Every Indian hospital that has taken the DPDP Act seriously has started in the same place: the medical records department. IT reviews the EMR, legal looks at the consent form, someone asks about server location, and the project is declared under way.
Meanwhile the marketing stack is sitting one floor up with an eleven-thousand-row spreadsheet of enquiry numbers, a WhatsApp broadcast list nobody remembers building, a lead form with a pre-ticked consent box, and a tag manager firing procedure names into two ad platforms.
That is where this law lands first, and it is where almost nobody is looking.
01The dates, so you can plan against them
The Digital Personal Data Protection Act, 2023 received assent in August 2023 but could not operate without rules. Those arrived as the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology as G.S.R. 846(E) on 13 November 2025.
Commencement is staggered, and the staggering is the single most useful thing to know:
From notification on 13 November 2025: the preliminary rules and the provisions covering the Data Protection Board of India's appointments and procedure.
From 13 November 2026: Rule 4, covering registration and obligations of Consent Managers.
From 13 May 2027: everything that governs day-to-day practice — the notice requirements, the security safeguards, breach notification, data principal rights, children's data, Significant Data Fiduciary duties, cross-border transfer and retention.
Read Rule 1 of the notification yourself rather than trusting any summary, including this one. It is two paragraphs and it decides your project plan.
The Board itself was constituted alongside the Rules, though appointments to it have lagged. Treat that as a reason to build well rather than a reason to wait — an eighteen-month runway on the substantive rules is not long for an organisation that has to rewrite every consent flow it owns.
02Four roles, and you are probably three of them
The Act names a Data Principal (the patient), a Data Fiduciary (the hospital or clinic, which decides why and how data is processed), a Data Processor (a vendor processing on the fiduciary's instructions — your CRM, your agency, your call centre, your chatbot provider), and a Consent Manager (a registered intermediary through which a person can give and withdraw consent).
A hospital is the fiduciary. It stays the fiduciary when it hands data to an agency. Liability does not transfer with the file.
03The part that actually changes marketing
Indian privacy discussion imports a lot of GDPR vocabulary, and one import is actively misleading.
There is no legitimate interest basis in the DPDP Act. Processing is either based on consent, or it falls within a short list of "certain legitimate uses" — things like a person voluntarily providing data for a specified purpose, medical treatment or health services during an epidemic or threat to life, employment purposes, and compliance with law.
Marketing is not on that list.
So the question for every row in your CRM is not "do we have a reasonable business interest in contacting this person". It is "can we show the consent, for this purpose, and can they withdraw it as easily as they gave it".
Consent under the Act has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose. Three common healthcare patterns fail that test outright: the pre-ticked box, the bundled consent that covers treatment and marketing in one sentence, and the consent that cannot practically be withdrawn because there is no mechanism to withdraw it.
And the notice that accompanies consent has to be a standalone, itemised description of what is collected and why — not a link to a privacy policy, and not a clause inside a longer form.
04The repurposing problem
This is the one that will cost Indian hospitals the most work.
A patient gave you their mobile number so the radiology department could tell them their scan was ready. That is data provided for a specified purpose. Using it eighteen months later for a health-check package campaign is a different purpose, and the original interaction did not authorise it.
The same applies to the discharge list, the OPD register, the insurance desk's records and the camp attendance sheet. Every one of those is a favourite source of marketing lists in Indian healthcare, and every one of them was collected for something else.
The fix is not complicated, it is just laborious: a separate, clearly worded marketing consent captured at a moment when the patient is not in distress, recorded with a timestamp and the exact wording shown, stored somewhere your CRM can read, and honoured on withdrawal within the same systems. Doing that properly is a CRM project before it is a compliance project, which is why we treat it as part of setting up a healthcare CRM rather than as a legal review.
05Children's data has a hard edge
Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and the Act prohibits tracking, behavioural monitoring and targeted advertising directed at children.
For paediatrics, paediatric dentistry, child psychiatry and vaccination services, that is not a footnote. It means remarketing audiences built from paediatric page visitors are a problem, it means a lead form that collects a child's details needs a parental consent step that can be evidenced, and it means the age question on your forms has to exist.
06Consent Managers, and why the November 2026 date matters
Rule 4 commences a year ahead of the rest, and it covers Consent Managers — registered intermediaries through which a person can give, manage, review and withdraw consent across the organisations holding their data, from a single interface.
For a hospital this is not an obligation so much as a signal about where the system is heading. The expectation is that a patient will eventually be able to withdraw marketing consent centrally, and your stack will have to honour that withdrawal without a human reading an email.
Which means the thing to build now is not a consent form. It is a consent record with a state that other systems can read and act on. A tick in a PDF stored in a shared drive will not survive contact with this.
07Where your marketing stack touches the Act
Walk the stack and mark each point:
The website lead form — notice, consent, purpose, storage. The CRM — lawful basis per record, retention, deletion on request. WhatsApp broadcast lists — consent per number, per purpose. Email lists — the same, plus a working unsubscribe that actually writes back to source. Call recordings — consent announced and logged. Pixels and server-side tagging — what identifiers leave your domain, to whom, and with what. Review request automations — these reach patients by definition. Reactivation campaigns — the repurposing problem in its purest form. Chatbots and AI receptionists — a processor holding conversation transcripts.
Each of those needs a named owner, a documented purpose, and a retention period. That inventory is the deliverable. Most organisations discover two or three systems nobody knew were running.
08Processor contracts, breaches and the large-organisation tier
Your agency and your vendors are processors, and you need contracts with them. Ask for: processing only on your instructions, defined security measures, no onward sub-processing without approval, breach notification to you without delay, deletion or return at termination, and cooperation with data principal requests.
If you are engaging a marketing agency in India and the contract is silent on all of this, that is a live gap, not a paperwork one.
On breaches, the Rules require intimation to affected data principals and to the Board, with an initial notification followed by a detailed report to the Board within seventy-two hours. Seventy-two hours is not long if nobody has decided in advance who declares a breach.
Significant Data Fiduciaries — a class the government notifies based on volume and sensitivity of data, among other factors — carry more: an annual data protection impact assessment, an independent audit, and a Data Protection Officer based in India. Large hospital groups should plan for the possibility of being notified rather than assume they will not be.
09What the Act does not say
It does not create a special category for health data. There is no GDPR-style sensitive personal data tier and no separate consent standard for medical information, which surprises most people. The older 2011 SPDI Rules did single out medical records; the DPDP framework does not.
It does not set medical record retention periods. Rule-level erasure obligations carve out data retained to comply with law, and your actual retention duties come from elsewhere — the Clinical Establishments rules in your state, and the retention requirements attached to the Ayushman Bharat Digital Mission.
And it is not HIPAA. There is no business associate agreement, no covered entity, no minimum necessary standard. An Indian clinic quoting HIPAA in its privacy notice is telling every informed reader that the notice was copied.
What you can and cannot say to patients in public is a separate rulebook again — the advertising side is covered in what Indian doctors are actually allowed to say online, and the wider regulatory picture sits on our compliance pages.
10What to do first
- 1Inventory every system holding patient or enquiry data for a marketing purpose. Name an owner for each.
- 2Find and kill every pre-ticked box and bundled consent on every form.
- 3Rewrite the notice as a standalone, itemised statement.
- 4Build a marketing consent record your CRM can read, with timestamp and wording.
- 5Get processor clauses into every vendor and agency contract at the next renewal.
- 6Write the breach procedure and name who declares one.
Start with the inventory. Everything else is guesswork until you know what you are holding.
---
If you want an outside read on what your current forms, lists and tags would look like under the 2025 Rules, get a free audit — we will send the findings whether or not you work with us. Or book a strategy call if you would rather talk through the sequencing before May 2027.