How should hospitals handle patient data under the DPDP Act? Healthcare Series Part 1
A plain guide for hospitals, clinics, labs and health apps: the three reasons you can use patient data, one form with many switches, emergencies, children, and what to do when a patient says no.
By Promiz · Published · 8 min read · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice
Summary
- A hospital uses one patient’s data for many things: treatment, bills, reminders, research and offers. The DPDP Act treats each one as a separate purpose.
- Treatment continues when a patient says no to research or marketing. The law expects you to keep these apart.
- In a real medical emergency, you can use a patient’s data without asking first. This ends when the emergency ends.
- For children, you need a verified parent’s or guardian’s consent, except for care itself.
- If you cannot prove what a patient agreed to, the problem is yours, not the patient’s.
Picture a hospital front desk at 9 a.m. A patient fills in one registration form, signs once, and walks in to see the doctor. That one signature is later used for the treatment, the bill, the insurance claim, reminder messages, a research study and a health-package offer.
The Digital Personal Data Protection (DPDP) Act, 2023 does not stop hospitals from treating people. It asks them to be clear about why they use each piece of data, and to be able to prove it. Its duties apply in full from 13 May 2027. This guide explains what that means in plain words, with examples from everyday hospital work.
Four words you will see
| Term | Meaning |
|---|---|
| Data Principal | The patient. For a child, a parent or guardian acts for them. |
| Data Fiduciary | The hospital, clinic, lab or app that decides how data is used. |
| Purpose | The reason you use the data: treatment, billing, research, offers. |
| Withdrawal | When a patient takes back a consent they gave earlier. |
How to read legal references. The DPDP Act is split into numbered Sections. A number in brackets after a section is a part of it: a sub-section if it is a number, such as Section 9, sub-section (1), or a clause if it is a letter, such as Section 7, clause (f), the sixth item in Section 7’s list. The DPDP Rules, 2025 are a separate document, split into numbered Rules, such as Rule 10.
Where patient data comes from
Most hospitals collect personal data at five or more points in a single visit. Each point often uses its own system.
Figure: One visit, five data points
- Appointment: Name, phone, symptoms
- Front desk: ID, address, insurance
- Doctor and lab: Notes, reports, scans
- Billing: Claims, payments
- After the visit: Reminders, app, offers
A single visit creates personal data in several systems, each with its own purpose.
Three reasons a hospital can use patient data
Under the DPDP Act, you need a lawful reason for each use. In a hospital, almost every use falls into one of three groups.
Figure: Three lawful reasons
| The patient agreed (Consent) | A law requires it (Legal obligation) | A listed exception (Legitimate use, Section 7) |
|---|---|---|
| Appointment reminders | Keeping medical records | A medical emergency |
| Research studies | Reports the law asks you to file | Treatment during an epidemic |
| Health offers and newsletters | Billing and tax records | Help during a disaster |
Label every purpose with one of these reasons before you collect the data.
1. The patient agreed. Consent must be for a specific purpose and given by a clear action, such as ticking a box or entering an OTP. The patient can take it back at any time, and taking it back must be as easy as giving it.
2. A law requires it. Some records must be kept because another law or regulation says so. Medical record-keeping rules are the common example. A patient’s withdrawal does not cancel a legal duty.
3. A listed exception. Section 7 of the Act lists situations where you can use data without consent. For hospitals, the important one is Section 7, clause (f): responding to a medical emergency that threatens the life or health of the patient or anyone else. Section 7, clause (g) covers treatment during an epidemic or other threat to public health.
Example: An unconscious accident victim arrives in the emergency room. The team can check their medical history and allergies without consent. Once the patient is stable, ongoing care and every other purpose need their normal reason again. The emergency exception never covers research, analytics or marketing.
One form, many switches
The simplest change a hospital can make is to its registration form. Instead of one signature for everything, give each optional purpose its own switch, and mark what is required.
Figure: A registration form that works
How we will use your information Choose for each purpose. You can change this later.
| Purpose | Note | State |
|---|---|---|
| Treatment and medical record | Needed to treat you | Required |
| Billing and insurance claim | Needed to process your bill | Required |
| Appointment reminders by SMS | Optional | Off |
| Use my reports for research | Optional | Off |
| Health packages and offers | Optional | Off |
Form footer: Available in English and Indian languages · Questions? Ask for our privacy officer.
Required purposes are marked. Optional ones start switched off. The patient decides each one.
Three rules make this form work:
- Nothing optional is pre-ticked. The patient must switch it on.
- One switch per purpose. Saying yes to reminders does not mean yes to research.
- The notice is in a language the patient reads. The Act allows English or any of the 22 languages in the Eighth Schedule to the Constitution.
A story: when one signature is not enough
Illustrative example
Asha, 34, has knee surgery at a made-up hospital we will call City Care. At the front desk she signs one form. Six months later she receives a wellness newsletter, a call from a partner insurer about a health plan, and an invitation to a study that uses her scans. She complains.
When City Care looks into it, it finds four problems:
- One signature covered treatment, marketing, partner sharing and research.
- Nobody can show which version of the form or notice Asha saw.
- Her number was shared with a partner for marketing she never chose.
- When she asked to stop, the email list stopped, but the SMS tool and the partner did not.
Under Section 6, sub-section (10), when consent is questioned, the hospital must prove the notice and the consent. City Care cannot.
What should have happened: a form with separate switches, a stored copy of the exact notice Asha saw, no partner sharing without its own consent, and one “stop” that reaches every tool and partner, with a record of who confirmed it.
Children’s data, in plain words
For a patient under 18, the Act requires verifiable consent from a parent or guardian (Section 9, sub-section (1)). The same applies to a person with a disability who has a lawful guardian. The hospital must check that the guardian is an identifiable adult; the DPDP Rules allow this through a virtual token from a Digital Locker service. The Act also bans tracking, behavioural monitoring and targeted advertising directed at children (Section 9, sub-section (3)).
There is a narrow exemption for care. The DPDP Rules (Rule 12 and the Fourth Schedule) exempt a clinical establishment, mental health establishment or healthcare professional when the processing is limited to providing health services to the child, as far as needed to protect the child’s health.
The exemption covers care, not everything around it. A child’s app account, a parenting newsletter or a research study still needs a verified guardian’s consent. Targeted ads to children stay banned.
When a patient says no
In most industries, the risk is that a “stop” is ignored. In a hospital, there is a second risk: a crude “withdraw all” button that cuts off data a doctor needs. Withdrawal must work one purpose at a time.
Figure: Asha withdraws from research
| Stops | Action | Continues |
|---|---|---|
| Use of her scans in the study | One click in the portal or the notice | Her medical record |
| Sharing with the research partner | Follow-up care | |
| Research emails | Billing and insurance claim |
A withdrawal stops one purpose and leaves care untouched.
A patient can also ask the hospital to erase their data. The hospital must erase what it no longer needs, but it can keep what a law requires it to keep. “Stop using it” and “delete it” are two different duties; keep them in two different queues.
Everyday situations
Lab reports on WhatsApp Sending the report is the service the patient asked for. Sending health-package offers to the same number is a separate purpose that needs its own consent and an easy way to stop.
Pharmacy app Processing a prescription is the service. Using a patient’s medicines to suggest products is a separate purpose. For users under 18, no targeted ads at all.
Free health camp Give a short notice at the camp, on paper or through a link. Use the phone numbers only for the follow-up you described, not for later marketing.
Telemedicine consultation The consultation is care. Using chat history to train a symptom checker, or to show ads, needs its own consent.
Cashless insurance claim Sharing details with the insurer or TPA to process the claim is part of the service. Say so in the notice. Do not reuse the data to sell other policies.
Child vaccination The vaccination record is care and falls within the exemption. A parenting newsletter from the same clinic needs a verified guardian’s consent.
These show common patterns, not legal advice. Your legal team decides the purpose and reason for each case.
A four-step plan
- List every entry point. Website, app, front desk, emergency, lab, pharmacy, call centre, health camps.
- Label every purpose. Give each one a reason (consent, legal obligation or a named Section 7 exception) and a retention period.
- Split the switches. Required purposes are marked. Optional ones get their own switch, off by default, in the patient’s language.
- Prove and act. Keep a copy of each notice version and each choice. Make sure a “stop” reaches every system and partner, and record who confirmed it.
Questions hospitals ask
Does a hospital need consent to treat a patient in an emergency?
No. Section 7, clause (f) of the DPDP Act allows a hospital to use personal data without consent to respond to a medical emergency that threatens a person’s life or health. When the emergency ends, the normal rules apply again.
Can a patient ask a hospital to delete their medical records?
A patient can ask for erasure. The hospital must erase data it no longer needs for the purpose, but it can keep what a law requires it to keep, such as medical records under record-keeping rules.
Do parents need to give consent for a child’s treatment data?
The Act requires verifiable consent from a parent or guardian for a child’s data. The DPDP Rules exempt clinical establishments and healthcare professionals when the processing is limited to providing health services to the child. Anything beyond care, such as app accounts or research, still needs the guardian’s consent.
The bottom line
The DPDP Act does not ask hospitals to choose between privacy and care. It asks them to stop bundling. Give each purpose its own reason, its own switch and its own clock, and keep the proof. Care continues, and the patient stays in control of everything else.
How Promiz helps
In Promiz, you set up each purpose in a notice with its own legal basis, data categories and retention period, and mark care purposes as essential. Optional purposes start unticked. Notices are served in English and 22 Indian languages, and front-desk staff can send a single-use email link to patients who are not online. Every consent is stored with the exact notice version, language and a snapshot of the screen.
Guardians are verified as adults through DigiLocker, and child-restriction flags block tracking and targeted ads. Withdrawals and erasures run in separate queues, one purpose at a time, and a signed webhook tells each connected system to stop. Purposes marked as legal obligation never trigger erasure.
References: DPDP Act, 2023 (MeitY) · DPDP Rules, 2025, Rules 10 and 12 and the Fourth Schedule. Promiz supports your DPDP compliance programme. It is not legal advice.