Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Share this article

Key Obligations for Hospitals Under the DPDP Act

Hospitals are Data Fiduciaries under the DPDP Act. See the 11 key obligations with section numbers, deadlines, penalties and a 7-step plan to 13 May 2027.

By the DPDPAct India team (editorial policy) · Last checked: 5 October 2026 · 12 min read

Quick answer: Under the DPDP Act, a hospital is a Data Fiduciary. From 13 May 2027 it must give clear notice, take valid consent, secure patient data, report breaches to patients and the Data Protection Board (with a detailed report within 72 hours), honour patient rights, run a grievance process, protect children's data and publish a contact person. Penalties go up to ₹250 crore for security failures.

If you run a hospital, a clinic or a diagnostic lab in India, you hold some of the most personal data there is. Diagnoses. Prescriptions. Scan reports. A phone number. The name of the relative who waited outside.

The DPDP Act treats all of it as personal data, and it treats you as the one answerable for it. The good news is that the rules are specific, so you do not have to guess. This guide walks through what the Act and the 2025 Rules ask of a hospital, in plain language, with section numbers so your legal team can check every line. We also say where things are still unclear, because pretending otherwise helps nobody.

The 11 duties at a glance

Think of these as eleven habits your hospital needs to build. Some are paperwork, some are IT, and some are about how your front desk talks to patients.

Mind map of the 11 hospital obligations under the DPDP ActA hospital in the centre with eleven duties around it: notice, consent, legitimate uses, accuracy and erasure, security, vendor control, breach reporting, patient rights, children's data, DPO or contact, and cross-border transfers.HospitalData Fiduciary1. Notice2. Consent3. Legitimate uses4. Data accuracy5. Security6. Vendor control7. Breach reporting8. Patient rights9. Children's data10. DPO or contact11. Cross-border
The 11 duties a hospital carries as a Data Fiduciary. Each one is explained below with its section number.

Does the DPDP Act apply to your hospital?

Almost certainly, yes. The Act covers digital personal data processed in India. It also covers paper records the moment you digitise them, so scanning old files counts. It applies to government and private hospitals, nursing homes, single-doctor clinics, diagnostic labs, telemedicine platforms and e-pharmacies. It also covers your own staff's data, because employees are people too.

As of 5 October 2026, we found no official exemption that lets small clinics skip the core duties.

The Act has its own vocabulary. Here is what the terms mean in a hospital.

Key DPDP terms in hospital language
TermPlain meaningIn your hospital
Data FiduciaryDecides why and how personal data is usedThe hospital or clinic
Data PrincipalThe person the data is aboutPatients, and staff
Data ProcessorHandles data on your behalfLab, EHR vendor, cloud host
Significant Data Fiduciary (SDF)A fiduciary the Government notifies as higher riskPossible for very large providers. Not notified as of 5 October 2026.
Data Protection BoardThe regulator that runs inquiries and imposes penaltiesReceives your breach reports

A note on "sensitive" health data. Unlike GDPR, the Act does not set up a separate sensitive-data tier. In practice, health data is where a breach hurts patients most, so treat it as your highest-risk data.

The dates that matter

The Act came into force in stages. For a hospital, one date matters most: 13 May 2027.

DPDP commencement timeline for hospitalsThree dates: 13 November 2025, 13 November 2026 and 13 May 2027, with what starts on each.12 months6 months13 Nov 2025Act's first sections and theData Protection Board start.Rules 1, 2 and 17 to 21.13 Nov 2026Consent Manager registrationbegins (s.6(9) and Rule 4).13 May 2027Core hospital duties start:notice, consent, s.8 duties,children, rights, penalties.
Commencement dates read from the Gazette notifications G.S.R. 843(E) and 846(E), as corrected by G.S.R. 892(E).
DPDP commencement dates and what they mean for hospitals
DateWhat startsWhat it means for you
13 Nov 2025Sections 1(2), 2, 18 to 26, 35, 38 to 43, 44(1) and 44(3). Rules 1, 2 and 17 to 21. The Board is established.Definitions and set-up. No patient-facing duty yet.
13 Nov 2026Section 6(9), section 27(1)(d) and Rule 4.Consent Manager registration. You are not a Consent Manager, but patients may use one.
13 May 2027Sections 3 to 17 (apart from 6(9)), 27 (apart from (d)), 28 to 34, 36, 37 and 44(2). Rules 3, 5 to 16, 22 and 23.Your core duties and the penalties start. This is your deadline.

What about the Board? The Data Protection Board was established on 13 November 2025. MeitY invited applications for a Chairperson and four Members on 6 May 2026. As of 5 October 2026, we found no official notification naming anyone. Rule 3 asks your notice to explain how a patient can complain to the Board, so word that line carefully and re-check before you print new forms.

The 11 key obligations explained

Each duty below has the section number, what it looks like in a hospital, and what to keep as proof.

1. Give a clear notice before you ask for consent (s.5, Rule 3)

Before a patient says yes to anything, they must see a notice. It has to make sense on its own, in plain language. It cannot hide inside a twelve-page admission form. Under Rule 3 it lists the specific data you collect, the specific purposes, a link to your website or app, how to withdraw consent, how to use their rights, and how to complain to the Board. Offer it in English or any language listed in the Eighth Schedule, so patients can read it in the language they actually use.

Already hold patient data? If you collected data with consent before the duties start, send the notice as soon as reasonably practicable. You may keep processing until the patient withdraws (s.5(2) and 5(3)).

Keep as proof: dated copies of every notice version and the languages offered.

Go deeper: Section 5 explained · Notice vs consent · Privacy notice under Section 5 · Consent notice generator

2. Take valid consent and make withdrawal easy (s.6)

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear action, and limited to the data needed for the stated purpose. A pre-ticked box is not a clear action. Do not make "agree to marketing" a condition of treatment.

Patients must be able to withdraw as easily as they agreed (s.6(4)). If a patient tapped a kiosk to say yes, they should not need a signed letter to say no. After withdrawal you stop processing and ask your processors to stop within a reasonable time, unless a law requires you to keep the data. The burden of proof is yours: you must be able to show that notice was given and consent was taken (s.6(10)).

Consent lifecycle for a patientFive steps: show a notice, take clear consent, use data only for the stated purpose, allow withdrawal at any time, then stop and tell vendors to stop unless law requires you to keep the data.1Show the noticefirst2Patient says yeswith a clearaction3Use data only forthe statedpurpose4Patient canwithdraw any time5Stop, and tellvendors to stopException: if a law requires you to keep the record, keep it and explain this to the patient.
The consent lifecycle. You must be able to prove notice and consent (s.6(10)).

Keep as proof: a consent log showing time, notice version and purpose for each patient.

Go deeper: Section 6 explained · Valid consent under Section 6 · Consent withdrawal guide · How to prove consent · Consent audit checklist

3. Know your legitimate uses, and do not stretch them (s.7)

Not everything needs consent. Section 7 lists a short, closed set of "legitimate uses". It includes data a patient volunteers for a stated purpose and has not objected to (s.7(a)), employment purposes for staff data (s.7(i)), and urgent medical situations. Ask counsel to confirm the exact fit before you rely on any of them.

A simple rule of thumb: use a legitimate use for the narrow thing it covers, and use consent for everything else, such as marketing messages or research.

Go deeper: Section 7 explained · Consent vs legitimate uses · Consent or legitimate use guide

4. Keep data accurate, and erase it when its purpose ends (s.8(3), s.8(7))

If you use patient data to decide something about a person, or share it with another organisation, it must be complete and accurate (s.8(3)). When a patient withdraws consent, or the purpose is served, you erase the data and ask your processors to do the same (s.8(7)), unless a law requires you to keep it.

Hospitals sit in a tricky spot here, because other laws and medical record rules may require you to retain records for set periods. So build a retention schedule that names the legal reason for each record type, instead of "we keep everything forever". Do not copy a retention number from a blog, this one included. Get it from counsel for your state and record type.

Example: a patient asks you to erase their record after discharge. You may not be allowed to delete the clinical record. Tell them what you can erase, such as their marketing contact details, what you must keep, and why.

Go deeper: Section 8 explained · Retention and erasure mapping · Retention and erasure register

5. Secure the data (s.8(4), s.8(5), Rule 6)

You must take reasonable security safeguards, and this is where the biggest penalty sits. Rule 6 sets minimum measures: encryption, masking or virtual tokens, access controls, logs and monitoring to detect unauthorised access, data backups, one-year retention of logs, and security terms in your processor contracts.

In hospital terms, that means role-based access in your HMS (a billing clerk should not open a psychiatry note), no shared logins at the front desk, encrypted and tested backups, and a clear rule on sending reports over email or WhatsApp.

Keep as proof: access reviews, backup test records and one year of logs.

Go deeper: Reasonable security safeguards · Privacy audit services

6. Control your vendors (s.8(1), s.8(2))

You stay responsible for personal data processed on your behalf, even when a vendor does the processing (s.8(1)). A processor can handle patient data only under a valid contract (s.8(2)).

Hospital and its data processorsA hospital in the centre, linked by contract to a pathology lab, radiology centre, EHR vendor, cloud host, billing and call centre, and teleconsult platform. The hospital stays responsible.Your hospitalData FiduciaryPathology labRadiology centreEHR or HMS vendorCloud hostBilling and call centreTeleconsult platformYou stay responsible for theirhandling of patient data (s.8(1)).
Vendors that handle data for you are processors. Each needs a valid contract (s.8(2)).

A good contract covers the purpose, security, breach alerts to you, what happens to the data when the contract ends, and any sub-contractors. Be careful with insurers and TPAs. They may decide their own purposes, which can make them fiduciaries in their own right. Map each relationship and ask: are they acting for us, or for themselves?

Go deeper: Data Fiduciary vs Data Processor · Data flow and processor mapping · Processor worksheet

7. Report breaches fast (s.8(6), Rule 7)

A personal data breach is any unauthorised processing, loss or disclosure that compromises the data (s.2(u)). If one happens, you must inform each affected patient without delay, and inform the Board without delay. Then send a detailed report to the Board within 72 hours of becoming aware, unless the Board allows longer in writing (Rule 7).

Breach response stepsFive steps: detect and contain, tell affected patients without delay, tell the Board without delay, send a detailed report within 72 hours, then fix the cause and keep logs.1Detect andcontain2Tell affectedpatients, withoutdelay3Tell the Board,without delay4Detailed reportto the Boardwithin 72 hours5Fix the cause andkeep logsThe Board can allow more than 72 hours, but only in writing (Rule 7).
A breach response sequence based on s.8(6) and Rule 7.

Decide your playbook before the incident: who confirms a breach, who calls the patients, who writes the Board report. The Act is in addition to other laws (s.38), so any reporting duties you already have do not go away. Review the incident reporting expectations from CERT-In too.

Go deeper: How to report a breach · Breach notification rule explained · Breach readiness mapping · Breach readiness worksheet

8. Honour patient rights and run a grievance process (ss.11 to 14, s.8(10), Rule 14)

Patient rights and what your hospital must be ready to do
RightWhat the patient can askSection
InformationA summary of their data you process and who you share it withs.11
Correction and completionFix wrong or incomplete data, and update its.12
ErasureDelete their data, unless law requires you to keep its.12, s.8(7)
Grievance redressalComplain to you first, before going to the Boards.13
Nominate someoneName a person to exercise their rights if they die or become incapacitateds.14

You must publish how patients can make a request and any identifier you need from them (Rule 14(1)). You must also publish your grievance response time, which cannot be longer than 90 days (Rule 14(3)). Registration is a natural place to offer the nominee option, because hospitals often deal with relatives collecting records for patients who cannot act for themselves.

Keep as proof: a request log with received and closed dates.

Go deeper: Right to access · Correction and erasure · Grievance redressal · Right to nominate · Mapping patient requests · Request worksheet

9. Protect children's data (s.9, Rules 10 and 12)

A child is anyone under 18 (s.2(f)). You need verifiable consent from a parent or lawful guardian before processing a child's data (s.9(1)), and due diligence that the person claiming to be the parent is an identifiable adult (Rule 10). You must not process in ways that harm a child's wellbeing (s.9(2)), and you must not track, monitor behaviour or target ads at children (s.9(3)).

There is relief for healthcare. Rule 12 and the Fourth Schedule exempt clinical establishments, mental health establishments and healthcare professionals from s.9(1) and s.9(3) for certain purposes, subject to conditions. That helps a paediatric ward do its job without chasing fresh parental consent at every step. But the no-harm rule in s.9(2) still applies, and the exemption does not cover marketing or advertising. Read the Schedule's conditions for your case.

Go deeper: Section 9 explained · Children's data · Verifiable consent

10. Publish a contact, and know when a DPO is mandatory (s.8(9), s.10)

Every hospital must publish the business contact of a DPO, if applicable, or of another person who can answer patients' questions (s.8(9)). Your consent requests should carry that contact too (s.6(3)).

Do you need a Data Protection Officer?Decision tree. If your hospital is notified as a Significant Data Fiduciary, appoint a DPO in India, an independent auditor and run yearly DPIA and audit. If not, publish a contact person and run a grievance process.Has the Government notified your hospital as a SignificantData Fiduciary (SDF)?YesNoExtra duties apply (s.10, Rule 13)• Appoint a DPO: an individual based in India,answerable to the board.• Appoint an independent data auditor.• Run a DPIA and an audit every 12 months, andreport to the Board.Standard duties apply (s.8(9), s.8(10))• Publish the contact of a DPO, if you have one, orof another person who can answer patient questions.• Run a grievance process and publish the responsetime.As of 5 October 2026, we found no official notification of any SDF.
A DPO is mandatory only for notified Significant Data Fiduciaries. Every hospital still needs a published contact.

A DPO is required only for Significant Data Fiduciaries. The DPO must be an individual based in India and answerable to the board (s.10(2)(a)). SDFs also appoint an independent data auditor and run a DPIA and audit every 12 months (Rule 13). Very large chains and AI-heavy providers may be notified one day, but that is the Government's decision. Naming a privacy lead now is a sensible step either way.

Watch out: there is no official "DPDP auditor certificate". Be wary of anyone selling one.

Go deeper: Data Protection Officer · Who qualifies as an SDF · Fiduciary vs SDF · DPO role guide

11. Check cross-border transfers (s.16, Rule 15)

Patient data can leave India, for example to an overseas cloud, a teleradiology partner or an international patient desk. But Rule 15 makes transfers subject to requirements the Government may set. Keep an inventory of where patient data physically sits and which partners are abroad. SDFs also face possible limits on specified data leaving India (Rule 13(4)). Watch for notifications.

Go deeper: Section 16 explained · Cross-border data transfer

Where hospitals usually trip up

  • Old records. Years of legacy data still count. Plan your notice for existing patients (s.5(2)).
  • Reports on WhatsApp and email. Convenient, but they test your security duty. Set one approved way to share reports.
  • Shared logins. If five people use one front-desk login, your logs prove nothing.
  • Marketing from patient lists. Health camp offers and promotions need their own consent, separate from treatment.
  • ABDM sharing. If you link records through ABDM, map each share to a stated purpose and a consent.
  • Staff data. Doctors, nurses and contractors are Data Principals too.

Penalties: what the Act says

Maximum DPDP penalties by provisionBar chart: security safeguards 250 crore rupees, breach notice 200, children's data 200, Significant Data Fiduciary duties 150, any other provision 50.Security safeguards (s.8(5))Up to ₹250 croreBreach notice (s.8(6))Up to ₹200 croreChildren's data (s.9)Up to ₹200 croreSignificant Data Fiduciary duties(s.10)Up to ₹150 croreAny other provision, such as notice,consent or vendor dutiesUp to ₹50 crore
Maximum penalties from the Schedule to the Act. A penalty follows a Board inquiry, not an automatic fine.
Maximum penalties under the Schedule to the Act
ProvisionMaximum
Security safeguards (s.8(5))₹250 crore
Breach notice (s.8(6))₹200 crore
Children's data (s.9)₹200 crore
SDF duties (s.10)₹150 crore
Duties of a Data Principal (s.15)₹10,000
Any other provision, including notice, consent and vendor duties₹50 crore

These are ceilings, not fixed fines. A penalty comes only after the Board runs an inquiry, finds a significant breach and gives you a chance to be heard (s.33(1)). Do not read "₹250 crore" as the price of any mistake. It is the top of the range for failing at security.

A 7-step plan to 13 May 2027

This is a suggested order, not a legal requirement. It works for a single clinic and for a multi-site hospital. For the whole-organisation view, see our 2027 compliance roadmap and compliance checklist.

  1. Name a privacy lead. Pull in admin, IT, medical records, nursing and legal.
  2. Map your data. Where does patient data come in, sit, and go out? Include labs, billing, apps and digitised files. Start with our data mapping guide and the step-by-step mapping exercise.
  3. Rewrite notice and consent. One clear notice in your patients' languages, with optional uses kept separate. Use our consent notice generator for a first draft, then have counsel review it.
  4. Lock down security. Role-based access, no shared logins, encryption, tested backups, one year of logs.
  5. Fix vendor contracts. List every vendor and sign security and breach terms. See processor mapping.
  6. Build your playbooks. Publish the rights request route and grievance time, and run a mock breach drill. Use the breach reporting guide.
  7. Train staff, then test. Front desk first, then nurses and doctors. Re-check the rules before 13 May 2027. Our employee awareness training can help.

Frequently asked questions

Does the DPDP Act apply to hospitals?
Yes. A hospital decides why and how patient data is used, so it is a Data Fiduciary. The Act covers digital personal data processed in India, including paper records once you digitise them.
When do hospital obligations under the DPDP Act start?
Most duties, including notice, consent, security, breach reporting and penalties, start on 13 May 2027. Consent Manager registration rules start earlier, on 13 November 2026.
Does a hospital need a Data Protection Officer?
Only if the Government notifies it as a Significant Data Fiduciary. Every hospital must still publish the contact of a DPO or another person who can answer patient questions (s.8(9)). As of 5 October 2026, we found no official notification of any Significant Data Fiduciary.
What is the penalty for a hospital that breaks the DPDP Act?
Penalties go up to ₹250 crore for failing to keep reasonable security safeguards, ₹200 crore for breach notice or children's data failures, and ₹50 crore for most other provisions. A penalty follows a Board inquiry with a hearing.
Can a hospital delete a patient's record when the patient asks?
Not always. The erasure duty in s.8(7) gives way when a law requires you to keep the data. Tell the patient what you will erase, what you must keep, and why.
Is HIPAA applicable in India?
No, HIPAA is a US law and does not govern Indian hospitals by default. It can reach you through contracts with US partners. In India, the DPDP Act is the main data protection law for patient data.
Who enforces the DPDP Act?
The Data Protection Board of India, which was established on 13 November 2025. As of 5 October 2026, we found no official notification naming its Chairperson or Members.
Do small clinics get an exemption?
As of 5 October 2026, we found no official exemption that lets small clinics skip the core duties. Smaller practices should scale their effort, but the duties still apply.

Sources

  • Digital Personal Data Protection Act, 2023, and the Schedule (MeitY)
  • Commencement notifications G.S.R. 843(E) and 846(E) of 13 November 2025, and corrigendum G.S.R. 892(E) of 10 December 2025 (Gazette of India)
  • Digital Personal Data Protection Rules, 2025, Rules 3, 4, 6, 7, 8, 10, 12 to 15

This guide is for education and is not legal advice (see our disclaimer). Laws and notifications change, so check the current text and speak to a qualified lawyer before you act. Last checked: 5 October 2026.

Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.