The SPDI Rules under the Information Technology Act singled out medical records and history, and physical, physiological and mental health condition for heightened protection as sensitive personal data.
The DPDP Act removes that tiering entirely. There is no sensitive category. A patient's diagnosis, a name and an email address all attract the same statutory baseline.
This is not a relaxation, and reading it as one is the mistake to avoid. Three reasons:
So the correct summary is: the category is gone, the risk is not, and the obligations went up.
Section 9 requires verifiable parental consent before processing a child's personal data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. A child is an individual who has not completed eighteen years.
Applied literally to a hospital, that would mean a treating clinician could not process a sixteen-year-old's data without first verifying parental identity — including in circumstances where doing so would delay care.
Section 9(4) permits sub-sections (1) and (3) to be disapplied for prescribed classes, purposes and conditions, and Rule 12 with the Fourth Schedule does exactly that. Part A begins with:
| Class of Data Fiduciary | Condition |
|---|---|
| A clinical establishment, mental health establishment, or healthcare professional | Processing is restricted to provision of health services to the child by that establishment or professional, to the extent necessary for the protection of her health |
| An allied healthcare professional | Processing is restricted to supporting implementation of a healthcare treatment and referral plan |
Note how tightly the conditions are drawn. The carve-out is purpose-bound, not entity-bound. A hospital does not step outside section 9 generally — it steps outside it for the provision of health services to that child, to the extent necessary for the protection of her health.
Which means the carve-out does not cover:
A hospital running a patient-engagement app is inside the carve-out for clinical functions and outside it for the rest, in the same system.
Section 7 permits processing without consent in several situations directly relevant to care delivery, including where processing is necessary:
These are situational rather than blanket. An emergency admission is covered; the subsequent twelve months of routine outpatient processing is not covered by the emergency limb and rests on other bases.
Not in the carve-out — in the estate.
Hospital data landscapes are typically the most fragmented of any sector: a hospital information system, an electronic medical record, radiology and laboratory information systems, pharmacy, billing, insurance and third-party administrator interfaces, appointment platforms, teleconsultation tools, and a long tail of departmental spreadsheets and legacy systems that nobody owns.
Three obligations become hard specifically because of that fragmentation:
Section 11 access requests. The individual is entitled to a summary of processing and the identities of all other Data Fiduciaries and Processors with whom the data was shared. In a hospital that chain runs to insurers, TPAs, referral labs, and sometimes research collaborations. Answering accurately requires a sharing register that most hospitals do not have.
Section 12 erasure. You cannot erase across systems you have not inventoried, and clinical records are subject to retention requirements that vary by record type.
Section 8(5) safeguards. The highest-penalty obligation, applied across an estate with legacy systems, shared workstations and clinical urgency working against access control.
Consiva provides the data inventory and sharing register, purpose-level consent separating clinical from commercial processing, rights intake with verification, and the retention register per record type. The clinical determinations — what is necessary for the protection of a child's health, what a record type requires — are medical and legal judgements that stay with your clinicians and counsel.
Data Discovery, ROPA auto-generation and the SDF module are on Enterprise, with on-premise deployment available for estates that cannot use a hosted platform. The clinical determinations — what is necessary for the protection of a child's health, what a record type requires — stay with your clinicians and counsel. → Pricing
Yes. Hospitals, clinics, diagnostic laboratories, telemedicine providers and pharmacies are Data Fiduciaries for patient personal data and carry the full Chapter II obligations.
No. The Act has no sensitive category — the SPDI Rules' separate treatment of medical records and health condition is gone. All personal data attracts the same baseline, though section 33(2) requires the Board to consider the type and nature of data affected when setting a penalty.
Rule 12 and the Fourth Schedule disapply section 9(1) and 9(3) for clinical establishments, mental health establishments, healthcare professionals and allied healthcare professionals, where processing is restricted to providing health services to the child to the extent necessary for the protection of her health.
No. The Fourth Schedule carve-out is purpose-bound to the provision of health services. Marketing, analytics and engagement beyond treatment fall outside it, and section 9(3)'s prohibition on targeted advertising directed at children continues to apply.
Section 7 permits processing without consent where necessary to respond to a medical emergency involving a threat to life or an immediate threat to health. The exemption is situational and does not extend to routine processing after the emergency.
The erasure right is subject to retention necessary for the specified purpose or for compliance with law, and clinical record retention requirements apply. Data outside any mandate must still be erased, and refusals should be explained and documented.
Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 7, 9, 11, 12, 33(2); DPDP Rules, 2025, Rule 12 and Fourth Schedule Part A. Clinical record retention requirements must be confirmed from the applicable instrument. Reference material about the law, not legal advice — see /disclaimer.
Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.
Start Free — No Credit Card →