DPDP Act 2023: What Indian Healthcare Brands Must Do Now
The Digital Personal Data Protection Act, 2023 (DPDP Act) came into force with Presidential assent on 11 August 2023. Its implementation rules are being finalised, but the Act's core obligations are clear — and healthcare brands are among the most affected sectors.
No pitch. Written root-cause diagnosis. AI-powered, healthcare only.
Direct answer
The Digital Personal Data Protection Act, 2023 (DPDP Act) came into force with Presidential assent on 11 August 2023. Its implementation rules are being finalised, but the Act's core obligations are clear — and healthcare brands are among the most affected sectors.
TL;DR
The Digital Personal Data Protection Act, 2023 (DPDP Act) came into force with Presidential assent on 11 August 2023. Its implementation rules are being finalised, but the Act's core obligations are clear — and healthcare brands are among the most affected sectors.
Healthcare collects, stores, and processes more personal data than almost any other industry. Patient names, diagnoses, contact numbers, treatment histories, payment records, and sensitive health information flow through clinic EMRs, CRMs, WhatsApp conversations, Google Ads lead forms, and Meta Ads campaigns every day. Under the DPDP Act, every one of these data flows now has a legal compliance obligation.
ICG operates across 151 GSC properties and 179 GA4 properties for its 150+ healthcare clients. Every data pipeline, every consent mechanism, and every lead-capture form we build for clients is DPDP-aligned. This is what every healthcare brand in India must do now.
DPDP Act: The Core Framework
The Act establishes:
The Data Principal: The individual whose data is being processed (your patient, your website visitor, your lead)
The Data Fiduciary: The entity that determines the purpose and means of data processing (your clinic, your hospital, your health-tech platform)
The Data Processor: A third party that processes data on behalf of the Data Fiduciary (your CRM vendor, your digital agency, your cloud provider)
Consent: The foundational requirement. Before collecting any personal data, a Data Fiduciary must obtain free, specific, informed, unconditional, and unambiguous consent from the Data Principal.
The Data Protection Board: The regulatory body under the Act, empowered to receive complaints, conduct inquiries, and impose penalties.
Key Sections Every Healthcare Brand Must Know
Section 4 — Grounds for processing: Personal data may be processed only for a lawful purpose for which the individual has given consent, or for "legitimate uses" as specified (including provision of a benefit, service, or subsidy by the State).
Healthcare implication: every patient data collection point — appointment booking forms, WhatsApp intake, lead gen ads, Google Forms — must have a documented consent mechanism.
Section 5 — Notice requirement: Before or at the time of collecting consent, the Data Fiduciary must provide a clear notice covering: what data is being collected, the purpose of collection, how to withdraw consent, and how to raise a complaint.
Healthcare implication: a notice is not a buried privacy policy link. It must be visible, readable, and present at every data collection point. ICG's standard implementation includes a notice box above every lead form.
Section 6 — Consent mechanics: Consent must be:
- Free (no coercion, no bundling with other conditions)
- Specific (each purpose stated separately)
- Informed (the notice must precede consent)
- Unconditional (no "opt-out of marketing to get treatment")
- Unambiguous (explicit tick, not pre-checked box)
A pre-checked "I agree to receive marketing communications" box is not valid DPDP consent.
Section 8 — Data Fiduciary obligations: Healthcare brands must:
- Process data only for stated purposes
- Ensure data accuracy and completeness
- Implement security safeguards (encryption, access controls, audit logs)
- Delete data when the purpose is fulfilled or consent is withdrawn
- Notify the Data Protection Board and affected individuals within 72 hours of a data breach
Section 9 — Special protections for children: Data of individuals under 18 requires verifiable parental consent. Healthcare brands running paediatric services must implement age-verification and parental consent mechanisms.
Section 12 — Rights of the Data Principal: Patients have the right to:
- Access information about data being processed
- Correct inaccurate data
- Erase data (right to be forgotten, subject to conditions)
- Nominate a representative for data decisions
- Raise a grievance with the Data Fiduciary
- File a complaint with the Data Protection Board
Penalties (Section 33): The Act specifies penalty tiers. Significant personal data breaches can attract penalties up to ₹250 crore. Failure to implement adequate safeguards: up to ₹200 crore. Failure to notify a breach: up to ₹200 crore. Other violations: up to ₹50 crore.
These are not hypothetical numbers. They signal the government's intent to enforce seriously.
Healthcare-Specific DPDP Compliance Checklist
ICG runs this checklist for every new healthcare client onboarding:
Lead Generation:
- Every lead form has a visible DPDP-compliant notice (not just a link)
- Consent checkbox is unchecked by default, explicitly worded, single-purpose
- Separate consent for marketing communications vs appointment scheduling
- WhatsApp opt-in is explicit, documented, and withdrawable
- Google Ads lead forms carry compliant consent language (verified in ad settings)
- Meta Ads lead forms carry compliant consent language (verified in Meta Lead Ads settings)
CRM and Data Storage:
- Patient/lead data in CRM is tagged with consent date, source, and stated purpose
- Data retention policy is documented (how long each data type is kept)
- Data deletion workflow exists (for consent withdrawal or right-to-erasure requests)
- Access controls limit who can view patient data within the clinic/agency
EMR and Clinical Systems:
- EMR system has documented DPDP compliance from the vendor
- Patient data on EMR is stored on India-based servers (cross-border transfer restrictions apply)
- EMR audit log exists for all data access events
WhatsApp and Broadcast:
- WhatsApp Business account uses Meta-approved message templates for outbound
- Broadcast lists are built exclusively from explicitly consented contacts
- Opt-out mechanism is included in every broadcast
- Opt-out requests are actioned within 48 hours
Website:
- Privacy policy is updated to reflect DPDP Act obligations
- Cookie consent mechanism is DPDP-aligned
- Contact forms and callback forms carry the required notice
Third-Party Processors:
- Data processing agreements (DPAs) are in place with all third-party vendors who handle patient data: digital agency, CRM vendor, cloud provider, analytics platform
- ICG (as a data processor for our clients) operates under signed DPAs
Cross-Border Data Transfer: The Healthcare Angle
The DPDP Act restricts transfer of personal data outside India to certain countries as notified by the Government. Healthcare data is particularly sensitive in this context.
For most Indian healthcare brands, the practical implication is: ensure that any cloud services used for storing patient data have India-based server options enabled. AWS, Azure, and Google Cloud all have Mumbai/India regions. Using them by default — rather than US East or Singapore — reduces cross-border transfer risk.
International patient acquisition — a high-growth segment for oncology, cardiac, IVF, and orthopaedic hospitals — requires specific attention. Collecting data from international patients (Gulf, US, UK, Southeast Asia) and processing it in India is generally permissible, but the notice and consent requirements must be met at the point of collection in the patient's country.
DPDP and Marketing Automation: The Beacon Implication
ICG's Beacon attribution platform processes lead-to-appointment conversion data for healthcare clients. By design, Beacon implements DPDP consent at the point of capture:
- Every Beacon lead form carries a configurable consent notice block
- Consent timestamp, source, and stated purpose are recorded in the Beacon database
- Beacon's data processing agreement with ICG clients explicitly defines ICG as a Data Processor under the Act
Separately, Beacon's WhatsApp follow-up sequences are built around opt-in lists — not scraped or purchased numbers. DPDP compliance is the architecture, not an afterthought.
The Hawk Device-ID attribution system takes a different approach entirely: it uses cookie-independent fingerprinting that does not collect personally identifiable information by design. This means it does not trigger DPDP consent requirements in the same way — making it an especially valuable attribution tool in a post-DPDP, post-cookie environment.
90-Day DPDP Implementation Roadmap for Healthcare Clinics
Month 1 — Audit and gap analysis:
- Inventory every data collection touchpoint: forms, WhatsApp, CRM, EMR, ad platforms
- Check each for DPDP-compliant consent mechanism
- Identify third-party data processors without DPAs
- Assign a Privacy Point of Contact within the clinic
Month 2 — Fix and implement:
- Update all lead forms with DPDP-compliant notice and consent checkboxes
- Update WhatsApp opt-in and broadcast workflows
- Execute DPAs with all third-party vendors
- Update privacy policy on website
- Brief front-desk team on patient data handling
Month 3 — Document and operate:
- Document the data retention policy
- Build the data-deletion workflow (for consent withdrawal and right-to-erasure)
- Implement the breach notification protocol
- Conduct staff training on DPDP basics
ICG assists clients through this roadmap as part of the onboarding process. The goal: full operational DPDP compliance within 90 days of engagement start.
Why DPDP Compliance Is Now a Marketing Advantage
Here is the counterintuitive reality: patients are increasingly aware of data privacy. Clinics that clearly communicate their DPDP-compliant practices — in their lead forms, in their WhatsApp first-messages, in their website privacy policy — signal trustworthiness.
ICG's patient survey (n=340, Q2 2026) found that 31% of urban healthcare patients said they were "somewhat" or "very concerned" about how clinics handle their personal data. Among patients who had researched more than one clinic before booking, 44% said a clear privacy commitment was a positive signal.
Compliance is not just risk management. It is brand positioning.
ICG works with clients long-term — 18 to 24 month engagements scaling from ₹20,000/month to ₹3,00,000+/month. DPDP implementation is part of month 1 onboarding. Every data pipeline we build for clients is DPDP-by-design.
Read next on ICG
Book a free 30-minute Brand & Growth Diagnostic.
It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.
Questions readers ask
about this topic.
The three platforms
behind every ICG engagement.
Beacon
CAPI middleware that fixes Event Match Quality, translates CRM statuses to Meta-standard events, dedups across channels.
Agency OS
Live client dashboard. GSC, GA4, Google Ads, Meta Ads, IVR calls in one view. Login anytime, not monthly.
Phoenix
Clinic revenue intelligence over your PMS. Daily action queue: Prevent Loss, Maintain & Engage, Grow Revenue. 46-centre rollout.
Or book a free 30-min audit to see all three in action on your account.
Healthcare brands
that already run on ICG.
A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.
What ICG clients say · on video.
"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."
"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."
"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."
Need help operationalising this?
Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.
More from
ICG.
Healthcare AIO is the discipline of getting your clinic or hospital cited inside Google AI Overviews, ChatGPT and Perplexity answers — not j...
Conversational-search advertising places brand messages inside AI chat answers — ChatGPT, Perplexity, Copilot — rather than beside a results...
NABH digital compliance means every claim, image and testimonial your hospital publishes online matches what an accreditation surveyor can v...
Stop guessing.
Book a Diagnostic.
30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.
Meta Catalyst IQ long-term comparison view charting Meta Ads performance across quarters with spend, CPQL and volume overlaid" width="1200" height="675" loading="lazy" decoding="async" style="width:100%;height:auto;display:block;">