The DPDP Act and Patient Data: A Plain Guide for Clinics
If your clinic takes patient names, numbers, and health details over the phone, the DPDP Act now shapes how you should handle that information. This is a plain-English explainer of India's Digital Personal Data Protection Act 2023 for a clinic, covering consent, notice, using data only for the reason you collected it, storing it safely, and telling callers the line is automated and may be recorded. It is general information, not legal advice, so please consult a qualified professional for your specific situation.
What the DPDP Act is, in one paragraph
The Digital Personal Data Protection Act 2023 is India's law on how organisations handle the personal data of individuals in digital form. When your clinic collects a patient's name, phone number, or details about their condition and stores or processes them digitally, the law treats your clinic as a data fiduciary, which is the entity that decides why and how that data is handled. The patient is the data principal. The rules below flow from that basic relationship. The Act is administered under the Ministry of Electronics and Information Technology, and you can read the official material at their site.
Consent: get it, and get it clearly
The core idea of the Act is consent. Before you use a patient's personal data, you should have their agreement, and that agreement should be free, specific, informed, and unambiguous. In plain terms, the patient should know what they are agreeing to and should be able to say no. For a clinic taking details on a call, this means the patient understands you are collecting their number and health details in order to book and manage their appointment.
Consent is also tied to a purpose. You ask for it in connection with the specific thing you are doing, such as booking a visit or sending an appointment reminder. You should not quietly reuse that same data for something the patient did not agree to, such as marketing an unrelated service.
Notice: tell the patient what you are doing
Alongside consent, the Act expects a notice. The patient should be told, in clear language, what personal data you are collecting and the purpose for it. For a clinic this can be short and honest: you are noting their name, number, and reason for calling so you can book and manage their appointment, and they can ask to have it corrected or removed.
You can give this notice on the call itself and back it up on your website or intake form. It does not need legal jargon. It needs to be understandable to the patient, and available in a language they can read where required.
Purpose limitation: use data only for why you collected it
This is the rule clinics most often overlook. If you collected a number to confirm an appointment, use it to confirm the appointment. Sending unrelated promotional messages to that number later is a different purpose the patient did not agree to. Keeping data forever "just in case" is also a poor fit with the Act, which points toward keeping personal data only as long as it serves the purpose.
A simple test helps here:
- Did the patient give me this data for this exact use? If not, stop.
- Do I still need it for that purpose? If not, plan to delete it.
- Am I sending anything the patient did not agree to receive? If so, do not.
Storing patient data safely
The Act expects a data fiduciary to take reasonable security safeguards to protect personal data. For a small clinic this is mostly common-sense hygiene rather than expensive technology. The goal is that a patient's details are not sitting open on a shared desktop or in a chat group anyone can scroll through.
| Do | Avoid |
|---|---|
| Password-protect the device and the sheet holding patient data | Leaving a patient list open on a shared front-desk screen anyone can see |
| Limit who on the team can see full records | Sharing details in an open WhatsApp group |
| Keep data only as long as you need it | Hoarding old lists with no purpose |
| Correct or delete data when a patient asks | Ignoring a patient's request to remove their data |
If you use a tool that stores enquiries in a Google Sheet, restrict who it is shared with and remove access for people who leave. Small steps like these are what "reasonable safeguards" looks like for a clinic.
The automated-and-recorded disclosure
If your calls are answered by an automated front desk and may be recorded, tell the caller. A short line at the start of the call is enough: the line is automated and may be recorded, and their details will be used to handle their enquiry. This respects the notice and consent ideas in the Act, and it is simply fair to the patient.
A well-set-up AI receptionist makes this disclosure at the start of every call, so you do not have to remember to add it. The caller hears a normal, helpful front desk, and they are told up front that the line is automated and may be recorded before they share anything.
Patient rights you should be ready for
The Act gives individuals rights over their data. A patient can ask what data you hold about them, ask you to correct it, and ask you to erase it when it is no longer needed for the purpose. Your clinic should have a simple way to receive and act on such a request, even if that is just one person who handles it and a note in your records that it was done.
You do not need a large compliance department for this. You need to know where patient data lives, be able to find one patient's records, and be able to correct or delete them on request. Keeping everything in one organised place, rather than scattered across notebooks and chat threads, is what makes this practical.
Working with a service that answers your calls
If an outside service answers your calls and stores enquiries for you, that service is handling patient data on your behalf. Under the Act, a data fiduciary can engage a data processor to process data, but the responsibility for how that data is handled does not simply disappear. So it is fair to expect a few basic things from any such service, and to ask about them before you sign up.
Practical questions worth asking:
- Does it make the automated-and-recorded disclosure to callers at the start of the call?
- Does it use patient data only to handle the enquiry, and not for anything else?
- Can you restrict who on your team sees the records it produces?
- Can a patient's data be corrected or deleted on request?
- Is the data stored with access limited to people who need it?
These are the same principles that apply to your own front desk, extended to a service you rely on. A tool that keeps enquiries in a Google Sheet you control, with the disclosure built into the call, fits this pattern well. As always, confirm the specifics for your clinic with a professional rather than assuming.
A short compliance checklist for a clinic
Use this as a starting point, then have it reviewed by a professional for your clinic:
- Tell callers, in plain language, what you collect and why.
- Disclose that the line is automated and may be recorded.
- Collect patient data only for booking and managing care.
- Do not reuse that data for unrelated marketing.
- Store records with a password and limited access.
- Keep data only as long as you need it, then delete it.
- Be able to find, correct, and erase one patient's data on request.
- Restrict who can see any shared sheet of enquiries.
This guide is general information about the DPDP Act 2023 and how it applies to a clinic that collects patient details by phone. It is not legal advice. Rules and official guidance can change, so please consult a qualified data protection professional or lawyer before finalising your clinic's practices. The official source for the Act and related notifications is the Ministry of Electronics and Information Technology.
Common questions
Does the DPDP Act apply to a small clinic?
The Act applies to organisations that process the personal data of individuals in digital form, which includes a clinic that stores patient names, numbers, and health details digitally. The scale of your clinic does not exempt you from the basic duties, though specifics can vary, so confirm with a professional.
Do I need to tell callers the line is recorded?
If your line is automated and calls may be recorded, it is fair and consistent with the Act's notice idea to tell the caller at the start. A short spoken disclosure before they share details is the simple way to do it.
Can I send appointment reminders under the Act?
Sending a reminder about an appointment the patient booked fits the purpose they gave their number for. Sending unrelated promotions to that number is a different purpose they did not agree to, and you should not do it without fresh consent.
How long can I keep patient data?
The Act points toward keeping personal data only as long as it serves the purpose you collected it for. Keep records while they are needed for care and your legitimate obligations, then delete what you no longer need.
Is this article legal advice?
No. This is general, plain-English information about the DPDP Act 2023. Please consult a qualified data protection professional or lawyer for advice specific to your clinic.
Sources: Ministry of Electronics and Information Technology
Keep reading
Related guides
Multilingual Receptionist for Indian Clinics: Keep the Patient Who Calls in Their Own Language
A multilingual receptionist answers Indian clinic calls in Hindi, Marathi, Tamil, Telugu, Bengali and...
AI Receptionist for Clinics in India: Answer Every Call, In Every Language
An AI receptionist for clinics in India answers every call in the patient's language, captures the lead,...
AI Receptionist for Dental Clinics in India: Fewer No-Shows, No Missed Calls
An AI receptionist for dental clinics in India answers pain calls after hours, sorts new from old...
Stop Missing Patient Calls: The Real Cost of Clinic Missed Calls in India
Clinic missed calls cost real patients in India, because the caller simply rings the next clinic. Here is...