Insights · Digital health

Your hospital has until May 2027 on data protection, and the first deadline is in November

Breach reporting in 72 hours with no materiality threshold, penalties to ₹250 crore, and an unresolved collision with medical record retention.

Substantive DPDP obligations commence for hospitals in May 2027

A hospital is one of the most data-intensive businesses in India, and almost none of the data is optional. The Digital Personal Data Protection Act received assent in August 2023, the Rules under it were notified in November 2025, and they commence in phases.

The dates that matter: 13 November 2026 for consent manager registration, and 13 May 2027 for the substantive compliance obligations.

You are inside the runway, not past it

As things stand today the substantive obligations are not yet in force. That is the good news and it is the whole of the good news. The work that has to be done — mapping where patient data sits, rebuilding notice and consent at every collection point, and standing up breach detection — takes most hospitals longer than the time remaining.

What the obligations are

Notice and consent. An itemised description of the personal data processed, the specific purposes, and a link that makes withdrawing consent as easy as giving it. The notice has to be separate, clear and in plain language. For a hospital this is not one form. It is registration, admission, diagnostics, pharmacy, insurance processing and any app or portal, each of which currently collects data under a signature nobody reads.

Breach notification. Affected individuals must be informed without delay, in plain language, covering what happened, the likely impact and the remedial steps. Reporting to the Data Protection Board is two-layered, with the detailed filing within 72 hours. There is no materiality threshold. Every breach is reportable, including the small ones that hospitals currently handle internally.

Logs. Personal data, traffic data and processing logs are to be retained for one year from the date of processing.

The penalties

These are per instance and they are large. Failure to take reasonable security safeguards carries up to ₹250 crore. Failure to notify a breach, up to ₹200 crore. Breach of children's-data obligations, up to ₹200 crore. Obligations of a Significant Data Fiduciary, up to ₹150 crore. Any other breach, up to ₹50 crore.

Whether hospitals or hospital groups will be notified as Significant Data Fiduciaries, which would add annual impact assessments, independent audits and a data protection officer, has not been announced. We could find no notification and no healthcare-specific guidance from the health ministry or the National Health Authority.

One thing genuinely in your favour, one thing nobody has answered

The favourable part: the requirement for verifiable parental consent before processing a child's data carries an exception where the processing relates to essential services such as healthcare. Paediatric care does not need a parent to complete a consent flow before a child is treated.

The unanswered part is more awkward. The Rules contemplate erasure of personal data after three years in some circumstances, framed around large-scale platforms. Hospitals are separately obliged to retain medical records, and a patient's right to erasure sits directly across that. We looked for an authoritative resolution and did not find one. We also could not verify, from any primary source we could reach, what India's medical record retention period actually is — the commonly quoted figures trace to secondary material. If your medical records policy cites a specific number of years, check where that number came from.

What this means for your hospital

Start with the map, not the policy. List every place patient data is collected, who collects it, what is collected, why, where it goes and who else can see it. Most hospitals discover during this exercise that data leaves through channels nobody had catalogued: a WhatsApp group for reports, a diagnostics vendor's portal, a consultant's personal device.

Then fix consent where it is collected, which is a front-office process change rather than a legal drafting exercise.

Then build the breach path. Decide now who is told, in what order, and who signs the 72-hour filing. A 72-hour clock is not survivable by a hospital that first has to work out who is in charge.

Do those three before May 2027 and the rest is documentation. Leave them and the exposure is not theoretical.

Sources

Unverified, stated as such: PIB gives the notification date as 14 November 2025 and two law firms give 13 November 2025, most likely a gazette-versus-announcement difference; we could not obtain the gazette number to settle it, so the phased dates above should be treated as approximate to within a day. We could not confirm whether hospitals will be notified as Significant Data Fiduciaries, and found no authoritative resolution of the erasure and medical-record-retention conflict.

Eighteen months is not long for a consent rebuild.

We map where patient data actually sits in your hospital, rebuild notice and consent at the points it is collected, and leave your team owning it.

More from Insights

WhatsApp us Call Email