Infosek
INFOSEK

DPDP for Healthcare and Health-Tech in India

There is no sensitive personal data category in the DPDP Act. That surprises people, and it does not make health data any less risky to hold.

DPDP for Healthcare and Health-Tech in India

No special category, but higher stakes

The Act does not carve out sensitive personal data. Health records are personal data and carry the ordinary obligations. What changes is exposure: volume and sensitivity are explicit factors in section 10 for notifying a Significant Data Fiduciary, and a breach of health data does more harm.

Where healthcare is usually exposed

Person with disability is expressly covered

Section 9(1) requires verifiable consent of the lawful guardian before processing the personal data of a person with disability who has a lawful guardian. Rule 11 addresses how this is handled. For providers in geriatric, psychiatric or disability care this is a specific workflow, not an edge case.

A hospital that can produce a full audit trail of who opened a record is in a very different position after an incident from one that can only say the record existed.

Infosek Team

Priorities

Common questions

Is health data treated as sensitive personal data under the DPDP Act?

The DPDP Act does not create a separate category of sensitive personal data as the earlier IT Rules did. Health data is personal data and carries the same obligations, though the volume and sensitivity of data processed is one of the factors under section 10 for notifying a Significant Data Fiduciary.

Does DPDP apply to hospitals and clinics?

Yes, to the extent they process digital personal data, including patient records collected on paper and digitised subsequently under section 3(a)(ii).

Handling patient data?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment