Guide
Key Obligations for Hospitals Under the DPDP Act
Hospitals are Data Fiduciaries under the DPDP Act. See the 11 key obligations with section numbers, deadlines, penalties and a 7-step plan to 13 May 2027.
Quick answer: Under the DPDP Act, a hospital is a Data Fiduciary. From 13 May 2027 it must give clear notice, take valid consent, secure patient data, report breaches to patients and the Data Protection Board (with a detailed report within 72 hours), honour patient rights, run a grievance process, protect children's data and publish a contact person. Penalties go up to ₹250 crore for security failures.
If you run a hospital, a clinic or a diagnostic lab in India, you hold some of the most personal data there is. Diagnoses. Prescriptions. Scan reports. A phone number. The name of the relative who waited outside.
The DPDP Act treats all of it as personal data, and it treats you as the one answerable for it. The good news is that the rules are specific, so you do not have to guess. This guide walks through what the Act and the 2025 Rules ask of a hospital, in plain language, with section numbers so your legal team can check every line. We also say where things are still unclear, because pretending otherwise helps nobody.
The 11 duties at a glance
Think of these as eleven habits your hospital needs to build. Some are paperwork, some are IT, and some are about how your front desk talks to patients.
Does the DPDP Act apply to your hospital?
Almost certainly, yes. The Act covers digital personal data processed in India. It also covers paper records the moment you digitise them, so scanning old files counts. It applies to government and private hospitals, nursing homes, single-doctor clinics, diagnostic labs, telemedicine platforms and e-pharmacies. It also covers your own staff's data, because employees are people too.
As of 5 October 2026, we found no official exemption that lets small clinics skip the core duties.
The Act has its own vocabulary. Here is what the terms mean in a hospital.
| Term | Plain meaning | In your hospital |
|---|---|---|
| Data Fiduciary | Decides why and how personal data is used | The hospital or clinic |
| Data Principal | The person the data is about | Patients, and staff |
| Data Processor | Handles data on your behalf | Lab, EHR vendor, cloud host |
| Significant Data Fiduciary (SDF) | A fiduciary the Government notifies as higher risk | Possible for very large providers. Not notified as of 5 October 2026. |
| Data Protection Board | The regulator that runs inquiries and imposes penalties | Receives your breach reports |
A note on "sensitive" health data. Unlike GDPR, the Act does not set up a separate sensitive-data tier. In practice, health data is where a breach hurts patients most, so treat it as your highest-risk data.
The dates that matter
The Act came into force in stages. For a hospital, one date matters most: 13 May 2027.
| Date | What starts | What it means for you |
|---|---|---|
| 13 Nov 2025 | Sections 1(2), 2, 18 to 26, 35, 38 to 43, 44(1) and 44(3). Rules 1, 2 and 17 to 21. The Board is established. | Definitions and set-up. No patient-facing duty yet. |
| 13 Nov 2026 | Section 6(9), section 27(1)(d) and Rule 4. | Consent Manager registration. You are not a Consent Manager, but patients may use one. |
| 13 May 2027 | Sections 3 to 17 (apart from 6(9)), 27 (apart from (d)), 28 to 34, 36, 37 and 44(2). Rules 3, 5 to 16, 22 and 23. | Your core duties and the penalties start. This is your deadline. |
What about the Board? The Data Protection Board was established on 13 November 2025. MeitY invited applications for a Chairperson and four Members on 6 May 2026. As of 5 October 2026, we found no official notification naming anyone. Rule 3 asks your notice to explain how a patient can complain to the Board, so word that line carefully and re-check before you print new forms.
The 11 key obligations explained
Each duty below has the section number, what it looks like in a hospital, and what to keep as proof.
1. Give a clear notice before you ask for consent (s.5, Rule 3)
Before a patient says yes to anything, they must see a notice. It has to make sense on its own, in plain language. It cannot hide inside a twelve-page admission form. Under Rule 3 it lists the specific data you collect, the specific purposes, a link to your website or app, how to withdraw consent, how to use their rights, and how to complain to the Board. Offer it in English or any language listed in the Eighth Schedule, so patients can read it in the language they actually use.
Already hold patient data? If you collected data with consent before the duties start, send the notice as soon as reasonably practicable. You may keep processing until the patient withdraws (s.5(2) and 5(3)).
Keep as proof: dated copies of every notice version and the languages offered.
Go deeper: Section 5 explained · Notice vs consent · Privacy notice under Section 5 · Consent notice generator
2. Take valid consent and make withdrawal easy (s.6)
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear action, and limited to the data needed for the stated purpose. A pre-ticked box is not a clear action. Do not make "agree to marketing" a condition of treatment.
Patients must be able to withdraw as easily as they agreed (s.6(4)). If a patient tapped a kiosk to say yes, they should not need a signed letter to say no. After withdrawal you stop processing and ask your processors to stop within a reasonable time, unless a law requires you to keep the data. The burden of proof is yours: you must be able to show that notice was given and consent was taken (s.6(10)).
Keep as proof: a consent log showing time, notice version and purpose for each patient.
Go deeper: Section 6 explained · Valid consent under Section 6 · Consent withdrawal guide · How to prove consent · Consent audit checklist
3. Know your legitimate uses, and do not stretch them (s.7)
Not everything needs consent. Section 7 lists a short, closed set of "legitimate uses". It includes data a patient volunteers for a stated purpose and has not objected to (s.7(a)), employment purposes for staff data (s.7(i)), and urgent medical situations. Ask counsel to confirm the exact fit before you rely on any of them.
A simple rule of thumb: use a legitimate use for the narrow thing it covers, and use consent for everything else, such as marketing messages or research.
Go deeper: Section 7 explained · Consent vs legitimate uses · Consent or legitimate use guide
4. Keep data accurate, and erase it when its purpose ends (s.8(3), s.8(7))
If you use patient data to decide something about a person, or share it with another organisation, it must be complete and accurate (s.8(3)). When a patient withdraws consent, or the purpose is served, you erase the data and ask your processors to do the same (s.8(7)), unless a law requires you to keep it.
Hospitals sit in a tricky spot here, because other laws and medical record rules may require you to retain records for set periods. So build a retention schedule that names the legal reason for each record type, instead of "we keep everything forever". Do not copy a retention number from a blog, this one included. Get it from counsel for your state and record type.
Example: a patient asks you to erase their record after discharge. You may not be allowed to delete the clinical record. Tell them what you can erase, such as their marketing contact details, what you must keep, and why.
Go deeper: Section 8 explained · Retention and erasure mapping · Retention and erasure register
5. Secure the data (s.8(4), s.8(5), Rule 6)
You must take reasonable security safeguards, and this is where the biggest penalty sits. Rule 6 sets minimum measures: encryption, masking or virtual tokens, access controls, logs and monitoring to detect unauthorised access, data backups, one-year retention of logs, and security terms in your processor contracts.
In hospital terms, that means role-based access in your HMS (a billing clerk should not open a psychiatry note), no shared logins at the front desk, encrypted and tested backups, and a clear rule on sending reports over email or WhatsApp.
Keep as proof: access reviews, backup test records and one year of logs.
Go deeper: Reasonable security safeguards · Privacy audit services
6. Control your vendors (s.8(1), s.8(2))
You stay responsible for personal data processed on your behalf, even when a vendor does the processing (s.8(1)). A processor can handle patient data only under a valid contract (s.8(2)).
A good contract covers the purpose, security, breach alerts to you, what happens to the data when the contract ends, and any sub-contractors. Be careful with insurers and TPAs. They may decide their own purposes, which can make them fiduciaries in their own right. Map each relationship and ask: are they acting for us, or for themselves?
Go deeper: Data Fiduciary vs Data Processor · Data flow and processor mapping · Processor worksheet
7. Report breaches fast (s.8(6), Rule 7)
A personal data breach is any unauthorised processing, loss or disclosure that compromises the data (s.2(u)). If one happens, you must inform each affected patient without delay, and inform the Board without delay. Then send a detailed report to the Board within 72 hours of becoming aware, unless the Board allows longer in writing (Rule 7).
Decide your playbook before the incident: who confirms a breach, who calls the patients, who writes the Board report. The Act is in addition to other laws (s.38), so any reporting duties you already have do not go away. Review the incident reporting expectations from CERT-In too.
Go deeper: How to report a breach · Breach notification rule explained · Breach readiness mapping · Breach readiness worksheet
8. Honour patient rights and run a grievance process (ss.11 to 14, s.8(10), Rule 14)
| Right | What the patient can ask | Section |
|---|---|---|
| Information | A summary of their data you process and who you share it with | s.11 |
| Correction and completion | Fix wrong or incomplete data, and update it | s.12 |
| Erasure | Delete their data, unless law requires you to keep it | s.12, s.8(7) |
| Grievance redressal | Complain to you first, before going to the Board | s.13 |
| Nominate someone | Name a person to exercise their rights if they die or become incapacitated | s.14 |
You must publish how patients can make a request and any identifier you need from them (Rule 14(1)). You must also publish your grievance response time, which cannot be longer than 90 days (Rule 14(3)). Registration is a natural place to offer the nominee option, because hospitals often deal with relatives collecting records for patients who cannot act for themselves.
Keep as proof: a request log with received and closed dates.
Go deeper: Right to access · Correction and erasure · Grievance redressal · Right to nominate · Mapping patient requests · Request worksheet
9. Protect children's data (s.9, Rules 10 and 12)
A child is anyone under 18 (s.2(f)). You need verifiable consent from a parent or lawful guardian before processing a child's data (s.9(1)), and due diligence that the person claiming to be the parent is an identifiable adult (Rule 10). You must not process in ways that harm a child's wellbeing (s.9(2)), and you must not track, monitor behaviour or target ads at children (s.9(3)).
There is relief for healthcare. Rule 12 and the Fourth Schedule exempt clinical establishments, mental health establishments and healthcare professionals from s.9(1) and s.9(3) for certain purposes, subject to conditions. That helps a paediatric ward do its job without chasing fresh parental consent at every step. But the no-harm rule in s.9(2) still applies, and the exemption does not cover marketing or advertising. Read the Schedule's conditions for your case.
Go deeper: Section 9 explained · Children's data · Verifiable consent
10. Publish a contact, and know when a DPO is mandatory (s.8(9), s.10)
Every hospital must publish the business contact of a DPO, if applicable, or of another person who can answer patients' questions (s.8(9)). Your consent requests should carry that contact too (s.6(3)).
A DPO is required only for Significant Data Fiduciaries. The DPO must be an individual based in India and answerable to the board (s.10(2)(a)). SDFs also appoint an independent data auditor and run a DPIA and audit every 12 months (Rule 13). Very large chains and AI-heavy providers may be notified one day, but that is the Government's decision. Naming a privacy lead now is a sensible step either way.
Watch out: there is no official "DPDP auditor certificate". Be wary of anyone selling one.
Go deeper: Data Protection Officer · Who qualifies as an SDF · Fiduciary vs SDF · DPO role guide
11. Check cross-border transfers (s.16, Rule 15)
Patient data can leave India, for example to an overseas cloud, a teleradiology partner or an international patient desk. But Rule 15 makes transfers subject to requirements the Government may set. Keep an inventory of where patient data physically sits and which partners are abroad. SDFs also face possible limits on specified data leaving India (Rule 13(4)). Watch for notifications.
Go deeper: Section 16 explained · Cross-border data transfer
Where hospitals usually trip up
- Old records. Years of legacy data still count. Plan your notice for existing patients (s.5(2)).
- Reports on WhatsApp and email. Convenient, but they test your security duty. Set one approved way to share reports.
- Shared logins. If five people use one front-desk login, your logs prove nothing.
- Marketing from patient lists. Health camp offers and promotions need their own consent, separate from treatment.
- ABDM sharing. If you link records through ABDM, map each share to a stated purpose and a consent.
- Staff data. Doctors, nurses and contractors are Data Principals too.
Penalties: what the Act says
| Provision | Maximum |
|---|---|
| Security safeguards (s.8(5)) | ₹250 crore |
| Breach notice (s.8(6)) | ₹200 crore |
| Children's data (s.9) | ₹200 crore |
| SDF duties (s.10) | ₹150 crore |
| Duties of a Data Principal (s.15) | ₹10,000 |
| Any other provision, including notice, consent and vendor duties | ₹50 crore |
These are ceilings, not fixed fines. A penalty comes only after the Board runs an inquiry, finds a significant breach and gives you a chance to be heard (s.33(1)). Do not read "₹250 crore" as the price of any mistake. It is the top of the range for failing at security.
A 7-step plan to 13 May 2027
This is a suggested order, not a legal requirement. It works for a single clinic and for a multi-site hospital. For the whole-organisation view, see our 2027 compliance roadmap and compliance checklist.
- Name a privacy lead. Pull in admin, IT, medical records, nursing and legal.
- Map your data. Where does patient data come in, sit, and go out? Include labs, billing, apps and digitised files. Start with our data mapping guide and the step-by-step mapping exercise.
- Rewrite notice and consent. One clear notice in your patients' languages, with optional uses kept separate. Use our consent notice generator for a first draft, then have counsel review it.
- Lock down security. Role-based access, no shared logins, encryption, tested backups, one year of logs.
- Fix vendor contracts. List every vendor and sign security and breach terms. See processor mapping.
- Build your playbooks. Publish the rights request route and grievance time, and run a mock breach drill. Use the breach reporting guide.
- Train staff, then test. Front desk first, then nurses and doctors. Re-check the rules before 13 May 2027. Our employee awareness training can help.
Keep learning: related guides, tools and services
Frequently asked questions
Does the DPDP Act apply to hospitals?
When do hospital obligations under the DPDP Act start?
Does a hospital need a Data Protection Officer?
What is the penalty for a hospital that breaks the DPDP Act?
Can a hospital delete a patient's record when the patient asks?
Is HIPAA applicable in India?
Who enforces the DPDP Act?
Do small clinics get an exemption?
Sources
- Digital Personal Data Protection Act, 2023, and the Schedule (MeitY)
- Commencement notifications G.S.R. 843(E) and 846(E) of 13 November 2025, and corrigendum G.S.R. 892(E) of 10 December 2025 (Gazette of India)
- Digital Personal Data Protection Rules, 2025, Rules 3, 4, 6, 7, 8, 10, 12 to 15
This guide is for education and is not legal advice (see our disclaimer). Laws and notifications change, so check the current text and speak to a qualified lawyer before you act. Last checked: 5 October 2026.
Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.