The DPDP Act and your clinic: what it asks for, and when
You have probably been told your clinic must be DPDP compliant, and that the penalties run to hundreds of crores. Both statements are technically true and together they give a misleading picture.
Here is where the law actually stands, what it will ask of a clinic, and what is worth doing now rather than in 2027.
Where the law stands
The Digital Personal Data Protection Act was passed in 2023. Nothing much followed until the Digital Personal Data Protection Rules were notified on 13 November 2025, which set out how the Act would actually work and when.
Commencement is staggered:
Already in force. The administrative provisions, and the Data Protection Board of India, which is the body that will hear complaints.
Around November 2026. The provisions governing Consent Managers — a registered intermediary through which people can give and withdraw consent across services.
Around mid-2027. The substantive framework. Notice and consent standards, security safeguards, breach notification, retention limits, and the rights of individuals to access, correct and erase their data. This is the part that will change what a clinic has to do.
So the accurate position today is that the core obligations are not yet in force. That is not a reason to ignore them — building consent flows, knowing what data you hold and being able to delete it takes longer than it sounds — but it is a reason to be sceptical of anyone selling urgency.
What your clinic is under the Act
The Act distinguishes two roles.
A Data Fiduciary decides why and how personal data is processed. A clinic holding patient records is a Data Fiduciary. The responsibility sits with the clinic, not with the individual member of staff who handled the data.
A Data Processor processes data on a Data Fiduciary's instructions. Your clinic software is typically a Processor. That does not transfer your responsibility to them; it means you are responsible for choosing them and for what they are contracted to do.
There is a further category, Significant Data Fiduciary, carrying heavier obligations. The government has not yet published which organisations fall into it. Health is among the sectors widely expected to feature, though that concerns large processors rather than individual clinics.
What will be required
When the substantive provisions commence, a Data Fiduciary will need to:
- give people a clear notice of what is being collected and why
- obtain consent that is specific, informed and freely given, and make withdrawing it as easy as giving it
- process data only for the purpose consented to
- apply reasonable security safeguards
- notify the Data Protection Board and affected individuals of a personal data breach
- not keep data longer than the purpose requires
- honour rights of access, correction and erasure
- publish the contact details of a person who will answer data grievances
Penalties under the Act are graded by the nature of the failure and run high at the top end. The headline figures quoted in marketing material are maximums attached to serious failures by large processors, not what a small clinic should expect to face.
What is worth doing now
None of this requires software. It requires knowing your own clinic.
Know what you hold and where. Patient names, phone numbers, conditions, prescriptions, photographs. On paper, in a register, in a computer, in WhatsApp, and — this is the one clinics miss — on staff members' personal phones.
Know who can see it. If your assistant's phone holds photographs of patient prescriptions, that is your clinic's data outside your clinic's control, and it remains your responsibility rather than theirs. We wrote about that in more detail here: /learn/whatsapp-prescriptions
Be able to delete it. A patient will eventually ask you to erase their data. Being able to answer that means knowing every place it exists.
Know what your vendors do with it. Ask any software you use: where is the data stored, who at your company can see it, what happens to it if we leave, and will you tell us if you have a breach. A vendor who cannot answer plainly is a risk you are carrying.
Write down what you do. Not a policy document for its own sake — a short, honest description of what you collect, why, who sees it and how long you keep it. Most of the work in 2027 will be proving you thought about this.
Where Nadi is
Records in Nadi are stored in India, access is gated by consent, and patients can request erasure.
We are working through the same preparation every Data Fiduciary is: retention periods, breach procedure, and the documentation that goes with them. We are not going to tell you we have made your clinic compliant with a framework whose main provisions are not yet in force.
Free to start at nadihealth.coThis page describes the DPDP Act and Rules in general terms and is not legal advice. Commencement dates and obligations may change; the Ministry of Electronics and Information Technology is the authoritative source. Consult your own counsel for your clinic's specific position.