The report on WhatsAppis still your report.
Speed moved the data out of your systems. The duty stayed in them.
In one line: DPDPA does not ban specific apps, but the Data Fiduciary must take reasonable security safeguards. Uncontrolled copies on staff and third-party devices make it harder to meet that duty and to respond to a breach.
Fast delivery. Permanent copies.
The scene
The lab's turnaround time was the best in the city because reports went straight to patients on WhatsApp. They also went to the referring doctor, the doctor's assistant, a family group, and the phone gallery of every one of them. When a report reached the wrong number, the lab had no way to recall it.
Where the thinking breaks
Designing a safer channel
A secure link with expiry and access logs gives the same speed with a fraction of the copies. It also gives you evidence of reasonable safeguards under Section 8(5).
Monday morning
- 01Find every team that sends reports by personal messaging.
- 02Count the phones involved.
- 03Pilot an expiring-link delivery for one location.
Questions, answered plainly
Is it lawful to send medical reports over WhatsApp under DPDPA?
DPDPA does not ban specific apps, but the Data Fiduciary must take reasonable security safeguards. Uncontrolled copies on staff and third-party devices make it harder to meet that duty and to respond to a breach.
What counts as a personal data breach in a hospital?
Under DPDPA a breach includes unauthorised processing, accidental disclosure, loss of access and similar events that compromise confidentiality, integrity or availability of personal data. A report sent to the wrong person can qualify.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner