Skip to content

Regulation and compliance

The DPDP Act for hospitals and diagnostic centres: what changes, and when

The Digital Personal Data Protection Act 2023 makes every hospital, laboratory and imaging centre a data fiduciary for its patients’ data. The DPDP Rules 2025, notified on 14 November 2025, phase the obligations in: the Data Protection Board now, consent managers around November 2026, and the substantive duties on notice, security, breach reporting, erasure and rights around May 2027.

By , Co-founder, RaydiacPublished 13 min read

A hospital or imaging centre in India must, under the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, give patients a plain-language notice and obtain consent; keep the data secure with encryption, access control and monitored logs; report any breach to the affected patients and to the Data Protection Board, with a detailed report within 72 hours; erase data when its purpose is served unless another law requires retention; answer patient requests within 90 days; and bind every vendor that touches the data by contract.1 The Rules were notified on 14 November 2025 and the heaviest obligations apply from around May 2027.

The timeline

Rule 1 of the DPDP Rules 2025 phases commencement over eighteen months.2 The dates in the table are calculated from the notification date of 14 November 2025.

DateWhat takes effectRules
14 November 2025Definitions and the Data Protection Board of India (constitution, procedure, appeals)Rules 1, 2 and 17 to 21
About 14 November 2026Registration and obligations of consent managersRule 4
About 14 May 2027Notice, security safeguards, breach intimation, erasure, children’s data, Significant Data Fiduciaries, data principal rights, cross-border transferRules 3, 5 to 16, 22 and 23

Unverified: one vendor guide reports that the Ministry of Electronics and Information Technology has floated advancing the substantive deadline to around November 2026, and describes that as not formally confirmed.9 No notification to that effect has been located. Treat May 2027 as the legal date and November 2026 as the prudent one.

Who is who

The Act uses four roles. The data principal is the person the data is about: the patient, or the parent of a child patient. The data fiduciary decides why and how personal data is processed; a hospital, laboratory or imaging centre is the fiduciary for its patients because it decides the purpose, which is diagnosis and treatment. A data processor processes data on the fiduciary’s behalf: a laboratory information system, a cloud host, a billing vendor, or a teleradiology reporting platform such as Raydiac when it reads a hospital’s studies. A Significant Data Fiduciary is one the Central Government designates on grounds such as volume and sensitivity; it carries extra duties, including a resident Data Protection Officer and annual audits.1

A reporting platform is a processor for the hospital’s diagnostic purpose and a fiduciary for its own purposes, such as radiologist credentialing, quality review and billing. Practitioner commentary on teleradiology assigns duties to the imaging centre, the teleradiology provider and the radiologist rather than to a single party, with primary liability resting with the healthcare institution.13

Rule 3 requires the notice to be a standalone document in plain language, describing the personal data collected, the purpose, the way the patient can withdraw consent, exercise rights and complain to the Board.1 Section 7 of the Act allows processing without consent for certain legitimate uses, including a purpose for which the individual voluntarily provided the data and medical emergencies; routine care still rests on consent.12

For patients under 18, the Act requires verifiable parental consent and bars tracking and targeted advertising. Rule 12 exempts the classes listed in Part A of the Fourth Schedule, which include clinical establishments and health services, from those restrictions where the processing is necessary for the health service.6 A paediatric CT can be reported on parental consent obtained at the hospital; the exemption does not cover using the child’s data for analytics or teaching.

Security safeguards

Rule 6 sets the minimum. A data fiduciary must protect personal data in its possession, and in the possession of its processors, with at least the following.3

SafeguardWhat it means for an imaging centre
Encryption, obfuscation, masking or tokenisationDICOM and reports encrypted at rest and in transit; identity separated from the study where reading does not require it
Access controlRole-based access to PACS, RIS and reporting systems; individual logins, no shared passwords; two-factor authentication for privileged roles
Logs with monitoringAccess and change logs that can show who opened which study, reviewed to detect and investigate unauthorised access
Continuity and disaster recoveryBackups that are tested, and a plan for continued reporting if the primary system is down
Log retention of at least one yearLogs kept for a year without alteration, so an incident can be reconstructed
Processor contractsA written agreement with every vendor that requires the same safeguards

Failure to take reasonable security safeguards attracts the highest penalty in the Act, up to ₹250 crore.1

Breach reporting

Rule 7 requires two notifications. On becoming aware of a personal data breach, the fiduciary must inform each affected data principal without delay, describing the breach, its likely consequences, the measures taken and a contact for queries. It must also inform the Data Protection Board without delay, then file a detailed report within 72 hours, or a longer period the Board allows on request.4 The 72 hours run for the fiduciary, so a hospital needs its processors to report to it fast enough to leave time for its own report.

Erasure and retention

Rule 8 requires personal data to be erased when the purpose is served or consent withdrawn, unless retention is necessary to comply with a law, and requires at least 48 hours’ notice to the data principal before erasure. Processing logs must be kept for at least a year.5 The Third Schedule’s inactivity thresholds apply to e-commerce and social media platforms with two crore or more users and online gaming platforms with fifty lakh or more; they do not apply to hospitals.9

For a hospital, retention is driven by medical-records law rather than by the DPDP clock. The MCI (Professional Conduct, Etiquette and Ethics) Regulations 2002 require indoor records to be kept for three years and produced within 72 hours of a request.11 Rule 8’s carve-out for retention required by law means those records are kept, and the erasure duty attaches to everything else, such as marketing lists and expired staff records.

Rights and grievances

Patients may access, correct and erase their data and nominate someone to exercise those rights. Rules 9 and 14 require the fiduciary to publish the contact details of a person able to answer questions about processing, or of the Data Protection Officer where one is mandatory, and to answer requests within 90 days.1 A formal DPO is mandatory only for Significant Data Fiduciaries; every other fiduciary needs a named contact and a working grievance process.9

Cross-border transfer

Rule 15 permits transfer of personal data outside India unless the Central Government restricts a country or territory by order, and no such order has been notified.7 Hosting in India settles storage; it does not settle tools. A foreign language-model API used to draft or summarise a report is a transfer of health data abroad, and must be disclosed in the notice and covered by a processor contract. Raydiac runs its drafting and proofreading model on its own servers in India and it sees only the radiologist’s text, never the images or the patient identity. The security page sets out where data lives and who can reach it.

Penalties

FailureMaximum penalty
Reasonable security safeguards₹250 crore
Breach notification to the Board or data principals₹200 crore
Obligations regarding children₹200 crore
Any other provision of the Act or Rules₹50 crore

Penalties are imposed by the Data Protection Board after inquiry, with appeals to the Telecom Disputes Settlement and Appellate Tribunal.1

Health data and the SPDI Rules

The DPDP Act does not define health data as a separate “sensitive” category; every category of personal data carries the same obligations. Health data is nonetheless high-risk in practice, because of the harm a breach causes and the penalty exposure that follows.8 The Act covers data about an individual who is identifiable by or in relation to the data; genuinely non-identifiable data falls outside it, while poorly anonymised data does not.12

The SPDI Rules 2011 under section 43A of the IT Act remain in force until section 43A is omitted at the eighteen-month mark, so both regimes apply in the interim.10 The SPDI Rules do treat medical records as sensitive personal data and require a published privacy policy, consent for collection and reasonable security practices. A hospital that meets the DPDP Rules will meet the SPDI Rules; the reverse is not true.

A practical checklist for a hospital

  1. A data map: which systems hold patient data (HIS, RIS, PACS, laboratory, billing, WhatsApp groups), who administers each, and which vendors receive copies.
  2. A privacy notice at registration, in plain language, in the languages patients read, with the purpose, the withdrawal route and the grievance contact.
  3. A data processing agreement with every vendor that touches patient data, including the reporting platform, cloud host, SMS and email providers.
  4. Rule 6 safeguards in place: encryption, individual logins with role-based access, monitored logs, tested backups.
  5. Log retention of at least one year, protected from alteration.
  6. A breach runbook: who decides, who drafts the patient notice, who files the Board report, and templates for both, so the 72 hours are not spent writing.
  7. A named grievance contact published on the website and at reception, and a process that closes requests within 90 days.
  8. A retention schedule aligned to the MCI three-year rule and any longer period the hospital chooses, with purpose-based erasure for everything else.

How a teleradiology processor should behave

A hospital outsourcing CT and MRI reads should expect its reporting platform to reduce, not add to, its DPDP exposure. Four behaviours matter. Pseudonymisation: the reading radiologist sees a pseudonym, age, sex and clinical history rather than the patient’s name, and identity is re-attached server-side only at signing. Raydiac holds identity in a separate encrypted vault and shows the radiologist a pseudonym such as RDX-26-000418. Encryption: TLS on every connection and encryption at rest, with the edge gateway authenticating by a per-site client certificate. Audit: an append-only, hash-chained log of every view, edit and signature, kept for at least a year. Residency: studies and reports on servers in India, with no patient data sent to foreign AI services. The hospital page describes the intake and reporting flow end to end.

What to write into the data processing agreement:

  • Purpose limitation: the platform processes studies only to produce the report the hospital ordered, plus quality review and the audit the hospital can inspect.
  • Security: the Rule 6 safeguards by name, with the right to evidence of them.
  • Sub-processors: a list, and notice before any change.
  • Breach cooperation: notice to the hospital within a fixed number of hours, with the facts needed for the hospital’s 72-hour Board report.
  • Retention and return: how long reports and images are kept, export within 72 hours on request, and deletion or return at contract end.
  • Location: data stays in India unless the hospital agrees otherwise in writing.
  • Secondary use: none of the hospital’s identifiable data for teaching, research or model training without separate consent.

The related guide on HIPAA in India explains why an American compliance label is not a substitute for this contract, and the teleradiology regulations guide covers the medical-practice rules that sit alongside data protection.

Questions people ask

When does the DPDP Act apply to hospitals?
In phases. The DPDP Rules 2025 were notified on 14 November 2025. The rules setting up the Data Protection Board took effect immediately; consent manager rules follow about a year later, around 14 November 2026; and the substantive obligations on notice, security safeguards, breach reporting, erasure, children’s data and data principal rights follow at eighteen months, around 14 May 2027. Raydiac builds to the Rules now rather than waiting for the last date.
Is a hospital a data fiduciary or a data processor?
A hospital is a data fiduciary: it decides why patient data is processed, which is the diagnosis and treatment of its patient. A vendor that processes data on the hospital’s behalf, such as a laboratory information system, a cloud host or a teleradiology reporting platform, is a data processor for that purpose and must be bound by a written contract. Raydiac acts as a processor for each hospital’s diagnostic purpose and signs a data processing agreement with every site.
What are the security safeguards a hospital must have under Rule 6?
Rule 6 lists reasonable security safeguards: encryption, masking or tokenisation of personal data; access control; logs with monitoring to detect and investigate unauthorised access; continuity and disaster recovery; retention of logs for at least one year; and contractual obligations on every data processor. Raydiac encrypts data in transit and at rest, pseudonymises studies for reading, enforces role-based access with mandatory two-factor authentication, and keeps a hash-chained audit trail for at least a year.
How quickly must a hospital report a data breach under the DPDP Rules?
Rule 7 requires a data fiduciary to inform every affected data principal without delay, and to inform the Data Protection Board without delay and then file a detailed report within 72 hours, extendable on request. Failure to notify carries a penalty of up to ₹200 crore. Raydiac’s processor contract commits it to notify the hospital of any incident affecting its studies so that the hospital can meet its own 72-hour obligation.
Does the DPDP Act require patient data to stay in India?
Not yet. Rule 15 permits transfer outside India unless the Central Government restricts a country by order, and no restriction has been notified. Sending health data to a foreign service, including a foreign AI or language-model API, is still a cross-border transfer that must be disclosed and secured. Raydiac keeps studies and reports on its own servers in India and sends no patient data to foreign AI services.
Does a hospital need a Data Protection Officer?
Only if it is designated a Significant Data Fiduciary by the Central Government. Every data fiduciary must publish the contact details of a person able to answer questions about processing and must respond to access, correction and erasure requests within 90 days. Raydiac publishes a grievance contact for its own processing and provides hospitals with the audit and export tools they need to answer patient requests within that window.
Do the SPDI Rules still apply to hospitals?
Yes, until section 43A of the IT Act is omitted at the eighteen-month mark of the DPDP Rules. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 treat medical records as sensitive personal data and require a published privacy policy, consent and reasonable security practices. Raydiac maintains a published privacy notice and documented security controls mapped to Rule 6 of the DPDP Rules, so both regimes are covered in the interim.

Sources

  1. 1.PIB, backgrounder on the DPDP Rules 2025, 17 Nov 2025
  2. 2.DPDP Rules 2025, Rule 1 (commencement), text at dpdpa.com
  3. 3.DPDP Rules 2025, Rule 6 (reasonable security safeguards), text at dpdpa.com
  4. 4.DPDP Rules 2025, Rule 7 (intimation of personal data breach), text at dpdpa.com
  5. 5.DPDP Rules 2025, Rule 8 (erasure and retention), text at dpdpa.com
  6. 6.DPDP Rules 2025, Rule 12 (exemptions for children’s data), text at dpdpa.com
  7. 7.DPDP Rules 2025, Rule 15 (transfer outside India), text at dpdpa.com
  8. 8.AMLegals, “Health data and the DPDP Act: a practical guide”, 20 Nov 2025
  9. 9.Seclore, “DPDP Rules 2025 compliance guide”, 2026 (notes an unconfirmed MeitY proposal to advance the deadline)
  10. 10.S&R Associates, “India’s digital personal data protection regime takes effect”, 2025
  11. 11.CAHO, “Medical records retention and destruction” (quoting MCI Regulations 2002, reg. 1.3.1 and 1.3.2)
  12. 12.PRS Legislative Research, summary of the Digital Personal Data Protection Bill 2023
  13. 13.Manipal Hospitals Radiology Group, “Understanding the DPDP Act: obligations for stakeholders in teleradiology”, 31 Jul 2024

This guide is general information for hospitals, diagnostic centres and radiologists in India. It is not legal, tax or medical advice. Regulations change; check the primary source before acting, and see the medical disclaimer.

Need CT and MRI reporting you can plan around?

Raydiac is a managed teleradiology network for hospitals and diagnostic centres in India. Credentialed radiologists, service-level targets, a published rate card and one monthly invoice.