Sec. 5, 6(1)
Consent at the point of care
Consent taken at admission has to cover the purposes it is later relied on for — treatment, insurance claim, research, marketing — and be separable. A single admission-form tick cannot carry all of them.
DPDP by industry
Health data attracts the closest scrutiny under the Act, and hospital estates are unusually fragmented — HIS, LIS, PACS, pharmacy, insurance desk and teleconsultation platforms each hold a copy of the same patient.
DPDP sits alongside these rather than replacing them. Where a sectoral rule requires retention and the Act requires erasure, both are satisfiable — but only where the basis is recorded per attribute.
Where the pressure lands
The Act applies uniformly. The obligations that bite first do not — these are the ones this sector fails on.
Sec. 5, 6(1)
Consent taken at admission has to cover the purposes it is later relied on for — treatment, insurance claim, research, marketing — and be separable. A single admission-form tick cannot carry all of them.
Sec. 8(4)–(5)
Linking records to a health ID broadens who can reach them. Access control has to be continuous rather than login-only, because shared clinical credentials are the most common route to unauthorised processing.
Sec. 9
Paediatric records require verifiable guardian consent, and the ban on behavioural advertising directed at children reaches any downstream marketing use of that data.
Sec. 8(7)
Clinical records carry statutory retention; the marketing and analytics copies of the same patient do not. Erasure has to distinguish them, which requires knowing every copy exists.
What closes them
Discovery first, because every other obligation is undeliverable without a catalogue. Everything after that consumes what it built.
Capture valid consent per purpose, give people self-service control, and make it the authoritative signal everywhere.
Sec. 5, 6, 9
Replace stale inventories with a live, identity-resolved map of every place personal data actually lives.
Sec. 8(3), 8(7)
Keep data usable for analytics, testing and support while the individual behind it stops being exposed.
Sec. 8(4), 8(5)
Receive, verify, fulfil and audit every access, correction, erasure and grievance request inside the statutory clock.
Sec. 11–14
From detection to defensible intimation and closure — a structured workflow that beats the regulatory clock.
Sec. 8(6)
Sequence
The same four phases apply in every sector; what changes is which systems go first.
Phase 1
Weeks 1–6
Phase 2
Weeks 4–12
Phase 3
Weeks 8–18
Phase 4
Weeks 14–26
Provider authentication and telemedicine session integrity, closing the gap between who claims to be on the call and who actually is.
A readiness walkthrough maps what you already run onto the eighteen obligations, and names what is missing with the exposure attached.