Patient Consent Under DPDPA: Treatment Is Not a Blank Cheque
Patient Consent Under DPDPA: Treatment Is Not a Blank Cheque
The emergency justifies the stretcher. It does not justify the newsletter.
The scene
A patient registered at the emergency desk at midnight. By morning her number was in the hospital's CRM. By the next week she was receiving offers for a full-body check-up package. She never gave consent to marketing. She was barely conscious when she gave her number.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Patients agree to everything at admission.
Admission forms bundle purposes; DPDPA consent must be specific to each.
Separate care, billing and marketing into distinct asks.
Medical data can be processed without consent.
Section 7's medical legitimate uses are for emergencies and threats to life or health, not routine commerce.
Use legitimate uses only where they plainly fit.
A three-column register
Care: what treatment needs. Compliance: what law requires. Commercial: everything else. Only the third column should ever reach marketing, and only with consent.
Monday morning
01 Read your admission form as a patient would.
02 Count the purposes bundled into one signature.
03 Split marketing consent out, and make it optional.
Questions, answered plainly
Can hospitals use patient data for marketing under DPDPA? +
Marketing is a separate purpose from treatment. It generally requires specific, freely given consent that the patient can refuse without affecting care.
When can health data be processed without consent under DPDPA? +
Section 7 allows processing for responding to a medical emergency involving a threat to life or immediate threat to health, and for certain health services during epidemics or public health threats, among other listed uses.
Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →
Healthcare & Pharma · Deep dive The report on WhatsApp is still your report. Read →
Healthcare & Pharma · Deep dive Consent for the trial is not consent for the product. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).