How the DPDPA classifies health data
The DPDPA defines personal data as any data about an individual who is identifiable by or in relation to such data (Section 2(t)). Patient names, hospital IDs, medical histories, diagnostic images, prescriptions, insurance policy numbers and genomic sequences all fall within this definition.
Unlike the GDPR (which designates health data as a “special category” under Article 9) or the 2011 SPDI Rules (which listed medical records as “sensitive personal data”), the DPDPA applies a uniform consent and safeguard framework. Heightened obligations emerge not from the data category but from the processing scale (SDF designation under Section 10) and from sector-specific regulations preserved by Section 16(2).
Consent and legitimate uses for health data
The default lawful basis is consent under Section 6: free, specific, informed, unconditional and unambiguous. For a hospital admitting a planned-surgery patient, this means a clear notice (Section 5) explaining what data is collected, why and how the patient can exercise rights—followed by affirmative consent.
Section 7 provides legitimate-use grounds that do not require consent. For health data, the most relevant are:
- Section 7(a): personal data voluntarily provided by the Data Principal for a specified purpose (e.g. filling in a registration form at a clinic)
- Section 7(h): medical emergency involving a threat to the life or immediate threat to the health of the Data Principal or another individual
- Section 7(b): state function or statutory purpose (e.g. notifiable-disease reporting under the Epidemic Diseases Act)
- Section 7(i): employment purposes—applicable to employee health records held by an employer
Security safeguards for health records
Section 8(5) requires reasonable security safeguards to prevent a personal data breach. For health data, “reasonable” must reflect the data’s sensitivity—a leaked medical diagnosis can cause irreversible reputational and personal harm.
Rule 6 of the DPDP Rules 2025 requires technical and organisational measures appropriate to the nature and volume of personal data processed. Industry benchmarks for health data include:
- Encryption of patient records at rest (AES-256) and in transit (TLS 1.2+)
- Role-based access control—physicians, nurses, billing staff see different data subsets
- Audit logging of every access to patient records, with tamper-proof storage
- Data-loss prevention controls on outbound channels (email, USB, API)
- Periodic vulnerability assessments and penetration testing of clinical systems
Sector-specific rules preserved by Section 16(2)
Section 16(2) preserves stricter obligations in other laws. For the health sector, this includes:
- Clinical Establishments (Registration and Regulation) Act, 2010: record-keeping obligations for registered hospitals and clinics
- NABH accreditation standards: data-handling, access-control and retention requirements
- IRDAI (Protection of Policyholders’ Interests) Regulations: handling of health insurance claims data
- Indian Council of Medical Research (ICMR) guidelines on biomedical and health research: consent and data-protection standards for clinical trials
- Drugs and Clinical Trials Rules, 2019: informed consent and data-handling for trial participants
Where a sector-specific rule imposes a stricter standard—longer retention, more detailed consent or additional security measures—that standard applies alongside the DPDPA. Compliance with the DPDPA alone is not sufficient if the sector rule demands more.
How AMLEGALS assists with health data compliance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm advises hospitals, healthtech platforms, insurers and clinical research organisations on mapping their health-data processing to the DPDPA framework, structuring consent flows for clinical and operational contexts, and designing security-safeguard programmes that satisfy both the DPDPA and sector-specific regulators.

