01
A decade-long journey. An 18-month window.
Privacy became a fundamental right in 2017. The DPDP Act was passed in August 2023 and the Rules were notified in November 2025. Hospitals now have until May 2027 to be compliant.
02
The cost of getting it wrong: up to ₹250 Cr per breach.
Penalties are cumulative. A single incident involving minors, combined with a missed 72-hour notification, can stack across categories and exceed an entire annual IT budget.
UP TO
₹250 Cr
Failure to prevent a data breach
Absence of reasonable security safeguards.
UP TO
₹200 Cr
Failure to notify a breach
Board and affected patients not informed in time.
UP TO
₹200 Cr
Non-compliance for children's data
Unlawful tracking or absent guardian consent.
UP TO
₹150 Cr
SDF obligation failure
No DPO, no independent audit, no impact assessment.
BOARD-LEVEL RISK
Breach + notification failure + child-data violation = multi-category fine stacking.
03
Who's who in a DPDPA compliance ecosystem.
Six roles the Act defines. As a hospital, you're the Data Fiduciary — and probably a Significant Data Fiduciary.
CORE ENTITY
Data Fiduciary — Hospital
Determines purpose and means of processing. Owns notice, consent, security and rights fulfilment.
REGULATOR
Data Protection Board of India
Enforcement agency. Receives breach intimations, conducts inquiries, levies penalties.
INDIVIDUAL
Data Principal — Patient
The individual whose data is processed. For minors and PwD, rights are exercised via parents or guardians.
OFFICER
Data Protection Officer (DPO)
India-based grievance contact. Mandatory for Significant Data Fiduciaries.
INTERMEDIARY
Consent Manager
Registered digital intermediary enabling accessible consent management for patients.
VENDOR
Data Processor
Cloud, labs, insurance. Processes data on your behalf, under a valid contract. Contractual liability only.
04
Three patient categories. Three consent flows.
Not every patient can consent for themselves. The Act's protections scale to that fact.
The adult patient
18+. Capable of independent decisions about their data.
GRANTS OWN CONSENTThe child patient
Under 18. Requires special protection under the Act.
VERIFIABLE PARENTAL CONSENTPerson with disability
Patients requiring assistance to exercise their data rights.
CONSENT VIA LAWFUL GUARDIAN05 · SECTIONS 5 & 6
Notice and consent, done properly.
Consent must be free, specific, informed, unconditional and unambiguous — with a clear affirmative action. Bundling unrelated purposes is not allowed.
1 · ITEMISED NOTICE
Notice before collection.
Describe the data points and the specific purpose. Available in English plus 22 Indian languages.
2 · VALID CONSENT
Free, specific, informed, unambiguous.
Clear affirmative action. No pre-ticked boxes, no dark patterns, no coercion.
3 · NO BUNDLING
Treatment consent ≠ marketing consent.
Purpose limitation is strictly enforced. Unrelated purposes must be captured separately.
4 · RIGHT TO WITHDRAW
Withdrawal is as easy as giving.
Processing must cease immediately. Withdrawal cannot be gated behind extra friction.
06 · SECTIONS 11–14
Five rights every hospital must enable.
The Data Principal — your patient — can now demand access, correction, erasure, nomination and withdrawal. Grievances must be answered within 72 hours.
SECTION
RIGHT
WHAT IT MEANS
Right to access
Summary of personal data, identities of third-party fiduciaries, description of data shared. Transparency obligation.
Correction & erasure
Update or delete personal data — unless retention is mandated by other law. Accuracy and minimisation.
Grievance redressal
Readily available mechanism. Response within 72 hours. Internal options exhausted first. Timely response.
Right to nominate
Nominate a representative to exercise rights upon death or incapacity. Continuity of rights.
Withdraw consent
Withdraw at any time; must be as easy as giving. Processing ceases promptly unless required by law. Control over data.
07 · SECTION 8(7)
Retention isn't unlimited. Erasure must cascade.
Two triggers for erasure: consent withdrawn, or purpose fulfilled. And "erased" means erased everywhere — including in every processor's copy.
TRIGGER 1
Withdrawal of consent
Processing must cease immediately. Data erased, unless law overrides.
TRIGGER 2
Purpose fulfilled
Default rule: erase, don't retain. Balance against medical retention laws.
The mechanics
48-hour notice. Patients notified 48 hrs before auto-erasure. If they log in, retention clock resets.
Downstream erasure. Erasure must cascade to cloud, labs and every processor holding a copy.
Statutory override. Do NOT erase where retention is mandated — tax, medical records, KYC/AML.
Security audit override. Logs and traffic data retained minimum 1 year for audit and breach review.
08 · SECTION 8(5–6)
Safeguards, incident, and a 72-hour clock.
Three stages: prevent, detect and respond. Missed steps stack into ₹250 Cr penalties.
STAGE 1
Protection & oversight
- • Encryption, masking, tokenisation.
- • Strict role-based access control.
- • Regular backups & business continuity.
- • Immutable logs, min. 1-year retention.
- • Continuous AI-driven audit.
STAGE 2
Incident
Any unauthorised access, acquisition, disclosure, alteration or loss impacting confidentiality, integrity or availability.
STAGE 3
Mandatory response
- • Board notice: immediate intimation.
- • Board update: within 72 hrs.
- • Patient notice: without delay.
- • Detail consequences, safety steps, remedial action.
All eight obligations, automated by Prodoc.
See how the platform maps to each section of the Act.