Genetic and genomic data is uniquely revealing and often processed by labs abroad, under ICMR guidelines and the DPDP Act.
In short
Genetic testing produces some of the most revealing personal data there is, frequently processed by offshore labs. ICMR biomedical and genetic-data guidelines apply alongside the DPDP Act harm-based, high-rigor approach. Explicit consent, strong security and careful cross-border handling are central. Penalties reach ₹250 crore.
What changes for this niche, and the specific rule it turns on.
Genetic data can reveal health, ancestry and family risk; treat it at the highest security bar under Section 8(5).
Consent must be specific about the test, its uses and any research or sharing; ICMR ethics apply.
Where sequencing happens abroad, the DPDP cross-border default permits it, but contract for security and watch for future restrictions.
Collect only what the test needs and de-identify for any secondary or research use.
Short, cite-able answers, mirrored in FAQPage schema.
Fix specific consent and offshore contracts first.
The readiness check flags consent, security and cross-border gaps.
Take the readiness check →