Skip to content
Back to blog

The DPDP deadline is May 2027. What clinics need before then.

The DPDP Rules were notified in November 2025 with an eighteen-month runway. Health data gets the strictest treatment, and small clinics are not exempt.

Qlinio
4 min read

The Digital Personal Data Protection Rules were notified on 13 November 2025 as G.S.R. 846(E). They carry an eighteen-month phased transition, which puts full compliance at 13 May 2027.

That sounds distant. It is about nine months away from the point most clinics will start, because the work that matters — knowing where patient data actually lives — takes longer than the paperwork that follows it.

You are a Data Fiduciary

There is no clinic-size exemption. If you decide why and how patient personal data is processed, you are a Data Fiduciary under the Act. A three-doctor clinic in a Tier 2 city holding names, phone numbers, diagnoses and prescriptions is squarely inside scope.

Health data is not a special category with its own chapter in the Indian law the way it is under GDPR — but it is data whose breach causes obvious, demonstrable harm, and the penalty schedule is built around consequences.

The numbers that concentrate the mind

The Schedule to the DPDP Act 2023 sets maximum penalties of:

  • ₹250 crore for failure to implement reasonable security safeguards
  • ₹200 crore for failure to notify the Data Protection Board or affected individuals of a breach

These are ceilings, not tariffs, and they scale to the nature of the breach. No regulator is going to levy ₹250 crore on a single-doctor clinic. But the second one is the one clinics get wrong, because it is not about being breached — it is about staying silent afterwards.

The phasing

  • November 2025 — the Data Protection Board became operational and the complaint mechanism went live. This part is already running.
  • November 2026 — Consent Manager registration opens.
  • May 2027 — full compliance: consent systems, privacy notices, data principal rights, breach protocols.

The Board being live from day one is the detail people miss. A patient can complain today. The eighteen months is a runway for building systems, not a shield.

What a clinic actually needs

A privacy notice in plain language. What you collect, why, how long you keep it, and how a patient reaches you about it. It must be available in English and, in practice, the language your patients use.

A consent record. Not a signature on a form in a drawer. A record showing what the patient agreed to and when, retrievable when asked.

A rights process. Patients can ask for access to their data, correction of it, and erasure. Someone at the clinic has to own answering that, with a defined turnaround.

A breach protocol written before you need it. Who is called, who assesses, who notifies the Board, in what window. A protocol invented during an incident is not a protocol.

Retention limits. "We keep everything forever" stops being acceptable. Decide how long records are held after a patient's last visit, and be able to justify it against medical record-keeping obligations.

Reasonable security safeguards. Encryption, access control by role, and audit logging of who viewed which record. This is the one with the ₹250 crore ceiling attached, and it is also the one software can largely solve for you.

Where software helps and where it does not

Role-based access, encryption at rest, audit logs and consent capture are product features. If your clinic software has them, you inherit most of the technical safeguard requirement. If it does not — if every staff member logs in as "admin" — no policy document will fix that.

What software cannot do is decide your retention period, write your notice, or nominate the person who answers a patient's erasure request. Those are decisions, and they are yours.

A reasonable order for the next nine months

  1. Map the data. Every place patient information sits — the software, the WhatsApp group, the receptionist's spreadsheet, the paper register in the back room. Most clinics are surprised by this step, and it is the one everything else depends on.
  2. Close the informal channels. Patient details in a WhatsApp group are the single most common exposure in Indian clinics and the hardest to defend.
  3. Fix access control. One login per staff member, permissions by role.
  4. Write the notice and the breach protocol.
  5. Set retention periods and document the reasoning.

Start with step one. It is unglamorous, it takes an afternoon, and everything after it is easier for having done it.

This is an operational summary, not legal advice. Have your notice and retention policy reviewed by a lawyer before you publish them.

Bringing your clinic online?

See how Qlinikit and the Qlinio platform fit your workflow — book a short walkthrough.