New: India's DPDP Act requires all healthcare providers to be compliant by May 2027. See how Prodoc helps.

DPDPA · Primer for hospitals

The Digital Personal Data Protection Act, 2023, decoded for healthcare.

What the Act means, who's responsible, what patients can now demand, and what the penalties look like. Written for hospital leadership; extended for DPOs.

01

A decade-long journey. An 18-month window.

Privacy became a fundamental right in 2017. The DPDP Act was passed in August 2023 and the Rules were notified in November 2025. Hospitals now have until May 2027 to be compliant.

2017
Puttaswamy v. Union of India. Supreme Court affirms privacy as a fundamental right.
2018–2022
Draft PDPB. Four years of drafts, committees, withdrawals.
Aug 2023
DPDPA passed. Parliament passes the Act; Presidential assent received.
Nov 2025
DPDP Rules notified. Phased commencement begins.
May 2027
Compliance deadline. 18-month window ends. Enforcement begins.

02

The cost of getting it wrong: up to ₹250 Cr per breach.

Penalties are cumulative. A single incident involving minors, combined with a missed 72-hour notification, can stack across categories and exceed an entire annual IT budget.

Up to

₹250 Cr

Failure to prevent a data breach

Absence of reasonable security safeguards.

Up to

₹200 Cr

Failure to notify a breach

Board and affected patients not informed in time.

Up to

₹200 Cr

Non-compliance for children's data

Unlawful tracking or absent guardian consent.

Up to

₹150 Cr

SDF obligation failure

No DPO, no independent audit, no impact assessment.

Board-level risk

Breach + notification failure + child-data violation = multi-category fine stacking.

03

Who's who in a DPDPA compliance ecosystem.

Six roles the Act defines. As a hospital, you're the Data Fiduciary, and probably a Significant Data Fiduciary.

Core entity

Data Fiduciary: Hospital

Determines purpose and means of processing. Owns notice, consent, security and rights fulfilment.

Regulator

Data Protection Board of India

Enforcement agency. Receives breach intimations, conducts inquiries, levies penalties.

Individual

Data Principal: Patient

The individual whose data is processed. For minors and PwD, rights are exercised via parents or guardians.

Officer

Data Protection Officer (DPO)

India-based grievance contact. Mandatory for Significant Data Fiduciaries.

Intermediary

Consent Manager

Registered digital intermediary enabling accessible consent management for patients.

Vendor

Data Processor

Cloud, labs, insurance. Processes data on your behalf, under a valid contract. Contractual liability only.

04

Three patient categories. Three consent flows.

Not every patient can consent for themselves. The Act's protections scale to that fact.

The adult patient

18+. Capable of independent decisions about their data.

Grants own consent

The child patient

Under 18. Requires special protection under the Act.

Verifiable parental consent

Person with disability

Patients requiring assistance to exercise their data rights.

Consent via lawful guardian

06 · Sections 11–14

Five rights every hospital must enable.

The Data Principal, your patient, can now demand access, correction, erasure, nomination and withdrawal. Grievances must be answered within 72 hours.

Section
Right
What it means
Sec 11
Right to access
Summary of personal data, identities of third-party fiduciaries, description of data shared. Transparency obligation.
Sec 12
Correction & erasure
Update or delete personal data, unless retention is mandated by other law. Accuracy and minimisation.
Sec 13
Grievance redressal
Readily available mechanism. Response within 72 hours. Internal options exhausted first. Timely response.
Sec 14
Right to nominate
Nominate a representative to exercise rights upon death or incapacity. Continuity of rights.
Sec 6
Withdraw consent
Withdraw at any time; must be as easy as giving. Processing ceases promptly unless required by law. Control over data.

07 · Section 8(7)

Retention isn't unlimited. Erasure must cascade.

Two triggers for erasure: consent withdrawn, or purpose fulfilled. And "erased" means erased everywhere, including in every processor's copy.

Trigger 1

Withdrawal of consent

Processing must cease immediately. Data erased, unless law overrides.

Trigger 2

Purpose fulfilled

Default rule: erase, don't retain. Balance against medical retention laws.

The mechanics

  • 48-hour notice. Patients notified 48 hrs before auto-erasure. If they log in, retention clock resets.
  • Downstream erasure. Erasure must cascade to cloud, labs and every processor holding a copy.
  • Statutory override. Do NOT erase where retention is mandated (tax, medical records, KYC/AML).
  • Security audit override. Logs and traffic data retained minimum 1 year for audit and breach review.

08 · Section 8(5–6)

Safeguards, incident, and a 72-hour clock.

Three stages: prevent, detect and respond. Missed steps stack into ₹250 Cr penalties.

Stage 1

Protection & oversight

  • Encryption, masking, tokenisation.
  • Strict role-based access control.
  • Regular backups & business continuity.
  • Immutable logs, min. 1-year retention.
  • Continuous AI-driven audit.

Stage 2

Incident

Any unauthorised access, acquisition, disclosure, alteration or loss impacting confidentiality, integrity or availability.

Stage 3

Mandatory response

  • Board notice: immediate intimation.
  • Board update: within 72 hrs.
  • Patient notice: without delay.
  • Detail consequences, safety steps.

All eight obligations, automated by Prodoc.

See how the platform maps to each section of the Act.

See the platform →

8 months to May 2027. Start now.

See the DPO console, walk through the two-agent architecture, and get a scoped rollout plan for your hospital in 30 minutes.

Read the DPDPA primer