updated policy that acknowledges its obligations as a Data Processor. Flag any vendor that does not - and decide whether to request a data processing agreement or switch platforms.
- This month - Check your WhatsApp broadcast lists. If you are using WhatsApp Business to send promotional, health-tip, or new-service messages to patients, confirm that each person on those lists provided explicit consent for that specific type of communication. If they did not - they consented only to appointment reminders - stop those broadcasts until you obtain fresh consent or establish a lawful basis.
- This month - Designate a data rights contact. Name one person in your clinic as the recipient for patient data rights requests. Make their contact details available on your website and intake materials. Create a simple log for requests received and responses given. This costs almost nothing and creates evidence of compliance if a complaint is ever filed.
- Ongoing - Monitor MeitY for subsidiary rules updates. The DPDPA's operational details are being progressively confirmed through subsidiary rules published by MeitY. Subscribe to MeitY's official notifications (meity.gov.in) or follow the Digital India updates from a reliable legal or professional body in your sector. The core obligations above are current law now; the detailed procedural specifications will be clarified as the rules are finalised.
---
8FAQs
Q: My clinic is small - does the DPDPA actually apply to me?
Yes. The DPDPA applies to every person or organisation that processes the digital personal data of individuals in India, unless they fall within a specific statutory exemption. The exemptions are narrow: personal or domestic data processing (not applicable to clinic operations), research and statistical purposes under certain conditions, courts and legal proceedings, and national security. Running a clinical practice, including maintaining patient appointment records, sharing phone numbers for follow-up reminders, and storing health histories on a computer, is unambiguously covered. The Act does not create a small-business exemption or a healthcare-specific carve-out beyond the narrow provisions in Section 7 (discussed below). If you process digital personal data about patients - which every clinic with a computer or a smartphone does - the DPDPA applies to you.
Q: Section 7 of the DPDPA says data can be processed without consent in certain situations, including by healthcare professionals. Does this mean clinics do not need patient consent for treatment-related data?
Section 7 provides for what the Act calls "deemed consent" - situations where consent is presumed to have been given by virtue of context rather than explicit affirmative action. One of those situations involves processing by healthcare professionals under circumstances of medical emergency or where the processing is necessary for the provision of healthcare by a licensed medical practitioner. This provision addresses emergency treatment situations where obtaining explicit prior consent is not practical. It does not eliminate the consent requirement for routine clinic operations. The appointment booking system that collects your patient's name, phone number, and reason for visit for administrative purposes is not operating under a medical emergency exemption. Your WhatsApp follow-up sequence is not a healthcare professional necessity exemption. Section 7 is a narrow carve-out for genuine clinical necessity situations, not a blanket exemption from consent for all patient data processing. Read the Section carefully and consider getting qualified legal opinion before relying on it for routine administrative data practices.
Q: What happens if a patient requests access to or erasure of their records? Can a clinic refuse on medical grounds?
Under Sections 12–16 of the DPDPA, patients have the right to obtain a summary of the personal data you have processed about them and the processing activities undertaken. They also have the right to request erasure of their data once the purpose for which it was collected is fulfilled - subject to exceptions for retention obligations imposed by other laws. This is where medical records retention requirements become directly relevant: if applicable regulations or legal standards require you to retain records for a minimum period (such as case records under medical council regulations), you have a lawful basis to decline an erasure request for the retained data during that period. You should document that basis clearly and communicate it to the patient. What you cannot do is ignore the request, refuse without explanation, or treat data rights requests as an inconvenience. A patient whose legitimate access request is denied without explanation has a clear path to a Data Protection Board complaint. Responding substantively - even if the response is "we cannot erase this record for the following legal reason" - is both good practice and legal protection.
Q: We use a cloud-based appointment booking platform. Are we responsible for how they handle patient data?
Yes. Under the DPDPA framework, your appointment booking platform is a Data Processor - a third party processing personal data on your behalf, under your instructions, as the Data Fiduciary. Data Fiduciaries are responsible for ensuring that their Data Processors handle data in a manner consistent with the Act's requirements. This means you should have a data processing agreement with your platform provider that specifies: what data they may process, for what purposes, under what security standards, for how long they retain data, and what happens in the event of a breach. Many platforms' standard terms of service do not constitute an adequate data processing agreement under the DPDPA framework. You may need to request a supplemental data processing addendum or data protection agreement from your vendor. If a vendor declines to provide one, that is a significant compliance risk signal. You remain responsible for the platform's data handling practices even if the breach originates with the vendor.
Q: The rules under the DPDPA were still being finalised as of mid-2026. Should a clinic wait for the final rules before doing anything?
No. The core obligations in the DPDPA - valid consent, notice requirements, data principal rights, reasonable security safeguards, and breach notification - are current law now. They are in force. The subsidiary rules being developed by MeitY will clarify specific procedural details: exact timelines, formats for notices, technical standards for security safeguards, and the operational specifications for the Data Protection Board. Waiting for those rules before beginning compliance work is a misunderstanding of the legal situation. The broad obligations are already in force and apply today. Beginning the compliance steps in the COMPLY framework now does not mean you will have to redo them when the final rules are published - it means you will be largely compliant when the rules arrive, rather than scrambling to implement processes under enforcement pressure. The sensible approach is to implement the core framework now and update specific procedural details as the subsidiary rules confirm them. Subscribe to MeitY updates and review your processes against each update as it is published.
---
9Related Resources
Internal - Influx Health Institute - Understanding the NMC Advertising Guidelines: What Indian Doctors Can and Cannot Say Online - Building a Compliance Culture in Your Practice: From Solo Clinic to Multi-Specialty Group - ABDM and Your Clinic: What the Ayushman Bharat Digital Mission Means for Patient Data
External - Authoritative Sources - Ministry of Electronics and Information Technology (MeitY) - Official DPDPA text and subsidiary rules notifications: https://www.meity.gov.in/data-protection-framework - Digital Personal Data Protection Act 2023, Government of India - official gazette: https://www.indiacode.nic.in (search "Digital Personal Data Protection Act 2023") - National Health Authority - ABDM Data Policy and Framework: https://abdm.gov.in/publications
---
10Call to Action
Read Next: Understanding the NMC Advertising Guidelines: What Indian Doctors Can and Cannot Say Online - the companion governance article covering professional conduct obligations for digital marketing by registered practitioners.
Assess Your Practice: Check your clinic's digital presence and data exposure at /dpm - the Digital Presence Meter shows where your clinic appears online, how patient-facing data points are distributed across platforms, and where your visibility and compliance posture have gaps.
Chat with Influx Health: Speak with the Influx Health team at /contact - if you would like a structured assessment of your clinic's DPDPA readiness, or help building the patient acquisition systems that work within these compliance boundaries.
--- ---
# Content Derivatives: Center 9, Article 2 - DPDPA for Indian Clinics
---
(a) Email Newsletter Version
Subject line: Your clinic may be violating India's new data protection law - here is what to check this week
---
Dear Dr. [Name],
The Digital Personal Data Protection Act 2023 has been in force since 2025, and most Indian clinic owners have not yet mapped its requirements against how they actually handle patient data. We want to be direct about what this means in practice, because the gap between awareness and compliance is significant across the sector.
Here is the core issue: the DPDPA applies to every business in India that collects or processes digital personal data - and that includes every clinic with a computer, a smartphone, or a third-party appointment booking platform. Patients are now Data Principals with enforceable rights. Clinics are Data Fiduciaries with specific legal obligations. The penalties for violations can reach ₹250 crore for significant breaches, and patients can file complaints directly with the Data Protection Board.
The four areas we see most commonly non-compliant in Indian clinics are: consent documentation that does not meet the Act's standard of being freely given, specific, informed, and unambiguous; WhatsApp broadcast lists that include patients who consented only to appointment reminders, not promotional or health-tips content; third-party software vendors holding patient data under terms that have not been reviewed for DPDPA compliance; and no documented process for handling patient requests to access, correct, or erase their data.
None of these are difficult to fix once you know what the standard is. Our latest Institute article walks through the COMPLY method - a six-element framework for small clinics - covering data inventory, consent documentation, patient rights workflows, security safeguards, retention policies, and breach notification planning. It also explains what the Act currently requires clearly versus what awaits finalisation in MeitY's subsidiary rules, so you know exactly what to act on now versus what to watch for.
The article takes approximately 12 minutes to read. It is written for clinic owners and administrators who need to understand their obligations without a law degree.
Read the full article: Patient Data and the DPDPA: What Every Indian Clinic Needs to Know
You can also run a quick assessment of your clinic's digital data footprint using the Digital Presence Meter at /dpm - it shows where your clinic's data appears across platforms and surfaces exposure points worth reviewing.
Best regards, The Influx Health Institute Research Team
---
(b) WhatsApp Summary
India's new data law now applies to your clinic - here is what matters (3-minute read)
The Digital Personal Data Protection Act 2023 is live. It applies to every Indian clinic, not just large hospitals or tech companies.
What it means for you:
- You are a Data Fiduciary - legally responsible for how patient data is collected, used, and protected
- Your patients are Data Principals - they have enforceable rights to access, correct, and erase their data
- Consent must be specific and documented - verbal consent or an unsigned form is not enough
The 3 most common violations we see:
- Using patient WhatsApp numbers for promotions when they only consented to appointment reminders
- Not having a process to respond when a patient asks "what data do you hold on me?"
- Third-party booking platforms holding patient data under terms the clinic has never reviewed
Detailed rules are still being finalised by MeitY - but the core obligations are current law now.
The COMPLY method gives you a practical 6-step framework: Catalog your data, Obtain proper consent, Map patient rights, Protect with security, Limit retention, Your breach plan.
Full article (12-minute read): /institute/governance-compliance/dpdpa-for-clinics
Check your clinic's digital data footprint: /dpm
---
(c) LinkedIn / Facebook Post
India's healthcare sector has a data compliance problem that most practitioners do not yet know they have.
The Digital Personal Data Protection Act 2023 entered operational effect in 2025. It applies to every Indian business that collects or processes digital personal data - including every clinic, diagnostic centre, and hospital group, regardless of size. There is no small-business exemption. There is no healthcare carve-out for routine administrative data practices.
What this means in practical terms: the patient contact list you use for appointment reminders is subject to DPDPA consent requirements. The WhatsApp broadcast you send about your new aesthetic treatment service needs a specific consent basis separate from the one that covers appointment follow-ups. The appointment booking software holding years of patient records has data processing obligations that flow back to the clinic as the Data Fiduciary. And patients now have enforceable rights - to access their records, request corrections, and in certain circumstances request erasure - with a complaint pathway to the Data Protection Board if those rights are not honoured.
The majority of Indian clinic owners and administrators are aware the Act exists. Most have not yet mapped their actual data practices against what the Act requires. That gap is where the compliance risk sits.
Our latest Institute article is a direct, non-alarmist walk through what the DPDPA actually requires from a small clinic without a compliance team - what is currently clear law, what is still being finalised in subsidiary rules by MeitY, and what a small practice can realistically implement this month. It includes the COMPLY framework: a six-step practical checklist covering data inventory, consent documentation, patient rights workflows, security measures, retention policies, and breach notification planning.
This is not a crisis article. The obligations are manageable for any clinic that decides to take them seriously. What it is not is optional.
Full article in comments. Digital Presence Meter for your clinic's data footprint: [/dpm]
---
(d) X / Twitter Thread
1/ India's Digital Personal Data Protection Act 2023 is in force. It applies to every Indian clinic.
Most clinic owners do not know what it actually requires. Thread.
2/ The DPDPA applies to every business processing digital personal data in India. No small-business exemption. No healthcare carve-out for routine admin.
Patient name + phone number + appointment record = personal data under the Act.
3/ Your clinic is a "Data Fiduciary." That means you determine what data is collected and why - and you carry full legal responsibility for it.
Your patients are "Data Principals" with enforceable rights to access, correct, and erase their data.
4/ The biggest compliance gap we see: WhatsApp broadcast lists.
If a patient gave you their number for appointment reminders, that consent does not cover promotional messages, health tips, or new service announcements.
Secondary use = separate consent required.
5/ Third-party software is a bigger issue than most clinics realise.
Your appointment booking platform, CRM, diagnostic report system - all of these are "Data Processors" handling patient data on your behalf.
The clinic is legally responsible for what they do with that data.
6/ Data Principal rights are not theoretical. Patients can: - Request a summary of what data you hold - Request corrections to inaccurate data - Request erasure once the purpose is fulfilled - File a formal complaint with the Data Protection Board
You need a process to handle these.
7/ Important caveat: detailed rules are still being finalised by MeitY as of July 2026.
But the core obligations - valid consent, data principal rights, security safeguards, breach notification - are current law now.
Do not wait for the final rules to start.
8/ The COMPLY method for small clinics (no compliance team needed):
C - Catalog your data assets O - Obtain documented consent M - Map patient rights into your workflow P - Protect data with basic security L - Limit retention lifecycles Y - Your breach notification plan
9/ Three actions you can take this week: - Run a data inventory (every place patient data lives) - Review your patient intake form for DPDPA-compliant consent language - Check whether your appointment booking platform has a data processing agreement
10/ Full 12-minute breakdown of every DPDPA obligation relevant to Indian clinics - including what the Act says now vs. what's being finalised:
[/institute/governance-compliance/dpdpa-for-clinics]
Check your clinic's digital data footprint: [/dpm]
--- Article published by the Influx Health Institute. Influx Health is a patient acquisition agency for healthcare organizations in India.