DPDPA Compliance Platform

    DPDPA · PRIMER FOR HOSPITALS

    The Digital Personal Data Protection Act, 2023 — decoded for healthcare.

    What the Act means, who's responsible, what patients can now demand, and what the penalties look like. Written for hospital leadership; extended for DPOs.

    01

    A decade-long journey. An 18-month window.

    Privacy became a fundamental right in 2017. The DPDP Act was passed in August 2023 and the Rules were notified in November 2025. Hospitals now have until May 2027 to be compliant.

    2017
    Puttaswamy v. Union of India.Supreme Court affirms privacy as a fundamental right.
    2018–2022
    Draft PDPB.Four years of drafts, committees, withdrawals.
    Aug 2023
    DPDPA passed.Parliament passes the Act; Presidential assent received.
    Nov 2025
    DPDP Rules notified.Phased commencement begins.
    Jul 2026
    Today.Implementation phase — you are here.
    May 2027
    Compliance deadline.18-month window ends. Enforcement begins.

    02

    The cost of getting it wrong: up to ₹250 Cr per breach.

    Penalties are cumulative. A single incident involving minors, combined with a missed 72-hour notification, can stack across categories and exceed an entire annual IT budget.

    UP TO

    ₹250 Cr

    Failure to prevent a data breach

    Absence of reasonable security safeguards.

    UP TO

    ₹200 Cr

    Failure to notify a breach

    Board and affected patients not informed in time.

    UP TO

    ₹200 Cr

    Non-compliance for children's data

    Unlawful tracking or absent guardian consent.

    UP TO

    ₹150 Cr

    SDF obligation failure

    No DPO, no independent audit, no impact assessment.

    BOARD-LEVEL RISK

    Breach + notification failure + child-data violation = multi-category fine stacking.

    03

    Who's who in a DPDPA compliance ecosystem.

    Six roles the Act defines. As a hospital, you're the Data Fiduciary — and probably a Significant Data Fiduciary.

    CORE ENTITY

    Data Fiduciary — Hospital

    Determines purpose and means of processing. Owns notice, consent, security and rights fulfilment.

    REGULATOR

    Data Protection Board of India

    Enforcement agency. Receives breach intimations, conducts inquiries, levies penalties.

    INDIVIDUAL

    Data Principal — Patient

    The individual whose data is processed. For minors and PwD, rights are exercised via parents or guardians.

    OFFICER

    Data Protection Officer (DPO)

    India-based grievance contact. Mandatory for Significant Data Fiduciaries.

    INTERMEDIARY

    Consent Manager

    Registered digital intermediary enabling accessible consent management for patients.

    VENDOR

    Data Processor

    Cloud, labs, insurance. Processes data on your behalf, under a valid contract. Contractual liability only.

    04

    Three patient categories. Three consent flows.

    Not every patient can consent for themselves. The Act's protections scale to that fact.

    The adult patient

    18+. Capable of independent decisions about their data.

    GRANTS OWN CONSENT

    The child patient

    Under 18. Requires special protection under the Act.

    VERIFIABLE PARENTAL CONSENT

    Person with disability

    Patients requiring assistance to exercise their data rights.

    CONSENT VIA LAWFUL GUARDIAN

    06 · SECTIONS 11–14

    Five rights every hospital must enable.

    The Data Principal — your patient — can now demand access, correction, erasure, nomination and withdrawal. Grievances must be answered within 72 hours.

    SECTION

    RIGHT

    WHAT IT MEANS

    Sec 11

    Right to access

    Summary of personal data, identities of third-party fiduciaries, description of data shared. Transparency obligation.

    Sec 12

    Correction & erasure

    Update or delete personal data — unless retention is mandated by other law. Accuracy and minimisation.

    Sec 13

    Grievance redressal

    Readily available mechanism. Response within 72 hours. Internal options exhausted first. Timely response.

    Sec 14

    Right to nominate

    Nominate a representative to exercise rights upon death or incapacity. Continuity of rights.

    Sec 6

    Withdraw consent

    Withdraw at any time; must be as easy as giving. Processing ceases promptly unless required by law. Control over data.

    07 · SECTION 8(7)

    Retention isn't unlimited. Erasure must cascade.

    Two triggers for erasure: consent withdrawn, or purpose fulfilled. And "erased" means erased everywhere — including in every processor's copy.

    TRIGGER 1

    Withdrawal of consent

    Processing must cease immediately. Data erased, unless law overrides.

    TRIGGER 2

    Purpose fulfilled

    Default rule: erase, don't retain. Balance against medical retention laws.

    The mechanics

    48-hour notice. Patients notified 48 hrs before auto-erasure. If they log in, retention clock resets.

    Downstream erasure. Erasure must cascade to cloud, labs and every processor holding a copy.

    Statutory override. Do NOT erase where retention is mandated — tax, medical records, KYC/AML.

    Security audit override. Logs and traffic data retained minimum 1 year for audit and breach review.

    08 · SECTION 8(5–6)

    Safeguards, incident, and a 72-hour clock.

    Three stages: prevent, detect and respond. Missed steps stack into ₹250 Cr penalties.

    STAGE 1

    Protection & oversight

    • • Encryption, masking, tokenisation.
    • • Strict role-based access control.
    • • Regular backups & business continuity.
    • • Immutable logs, min. 1-year retention.
    • • Continuous AI-driven audit.

    STAGE 2

    Incident

    Any unauthorised access, acquisition, disclosure, alteration or loss impacting confidentiality, integrity or availability.

    STAGE 3

    Mandatory response

    • • Board notice: immediate intimation.
    • • Board update: within 72 hrs.
    • • Patient notice: without delay.
    • • Detail consequences, safety steps, remedial action.

    All eight obligations, automated by Prodoc.

    See how the platform maps to each section of the Act.

    See the platform

    Ready to talk implementation?

    See how Prodoc's DPDPA Compliance Platform helps hospitals automate consent collection, rights fulfilment, and breach management. Book a 30-minute walkthrough.

    We use cookies

    We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.