complianceclinic operationspatient records7 min read

DPDP Act compliance for clinics: what patient data rules mean for you

A plain-language guide to India's DPDP Act for clinics and polyclinics — what counts as personal data, what your obligations are, and what to check in your clinic software.

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection law, and it applies to your clinic the moment you store a patient's name, phone number, or health record digitally. This is not a law written specifically for hospitals — but health data is treated with particular sensitivity, and clinics of every size are within scope. Here is what it actually means for day-to-day clinic operations, in plain language.

Who this applies to

If your clinic collects, stores, or processes any digital personal data — patient names, phone numbers, appointment history, prescriptions, lab results — you are a "Data Fiduciary" under the Act. This applies whether you are a solo practitioner with a basic appointment app or a multi-doctor polyclinic with a full patient records system. There is no exemption for small clinics simply because of size.

What counts as personal data in a clinic setting

Practically, almost everything your clinic's software touches about a patient falls under this. Health data in particular tends to attract closer scrutiny because of the harm that can follow from it being mishandled — a leaked diagnosis or prescription history is not the same category of risk as a leaked shopping list.

What the Act actually requires of your clinic

1. Consent, in clear language

You need a lawful basis to collect and use patient data, and consent is the primary one for a clinic. That consent notice needs to be in clear language — not buried in fine print — explaining what data you collect and why. A registration form that says "by booking, you agree to our data practices" without ever stating what those practices are does not meet the bar.

2. Purpose limitation

Data collected for treatment should be used for treatment-related purposes — not repurposed for unrelated marketing without separate consent. If your clinic wants to send promotional messages using patient contact details collected at registration, that is a distinct use that needs its own basis.

3. Reasonable security safeguards

The Act requires you to protect personal data against breach, using safeguards "reasonable" for the sensitivity of the data involved. For health data, that practically means: access controls so only relevant staff can see a given record, encrypted storage and transmission, and protection against unauthorized access whether from outside attackers or from staff who have no clinical reason to view a particular patient's file.

4. Breach notification

If a data breach occurs, you are required to notify the Data Protection Board and affected individuals. This is a strong incentive to know, at all times, who can access what in your systems — because you cannot assess or report a breach you cannot detect.

5. Data principal rights

Patients (the Act calls them "Data Principals") have rights to access their data, correct it, and request its erasure in certain circumstances. Your clinic needs an actual process for handling such a request — not just a policy document that says one exists.

6. Retention limits

Personal data should not be retained longer than necessary for the purpose it was collected for, subject to other legal requirements (medical record retention rules vary by state and specialty and can require longer retention — the DPDP Act does not override those). The practical takeaway is that "keep everything forever, in case" is not a compliant default; retention should be a deliberate, documented decision.

What to check in your clinic software

Most of DPDP compliance for a clinic comes down to whether your systems support it, not whether you have a policy binder in a drawer. Check for:

Software with a scanned-PDF approach to records makes several of these harder — you cannot apply granular access control or generate a clean audit trail on a folder of image files the way you can on structured records. This is one of several reasons the EHR vs EMR distinction matters beyond convenience.

This is not just a compliance exercise

The controls DPDP asks for — access control, audit trails, deliberate retention — are also good operational practice independent of the law. They reduce the chance of an embarrassing internal incident (a staff member browsing a record they had no reason to open), and they make it far easier to answer a patient who asks "who has seen my file?" A clinic that treats this seriously earns a kind of trust that shows up in patient retention, not just in an audit.

How Prvaha handles this

Prvaha's patient records are structured and role-based by design: staff see only what their role requires, every access is logged, and data is encrypted in storage and transit. Consent capture is built into the patient registration and booking flow rather than bolted on as a separate form, and retention settings are configurable rather than defaulted to "keep forever." See our clinic management software for India page for how this fits into the rest of your clinic's operations.

This article is general information, not legal advice. For your clinic's specific compliance obligations, consult a lawyer familiar with the DPDP Act and healthcare data regulation.

Ready to see this in your clinic?

Book a demo and we will show you Prvaha with your clinic's workflows, volumes, and team in mind.

By clicking “Accept”, you agree to the storing of cookies on your device.

DPDP Act compliance for clinics: what patient data rules mean for you | Prvaha