Pentapod
Insights/Compliance

The DPDP Act and hospitals: what to do before May 2027

India's data protection law applies in full from May 2027. What it means for hospitals and clinics that hold patient data, and five steps to take now.

Pentapod · 14 September 2026 · 8 min read

When the law applies

The Digital Personal Data Protection Act, 2023 received the President's assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and the government brought the Act into force in phases from that date.

  • Immediately (November 2025): definitions and the provisions setting up the Data Protection Board of India.
  • After 12 months (around 13 November 2026): registration of Consent Managers.
  • After 18 months (around 13 May 2027): the duties of organisations, the rights of individuals and the penalties.

Until the 18-month mark, the Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 — the SPDI Rules, which treat medical records as sensitive — continue to apply. The DPDP Act repeals their legal basis only when its main provisions start.

What changes for a hospital

The Act has no special category for health data. Patient information is personal data like any other, and the Act covers it whether it was collected digitally or on paper and digitised later. A hospital or clinic that decides why and how patient data is processed is a Data Fiduciary, and carries these duties:

  • Give a clear, standalone notice that lists the data collected and the specific purposes, and explains how to withdraw consent, exercise rights and complain to the Board.
  • Make withdrawing consent as easy as giving it.
  • Take reasonable security safeguards. The Rules set a minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups; and keeping logs for at least one year.
  • Use vendors that process patient data — software, cloud, laboratory systems — only under a valid contract that includes security safeguards.
  • Erase data once its purpose is served or consent is withdrawn, unless another law requires it to be kept. Medical record-keeping rules still apply.
  • Publish a contact person for data questions and run a grievance process. The Rules require responses within 90 days at most.

Where consent is not needed

Section 7 lists "certain legitimate uses" that do not require consent. Two matter directly to healthcare: responding to a medical emergency involving a threat to someone's life or health, and providing treatment or health services during an epidemic or other threat to public health. Processing to meet a legal obligation or comply with a court order is also covered. Everyday treatment otherwise relies on consent, or on information a patient gives voluntarily for a specific purpose.

Children's data

Anyone under 18 is a child under the Act. Organisations normally need verifiable consent from a parent or lawful guardian, and must not track or behaviourally monitor children. The Rules exempt clinical establishments, mental health establishments and healthcare professionals from these two requirements — but only to the extent necessary to provide health services to protect the child's health.

When something goes wrong

Every personal data breach must be reported, with no minimum size. Under Rule 7, the hospital must tell each affected patient without delay, in plain language: what happened, the likely consequences, what is being done and what they can do. It must also inform the Board without delay, followed by a detailed report within 72 hours.

This is separate from CERT-In's 2022 Directions, which already require many cyber security incidents to be reported to CERT-In within six hours of being noticed. A single ransomware attack can trigger both.

Penalties

  • Up to ₹250 crore for failing to take reasonable security safeguards.
  • Up to ₹200 crore for failing to notify a breach.
  • Up to ₹200 crore for breaching the obligations on children's data.
  • Up to ₹50 crore for other breaches of the Act or Rules.

The Board decides penalties case by case. It was formally established in November 2025; as of August 2026, its Chairperson and Members had not yet been appointed.

Significant Data Fiduciaries

The government can designate organisations as Significant Data Fiduciaries based on factors including the volume and sensitivity of the data they process. These carry extra duties: a Data Protection Officer based in India, an independent data audit and an annual data protection impact assessment. No Significant Data Fiduciaries have been notified yet, and it is not known whether hospitals will be.

Five steps to take before May 2027

  1. 01

    Map where patient data lives

    Hospital information systems, laboratory and imaging systems, billing, spreadsheets, messaging apps, backups and every vendor that touches data. You cannot protect what you have not found.

  2. 02

    Rewrite notices and consent

    Plain-language, itemised notices at registration and on digital channels, with a simple way to withdraw consent. Record which legitimate use applies where consent is not needed.

  3. 03

    Bring security up to the Rule 6 baseline

    Encryption, role-based access so staff see only what they need, logging kept for at least a year, tested backups and monitoring that would actually notice a breach.

  4. 04

    Prepare for a breach

    Put data protection clauses into vendor contracts, and write one incident plan that meets both the DPDP timelines and CERT-In's six hours. Rehearse it.

  5. 05

    Set retention and grievance processes

    A retention schedule that reconciles erasure with medical record-keeping rules, a published contact person, and a grievance process that answers within 90 days.

In January 2026, MeitY reportedly proposed shortening the 18-month period to 12 months, mainly for large organisations. As of September 2026 we found no notification making that change. Check egazette.gov.in and MeitY for the current position before planning around dates.

This article is general information, not legal advice. Rules change — check the official sources below before acting.

Sources
  1. 01MeitY: Digital Personal Data Protection Act, 2023 (full text)
  2. 02MeitY: Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E)
  3. 03MeitY: Commencement notification for the Act — G.S.R. 843(E)
  4. 04MeitY: Establishment of the Data Protection Board — G.S.R. 844(E)
  5. 05PIB: DPDP Rules, 2025 notified
  6. 06CERT-In: Directions under section 70B(6), 28 April 2022
  7. 07NMC: Code of Medical Ethics Regulations, 2002
  8. 08LiveLaw: What the Data Protection Board vacancy means (September 2026)
  9. 09S.S. Rana & Co.: MeitY plans to shorten DPDP compliance timeline (February 2026)
Work with us

Have a project in mind?

Tell us what you need to build, connect or protect. We'll come back with honest next steps.

Start a project