DPDPA for Hospitals, Healthcare and Pharma
DPDPA for Hospitals, Healthcare and Pharma
Emergency is a legitimate use. Convenience is not.
The scene
A diagnostic chain shared reports over a messaging app because it was fast. Doctors loved it. Patients got results in minutes. Every report sat on personal phones, forwarded, screenshotted, backed up to clouds nobody had contracted.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Treating the patient covers all processing.
Section 7's medical legitimate uses are narrow; research, marketing and analytics need their own basis.
Separate care from everything built on top of care.
Health data isn't special under DPDPA.
The Board weighs the type and nature of personal data when deciding penalty.
Protect health data as though the Act named it.
The TPA and lab are separate.
Where they process on your behalf, their breach is yours.
Map every hand a report passes through.
Pharma and trials
Patient support programmes, pharmacovigilance and trial data each rest on different bases. Consent given to a trial does not extend to marketing a later product.
The full Healthcare & Pharma briefing 3 deep dives
Deep dive 01 →
Treatment is not a blank cheque.
The emergency justifies the stretcher. It does not justify the newsletter.
Deep dive 02 →
The report on WhatsApp is still your report.
Fast delivery. Permanent copies.
Deep dive 03 →
Consent for the trial is not consent for the product.
The protocol ends. The purpose ends with it.
Monday morning
01 Find every channel reports travel through, including messaging apps.
02 Split processing into care, compliance and commercial.
03 Check whether consent exists for the commercial column.
Questions, answered plainly
Does DPDPA have a sensitive personal data category for health data? +
No. DPDPA does not create separate categories. However, under Section 33 the Board considers the type and nature of personal data when determining penalties, so health data breaches are likely to be treated as more serious.
Can hospitals process patient data without consent under DPDPA? +
Section 7 permits certain processing without consent, including responding to a medical emergency involving a threat to life or health. Routine care, research and marketing should be assessed separately and often need consent.
Sector · EdTech A child's data is not a cookie. Stop treating it like one. Read →
Sector · E-commerce & D2C Your funnel runs on consent. The Act just redefined consent. Read →
Sector · SaaS & IT services You think you're the processor. Your contract may disagree. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
