DPDP Act Compliance Reaches the Hospital Board Room — and India's Two Consent Regimes Don't Match
Hospital leaders put DPDP Act compliance at the centre of governance this week. The catch: ABDM consent artefacts don't satisfy the DPDP Act.
#DPDP Act Compliance Reaches the Hospital Board Room — and India's Two Consent Regimes Don't Match
India's hospital sector spent the last week of July moving DPDP Act compliance from the IT department to the board table, and in doing so walked straight into the most under-discussed problem in Indian data protection: the consent architecture that healthcare has spent five years building under the Ayushman Bharat Digital Mission does not, on its own, satisfy the Digital Personal Data Protection Act, 2023. Hospitals have until 13 May 2027 to reconcile the two, with a hard waypoint on 13 November 2026 — and roughly 82.69 crore linked health records riding on the outcome.
The trigger was the Association of Healthcare Providers (India) Leadership Conclave in Nagpur on 28 July 2026, where AHPI Director General Dr. Girdhar Gyani told CEOs, medical directors and chief administrators from across the Vidarbha region that the DPDP Act will require hospitals to strengthen data privacy, cybersecurity and regulatory compliance as a governance function, not a technical one. Healthcare then led India's DPDP news cycle for three consecutive days, on 30 July and again on 31 July, as the sector's implementation problems drew wider attention.
That framing — governance, not IT — is the correct one, and it is worth explaining why.
#The DPDP Act does not have a "sensitive data" category, and that surprises hospitals
Start with a structural point that catches healthcare compliance teams off guard. Unlike the GDPR, which puts health data into a special Article 9 category with its own lawful bases, the DPDP Act has no separate tier for sensitive personal data. A patient's HIV status and a retailer's mailing list are, as a matter of statutory text, the same thing: digital personal data.
This is not the relief it first appears to be. Because the Act declines to grade data by sensitivity, it grades fiduciaries by risk instead — and it does so through Section 10, which empowers the Central Government to designate any entity a Significant Data Fiduciary based on the volume and sensitivity of the personal data it processes, the risk to data principals, and considerations including public order and the sovereignty and integrity of India. Health data trips nearly every one of those triggers simultaneously.
Practitioners now read the threshold as far lower than hospital boards assume. One analysis of health data under the DPDP regime argues that a mid-size regional network handling on the order of 50,000 patient records a month sits within SDF territory — meaning the designation is not reserved for the Apollos and Fortises of the sector. A three-hospital chain in a tier-2 city is a plausible candidate.
SDF status is not a badge. Under Rule 13 of the DPDP Rules, 2025, a designated entity must conduct a Data Protection Impact Assessment and an independent audit every twelve months, submit significant observations from both to the Data Protection Board, appoint a Data Protection Officer based in India who reports to the board or its equivalent, and exercise algorithmic due diligence over any automated system that processes personal data. For a hospital running AI triage, radiology-reading or sepsis-prediction tooling, that last clause is a live obligation, not a hypothetical.
#ABDM consent artefacts and DPDP consent are not the same instrument
Here is the gap that the Nagpur conclave circled but that deserves stating plainly.
The Ayushman Bharat Digital Mission built India's health data exchange on a consent artefact model. A patient with an ABHA ID grants a Health Information User time-bound access to records held by a Health Information Provider; the grant is logged, it expires, and it can be revoked. As of January 2026 the mission reported more than 84.79 crore ABHA IDs created and 82.69 crore health records linked. By any measure, it works as plumbing.
But the DPDP Act asks a different question. Section 6(1) requires consent that is free, specific, informed, unconditional and unambiguous, given for a specified purpose and limited to the personal data necessary for that purpose. An ABDM artefact answers "who may see this record, and for how long." The DPDP Act asks "for what purpose is this data being processed, and was that purpose disclosed in a Section 5 notice before consent was taken."
Those are not the same question, and an access grant does not answer the second one. A consent artefact permitting a specialist to view a discharge summary says nothing about whether the hospital may subsequently use that summary for outcomes research, service-line analytics, a quality registry, insurer negotiation, or training a diagnostic model. Each of those is a distinct purpose under the DPDP Act, and each needs its own disclosed basis.
The sequencing requirement bites harder than the substance. Section 5 requires the notice to precede consent — not accompany it, and certainly not follow it inside a discharge packet. Indian hospitals overwhelmingly obtain consent through admission paperwork signed at the point of registration, when the patient is ill, hurried, or accompanied by an attendant signing on their behalf. Consent taken under those conditions is difficult to characterise as free and specific, and the DPDP Act offers no clinical exception to the standard.
Withdrawal compounds it. Section 6(4) requires that withdrawing consent be as easy as giving it. A hospital that collects consent on paper at a registration desk has, in effect, promised a paper withdrawal channel at that same desk — staffed, logged, and capable of propagating the withdrawal downstream to every processor holding the data. Few have built it.
#The Fourth Schedule carve-out for children is narrower than hospitals think
The DPDP Rules do give healthcare a genuine exemption, and it is routinely overread.
Section 9(1) requires verifiable parental consent before processing a child's personal data, and Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children. The Fourth Schedule to the DPDP Rules, 2025 disapplies both for defined classes of fiduciaries — clinical establishments as defined under the Clinical Establishments (Registration and Regulation) Act, 2010; mental health establishments; healthcare professionals and allied healthcare professionals as defined under the National Commission for Allied and Healthcare Professions Act, 2021 — to the extent necessary to provide health services to a child.
Read the qualifier. The relief is scoped to the delivery of care, and it does not travel. A paediatric hospital may treat a child without first running a parental-consent verification workflow. That same hospital may not use the resulting records for research recruitment, marketing a vaccination programme, or a healthtech partner's product analytics on the strength of the Fourth Schedule. The moment processing steps outside the therapeutic purpose, Section 9 reattaches in full — and the Schedule to the Act prices a children's-data violation at up to ₹200 crore.
For paediatric and maternal-health providers, this makes purpose tagging at the record level a compliance necessity rather than a data-governance nicety. The system has to know which processing operations sit inside the carve-out and which fall outside it.
#Retention and erasure pull in opposite directions
Clinical record-keeping obligations under state clinical establishment rules, the National Medical Commission's professional conduct regulations, and insurance and litigation timelines all require hospitals to keep records for defined periods. Section 12 of the DPDP Act gives the patient a right to seek erasure, and Section 8(7) requires a fiduciary to erase personal data once the purpose is served and retention is no longer necessary for a legal obligation.
The tension is real but resolvable, and the resolution is procedural. A hospital receiving an erasure request should acknowledge it, identify the statutory or contractual retention obligation that overrides it, state the date on which that obligation lapses and deletion will occur, and log the whole exchange. What fails is silence — treating an erasure request as inapplicable because medical records are retained by law, and never responding.
Worth noting: the three-year automatic-erasure regime in Rule 8 read with the Third Schedule applies to specified classes — large e-commerce platforms, online gaming intermediaries and social media intermediaries above user thresholds. Hospitals are not in that Schedule. Their retention discipline comes from Section 8(7)'s general purpose-limitation duty, which is less mechanical but not less binding.
#Two breach clocks, and the shorter one is not in the DPDP Act
A hospital suffering a ransomware incident is running two timers at once.
Under Rule 7 of the DPDP Rules, the fiduciary must inform affected data principals without delay, notify the Data Protection Board on becoming aware of the breach, and file a detailed report within 72 hours covering the facts, mitigation steps, findings on the cause, remedial measures and confirmation of the intimations sent to patients. Separately, the CERT-In Directions of 2022 require reporting of cyber incidents within six hours of detection. The six-hour clock is the operative constraint, and it starts before anyone has a clear picture of what happened.
The stakes are not abstract. Indian hospitals and diagnostic chains face more than 1,800 cyberattacks a week, with an average healthcare breach costing around ₹20 crore — before any regulatory penalty. The 2024 Star Health breach exposed medical diagnoses, test results and treatment histories belonging to roughly 31 million people. Under the DPDP Act's Schedule, a failure of reasonable security safeguards under Section 8(5) is the most expensive violation in the statute at up to ₹250 crore, with failure to notify a breach carrying up to ₹200 crore. A single incident can attract both.
#The sector knows it is behind
The readiness data is unflattering. Survey work on Indian hospitals finds roughly 36% describing themselves as very confident about DPDP compliance, close to half reporting only moderate confidence, and 15.9% not confident at all — with the gaps concentrated in consent management and incident response. EY's broader Indian assessment found around 77% of organisations not equipped to adopt privacy technologies such as consent management, data discovery or rights-fulfilment tooling, and named healthcare among the sectors most hampered by fragmented data environments and legacy systems.
Meanwhile the enforcement machinery is warming up. The Data Protection Board's budget rose fivefold in the Union Budget 2026, from ₹2 crore to ₹10 crore, which is a small absolute number and a loud directional signal. The Board's chairperson and members were appointed in June 2026. Consent Manager registration under Rule 4 opens on 13 November 2026, requiring a ₹2 crore net worth and registration with the Board before an entity may operate. Full substantive compliance — consent, notice, rights, safeguards and penalties — lands on 13 May 2027.
#What hospital boards should be doing in the next fifteen months
Concretely, and in rough order of leverage:
Map the purposes, not just the data. A data inventory that lists systems and record types is insufficient. The DPDP Act is purpose-driven, so the inventory has to enumerate every processing purpose — treatment, billing, insurance adjudication via NHCX, research, quality registries, marketing, model training — and identify the lawful basis and notice for each.
Separate treatment consent from data-processing consent. The clinical consent a surgeon takes for a procedure and the DPDP consent a hospital takes for processing personal data are different instruments serving different statutes. Collapsing them into one admission form is the single most common defect, and it invalidates both.
Fix the notice sequence. Notice before consent, in the patient's chosen language from the Eighth Schedule, in plain terms, itemised by purpose. Registration-desk workflows and patient-portal onboarding both need rebuilding around this order.
Build the withdrawal path before the deadline. Section 6(4) parity means a withdrawal channel at least as accessible as the collection channel, with propagation to every processor — cloud vendors, billing systems, diagnostic labs, TPAs and insurers — under Section 8(2), which makes the hospital answerable for its processors' conduct.
Decide the SDF question early. Do not wait for a government notification to start behaving like a Significant Data Fiduciary if the volume and sensitivity profile suggests designation is likely. A DPIA and an independent audit are twelve-month cycles; starting them in 2027 is starting them late.
Reconcile ABDM and DPDP deliberately. ABDM's consent artefact remains the right mechanism for record access and should be retained. What it needs is a purpose layer on top — an auditable record of what each processing operation is for, tied to a notice the patient actually received. Organisations working through that architecture may find our consent manager guidance useful for the interoperability questions Rule 4 raises, and the broader resources library for DPIA and breach-response templates.
#What it means for patients
For a patient, the practical change is that the ABHA-linked record becomes something you can reason about rather than merely access. Today you can see which provider looked at your discharge summary. From May 2027 you are entitled to know why your data is being processed, to refuse a purpose without being denied care that does not depend on it, to withdraw a consent you gave at a registration desk, and to be told — without delay — when your records are exposed.
Whether that entitlement is worth anything depends on execution, and healthcare's execution problem is genuine: fragmented systems, paper workflows, thin privacy staffing and a consent culture built around clinical rather than informational autonomy. Fifteen months is enough time to fix it. It is not enough time to start in month twelve.
The Nagpur conclave's contribution was to put the problem in front of the people who control hospital budgets. That is a necessary first step, and on the current readiness numbers, an overdue one.
Running a hospital, diagnostic chain, healthtech platform or insurer processing Indian health data? Map your processing purposes against the DPDP Act now — start with our DPDP resources library, and review how consent manager interoperability will affect your ABDM integration before Rule 4 registration opens on 13 November 2026.