Regulation and compliance
The DPDP Act for hospitals and diagnostic centres: what changes, and when
The Digital Personal Data Protection Act 2023 makes every hospital, laboratory and imaging centre a data fiduciary for its patients’ data. The DPDP Rules 2025, notified on 14 November 2025, phase the obligations in: the Data Protection Board now, consent managers around November 2026, and the substantive duties on notice, security, breach reporting, erasure and rights around May 2027.
A hospital or imaging centre in India must, under the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, give patients a plain-language notice and obtain consent; keep the data secure with encryption, access control and monitored logs; report any breach to the affected patients and to the Data Protection Board, with a detailed report within 72 hours; erase data when its purpose is served unless another law requires retention; answer patient requests within 90 days; and bind every vendor that touches the data by contract.1 The Rules were notified on 14 November 2025 and the heaviest obligations apply from around May 2027.
The timeline
Rule 1 of the DPDP Rules 2025 phases commencement over eighteen months.2 The dates in the table are calculated from the notification date of 14 November 2025.
| Date | What takes effect | Rules |
|---|---|---|
| 14 November 2025 | Definitions and the Data Protection Board of India (constitution, procedure, appeals) | Rules 1, 2 and 17 to 21 |
| About 14 November 2026 | Registration and obligations of consent managers | Rule 4 |
| About 14 May 2027 | Notice, security safeguards, breach intimation, erasure, children’s data, Significant Data Fiduciaries, data principal rights, cross-border transfer | Rules 3, 5 to 16, 22 and 23 |
Unverified: one vendor guide reports that the Ministry of Electronics and Information Technology has floated advancing the substantive deadline to around November 2026, and describes that as not formally confirmed.9 No notification to that effect has been located. Treat May 2027 as the legal date and November 2026 as the prudent one.
Who is who
The Act uses four roles. The data principal is the person the data is about: the patient, or the parent of a child patient. The data fiduciary decides why and how personal data is processed; a hospital, laboratory or imaging centre is the fiduciary for its patients because it decides the purpose, which is diagnosis and treatment. A data processor processes data on the fiduciary’s behalf: a laboratory information system, a cloud host, a billing vendor, or a teleradiology reporting platform such as Raydiac when it reads a hospital’s studies. A Significant Data Fiduciary is one the Central Government designates on grounds such as volume and sensitivity; it carries extra duties, including a resident Data Protection Officer and annual audits.1
A reporting platform is a processor for the hospital’s diagnostic purpose and a fiduciary for its own purposes, such as radiologist credentialing, quality review and billing. Practitioner commentary on teleradiology assigns duties to the imaging centre, the teleradiology provider and the radiologist rather than to a single party, with primary liability resting with the healthcare institution.13
Consent and notice
Rule 3 requires the notice to be a standalone document in plain language, describing the personal data collected, the purpose, the way the patient can withdraw consent, exercise rights and complain to the Board.1 Section 7 of the Act allows processing without consent for certain legitimate uses, including a purpose for which the individual voluntarily provided the data and medical emergencies; routine care still rests on consent.12
For patients under 18, the Act requires verifiable parental consent and bars tracking and targeted advertising. Rule 12 exempts the classes listed in Part A of the Fourth Schedule, which include clinical establishments and health services, from those restrictions where the processing is necessary for the health service.6 A paediatric CT can be reported on parental consent obtained at the hospital; the exemption does not cover using the child’s data for analytics or teaching.
Security safeguards
Rule 6 sets the minimum. A data fiduciary must protect personal data in its possession, and in the possession of its processors, with at least the following.3
| Safeguard | What it means for an imaging centre |
|---|---|
| Encryption, obfuscation, masking or tokenisation | DICOM and reports encrypted at rest and in transit; identity separated from the study where reading does not require it |
| Access control | Role-based access to PACS, RIS and reporting systems; individual logins, no shared passwords; two-factor authentication for privileged roles |
| Logs with monitoring | Access and change logs that can show who opened which study, reviewed to detect and investigate unauthorised access |
| Continuity and disaster recovery | Backups that are tested, and a plan for continued reporting if the primary system is down |
| Log retention of at least one year | Logs kept for a year without alteration, so an incident can be reconstructed |
| Processor contracts | A written agreement with every vendor that requires the same safeguards |
Failure to take reasonable security safeguards attracts the highest penalty in the Act, up to ₹250 crore.1
Breach reporting
Rule 7 requires two notifications. On becoming aware of a personal data breach, the fiduciary must inform each affected data principal without delay, describing the breach, its likely consequences, the measures taken and a contact for queries. It must also inform the Data Protection Board without delay, then file a detailed report within 72 hours, or a longer period the Board allows on request.4 The 72 hours run for the fiduciary, so a hospital needs its processors to report to it fast enough to leave time for its own report.
Erasure and retention
Rule 8 requires personal data to be erased when the purpose is served or consent withdrawn, unless retention is necessary to comply with a law, and requires at least 48 hours’ notice to the data principal before erasure. Processing logs must be kept for at least a year.5 The Third Schedule’s inactivity thresholds apply to e-commerce and social media platforms with two crore or more users and online gaming platforms with fifty lakh or more; they do not apply to hospitals.9
For a hospital, retention is driven by medical-records law rather than by the DPDP clock. The MCI (Professional Conduct, Etiquette and Ethics) Regulations 2002 require indoor records to be kept for three years and produced within 72 hours of a request.11 Rule 8’s carve-out for retention required by law means those records are kept, and the erasure duty attaches to everything else, such as marketing lists and expired staff records.
Rights and grievances
Patients may access, correct and erase their data and nominate someone to exercise those rights. Rules 9 and 14 require the fiduciary to publish the contact details of a person able to answer questions about processing, or of the Data Protection Officer where one is mandatory, and to answer requests within 90 days.1 A formal DPO is mandatory only for Significant Data Fiduciaries; every other fiduciary needs a named contact and a working grievance process.9
Cross-border transfer
Rule 15 permits transfer of personal data outside India unless the Central Government restricts a country or territory by order, and no such order has been notified.7 Hosting in India settles storage; it does not settle tools. A foreign language-model API used to draft or summarise a report is a transfer of health data abroad, and must be disclosed in the notice and covered by a processor contract. Raydiac runs its drafting and proofreading model on its own servers in India and it sees only the radiologist’s text, never the images or the patient identity. The security page sets out where data lives and who can reach it.
Penalties
| Failure | Maximum penalty |
|---|---|
| Reasonable security safeguards | ₹250 crore |
| Breach notification to the Board or data principals | ₹200 crore |
| Obligations regarding children | ₹200 crore |
| Any other provision of the Act or Rules | ₹50 crore |
Penalties are imposed by the Data Protection Board after inquiry, with appeals to the Telecom Disputes Settlement and Appellate Tribunal.1
Health data and the SPDI Rules
The DPDP Act does not define health data as a separate “sensitive” category; every category of personal data carries the same obligations. Health data is nonetheless high-risk in practice, because of the harm a breach causes and the penalty exposure that follows.8 The Act covers data about an individual who is identifiable by or in relation to the data; genuinely non-identifiable data falls outside it, while poorly anonymised data does not.12
The SPDI Rules 2011 under section 43A of the IT Act remain in force until section 43A is omitted at the eighteen-month mark, so both regimes apply in the interim.10 The SPDI Rules do treat medical records as sensitive personal data and require a published privacy policy, consent for collection and reasonable security practices. A hospital that meets the DPDP Rules will meet the SPDI Rules; the reverse is not true.
A practical checklist for a hospital
- A data map: which systems hold patient data (HIS, RIS, PACS, laboratory, billing, WhatsApp groups), who administers each, and which vendors receive copies.
- A privacy notice at registration, in plain language, in the languages patients read, with the purpose, the withdrawal route and the grievance contact.
- A data processing agreement with every vendor that touches patient data, including the reporting platform, cloud host, SMS and email providers.
- Rule 6 safeguards in place: encryption, individual logins with role-based access, monitored logs, tested backups.
- Log retention of at least one year, protected from alteration.
- A breach runbook: who decides, who drafts the patient notice, who files the Board report, and templates for both, so the 72 hours are not spent writing.
- A named grievance contact published on the website and at reception, and a process that closes requests within 90 days.
- A retention schedule aligned to the MCI three-year rule and any longer period the hospital chooses, with purpose-based erasure for everything else.
How a teleradiology processor should behave
A hospital outsourcing CT and MRI reads should expect its reporting platform to reduce, not add to, its DPDP exposure. Four behaviours matter. Pseudonymisation: the reading radiologist sees a pseudonym, age, sex and clinical history rather than the patient’s name, and identity is re-attached server-side only at signing. Raydiac holds identity in a separate encrypted vault and shows the radiologist a pseudonym such as RDX-26-000418. Encryption: TLS on every connection and encryption at rest, with the edge gateway authenticating by a per-site client certificate. Audit: an append-only, hash-chained log of every view, edit and signature, kept for at least a year. Residency: studies and reports on servers in India, with no patient data sent to foreign AI services. The hospital page describes the intake and reporting flow end to end.
What to write into the data processing agreement:
- Purpose limitation: the platform processes studies only to produce the report the hospital ordered, plus quality review and the audit the hospital can inspect.
- Security: the Rule 6 safeguards by name, with the right to evidence of them.
- Sub-processors: a list, and notice before any change.
- Breach cooperation: notice to the hospital within a fixed number of hours, with the facts needed for the hospital’s 72-hour Board report.
- Retention and return: how long reports and images are kept, export within 72 hours on request, and deletion or return at contract end.
- Location: data stays in India unless the hospital agrees otherwise in writing.
- Secondary use: none of the hospital’s identifiable data for teaching, research or model training without separate consent.
The related guide on HIPAA in India explains why an American compliance label is not a substitute for this contract, and the teleradiology regulations guide covers the medical-practice rules that sit alongside data protection.
Questions people ask
When does the DPDP Act apply to hospitals?
Is a hospital a data fiduciary or a data processor?
What are the security safeguards a hospital must have under Rule 6?
How quickly must a hospital report a data breach under the DPDP Rules?
Does the DPDP Act require patient data to stay in India?
Does a hospital need a Data Protection Officer?
Do the SPDI Rules still apply to hospitals?
Sources
- 1.PIB, backgrounder on the DPDP Rules 2025, 17 Nov 2025
- 2.DPDP Rules 2025, Rule 1 (commencement), text at dpdpa.com
- 3.DPDP Rules 2025, Rule 6 (reasonable security safeguards), text at dpdpa.com
- 4.DPDP Rules 2025, Rule 7 (intimation of personal data breach), text at dpdpa.com
- 5.DPDP Rules 2025, Rule 8 (erasure and retention), text at dpdpa.com
- 6.DPDP Rules 2025, Rule 12 (exemptions for children’s data), text at dpdpa.com
- 7.DPDP Rules 2025, Rule 15 (transfer outside India), text at dpdpa.com
- 8.AMLegals, “Health data and the DPDP Act: a practical guide”, 20 Nov 2025
- 9.Seclore, “DPDP Rules 2025 compliance guide”, 2026 (notes an unconfirmed MeitY proposal to advance the deadline)
- 10.S&R Associates, “India’s digital personal data protection regime takes effect”, 2025
- 11.CAHO, “Medical records retention and destruction” (quoting MCI Regulations 2002, reg. 1.3.1 and 1.3.2)
- 12.PRS Legislative Research, summary of the Digital Personal Data Protection Bill 2023
- 13.Manipal Hospitals Radiology Group, “Understanding the DPDP Act: obligations for stakeholders in teleradiology”, 31 Jul 2024
This guide is general information for hospitals, diagnostic centres and radiologists in India. It is not legal, tax or medical advice. Regulations change; check the primary source before acting, and see the medical disclaimer.