Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Healthcare & Pharma

The DPDP Act for Healthcare & Pharma

For hospitals, labs, pharma and telemedicine, the Act layers strict consent, security and retention duties onto medical data.

In short

Hospitals, clinics, labs and pharma companies handle health data, among the most sensitive personal data the Act covers. You need clear consent, tight access controls, careful retention and fast breach reporting, alongside existing medical-records rules. Penalties reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Consent for health data

Take explicit, purpose-specific consent for collecting and sharing health and treatment data.

Sensitive-data security

Health records demand your strongest access controls, encryption and audit trails.

Purpose limitation

Patient data gathered for care cannot be reused for marketing or research without fresh consent.

Retention and erasure

Reconcile medical-record retention rules with the right to erase; document why you keep what you keep.

Patient rights

Let patients access, correct and request erasure of their records within legal limits.

Processors and sharing

Labs, TPAs, insurers and cloud EHR vendors are processors; their handling is your liability.

Full guide

Running a hospital? Our guide to the key obligations for hospitals under the DPDP Act walks through all 11 duties, deadlines and penalties.

\n

See where you stand.

Run the free readiness check for a sector-specific gap report.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

Take the readiness check →