Patient Data Privacy in India: The DPDP Act 2023 Explained for Clinics
The JenPulse team · 5 October 2026 · 4 min read

Clinics handle some of the most sensitive information there is: diagnoses, medicines, test results, mental health notes. India's Digital Personal Data Protection Act, 2023 (DPDP Act) sets out how organisations must handle personal data, and it applies to clinics as much as to any business.
This guide explains the main ideas in practical terms. It is not legal advice. The Act's detailed rules are being phased in, so check the latest notifications or speak to a lawyer for decisions specific to your clinic.
The key idea: you are responsible for the data you collect
Under the Act, an organisation that decides why and how personal data is processed is a data fiduciary. For your patients' records, that is your clinic. If you use software or a cloud service to store the data, that provider processes it on your behalf, but the responsibility to protect it stays with you.
What the Act asks of a clinic
Collect data for a clear purpose
Collect what you need to treat and bill the patient, and use it for that purpose. If you want to use it for something else, such as marketing messages about a new service, that needs its own clear basis, usually consent.
Tell patients what you collect and why
Patients should get a simple notice explaining what data you collect, why, and how they can contact you about it. A short printed notice at reception and a privacy section on your website are a practical start. Write it in plain language, and offer it in the languages your patients use.
Get valid consent where it is needed
Consent should be free, specific, informed and clear, given by an action like signing or ticking a box, not assumed from silence. The Act also allows certain processing without consent in specific situations, such as medical emergencies. Keep a record of the consent you take.
Keep the data secure
You must take reasonable security safeguards to prevent breaches. In practice, for a clinic, that means:
- A separate login for every staff member, no shared passwords
- Role-based access, so each person sees only what their job needs
- An audit trail of who viewed or changed records
- Encrypted storage and secure backups
- Locked cabinets for any remaining paper files
- Care with personal phones and WhatsApp for sharing reports
Report breaches
If personal data is breached, the Act requires notifying the Data Protection Board of India and the affected individuals. Have a simple plan: who to call, how to find out what happened, and how to inform patients.
Respect patient rights
Patients have rights to access a summary of their data, to correct and update it, to have it erased when it is no longer needed (subject to laws that require you to keep medical records), and to have a way to raise grievances. Name a person in your clinic who handles these requests.
Don't keep data longer than needed
Keep records for as long as medical and legal requirements say, then dispose of them securely. Medical record retention rules still apply, so this doesn't mean deleting records early.
Children's data needs extra care
For patients under 18, the Act requires verifiable consent from a parent or guardian for processing their data, with exceptions that may apply to healthcare. Paediatric clinics in particular should check the detailed rules.
The penalties are significant
The Act allows the Data Protection Board to impose large financial penalties, running into crores of rupees for serious failures such as not taking reasonable security safeguards. For a small clinic, the bigger risk is often reputational: patients trust you with private information.
A practical checklist for your clinic
- Write a short privacy notice for patients and put it at reception and on your website
- Give every staff member their own login and remove shared accounts
- Set roles so staff only see what they need
- Turn on, and occasionally check, the audit log in your software
- Stop sharing reports through personal WhatsApp where you can
- Ask your software provider where data is stored, how it is encrypted and how they would notify you of a breach
- Name a person to handle patient data requests and complaints
- Write a one-page breach response plan
How JenPulse helps
JenPulse gives every staff member their own login, lets you set exactly what each role can see down to individual fields, and records an audit trail of changes and sign-ins. Each clinic's data is kept separate from every other clinic's. You can read more in our privacy policy, or contact us with any questions about how we protect your data.