The Act has no 'sensitive' category.Your patients do.

DPDPA treats all personal data alike on paper. A breach of a diagnosis will not be treated alike in practice.

In one line: No. DPDPA does not create separate categories. However, under Section 33 the Board considers the type and nature of personal data when determining penalties, so health data breaches are likely to be treated as more serious.

The estate · Healthcare & PharmaHover to inspect

Emergency is a legitimate use. Convenience is not.

The scene

A diagnostic chain shared reports over a messaging app because it was fast. Doctors loved it. Patients got results in minutes. Every report sat on personal phones, forwarded, screenshotted, backed up to clouds nobody had contracted.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
Treating the patient covers all processing. Section 7's medical legitimate uses are narrow; research, marketing and analytics need their own basis. Separate care from everything built on top of care.
Health data isn't special under DPDPA. The Board weighs the type and nature of personal data when deciding penalty. Protect health data as though the Act named it.
The TPA and lab are separate. Where they process on your behalf, their breach is yours. Map every hand a report passes through.

Pharma and trials

Patient support programmes, pharmacovigilance and trial data each rest on different bases. Consent given to a trial does not extend to marketing a later product.

The full Healthcare & Pharma briefing

3 deep dives
Deep dive 01→

Treatment is not a blank cheque.

The emergency justifies the stretcher. It does not justify the newsletter.

Deep dive 02→

The report on WhatsApp is still your report.

Fast delivery. Permanent copies.

Deep dive 03→

Consent for the trial is not consent for the product.

The protocol ends. The purpose ends with it.

Monday morning

  1. 01Find every channel reports travel through, including messaging apps.
  2. 02Split processing into care, compliance and commercial.
  3. 03Check whether consent exists for the commercial column.

Questions, answered plainly

Does DPDPA have a sensitive personal data category for health data?

No. DPDPA does not create separate categories. However, under Section 33 the Board considers the type and nature of personal data when determining penalties, so health data breaches are likely to be treated as more serious.

Can hospitals process patient data without consent under DPDPA?

Section 7 permits certain processing without consent, including responding to a medical emergency involving a threat to life or health. Routine care, research and marketing should be assessed separately and often need consent.

Sector · EdTechA child's data is not a cookie. Stop treating it like one.Read → Sector · E-commerce & D2CYour funnel runs on consent. The Act just redefined consent.Read → Sector · SaaS & IT servicesYou think you're the processor. Your contract may disagree.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner