DPDP COMPLIANCE

What is the DPDP Act - and why does it matter for Healthcare?

By Mimansa Ambastha, Managing Partner, Starlex Consultants LLP · Last updated: August 03, 2026
Quick summary

India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) is the country’s first comprehensive data protection law. Passed by Parliament in August 2023 and enforceable starting May 2027, it governs how personal data must be collected, stored, used, and protected by organisations operating in India.

For doctors and clinic owners, this law matters more than it might initially appear. Healthcare is among the highest-risk categories under DPDP.

DPDP Act 2023 Guide for Healthcare Industry

Why Healthcare is a High-Risk Category

First, every interaction with a patient generates personal data (names, phone numbers, diagnoses, prescriptions, lab results, even photographs). Second, this data is sensitive by nature: a breach does not just inconvenience a patient, it can expose private health conditions to employers, insurers, or the public. Third, the doctor-patient relationship is built on trust. Patients share information they share with almost no one else.

The DPDP Act formalises what patients have always expected - that their information will be handled carefully, used only for the purpose it was given, and never shared without their knowledge.

Non-compliance is not a theoretical risk. The DPDP Act empowers the Data Protection Board of India to investigate complaints and impose penalties of up to ₹250 crore for significant violations. For a clinic or hospital, that is not merely a fine - it is an existential event that can cause irreparable financial and reputational loss. The time to prepare is now, before enforcement begins in earnest.

What specific risks do doctors and clinics face under DPDP?

Most clinics are already exposed to DPDP liability in multiple ways - they simply do not know it yet. Here are eight of the most common risk scenarios facing healthcare practices in India today.

RISK 01: Patient Consent on Websites

If your clinic’s website has a contact form, an appointment booking widget, or any field where a patient enters their name, phone number, or email address, you are collecting personal data. Under the DPDP Act, this requires a lawful basis - and in healthcare, valid consent is the primary route. That consent must be specific, informed, and freely given (no pre-ticked boxes). Most clinic websites collect this data without a compliant consent banner, a privacy notice, or a mechanism for patients to withdraw consent. Each such collection is a potential violation.

RISK 02: WhatsApp Patient Communication

The clinical use of WhatsApp is near-universal in India. Under the DPDP Act, using a patient’s phone number to send them messages requires explicit, specific consent for that purpose. A phone number collected at reception for “registration” does not automatically authorise you to message the patient on WhatsApp. Worse, informal broadcast lists or WhatsApp groups that include patients who never consented to group messaging create compounded exposure. Each patient in such a group represents a separate risk.

RISK 03: Review Collection and Testimonials

Asking a patient to leave a Google review, rate your practice, or provide a video testimonial involves the use of their personal data and likeness. Under the DPDP Act, consent for this specific use must be captured separately from any consent obtained for clinical purposes. A patient who consented to receiving appointment reminders has not thereby consented to appearing in your practice’s marketing materials. Review requests must be accompanied by a clear explanation of how the content will be used.

RISK 04: Third-Party Data Sharing

When a clinic shares patient data with a digital marketing agency for purposes such as running online advertisements, managing a CRM, or sending promotional emails, that agency becomes a “Data Processor”. The clinic remains the “Data Fiduciary” - the entity legally responsible for how that data is handled. This requires a Data Processing Agreement (DPA) spelling out what data is shared, for what purpose, and what security standards apply. Without a DPA, the clinic is fully liable for any misuse by the agency.

RISK 05: CRM Systems and Patient Databases

Many clinics maintain patient information in Excel sheets, Google Sheets, or third-party CRM platforms. Under the DPDP Act, Data Fiduciaries have obligations around the security of data they store, the retention period, and deletion when no longer needed. A database maintained indefinitely without adequate security is a compliance failure waiting to be exposed. The Act also requires that personal data be used only for its collected purpose: contact details for reminders cannot be repurposed for marketing without fresh consent.

RISK 06: Employee Handling of Patient Data

Clinic staff routinely access patient records, handle appointment systems, and use WhatsApp for patient communication, often from personal devices. The DPDP Act holds the clinic responsible for data breaches caused by its employees. An untrained receptionist who saves a patient’s lab report to her personal phone creates direct legal exposure. Compliance requires not just policies, but documented training - of the kind Starlex Consultants has delivered to over 5,000 professionals across India.

RISK 07: Children’s Data

Pediatric clinics and any practice collecting data from patients under 18 face heightened obligations. Processing a child’s personal data requires verifiable parental or guardian consent. Clinics must implement age-verification mechanisms and must not subject children’s data to behavioural monitoring or targeted advertising under any circumstances. Practices that treat minors without separate consent procedures are almost certainly non-compliant.

RISK 08: Data Breach Notification

Under the DPDP Act, if a data breach occurs - if patient records are accessed by an unauthorised person, a device is stolen, or a vendor suffers an incident - the clinic must notify the Data Protection Board of India and the affected patients. Most clinics have no breach response protocol: no designated person, no process, and no template. Under the DPDP Act, failure to notify can constitute a separate violation with penalties upto INR 200 crores.

What DoubleSure + Starlex Offer

DoubleSure and Starlex have partnered to offer healthcare practices in India an integrated DPDP compliance solution - one that addresses both the digital infrastructure and the legal framework simultaneously.

DoubleSure: The Digital Side

Your clinic’s website, patient review systems, CRM, and WhatsApp communication channels are audited, redesigned, and rebuilt to be DPDP-ready from the ground up.

Starlex: The Legal Architecture

We draft and implement the consent frameworks, privacy notices, Data Processing Agreements with your vendors and agencies, employee data-handling policies, and breach response protocols your practice needs.

Together, we offer something that neither a digital marketing agency nor a law firm can provide independently - an end-to-end solution that is both technically functional and legally sound. For the first time, your clinic can have a marketing engine that grows your practice and a compliance framework that protects it, built to work together rather than in conflict.

Five Questions for Doctors and Clinic Owners

Is my clinic legally required to comply with the DPDP Act?
Yes. If your clinic collects personal data from patients - names, phone numbers, email addresses, health records, or any other information that can identify a person - and you operate in India, you are a ‘Data Fiduciary’ under the Digital Personal Data Protection Act, 2023. Compliance is not optional. The Act applies to all organisations that process personal data of individuals in India, regardless of the size of the practice. A solo practitioner’s clinic is subject to the same framework as a large hospital chain, though the specific obligations may be scaled to risk.
What is the penalty for non-compliance with DPDP for a healthcare practice?
The DPDP Act empowers the Data Protection Board of India to impose financial penalties of up to ₹250 crore for significant violations, such as failing to implement adequate security measures or processing children’s data without parental consent. Smaller violations attract penalties up to ₹50 crore. Beyond financial penalties, the reputational damage of a publicly disclosed data breach in a healthcare practice - where patient trust is the foundation of the relationship - can be severe and irreversible.
Do I need a separate consent form for collecting patient data on my website?
Yes. A standard appointment booking form on your clinic website collects personal data and requires a DPDP-compliant consent mechanism before that data is submitted. This means a clear, plain-language privacy notice explaining what data is collected, why it is collected, and how it will be used - along with an explicit consent checkbox that is not pre-ticked. A buried link to a generic ‘Privacy Policy’ page is not sufficient under the DPDP Act. The consent must be specific, informed, and freely given. Patients must also be able to withdraw consent, which means your process must accommodate deletion requests.
If I use a WhatsApp Business account to communicate with patients, does DPDP apply?
Yes, DPDP applies fully. Using WhatsApp Business does not change your obligations as a Data Fiduciary - it simply means you are using a third-party platform to process personal data. Every patient whose phone number you use for WhatsApp communication must have provided valid consent for that specific use. If you collected a patient’s number at reception without specifying that it would be used for WhatsApp messages, that use is potentially non-compliant. You should also be aware that WhatsApp’s infrastructure involves data processed by Meta - which means your Data Processing Agreement considerations extend to your chosen communication platforms.
What is a Data Processing Agreement and do I need one with my marketing agency?
A Data Processing Agreement (DPA) is a contract between you (the Data Fiduciary - your clinic) and any third party that handles patient data on your behalf (the Data Processor - your marketing agency, CRM provider, or email platform). The DPDP Act requires Data Fiduciaries to ensure that their Data Processors handle personal data only in accordance with the Fiduciary’s instructions and in compliance with the Act. Without a DPA, you have no contractual basis to enforce those obligations - and you remain legally responsible if the agency misuses patient data. If your clinic runs digital marketing campaigns or uses any third-party platform that touches patient information, a DPA is not optional.

Protect Your Practice with DPDP Compliance

Book Your Consultation