Skip to main content
Compliance

The DPDP Act for Healthcare: What the 2025 Rules Mean for Patient Data in Marketing

Indian hospitals are reading DPDP as a records problem. It lands first on the CRM, the WhatsApp list and the lead form. The commencement dates, the consent standard, and what to fix before May 2027.

NS
Founder & CEO · October 19, 2026 · 8 min read
FILE · DPDP-ACT
The DPDP Act for Healthcare: What the 2025 Rules Mean for Patient Data in Marketing

Every Indian hospital that has taken the DPDP Act seriously has started in the same place: the medical records department. IT reviews the EMR, legal looks at the consent form, someone asks about server location, and the project is declared under way.

Meanwhile the marketing stack is sitting one floor up with an eleven-thousand-row spreadsheet of enquiry numbers, a WhatsApp broadcast list nobody remembers building, a lead form with a pre-ticked consent box, and a tag manager firing procedure names into two ad platforms.

That is where this law lands first, and it is where almost nobody is looking.

The dates, so you can plan against them

The Digital Personal Data Protection Act, 2023 received assent in August 2023 but could not operate without rules. Those arrived as the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology as G.S.R. 846(E) on 13 November 2025.

Commencement is staggered, and the staggering is the single most useful thing to know:

From notification on 13 November 2025: the preliminary rules and the provisions covering the Data Protection Board of India's appointments and procedure.

From 13 November 2026: Rule 4, covering registration and obligations of Consent Managers.

From 13 May 2027: everything that governs day-to-day practice — the notice requirements, the security safeguards, breach notification, data principal rights, children's data, Significant Data Fiduciary duties, cross-border transfer and retention.

Read Rule 1 of the notification yourself rather than trusting any summary, including this one. It is two paragraphs and it decides your project plan.

The Board itself was constituted alongside the Rules, though appointments to it have lagged. Treat that as a reason to build well rather than a reason to wait — an eighteen-month runway on the substantive rules is not long for an organisation that has to rewrite every consent flow it owns.

Four roles, and you are probably three of them

The Act names a Data Principal (the patient), a Data Fiduciary (the hospital or clinic, which decides why and how data is processed), a Data Processor (a vendor processing on the fiduciary's instructions — your CRM, your agency, your call centre, your chatbot provider), and a Consent Manager (a registered intermediary through which a person can give and withdraw consent).

A hospital is the fiduciary. It stays the fiduciary when it hands data to an agency. Liability does not transfer with the file.

The part that actually changes marketing

Indian privacy discussion imports a lot of GDPR vocabulary, and one import is actively misleading.

There is no legitimate interest basis in the DPDP Act. Processing is either based on consent, or it falls within a short list of "certain legitimate uses" — things like a person voluntarily providing data for a specified purpose, medical treatment or health services during an epidemic or threat to life, employment purposes, and compliance with law.

Marketing is not on that list.

So the question for every row in your CRM is not "do we have a reasonable business interest in contacting this person". It is "can we show the consent, for this purpose, and can they withdraw it as easily as they gave it".

Consent under the Act has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose. Three common healthcare patterns fail that test outright: the pre-ticked box, the bundled consent that covers treatment and marketing in one sentence, and the consent that cannot practically be withdrawn because there is no mechanism to withdraw it.

And the notice that accompanies consent has to be a standalone, itemised description of what is collected and why — not a link to a privacy policy, and not a clause inside a longer form.

The repurposing problem

This is the one that will cost Indian hospitals the most work.

A patient gave you their mobile number so the radiology department could tell them their scan was ready. That is data provided for a specified purpose. Using it eighteen months later for a health-check package campaign is a different purpose, and the original interaction did not authorise it.

The same applies to the discharge list, the OPD register, the insurance desk's records and the camp attendance sheet. Every one of those is a favourite source of marketing lists in Indian healthcare, and every one of them was collected for something else.

The fix is not complicated, it is just laborious: a separate, clearly worded marketing consent captured at a moment when the patient is not in distress, recorded with a timestamp and the exact wording shown, stored somewhere your CRM can read, and honoured on withdrawal within the same systems. Doing that properly is a CRM project before it is a compliance project, which is why we treat it as part of setting up a healthcare CRM rather than as a legal review.

Children's data has a hard edge

Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and the Act prohibits tracking, behavioural monitoring and targeted advertising directed at children.

For paediatrics, paediatric dentistry, child psychiatry and vaccination services, that is not a footnote. It means remarketing audiences built from paediatric page visitors are a problem, it means a lead form that collects a child's details needs a parental consent step that can be evidenced, and it means the age question on your forms has to exist.

Rule 4 commences a year ahead of the rest, and it covers Consent Managers — registered intermediaries through which a person can give, manage, review and withdraw consent across the organisations holding their data, from a single interface.

For a hospital this is not an obligation so much as a signal about where the system is heading. The expectation is that a patient will eventually be able to withdraw marketing consent centrally, and your stack will have to honour that withdrawal without a human reading an email.

Which means the thing to build now is not a consent form. It is a consent record with a state that other systems can read and act on. A tick in a PDF stored in a shared drive will not survive contact with this.

Where your marketing stack touches the Act

Walk the stack and mark each point:

The website lead form — notice, consent, purpose, storage. The CRM — lawful basis per record, retention, deletion on request. WhatsApp broadcast lists — consent per number, per purpose. Email lists — the same, plus a working unsubscribe that actually writes back to source. Call recordings — consent announced and logged. Pixels and server-side tagging — what identifiers leave your domain, to whom, and with what. Review request automations — these reach patients by definition. Reactivation campaigns — the repurposing problem in its purest form. Chatbots and AI receptionists — a processor holding conversation transcripts.

Each of those needs a named owner, a documented purpose, and a retention period. That inventory is the deliverable. Most organisations discover two or three systems nobody knew were running.

Processor contracts, breaches and the large-organisation tier

Your agency and your vendors are processors, and you need contracts with them. Ask for: processing only on your instructions, defined security measures, no onward sub-processing without approval, breach notification to you without delay, deletion or return at termination, and cooperation with data principal requests.

If you are engaging a marketing agency in India and the contract is silent on all of this, that is a live gap, not a paperwork one.

On breaches, the Rules require intimation to affected data principals and to the Board, with an initial notification followed by a detailed report to the Board within seventy-two hours. Seventy-two hours is not long if nobody has decided in advance who declares a breach.

Significant Data Fiduciaries — a class the government notifies based on volume and sensitivity of data, among other factors — carry more: an annual data protection impact assessment, an independent audit, and a Data Protection Officer based in India. Large hospital groups should plan for the possibility of being notified rather than assume they will not be.

What the Act does not say

It does not create a special category for health data. There is no GDPR-style sensitive personal data tier and no separate consent standard for medical information, which surprises most people. The older 2011 SPDI Rules did single out medical records; the DPDP framework does not.

It does not set medical record retention periods. Rule-level erasure obligations carve out data retained to comply with law, and your actual retention duties come from elsewhere — the Clinical Establishments rules in your state, and the retention requirements attached to the Ayushman Bharat Digital Mission.

And it is not HIPAA. There is no business associate agreement, no covered entity, no minimum necessary standard. An Indian clinic quoting HIPAA in its privacy notice is telling every informed reader that the notice was copied.

What you can and cannot say to patients in public is a separate rulebook again — the advertising side is covered in what Indian doctors are actually allowed to say online, and the wider regulatory picture sits on our compliance pages.

What to do first

  1. Inventory every system holding patient or enquiry data for a marketing purpose. Name an owner for each.
  2. Find and kill every pre-ticked box and bundled consent on every form.
  3. Rewrite the notice as a standalone, itemised statement.
  4. Build a marketing consent record your CRM can read, with timestamp and wording.
  5. Get processor clauses into every vendor and agency contract at the next renewal.
  6. Write the breach procedure and name who declares one.

Start with the inventory. Everything else is guesswork until you know what you are holding.

---

If you want an outside read on what your current forms, lists and tags would look like under the 2025 Rules, get a free audit — we will send the findings whether or not you work with us. Or book a strategy call if you would rather talk through the sequencing before May 2027.

FILED UNDERdpdp act for healthcaredpdp rules 2025 effective datedpdp act for hospitalsdpdp act healthcarepatient data consent india
Stop reading. Start ranking.
Get a free compliance audit — we'll show you exactly what's missing.
Book audit →
Author
Founder & CEO · Gurugram, India

Nishu founded Branding Pioneers in 2016 with one rule that hasn't changed since: healthcare only. She'd run digital strategy at a top-10 Indian agency and watched generalist marketing underserve medical clients who needed something built for how patients actually search and decide. So she left to build the specialist instead. It's now an 80-person team working with healthcare brands worldwide.

The Patient Acquisition Blueprint (2026 Edition) — guide cover
Free · 15 pages

The Patient Acquisition Blueprint (2026 Edition)

The exact 90-day patient-acquisition system, step by step.

We never share your details

FREE · 30 MIN
See your compliance opportunity gap.

Senior strategist, no boilerplate. Reply within 4 hours.

Book audit → Or call us directly
The Pioneers Brief · weekly
One essay. Three benchmarks. One teardown.
Subscribe — free
The Patient Acquisition Blueprint (2026 Edition) — guide cover
Free for compliance readers

The Patient Acquisition Blueprint (2026 Edition)

The exact 90-day patient-acquisition system, step by step.

  • The 90-day patient acquisition operating system
  • Channel-by-channel budget allocation (₹50L–₹5Cr/yr)
  • 12 real, named client engagements walked through
  • ROI tracking spreadsheet (CAC, LTV, payback)
15 pages · Used by 350+ healthcare clients · Updated for AI search

We never share your details

Continue reading

More on compliance.

BROWSE ALL →
From the studio

This thinking, applied.

Max Smart Super Speciality — editorial feature and doctor-led video feature
Editorial · Video
Max Smart — editorial feature and video
Google Ads campaign management console
Google Ads
Google Ads — campaign management
Corporate hospital clients
Clients
Corporate hospitals
Branding Pioneers awards and platform partnerships
Recognition
Awards and platform partnerships
Apollo Hospitals — doctor-led video library
Video · Library
Apollo — the doctor-led video library
Why choose us

Why healthcare brands choose us.

Six reasons hospitals, clinics, and doctors pick a healthcare-only firm over a generalist agency.

  • Healthcare-only

    It's all we do. No retail, no fintech — the whole team thinks in patient journeys, clinical trust, and the way people actually choose a doctor.

  • AI-first systems

    Receptionists, WhatsApp triage, and attribution built in-house — we answer patients in seconds and tie every click to a booked appointment.

  • Compliance built-in

    HIPAA-aware handling, ASCI-reviewed creative, and GDPR/DPDP sign-off on every campaign — our standard, not an upcharge or an afterthought.

  • Senior on every account

    The senior who pitched you stays on the engagement. No bait-and-switch to juniors learning on your budget.

  • Measured to the appointment

    Patient-level attribution across calls, forms, and walk-ins. Monthly reports show booked patients — not just clicks and impressions.

  • Receipts, not promises

    We name our clients and show the work. Quarterly reviews with the numbers attached, every cycle.

The Branding Pioneers healthcare-marketing team at work
Healthcare-only · since 2016
A team that does one thing well.
More from the brief

If this resonated, here’s what else lands.

Adjacent practices, the relevant tools, and the case files where we shipped this thinking against real patient-acquisition targets.

THE PIONEERS BRIEF · WEEKLY

One essay,
three benchmarks,
one teardown.

Healthcare growth, every Thursday morning. No hype, no fluff.