DPDP Act 2023 for GBP Lead Capture — Consent, Purpose, and Erasure
The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively
No pitch. Written root-cause diagnosis. AI-powered, healthcare only.
Direct answer
The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively
TL;DR
TL;DR
- The Digital Personal Data Protection Act 2023 applies to all patient data collected through GBP-adjacent channels: appointment booking forms, contact forms, WhatsApp messages, and review request campaigns
- The most common DPDP violation ICG finds in healthcare lead capture: using patient phone numbers collected for appointment reminders to send marketing WhatsApp messages without separate marketing consent
- Purpose limitation is the core principle: data collected for one purpose (booking an appointment) cannot be used for a different purpose (marketing) without new, specific consent
- Review response DPDP risk: publicly confirming that a reviewer was your patient, or referencing their clinical situation, is a public disclosure of health data — the most sensitive personal data category under DPDP
- Erasure requests: patients can request deletion of their personal data; your GBP-adjacent data systems must have a documented erasure workflow
The Digital Personal Data Protection Act 2023 is India's comprehensive personal data protection framework. It came into force in 2023 and its enforcement provisions are being implemented progressively through 2025–2026.
For healthcare businesses, the DPDP Act is not an IT department concern. It reaches into every patient touchpoint — including the data flows connected to your Google Business Profile: appointment booking forms, WhatsApp review request messages, satisfaction survey campaigns, and CRM remarketing using patient data.
Most healthcare practices have not audited these data flows against DPDP requirements. This guide is that audit.
Section 1 — The DPDP principles relevant to GBP lead capture
1.1 Lawful purpose and consent
Under the DPDP Act, personal data (including patient name, phone number, email, and health-related information) can only be processed for a specific, clearly stated purpose. The patient must give free, informed, specific, and unambiguous consent for that purpose.
Critically: consent for one purpose does not extend to another.
If a patient provides their phone number to book an appointment, they have consented to data processing for appointment management. They have not consented to:
- WhatsApp health tips
- Marketing messages for new services
- Promotional offers
- Recall campaigns for future appointments
Each additional use requires separate, explicit consent at the time of collection.
1.2 Data minimisation
Collect only the data needed for the stated purpose. An appointment booking form that asks for the patient's name, phone number, and preferred appointment time has collected what is needed. The same form asking for date of birth, gender, employer, insurance details, and medical history is collecting data for which the appointment booking purpose does not provide justification.
1.3 Storage limitation
Personal data should not be retained longer than necessary for the stated purpose. For appointment data: retain for the duration of the patient relationship plus a reasonable period for follow-up (typically 12–24 months for non-clinical contact data). For clinical records: Indian law establishes separate retention requirements (typically 7 years minimum for clinical records). These are different retention schedules and should be managed separately.
1.4 Data subject rights
The DPDP Act grants patients several rights over their personal data:
- Right to access: patients can ask what data you hold about them
- Right to correction: patients can ask for inaccurate data to be corrected
- Right to erasure: patients can ask for their data to be deleted (with exceptions for data where legal retention requirements apply)
- Right to nominate: patients can nominate someone to exercise these rights on their behalf
Your GBP-adjacent data systems must have documented processes to respond to these requests.
Section 2 — The GBP lead capture data flows and their DPDP implications
2.1 Appointment booking form (website / GBP linked)
Data collected: Name, phone, email, preferred department or doctor, preferred date.
Lawful basis: Contractual necessity (the patient is requesting a service).
What you can do with this data: Contact the patient to confirm, reschedule, or follow up on the appointment. Send appointment reminders.
What you cannot do without additional consent: Send marketing messages, add to a newsletter list, use for remarketing campaigns, pass to a CRM for promotional follow-up.
DPDP-compliant appointment form design:
- Collect only: name, phone, preferred appointment details (department, date/time preference)
- Include a clear purpose statement: "Your details will be used to confirm your appointment and send appointment reminders."
- Separate checkbox for marketing consent (unchecked by default): "I would also like to receive health tips and updates from [clinic name] via WhatsApp."
2.2 Walk-in patient registration
Data collected: Name, phone, address, DOB, health information.
Lawful basis: Contractual necessity (clinical care) — for clinical data. For marketing use: explicit consent required separately.
Most common DPDP violation in healthcare: Using the registration desk's patient phone number database (collected for clinical purposes) to send WhatsApp marketing campaigns. These are two different purposes. The clinical data collection does not provide lawful basis for the marketing use.
Compliant approach: Separate consent collection at registration — two distinct tick-boxes:
- "I consent to the collection and processing of my personal and health information for my clinical care." (implied or explicit consent for clinical care)
- "I would like to receive health tips, appointment reminders for future care, and updates from [clinic name] via WhatsApp." (explicit, unambiguous, separate consent for marketing communications)
Only patients who check box 2 can be added to marketing WhatsApp lists.
2.3 WhatsApp review request campaigns
The data flow: Patient phone numbers (collected at registration for clinical purposes) → WhatsApp message asking for a Google review.
DPDP analysis: The phone number was collected for clinical appointment management. Using it for a review request campaign is a different purpose — customer feedback and marketing — that was not covered by the original consent.
Compliant approach:
- Option A: Collect explicit marketing consent at registration (box 2 above) and only send review requests to consenting patients.
- Option B: Send the review request as part of the appointment follow-up (same purpose — appointment management) with a natural, non-pressured ask: "We hope your visit today was comfortable. If you'd like to share your experience: [link]." This sits closer to the original appointment purpose than a scheduled marketing campaign.
- Option C: In-person review request at checkout — a staff member verbally asks the patient if they would be willing to share a review and hands them a card with the QR code. No personal data processing involved.
2.4 CRM list upload for Google/Meta remarketing
The data flow: Patient phone numbers or emails from CRM → hashed list uploaded to Google Ads / Meta Ads for Custom Audience remarketing.
DPDP analysis: This is a data sharing action — patient data is being transmitted to a third-party data processor (Google or Meta). This requires:
- Explicit patient consent for marketing communications (same as 2.3)
- A Data Processing Agreement (DPA) with Google/Meta as a data processor
- Purpose limitation: the remarketing must be for a purpose consistent with what patients consented to
Compliant approach: Only upload consented marketing contacts (patients who have explicitly opted into marketing communications). Document the consent basis. Ensure your Google Ads and Meta Ads accounts have data processing terms accepted (both platforms have GDPR/DPA frameworks that serve as the DPA mechanism).
2.5 Review responses — the public data disclosure risk
The data flow: Patient writes a Google review → clinic responds publicly.
DPDP analysis: Health data is the most sensitive personal data category under the DPDP Act. If a clinic's response to a review confirms that the reviewer was their patient, references their clinical situation, or includes any information from their medical encounter — the clinic has publicly disclosed sensitive personal data without consent.
The patient chose to write a public review. That does not give the clinic consent to publicly add clinical context that was not in the patient's own review.
Non-compliant review response: "Dear Mr. Kumar, thank you for your review. We're glad your knee replacement surgery went well and that you're recovering comfortably. We look forward to seeing you at your 3-month follow-up."
Why it fails: confirms the patient's identity (name), confirms the clinical procedure (knee replacement), and references the care relationship — all without explicit consent for this public disclosure.
Compliant review response (for the same situation): "Thank you for taking the time to share your experience. We're delighted to hear you felt well-supported throughout your care journey. We look forward to continuing to provide the same standard of care. — [Clinic name] team"
Section 3 — The erasure request workflow
A patient can request deletion of their personal data. Your response workflow must:
For non-clinical marketing data (WhatsApp contact list, email newsletter list): Delete within a reasonable timeframe (30 days is the standard). Confirm deletion in writing to the patient.
For appointment data: Delete contact information after the reasonable appointment follow-up retention period. If the patient requests deletion before this period ends, comply unless there is a specific clinical or legal reason not to.
For clinical records: Clinical records (diagnosis, treatment, prescriptions, test results) have mandatory minimum retention periods under Indian law — typically 7 years. An erasure request cannot override these legal retention requirements. Inform the patient that clinical records are retained for the legally required period but will be deleted after that period ends.
Documentation: Every erasure request and your response must be documented. Date of request, patient identity, scope of data requested for deletion, action taken, date of completion.
Section 4 — DPDP compliance checklist for GBP-adjacent data systems
| Data flow | Consent collected? | Purpose documented? | Retention policy? | Erasure workflow? |
|---|---|---|---|---|
| Appointment booking form | [ ] | [ ] | [ ] | [ ] |
| Walk-in registration | [ ] | [ ] | [ ] | [ ] |
| WhatsApp recall/review campaign | [ ] | [ ] | [ ] | [ ] |
| CRM list upload for remarketing | [ ] | [ ] | [ ] | [ ] |
| Review response workflow | [ ] (N/A — no data collected) | [ ] | [ ] (N/A) | [ ] (N/A) |
| Satisfaction survey | [ ] | [ ] | [ ] | [ ] |
All five boxes for every data flow should be checked before any lead capture or patient communication campaign goes live.
Frequently asked questions
Q1: Does the DPDP Act apply to small clinics and solo practitioners? Yes — the DPDP Act applies to all entities processing personal data of Indian citizens, regardless of organisation size. There is no SME exemption for healthcare entities. The practical enforcement priority is likely to focus initially on larger organisations, but the legal obligation applies from the Act's commencement.
Q2: Can we send WhatsApp appointment reminders without separate consent? Appointment reminders fall within the purpose for which the patient provided their phone number at booking (appointment management). This is generally considered within the original consent scope. Marketing campaigns, health tips, recall campaigns, and review requests go beyond appointment management and require separate, explicit consent.
Q3: What is a Data Processing Agreement and do we need one with Google/Meta? A DPA is a formal agreement with a third party that processes data on your behalf, specifying the terms and obligations of that data processing. When you upload patient data to Google or Meta for remarketing, they become data processors for that data. Both Google Ads and Meta Ads have standard DPA terms within their platforms — you need to have accepted these terms and have them on record. ICG reviews DPA compliance as part of setting up CRM remarketing for healthcare clients.
Q4: What is the penalty for DPDP non-compliance? The DPDP Act provides for penalties up to ₹250 crore for significant violations (such as failure to implement data protection obligations or breach notification failures). Penalties are imposed by the Data Protection Board of India. The enforcement mechanism is still being established as of 2026, but the legal framework and penalties are in place.
Q5: Do patients have the right to know what data we hold about them? Yes. Under the DPDP Act's right to access, patients can request information about what personal data you hold, for what purpose, and to whom it has been disclosed. You must respond to access requests — the timeframe will be specified in the DPDP Rules when finalised, but 30 days is a reasonable operational target.
Q6: How does ICG handle DPDP compliance in GBP-adjacent data workflows? ICG implements consent collection at appointment booking (separate clinical and marketing consent), uses only consented contacts for review request and recall campaigns, ensures review responses are DPDP-compliant (no patient data disclosed), and documents consent bases for all CRM remarketing uploads. For hospital clients, ICG's technical team can audit the appointment booking form and CRM data flows against DPDP requirements as part of the engagement.
Sources:
- DPDP Act 2023 — meity.gov.in (Digital Personal Data Protection Act)
- NMC Ethics Code 2026 — nmc.org.in (patient confidentiality provisions)
- Google Ads Data Processing Terms — ads.google.com
- Meta Data Processing Terms — facebook.com/legal/terms/dataprocessing
- ICG internal DPDP compliance audit data, 2026
Compliance note. This article provides general guidance on DPDP Act compliance for GBP-adjacent data flows. It does not constitute legal advice. The DPDP Rules (which will specify operational implementation requirements) were pending finalisation as of mid-2026 — check meity.gov.in for current rules before implementing any data management policy changes. Consult a legal professional for specific compliance guidance.
Internal links:
- NMC-Safe GBP Content for Doctors
- NABH Digital Standards for Hospital GBPs
- Google Review Management — How Reviews Drive Rankings
- Local SEO for Healthcare — Complete 2026 Guide
- Google Business Profile Management Services
- Healthcare App Development Agency India
Book a free 30-minute Brand & Growth Diagnostic.
It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.
Questions readers ask
about this topic.
The three platforms
behind every ICG engagement.
Beacon
CAPI middleware that fixes Event Match Quality, translates CRM statuses to Meta-standard events, dedups across channels.
Agency OS
Live client dashboard. GSC, GA4, Google Ads, Meta Ads, IVR calls in one view. Login anytime, not monthly.
Phoenix
Clinic revenue intelligence over your PMS. Daily action queue: Prevent Loss, Maintain & Engage, Grow Revenue. 46-centre rollout.
Or book a free 30-min audit to see all three in action on your account.
Healthcare brands
that already run on ICG.
A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.
What ICG clients say · on video.
"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."
"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."
"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."
Need help operationalising this?
Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.
More from
ICG.
Healthcare AIO is the discipline of getting your clinic or hospital cited inside Google AI Overviews, ChatGPT and Perplexity answers — not j...
Conversational-search advertising places brand messages inside AI chat answers — ChatGPT, Perplexity, Copilot — rather than beside a results...
NABH digital compliance means every claim, image and testimonial your hospital publishes online matches what an accreditation surveyor can v...
Stop guessing.
Book a Diagnostic.
30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.

Meta Catalyst IQ long-term comparison view charting Meta Ads performance across quarters with spend, CPQL and volume overlaid" width="1200" height="675" loading="lazy" decoding="async" style="width:100%;height:auto;display:block;">