Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Healthcare & Pharma · Hospitals

The DPDP Act for Hospitals & Clinics

A hospital is a Data Fiduciary for a patient's entire record, from registration identifiers to diagnoses, mental-health and reproductive-health data.

In short

The Act does not tag health data as a separate legal category; instead it scales the bar to the risk of harm, and hospital data sits near the top. You need informed consent, tight access control, careful retention and fast breach reporting, and a large hospital may be a Significant Data Fiduciary. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Consent across the record

Take informed consent at registration and again for creating, sharing and retaining health records, including mental-health and reproductive-health data.

SDF duties may apply

A large hospital can be designated a Significant Data Fiduciary, adding a DPO, independent audits and impact assessments.

Retention vs erasure

Medical-record retention rules coexist with the right to erase; keep records for the required period, no longer, and be able to justify it.

Access control and security

Least-privilege access, encryption and audit trails across HIS, EHR and billing systems.

Patient rights and Consent Manager

Patients can access, correct and withdraw consent, and, once the Consent Manager framework goes live (registration opens 13 Nov 2026), through a registered Consent Manager spanning hospital, lab and insurer.

Processors

Cloud EHR, labs, TPAs and billing vendors are processors under contract, with your oversight.

Full guide

Want every duty in one place? Read our guide to the key obligations for hospitals under the DPDP Act: 11 duties with section numbers, deadlines and a 7-step plan.

\n

Check your hospital data flows.

The readiness check maps consent, retention, access and SDF gaps across your systems.

Take the readiness check →