DPDP for Healthcare and Health-Tech in India
There is no sensitive personal data category in the DPDP Act. That surprises people, and it does not make health data any less risky to hold.
No special category, but higher stakes
The Act does not carve out sensitive personal data. Health records are personal data and carry the ordinary obligations. What changes is exposure: volume and sensitivity are explicit factors in section 10 for notifying a Significant Data Fiduciary, and a breach of health data does more harm.
Where healthcare is usually exposed
- Access control. Clinical systems often grant broad read access for continuity of care. Rule 6(1)(b) and the logging in 6(1)(c) require this to be controlled and visible.
- Retention. Medical records are held under professional and legal requirements. Rule 8 permits retention required by law, but the justification has to be recorded rather than assumed.
- Paediatric care. Section 9 requires verifiable parental consent for processing a child's data and bars tracking, behavioural monitoring and targeted advertising directed at children.
- Third parties. Labs, diagnostics partners, billing services and teleconsultation platforms are Data Processors requiring the Rule 6(1)(f) clause.
Person with disability is expressly covered
Section 9(1) requires verifiable consent of the lawful guardian before processing the personal data of a person with disability who has a lawful guardian. Rule 11 addresses how this is handled. For providers in geriatric, psychiatric or disability care this is a specific workflow, not an edge case.
A hospital that can produce a full audit trail of who opened a record is in a very different position after an incident from one that can only say the record existed.
Infosek Team
Priorities
- Log access to clinical records and retain those logs for the year Rule 6(1)(e) requires.
- Record, per record type, which law or professional requirement justifies the retention period.
- Build the guardian consent workflow for paediatric and disability care.
- Get processor clauses in place with labs, billing and teleconsult vendors.
Common questions
Is health data treated as sensitive personal data under the DPDP Act?
The DPDP Act does not create a separate category of sensitive personal data as the earlier IT Rules did. Health data is personal data and carries the same obligations, though the volume and sensitivity of data processed is one of the factors under section 10 for notifying a Significant Data Fiduciary.
Does DPDP apply to hospitals and clinics?
Yes, to the extent they process digital personal data, including patient records collected on paper and digitised subsequently under section 3(a)(ii).
Handling patient data?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment