India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) is the country’s first comprehensive data protection law. Passed by Parliament in August 2023 and enforceable starting May 2027, it governs how personal data must be collected, stored, used, and protected by organisations operating in India.
For doctors and clinic owners, this law matters more than it might initially appear. Healthcare is among the highest-risk categories under DPDP.
First, every interaction with a patient generates personal data (names, phone numbers, diagnoses, prescriptions, lab results, even photographs). Second, this data is sensitive by nature: a breach does not just inconvenience a patient, it can expose private health conditions to employers, insurers, or the public. Third, the doctor-patient relationship is built on trust. Patients share information they share with almost no one else.
The DPDP Act formalises what patients have always expected - that their information will be handled carefully, used only for the purpose it was given, and never shared without their knowledge.
Non-compliance is not a theoretical risk. The DPDP Act empowers the Data Protection Board of India to investigate complaints and impose penalties of up to ₹250 crore for significant violations. For a clinic or hospital, that is not merely a fine - it is an existential event that can cause irreparable financial and reputational loss. The time to prepare is now, before enforcement begins in earnest.
Most clinics are already exposed to DPDP liability in multiple ways - they simply do not know it yet. Here are eight of the most common risk scenarios facing healthcare practices in India today.
If your clinic’s website has a contact form, an appointment booking widget, or any field where a patient enters their name, phone number, or email address, you are collecting personal data. Under the DPDP Act, this requires a lawful basis - and in healthcare, valid consent is the primary route. That consent must be specific, informed, and freely given (no pre-ticked boxes). Most clinic websites collect this data without a compliant consent banner, a privacy notice, or a mechanism for patients to withdraw consent. Each such collection is a potential violation.
The clinical use of WhatsApp is near-universal in India. Under the DPDP Act, using a patient’s phone number to send them messages requires explicit, specific consent for that purpose. A phone number collected at reception for “registration” does not automatically authorise you to message the patient on WhatsApp. Worse, informal broadcast lists or WhatsApp groups that include patients who never consented to group messaging create compounded exposure. Each patient in such a group represents a separate risk.
Asking a patient to leave a Google review, rate your practice, or provide a video testimonial involves the use of their personal data and likeness. Under the DPDP Act, consent for this specific use must be captured separately from any consent obtained for clinical purposes. A patient who consented to receiving appointment reminders has not thereby consented to appearing in your practice’s marketing materials. Review requests must be accompanied by a clear explanation of how the content will be used.
When a clinic shares patient data with a digital marketing agency for purposes such as running online advertisements, managing a CRM, or sending promotional emails, that agency becomes a “Data Processor”. The clinic remains the “Data Fiduciary” - the entity legally responsible for how that data is handled. This requires a Data Processing Agreement (DPA) spelling out what data is shared, for what purpose, and what security standards apply. Without a DPA, the clinic is fully liable for any misuse by the agency.
Many clinics maintain patient information in Excel sheets, Google Sheets, or third-party CRM platforms. Under the DPDP Act, Data Fiduciaries have obligations around the security of data they store, the retention period, and deletion when no longer needed. A database maintained indefinitely without adequate security is a compliance failure waiting to be exposed. The Act also requires that personal data be used only for its collected purpose: contact details for reminders cannot be repurposed for marketing without fresh consent.
Clinic staff routinely access patient records, handle appointment systems, and use WhatsApp for patient communication, often from personal devices. The DPDP Act holds the clinic responsible for data breaches caused by its employees. An untrained receptionist who saves a patient’s lab report to her personal phone creates direct legal exposure. Compliance requires not just policies, but documented training - of the kind Starlex Consultants has delivered to over 5,000 professionals across India.
Pediatric clinics and any practice collecting data from patients under 18 face heightened obligations. Processing a child’s personal data requires verifiable parental or guardian consent. Clinics must implement age-verification mechanisms and must not subject children’s data to behavioural monitoring or targeted advertising under any circumstances. Practices that treat minors without separate consent procedures are almost certainly non-compliant.
Under the DPDP Act, if a data breach occurs - if patient records are accessed by an unauthorised person, a device is stolen, or a vendor suffers an incident - the clinic must notify the Data Protection Board of India and the affected patients. Most clinics have no breach response protocol: no designated person, no process, and no template. Under the DPDP Act, failure to notify can constitute a separate violation with penalties upto INR 200 crores.
DoubleSure and Starlex have partnered to offer healthcare practices in India an integrated DPDP compliance solution - one that addresses both the digital infrastructure and the legal framework simultaneously.
Your clinic’s website, patient review systems, CRM, and WhatsApp communication channels are audited, redesigned, and rebuilt to be DPDP-ready from the ground up.
We draft and implement the consent frameworks, privacy notices, Data Processing Agreements with your vendors and agencies, employee data-handling policies, and breach response protocols your practice needs.
Together, we offer something that neither a digital marketing agency nor a law firm can provide independently - an end-to-end solution that is both technically functional and legally sound. For the first time, your clinic can have a marketing engine that grows your practice and a compliance framework that protects it, built to work together rather than in conflict.