The DPDP Act 2023 turns every Indian clinic that handles patient data into a Data Fiduciary with real legal duties, and with the DPDP Rules notified in November 2025, the compliance clock is now running. This is written for clinic owners and doctors, not lawyers. It covers what the law asks of you, what a slip can cost, and the questions to put to any software you buy. Not legal advice. Confirm the specifics with counsel. What it gives you is the shortlist of things worth confirming.
Key takeaways
- The DPDP Act applies to clinics of any size; you are a “Data Fiduciary” the moment you decide how patient data is used.
- The DPDP Rules were notified on 14 November 2025, with most obligations phasing in over roughly 18 months. The window is open now.
- Penalties reach up to ₹250 crore for security-safeguard failures that lead to a breach.
- Every software purchase is now a fiduciary decision; the right vendor questions are short and specific.
DPDP Act 2023 enacted
DPDP Rules, 2025 notified; the compliance clock starts here
Approximate phase-in window for most substantive obligations from notification
Source: PIB / MeitY, DPDP Rules 2025 backgrounder, November 2025.
Does the DPDP Act actually apply to my clinic?
Yes. Practice size has nothing to do with it. The Digital Personal Data Protection Act, enacted on 11 August 2023, applies to any “Data Fiduciary”: the person or organization that determines the purpose and means of processing personal data. A two-doctor clinic keeping digital patient records is deciding why and how that data gets handled, and that makes it a Data Fiduciary with obligations. There’s no lighter tier for health data. If anything the sensitivity of it raises the stakes.
What flips the switch is digitization. Paper-only records sit outside the Act’s core machinery. But the moment patient data goes digital, DPDP duties attach, and “digital” is a broad word here: an EMR, a billing system, a WhatsApp number, an AI scribe.
When do I actually have to comply?
Now. The DPDP Rules, 2025 were notified on 14 November 2025, and most substantive obligations phase in over roughly an 18-month window from notification. Enforcement isn’t retrospective to 2023, so nobody’s coming after old records. But the runway is finite and it has already started ticking. Clinics that use 2026 to get consent, security, and vendor contracts in order are the ones who won’t be scrambling when the obligations actually bite.
Don’t wait for a notice from the Data Protection Board. Compliance is cheapest when you build it before anyone asks for it.
What does DPDP actually require a clinic to do?
Six duties, in plain terms:
- Take consent properly. Collect patient data on the basis of consent that is free, specific, informed, and unambiguous, with a clear notice of what you’re collecting and why. A handful of medical situations carry carve-outs. Consent is the default footing otherwise.
- Stick to the purpose you stated. Patient data gathered for treatment isn’t a marketing list.
- Keep reasonable security safeguards: encryption, access control, logging, the appropriate technical and organizational measures. This is the duty with the largest penalty attached, which tells you how seriously the law takes it.
- Report breaches. If a personal-data breach occurs, notify the Data Protection Board and affected individuals, in plain language, without delay.
- Honor data-principal rights. Patients can ask what you hold, request correction, and request erasure, and you answer within the timelines the Rules set (within 90 days for certain requests).
- Do your vendor diligence. Hand data to a processor, whether an EMR host, a scribe, or a billing service, and you stay responsible. Their handling is your liability.
What are the penalties?
They are large and tiered. The DPDP Act’s schedule sets statutory ceilings applied by the Data Protection Board:
| Failure | Penalty up to |
|---|---|
| Failure to maintain reasonable security safeguards leading to a breach | ₹250 crore |
| Failure to notify a breach; breach of children’s-data obligations | ₹200 crore |
| Other violations | ₹50 crore |
These are ceilings, not automatic fines, and the Board applies them case by case. No clinic should read this as “you will be fined ₹250 crore.” Read it instead as a signal of priorities. The biggest number sits on the security-safeguards duty, which is the law’s way of telling you that protecting the data is the obligation it cares about most.
How does DPDP sit alongside medical record-keeping rules?
They stack rather than collide. DPDP governs how you handle data; the medical-council ethics rules govern what records you keep and for how long. There’s a retention nuance a lot of guides get wrong, so here it is. The NMC’s 2023 conduct regulations, which proposed three-year retention for all patients and records supplied within five working days, were held in abeyance shortly after notification. So they don’t bind you. The rules actually in force are the older MCI 2002 ethics regulations: keep inpatient records three years from the start of treatment, produce records within 72 hours of a request, and treat a failure as professional misconduct.
Put together, MCI 2002 sets your retention floor and your production duty, and DPDP layers purpose-limitation, security, consent, and the duty to delete once the purpose ends on top. A complete, retrievable record serves both at once. It’s also why thin or missing notes are a liability under either regime. (The retention rules deserve their own read with counsel; this is the short version.)
Inpatient record retention from commencement of treatment, MCI 2002
Window to produce records on request, MCI 2002
Window to answer certain data-principal requests under the DPDP Rules
Sources: NMC / MCI Code of Medical Ethics 2002; PIB / MeitY DPDP Rules 2025 backgrounder.
What should I ask an AI scribe or health-tech vendor?
Every software purchase is now a fiduciary decision, because the vendor’s handling becomes your exposure. Four questions settle most of it.
- “What patient data do you collect, and where is it stored?” Without the data map you can’t honor purpose-limitation or answer a patient request.
- “How long do you retain it, and can I delete any record on demand?” Deletion once the purpose is done is a DPDP duty, so the vendor has to support it.
- “Is visit audio stored, and if so for how long?” Stored audio is about the most sensitive thing a clinic can hold. A vendor that processes audio in memory and never stores it takes a whole category of risk off your books.
- “Is my patients’ data used for anything beyond my care, like model training, analytics, or resale?” This is where purpose-limitation lives or dies.
AI Medical Scribe by Patient Square is an ambient AI medical scribe that listens during the visit and hands back a structured SOAP note, ICD-10 suggestions, and a prescription draft, ready to review and sign about two minutes after the visit. It’s built so those four answers come out short. Visit audio is processed in memory and discarded the moment the note is drafted, so there is no audio archive. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), access is role-scoped and logged, and you can export or delete any visit at any time. We call this handling data to DPDP Act 2023 standards, consent-first and purpose-limited, and we don’t call it a certification, because a DPDP certification for vendors doesn’t exist. The full posture, in the same plain terms, is on our security page.
Pick vendors with this discipline and you’ve done most of your DPDP work at procurement, before a single patient walks in. If you’re still weighing tools, the India scribe comparison covers how the main options handle data. Or test our answers yourself: book a short demo and ask the four questions above, or run the 7-day trial and watch where the audio goes. (Nowhere. That’s the design.)