What is the DPDP Act, and why should your clinic care?
The Digital Personal Data Protection Act, 2023 — DPDP Act — is India's version of Europe's GDPR. It came into force in phases through 2024–2025 and applies to every clinic that processes patient data digitally. That includes you if you use WhatsApp for appointment reminders, store patient records in Excel, or run any clinic software.
For years, small clinics assumed data protection laws only applied to hospitals and IT companies. The DPDP Act ended that assumption. Every clinic — from a solo GP in Sector 22 to a multi-specialty in Sector 46 — now has legal obligations.
If you collect a patient's phone number, name, or any medical detail, you're a Data Fiduciary under the DPDP Act. That comes with responsibilities. And, potentially, penalties up to ₹250 crore.
The seven things every Indian clinic must do under DPDP
Not every DPDP requirement applies equally to every clinic, but seven principles cover the essentials for small and mid-sized practices:
- 1 Explicit consent for data collection. Verbal consent isn't enough anymore. You need a documented consent — a signed intake form, a checkbox on your patient portal, or an SMS/WhatsApp confirmation. Consent must specify what data is collected and why.
- 2 Data minimization. Only collect what you need. If you don't need a patient's Aadhaar to treat them, don't collect it. If you don't need their address for a walk-in, don't ask.
- 3 Purpose limitation. Data collected for appointment booking can't be used for marketing without separate consent.
- 4 Right to access. Patients can request all data you hold about them. You must provide it within 30 days.
- 5 Right to erasure. Patients can request deletion (with limited medical record retention exceptions). You must honor this.
- 6 Breach notification. If patient data is compromised, you must notify the Data Protection Board and affected patients within 72 hours.
- 7 Data localization for sensitive data. Patient health records should be stored on Indian servers. This affects your choice of clinic software vendor.
The specific consent language every clinic should adopt
Here's a concrete template you can adopt today, adapted from DPDP Act consent requirements. Print it and have new patients sign it:
"I consent to [Clinic Name] collecting and processing my personal and medical information for the purposes of providing healthcare services, including appointment scheduling, treatment records, prescriptions, and follow-up communications via SMS and WhatsApp. I understand my data will be stored securely on servers within India, will not be shared with third parties without my separate consent, and I have the right to access or request deletion of my data at any time by contacting [clinic email]."
What DhiDoc does to keep you compliant
We built DhiDoc from day one assuming DPDP compliance was non-negotiable. Here's how the product handles the requirements:
- ✓ Consent flow built into patient onboarding. First-time patients see and agree to your clinic's data use terms before any data is stored.
- ✓ All data hosted in Mumbai region. Supabase ap-south-1 region — data never leaves Indian jurisdiction.
- ✓ Purpose-specific consent for marketing. Appointment reminders (utility templates) are separate from any promotional messages.
- ✓ Audit logs for every record access. You can prove who accessed which patient record and when.
- ✓ One-tap patient data export. When a patient requests their data, you can generate a complete export in under a minute.
- ✓ Row-level security. Clinic A can never accidentally see Clinic B's patients. Enforced at the database layer.
- ✓ Encrypted at rest and in transit. AES-256 encryption, TLS 1.2+, standard modern controls.
What you need to do in the next 30 days
Even if you use DhiDoc, the DPDP Act has obligations that require the clinic — not the software — to act. Here's your 30-day compliance checklist:
- ✓ Update your patient intake form with explicit DPDP-compliant consent language (template above).
- ✓ Post your data protection policy visibly at reception and on your website/patient portal.
- ✓ Designate one staff member as the point of contact for patient data requests.
- ✓ Document your data retention policy (Indian medical records typically kept 7 years).
- ✓ If you use WhatsApp for patient communication, verify your BSP is DPDP-compliant.
- ✓ Set up a simple email address like privacy@yourclinic.in for patient data requests.
- ✓ Train your reception staff — even 15 minutes — on what to do if a patient requests their data.
Many clinics assume that because they don't do 'marketing', DPDP doesn't apply to them. Wrong. DPDP applies to any personal data processing — including a phone number stored to send appointment reminders. It's not about marketing intent; it's about data handling.
Penalties, and why the ₹250 crore number is scary
The maximum penalty under the DPDP Act is ₹250 crore per violation. That number is designed for large corporations and rarely applies to small clinics. But smaller violations can still result in penalties of a few lakh rupees — significant for a clinic making ₹40-50 lakh a year.
More practically: the reputational risk of a data breach or a DPDP complaint filed by a patient can be devastating for a clinic that depends on word-of-mouth referrals. The best defense is prevention.
The one-line summary
If you take one thing from this article: the DPDP Act is real, it applies to your clinic, and getting compliant is not expensive. Most small clinics can achieve substantial compliance in a weekend with the right consent form, a compliant software vendor, and 15 minutes of staff training.