The Digital Personal Data Protection Act, 2023 (DPDP Act) plus the DPDP Rules, 2025 (notified 13 November 2025) is now the primary data-privacy law governing how hospitals and EMR/health-tech companies in India collect, store, and share patient data. Here's how it works and what it actually changes.
1. Who is who under the Act
- Data Principal - the patient (the individual the data belongs to).
- Data Fiduciary - the entity that decides why and how data is processed. Hospitals, clinics, diagnostic centres, telemedicine platforms, and health-tech companies are Data Fiduciaries with respect to patient data, since they determine the purpose of collection.
- Data Processor - entities that process data on behalf of a fiduciary, following its instructions. EMR/EHR vendors, cloud hosting providers, billing software, and lab-integration platforms are typically Data Processors, per this breakdown of healthcare data compliance under DPDPA.
- Significant Data Fiduciary (SDF) - a category the government can notify based on volume/sensitivity of data, risk to rights of individuals, and other factors under Section 10. Large hospital chains or health-tech platforms handling data at scale could be notified as SDFs, which brings extra obligations (mandatory Data Protection Officer, Data Protection Impact Assessments, independent audits).
Important nuance: unlike the old IT Rules 2011 ("SPDI Rules"), which had a distinct "sensitive personal data" category with special rules for health/medical data, the DPDP Act itself applies uniformly to all personal data - it doesn't carve out a separate legal tier for health data. In practice, though, health data's inherent sensitivity means hospitals are still expected to apply heightened security and stricter consent discipline, since a breach involving health data creates larger harm and larger penalty exposure. Be aware some secondary sources loosely describe health data as "sensitive personal data under Section 3(d)" - that's describing the practical treatment, not a formal statutory category.
2. What hospitals (as Data Fiduciaries) must do
Consent: Must be free, specific, informed, unconditional, and unambiguous, given via a clear notice in plain language (not buried in a generic admission form). A vague blanket admission-form clause is not considered valid DPDPA consent - hospitals need itemized consent covering: record creation/maintenance, internal specialist consultation, insurance/billing data sharing, use of anonymized data for research, and follow-up communication, with an explicit right to withdraw consent at any time.
Purpose limitation & data minimization: Only collect data necessary for the stated healthcare purpose, and stop processing once that purpose is served.
Children's data - Rule 12 exemption: Clinical establishments and healthcare professionals get a narrow, purpose-bound exemption from the general requirement of verifiable parental consent, but only when processing is necessary to actually deliver health services. It does not exempt them from security safeguards or breach notification, and it doesn't cover any other use of a minor's data beyond direct treatment.
Security safeguards: Encryption, access controls, audit trails, staff training, breach-response plans. Failure to implement "reasonable security safeguards" is the single largest penalty exposure - up to INR 250 crore.
Breach notification: Hospitals must notify both the Data Protection Board of India and affected patients when a breach occurs. Failure to notify can attract penalties of up to INR 200 crore.
Data retention vs. deletion: The Act's default principle is that data should be deleted/anonymized once its purpose is served - but Section 17 carves out exemptions where another law requires retention. This directly reconciles with the NMC 3-year rule and various hospital retention practices discussed earlier: a hospital cannot use "DPDP requires deletion" as an excuse to destroy records early if the NMC regulations, Clinical Establishments Rules, or ongoing litigation require them to be kept longer. In effect, the older retention laws still govern how long records must be kept; DPDP governs how they must be secured and consented to while they're held.
Cross-border transfer: Section 16 allows data transfer outside India except to countries the government specifically restricts (a blacklist approach, not a strict localization mandate). Telemedicine and health-tech platforms with servers or specialists abroad need to check this list and build it into consent language - several compliance guides flag telemedicine cross-border transmission as a high-risk area needing end-to-end encryption and explicit consent.
3. What this means specifically for EMR/health-tech companies
This is the part that trips up most vendors:
- The hospital remains the liable party, not the EMR vendor, even when the vendor's system is what actually leaks data. Per the interlegal.net analysis of vendor liability: "statutory liability rests with the healthcare entity as Data Fiduciary, not the cloud vendor... regardless of any contractual arrangement." If an EMR vendor's cloud infrastructure is breached, the hospital still faces the full DPDPA penalty exposure.
- Because of this, hospitals need proper Data Processing Agreements (DPAs) with every EMR vendor, cloud host, lab-integration partner, and billing processor - contracts that impose matching security obligations, confidentiality terms, breach-cooperation clauses, and indemnification. A hospital relying on a vendor's generic SaaS terms-of-service, not calibrated to DPDPA, still carries the compliance risk itself.
- EMR vendors' own obligations: as Data Processors, they must follow the fiduciary's instructions, implement the security measures contractually required, support audit trails and access logs (critical for demonstrating tiered access control by department/specialty), and cooperate on breach investigation and Data Protection Board inquiries.
- When an EMR company can become a Data Fiduciary in its own right: if it independently decides to use patient data for its own purposes - e.g., aggregating de-identified data for a commercial analytics product, training an AI model, or selling insights - it stops acting purely as a processor for that specific use and takes on fiduciary obligations (its own consent basis, notice, and liability) for that processing activity.
- Health-tech/EMR companies operating at scale (large patient volumes, multiple hospital clients) are prime candidates for being notified as Significant Data Fiduciaries, triggering mandatory DPO appointment, periodic DPIAs, and independent data audits.
4. How DPDP interacts with the older framework
The DPDP Act doesn't replace the earlier rules discussed previously - it layers on top of them:
- NMC Code of Ethics Regulations 2002 (3-year retention, 72-hour access) still governs retention duration and the patient's right to get their own records.
- Clinical Establishments Act 2010 + Rules 2012 (EMR/EHR maintenance standards) now needs updated breach-reporting and record-management practices to align with DPDP.
- IT Act 2000, Sections 43A and 72A (compensation for negligent handling of sensitive data, and penalty for disclosure in breach of contract) continue to apply alongside DPDP, not instead of it.
- Mental Healthcare Act 2017 and Rights of Persons with Disabilities Act 2016 protections for particularly sensitive categories (psychiatric records, disability data) are reinforced, not superseded, by DPDP.
- The Ayushman Bharat Digital Mission (ABDM)/ABHA ecosystem, where records increasingly move between hospitals digitally with patient consent, now operates under the DPDP consent framework as its legal backbone.
5. Practical compliance checklist
For hospitals: map every place patient data flows (EMR, lab/imaging systems, billing, telemedicine, third-party integrations); rebuild consent forms into itemized, specific-purpose consent rather than one blanket admission clause; sign DPDPA-calibrated DPAs with every vendor; establish breach-response protocols; assess whether a DPO is needed.
For EMR/health-tech vendors: build consent-tracking and audit-trail features directly into the product (since hospitals will demand this contractually); offer India-based hosting options to simplify cross-border transfer questions; be prepared to sign indemnification-backed DPAs; and separately evaluate any secondary use of aggregated/anonymized data, since that can shift you into fiduciary status with independent liability.
The overall effect: DPDP doesn't change how long hospitals must keep records (that's still the NMC/CE Act territory), but it substantially raises the bar on how that data must be consented to, secured, and accounted for - and it makes clear that outsourcing IT infrastructure to an EMR company does not outsource legal liability.