← All articles

August 13, 2026 · 12 min read

DPDP for Hospitals: Health Data Is Not "Sensitive Personal Data" Under This Act

Several published healthcare DPDP guides state that health data is sensitive personal data under the Act, and that health data must be localised. Neither is true — that framework came from the 2011 SPDI Rules the DPDP Act supersedes

DPDP for Hospitals: Health Data Is Not "Sensitive Personal Data" Under This Act

By Yatin Chaudhary, SEO Specialist at ProtectComply · Reviewed by Jupinder Singh Bedi, CEO & Co-Founder · Last updated 13 August 2026 · 13 min read

Quick answer

Three things published healthcare DPDP guides get wrong, and hospitals are building programmes on them:

1. There is no "sensitive personal data" category. Several guides cite a section of the DPDP Act creating heightened obligations for health data. No such provision exists. That taxonomy came from the 2011 SPDI Rules under the IT Act, which the DPDP Act supersedes. All personal data is treated uniformly.

2. There is no health data localisation mandate. The Rules use a blacklist model — transfers permitted except to restricted territories. ABDM's own policies may impose separate requirements, but the DPDP Act does not localise health data.

3. ABDM consent is not DPDP consent. Being ABDM-compliant does not make you DPDP-compliant, and this is where most hospitals are actually exposed.

What does apply to hospitals is harsher than the myth in one specific place: every patient under 18 requires verifiable parental consent. Paediatric, adolescent mental health and school health programmes are the real exposure, and almost nobody is writing about it.

Why "no sensitive data category" cuts both ways

The absence of a special category is not relief.

Under GDPR, health data sits in Article 9 with heightened conditions and a defined set of lawful bases. Hospitals with GDPR experience expect a similar structure and look for the equivalent provision. There isn't one.

What that means practically:

You do not get a special lawful basis for medical treatment the way GDPR provides one. Processing rests on consent or on the enumerated legitimate uses — one of which covers medical emergencies and threats to life. Outside those, consent.

Nor does the absence of a category reduce the harm profile. A leaked diagnosis, HIV status, mental health record or genetic result causes damage that a leaked email address does not. Your security safeguards should reflect sensitivity even where the statute does not distinguish — because the ₹250 crore penalty head attaches to failure to maintain reasonable safeguards, and what counts as reasonable scales with the harm at stake.

So: uniform obligations, non-uniform risk. Design to the risk.

ABDM consent does not satisfy DPDP

This is the gap most hospitals have, and it is structural rather than a documentation problem.

ABDM's consent artefact model is genuinely sophisticated. A patient grants a Health Information User access to records linked to their ABHA ID, access expires, requests are logged, and FHIR-standard exchange makes records portable between a hospital in Pune and a specialist in Chennai.

But an ABDM consent artefact grants access for a defined period. It does not specify what the receiving party will do with the data.

The DPDP Act requires consent that is free, specific, informed, unconditional and unambiguous, tied to a stated purpose. "Access to your discharge summary for 30 days" is an access grant. It is not purpose-specific consent.

The distinction matters when the same accessed record feeds an insurance underwriting model, a pharmaceutical research database, or a clinical second opinion. Those are three different purposes with three different consent requirements, and the ABDM artefact covers none of them individually.

What hospitals need to build: a consent layer that captures DPDP-grade purpose-linked consent alongside ABDM consent artefacts, with the two reconciled against each other. Not one replacing the other — both, linked.

The children's problem nobody is writing about

Under the DPDP Act a child is anyone under 18, uniformly, and processing children's data requires verifiable parental or guardian consent.

Now consider what that means in a hospital.

Paediatrics. Every patient under 18 in your paediatric department requires verifiable parental consent for data processing — not just for treatment, which is separate clinical consent, but for the processing of their personal data.

Adolescent care. A 17-year-old presenting for mental health, reproductive health or substance-related care is a child under the Act. Verifiable parental consent for data processing sits in genuine tension with clinical confidentiality norms for adolescent patients. This is unresolved and hospitals should be seeking counsel on it rather than assuming.

School health programmes and vaccination drives. Bulk processing of minors' health data, frequently with consent collected by an intermediary rather than by you.

Legacy paediatric records. Records collected before the Act took effect, for patients still under 18.

Children's data violations sit near the top of the penalty schedule. And "verifiable" is a higher bar than a signature on a form — it means you can demonstrate the consenting adult was in fact the parent or guardian.

If you take one operational action from this article, audit your paediatric consent flow.

The retention conflict, and why it differs from banking

Everyone writes about the RBI-versus-DPDP retention conflict. Healthcare has its own version and it is messier, because the retention obligations are fragmented.

Clinical establishment regulations, state-level medical records rules, Medical Council record-keeping requirements, insurance claim retention and clinical trial obligations all impose different retention periods on different record types. There is no single healthcare equivalent of RBI's KYC Master Direction.

The resolution is the same in principle: processing necessary to comply with a legal obligation does not stop because consent was withdrawn. You can lawfully decline erasure to the extent a statutory retention mandate applies.

The operational difficulty is worse: you need to know which specific rule governs which specific record type, and those rules vary by state and by establishment class. A hospital chain operating across four states may face four different answers for the same record.

And the override covers only what the statute requires. Marketing preferences, appointment-reminder data, patient-portal behavioural analytics and feedback survey responses have no retention mandate — those must be erased on request even while the clinical record is held.

What to build: a retention schedule keyed to record type and jurisdiction, not to patient. Then separate statutory-hold data from consent-governed data at the architecture level, so partial erasure is executable rather than theoretical.

Who is the Data Fiduciary in a patient journey?

A single episode of care touches the hospital, a diagnostic lab, a pharmacy, an insurer, a telemedicine platform, and increasingly an ABDM-linked Health Information Exchange.

Each handles patient personal data. Most arrangements have no documented allocation of who is the Data Fiduciary and who is the Processor.

Questions your contracts should answer:

  • Is your diagnostic partner a processor acting on your instruction, or a fiduciary determining its own purposes? A lab running its own research on samples is doing something different from one returning results.
  • When a patient withdraws consent, how does that propagate to the lab, the pharmacy, the insurer and any HIU that accessed records? Within what timeframe?
  • When a patient exercises an access right, who assembles the response across all parties?
  • If a breach occurs at your imaging vendor, who notifies the Board and who notifies the patient?

The Data Fiduciary is accountable for processing carried out by processors on its behalf. If your contracts are silent, you are likely holding liability you never priced.

Record the allocation per processing activity in your RoPA, with the contract reference attached. That is what turns a legal question into an operational control.

Are you a Significant Data Fiduciary?

Almost certainly, if you are at any scale.

Section 10 lets the Central Government designate Significant Data Fiduciaries based on volume and sensitivity of personal data, risk to Data Principals, and impacts on sovereignty, security of the State and public order. Health data clears the sensitivity criterion without argument.

A mid-sized private hospital chain processing 50,000 patient records monthly — diagnostics, discharge summaries, prescription histories, insurance claims — sits squarely in that profile.

No designations have been notified yet. The category is currently empty. But designation happens by government notification with no preparation window, and the obligations are substantial: a Data Protection Officer based in India, an independent data auditor, periodic audits, and DPIAs — where the trigger is entity-based rather than activity-based, so the obligation attaches across your processing rather than to selected activities.

Build the capability before the notification arrives.

The breach clock is tighter than you think

A hospital breach starts multiple clocks.

CERT-In — cyber incidents reportable within six hours of noticing them.

Data Protection Board — intimation without delay on becoming aware, followed by detailed particulars within 72 hours: the facts and reasons, mitigation implemented, findings on cause, remedial measures, and a report on the intimations given to patients.

Every affected patient — notified without delay, in plain language, with the nature and extent of the breach, likely consequences, mitigation taken, and steps they can take.

That last obligation has no materiality filter. GDPR lets you skip notifying individuals where risk is unlikely to be high. That exception is not available here.

For a hospital, notifying affected patients means enumerating them accurately and reaching them — potentially across Eighth Schedule languages, potentially including patients whose contact details are stale, potentially including minors whose parents must be notified instead.

That is a data-mapping problem solved before an incident, not during one.

The hospital checklist

  1. Stop treating health data as a special category — it is not one under this Act. Design safeguards to the harm, not to a statutory tier that does not exist.
  2. Audit paediatric consent. Every patient under 18, verifiable parental consent. Start here.
  3. Build DPDP consent alongside ABDM artefacts — purpose-specific, not access-window-based.
  4. Map every system holding patient data — HMS, EMR, LIS, RIS/PACS, pharmacy, billing, patient portal, appointment system, feedback tools, WhatsApp channels.
  5. Build a retention schedule by record type and state, not by patient.
  6. Separate statutory-hold from consent-governed data at the architecture level.
  7. Assign Fiduciary and Processor roles across every lab, pharmacy, insurer and telemedicine partner, in contract.
  8. Rewrite the breach playbook for the dual notification obligation with no materiality filter.
  9. Stand up DPIA capability ahead of SDF designation.
  10. Run a mock inquiry and try to produce the evidence pack.

Frequently asked questions

Is health data sensitive personal data under the DPDP Act?

No. The DPDP Act does not create a sensitive personal data category — that framework came from the 2011 SPDI Rules under the IT Act, which the DPDP Act supersedes. All personal data carries the same statutory obligations. Several published guides state otherwise and are incorrect. The harm profile of health data remains higher, which should inform your security safeguards even though the statute does not distinguish.

Does DPDP require health data to be stored in India?

No. The Rules adopt a blacklist model — cross-border transfers are permitted except to territories the Central Government restricts. ABDM's own health data policies may impose separate requirements, but the DPDP Act does not mandate health data localisation.

Does ABDM compliance mean DPDP compliance?

No. ABDM's consent artefact grants time-limited access to records. DPDP requires purpose-specific consent — what the receiving party will actually do with the data. Hospitals need both, reconciled against each other.

What is the consent age for patients under DPDP?

Under 18, requiring verifiable parental or guardian consent. This applies to paediatric records, adolescent care and school health programmes, and creates genuine tension with clinical confidentiality norms for adolescent patients. Seek counsel rather than assuming.

Can patients demand deletion of their medical records?

Not to the extent clinical establishment regulations, state medical records rules or insurance retention obligations require you to hold them. But you must explain the specific statutory basis in writing and erase everything outside that scope — including marketing preferences, portal analytics and feedback data.

Will hospitals be designated Significant Data Fiduciaries?

Likely, given the volume and sensitivity of health data. No designations have been notified yet, but designation comes without a preparation window, so build DPO, audit and DPIA capability in advance.

How does DPDP compare to HIPAA?

HIPAA is a US healthcare-specific law. DPDP is India's general data protection law covering health data among all other categories. Strong HIPAA-aligned security practices help but do not discharge DPDP obligations — consent architecture, Data Principal rights and grievance redressal have no HIPAA equivalent.

What are the penalties?

Up to ₹250 crore for failing to maintain reasonable security safeguards, with separate heads for breach notification failures and children's data violations. Assessed per contravention rather than per organisation.

Your timeline

Full compliance is due 13 May 2027, per the DPDP Rules timeline. Penalty provisions become operative 13 November 2026.

For hospitals the binding constraint is not the deadline — it is that patient data sits across HMS, EMR, lab systems, imaging, pharmacy, billing and third-party partners, and mapping that estate takes longer than anyone budgets.

Where to start

Map before you buy. A gap analysis scoped to healthcare tells you which of these exposures you actually carry — and for most hospitals the paediatric consent gap is larger than the one they came in worried about.

For the platform question, see our comparison of DPDP platforms in India.

ProtectComply runs discovery → RoPA → DPIA end to end, with each processing activity linked to its consent basis, processor registry and retention rule — which is what makes statutory-hold separation and multi-party role allocation operationally tractable rather than a legal memo.

Book a healthcare walkthrough

About this guide

About the authorYatin Chaudhary is an SEO Specialist at ProtectComply, where he writes about India's data protection framework and how organisations operationalise it.

Reviewed by Jupinder Singh Bedi, CEO & Co-Founder, ProtectComply.

Written against the DPDP Act, 2023 and the DPDP Rules, 2025 as notified. Where published guidance conflicts with the statute — as it does on the sensitive-data question — we follow the statute and say so.

Corrections: write to [corrections email] and we will review and update.

Sources

  • The Digital Personal Data Protection Act, 2023 — Sections 3, 6, 7, 9, 10
  • Digital Personal Data Protection Rules, 2025 — gazette notification G.S.R. 846(E), 13 November 2025
  • CERT-In directions on cyber incident reporting, 2022
  • Ayushman Bharat Digital Mission Health Data Management Policy

General information, not legal advice. Retention obligations vary by state and establishment class. Consult qualified counsel before finalising your compliance position.

← Back to all articles