DPDPComplianceData protection
DPDP Rules 2025: the compliance clock for hospitals and labs
The DPDP Rules were notified on 14 November 2025 with an 18-month phased timeline. What hospitals, labs and small businesses must have in place by May 2027.
- Author
- Kentron Technologies
- Published
- Reading time
- 5 min read

The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 and put the DPDP Act, 2023 fully into operation, with most obligations arriving in phases over eighteen months. Every hospital, diagnostic lab, clinic and business that decides why and how patient or customer data is processed is a data fiduciary under the Act. This article sets out the dates, the duties and what to fix first.
The dates that matter
The Ministry of Electronics and Information Technology notified the Rules on 14 November 2025 after a consultation that drew 6,915 inputs. Rule 1 splits commencement into three stages. Rules 1, 2 and 17 to 21, which set up the Data Protection Board, took effect on publication. Rule 4, on registration of Consent Managers, takes effect one year after publication. The substantive Rules 3, 5 to 16, 22 and 23 take effect eighteen months after publication. For a data fiduciary, that means the consent notice, security, breach, retention and rights obligations become enforceable in May 2027, and Consent Manager registration opens in November 2026.
| Stage | Rules | When | What it covers |
|---|---|---|---|
| On publication | 1, 2, 17 to 21 | November 2025, in force | Definitions, the Data Protection Board of India, appeals |
| After one year | 4 | November 2026 | Registration and obligations of Consent Managers |
| After eighteen months | 3, 5 to 16, 22, 23 | May 2027 | Consent notices, security safeguards, breach intimation, retention, rights of data principals, children, Significant Data Fiduciaries |
What the Rules require of a data fiduciary
- A standalone consent notice, in clear and simple language, that states the specific purpose for which personal data is collected and used (PIB, 14 November 2025).
- Reasonable security safeguards. The highest penalty under the Act, up to ₹250 crore, applies to failure to maintain them.
- Breach intimation. Rule 7 requires that affected individuals be told without delay, that the Board be given an initial description without delay, and that a detailed report reach the Board within seventy-two hours of the fiduciary becoming aware of the breach.
- A response to requests to access, correct, update or erase personal data within ninety days.
- Published contact details of a designated officer or Data Protection Officer for questions about personal data (PIB).
- Verifiable parental consent before processing a child's data, with a limited exemption for essential purposes such as healthcare.
Consent Managers, the platforms through which a person can give, review and withdraw consent, must be companies based in India. Significant Data Fiduciaries, a class the government will notify, carry extra duties including independent audits, impact assessments and stronger due diligence for the technology they deploy (PIB). The official text of the Rules is on the MeitY website.
Penalties
| Failure | Maximum penalty |
|---|---|
| Failure to maintain reasonable security safeguards | ₹250 crore |
| Failure to notify the Board or affected individuals of a breach | ₹200 crore |
| Breach of obligations relating to children | ₹200 crore |
| Any other violation by a data fiduciary | ₹50 crore |
Source: PIB backgrounder, 17 November 2025. Appeals against the Board go to the Telecom Disputes Settlement and Appellate Tribunal. The Board itself is a fully digital body of four members that takes complaints online and lets citizens track cases through a portal and app, so complaining will be easy.
What this means for hospitals, labs and clinics
A practice guide on Indian cybersecurity law notes that hospitals, clinics, health-tech platforms and diagnostic labs are formally categorised as data fiduciaries under the Act. A 30-bed hospital with an HMIS, or a lab with a LIMS, decides why and how patient data is processed, so it carries the fiduciary duties. The vendor that hosts the software is a data processor acting on the hospital's instructions, and the contract should say so.
The 72-hour clock deserves attention. It starts when the hospital becomes aware of a breach, not when the investigation ends. A hospital without audit logs cannot say what was accessed and cannot write the report the Board expects. The patient notice must be in plain language and explain what happened, what it means for them, what has been done and whom to contact (Rule 7).
A practical order of work
- Map where personal data lives: HMIS, LIMS, WhatsApp exports, Excel sheets, the billing machine, the insurance desk.
- Rewrite the registration consent as a standalone notice that names each purpose, and record consent against the patient record.
- Assign a named contact for data queries and publish it at reception and on the website.
- Ask each software vendor for role-based access, audit logs, encrypted backups and a written breach-notification commitment that fits the 72-hour rule.
- Write a one-page breach playbook: who calls whom, what the patient message says, what goes to the Board.
- Set retention rules and delete what you no longer need.
Our hospital and lab products carry audit logs, role-based access and India-hosted data by default; you can see how this is set up on the Healthixio and Pathixio pages. None of that replaces the notice, the playbook and the contract, which are the hospital's own work.
Frequently asked questions
Does the DPDP Act apply to a small clinic or a two-room lab?
Yes, on the definitions. The Act defines a data fiduciary as an entity that decides why and how personal data is processed, and a clinic or lab that stores patient records on a computer fits that definition. The heavier duties for Significant Data Fiduciaries apply only to classes the government notifies, but the core obligations apply to everyone processing digital personal data.
When do we actually have to be compliant?
The Rules were notified on 14 November 2025. The Data Protection Board provisions are already in force. Consent Manager registration under Rule 4 opens one year after publication, in November 2026. The substantive obligations for data fiduciaries, including consent notices, security safeguards and breach intimation, apply eighteen months after publication, which is May 2027.
What is a Consent Manager, and does a hospital need to become one?
A Consent Manager is a registered platform through which a person can give, manage, review or withdraw consent across services. It must be an Indian company and registration opens under Rule 4 in November 2026. A hospital is a data fiduciary, not a Consent Manager; it needs its own consent notice and records, and may later connect to registered managers.
