DPDP Act 2023 Healthcare Marketing Guide — Clinics + Hospitals | ICG
Author: Deep Das · Co-Founder, ICG · IIT BHU · July 2026 The Digital Personal Data Protection Act 2023 received Presidential assent in August 2023 and is being implemented in phases through 2025-2026. For healthcare marketing teams, it crea...
No pitch. Written root-cause diagnosis. AI-powered, healthcare only.
Direct answer
Author: Deep Das · Co-Founder, ICG · IIT BHU · July 2026 The Digital Personal Data Protection Act 2023 received Presidential assent in August 2023 and is being implemented in phases through 2025-2026. For healthcare marketing teams, it crea...
TL;DR
Author: Deep Das · Co-Founder, ICG · IIT BHU · July 2026
The Digital Personal Data Protection Act 2023 received Presidential assent in August 2023 and is being implemented in phases through 2025-2026. For healthcare marketing teams, it creates specific obligations around patient data collection, storage, and use that intersect directly with every major marketing channel: Google Ads, Meta Ads, WhatsApp marketing, CRM management, lead forms, and patient testimonials.
Most healthcare marketing programmes in India are not yet fully DPDP-compliant. This guide explains what is required and how to implement it without disrupting the marketing programme.
Why healthcare is DPDP's highest-risk category
Under DPDP Act 2023, health data is implicitly treated as sensitive personal data — requiring the highest level of protection and the most explicit consent standard.
Healthcare marketing generates health-adjacent data at every touchpoint:
- A patient who fills in a "Book a LASIK consultation" form is disclosing that they are considering a medical procedure
- A patient who messages a WhatsApp bot about IVF is sharing reproductive health information
- A CRM lead record that includes "IVF enquiry" in the notes field contains health-related personal data
- A patient testimonial video where the patient describes their fertility journey is health data
Every one of these data points is governed by DPDP Act 2023's consent, minimisation, accuracy, retention, and security obligations.
The 5 core DPDP obligations for healthcare marketers
Obligation 1: Explicit, informed, specific consent
Before collecting any patient personal data, obtain consent that is:
- Explicit: Active affirmation required — not a pre-ticked checkbox, not a "by using this website" clause
- Informed: Clear explanation of what data is collected, why, how it will be used, who it will be shared with, and for how long
- Specific: Separate consent for each distinct use. Consent for appointment scheduling does not cover use for marketing broadcasts
ICG's implementation:
WhatsApp 4-Bot first message: "By continuing this conversation, you consent to [Clinic Name] collecting your contact details and health information for appointment scheduling. For health updates and offers, reply YES to opt in."
This two-part structure:
- Appointment scheduling consent: implicit in continuing the conversation (legitimate purpose basis)
- Marketing communication consent: explicit opt-in required separately
Obligation 2: Data minimisation
Collect only what is necessary for the stated purpose. A lead form asking for "name, phone, email, and condition of interest" is appropriate for appointment scheduling. The same form asking for date of birth, Aadhaar number, and current medication is not — this exceeds what is necessary.
ICG's audit of healthcare marketing lead forms at engagement start: 60-70% of forms collect at least one field that exceeds the minimisation standard. Common violations: asking for date of birth in initial enquiry forms, asking for current doctor's name (not necessary for appointment scheduling), asking for specific diagnosis in the enquiry form.
Obligation 3: Data accuracy
Patient contact details in the CRM must be kept current. Outdated phone numbers, moved addresses, changed WhatsApp numbers — all represent accuracy failures. CRM systems should prompt for contact detail verification at each patient interaction.
Obligation 4: Retention limits
Healthcare records: minimum 3 years under CEA regulations. Beyond minimum retention, data should be deleted or anonymised. CRM marketing data (enquiry records for patients who never converted to patients): 12-24 months is the reasonable retention period. Marketing list data (WhatsApp Broadcast opt-ins): active consent should be refreshed annually.
Obligation 5: Data security
Minimum requirements: password-protected EMR and CRM access (individual logins, no shared passwords), two-factor authentication for cloud-based platforms, encrypted storage for patient data, role-based access controls (reception staff should not access clinical records beyond appointment scheduling data), and a documented data breach response protocol.
DPDP compliance for specific marketing channels
Google Ads and Meta Ads
Google and Meta are data processors under DPDP Act 2023 — they process conversion event data (clicks, form submissions, WhatsApp initiations) on behalf of the healthcare advertiser (the data fiduciary). Data Processing Agreements with Google and Meta are established through their standard Terms of Service, which are sufficient for DPDP compliance. However: the healthcare advertiser is responsible for obtaining DPDP-compliant consent from patients before their data (hashed identifiers) is sent to Google Enhanced Conversions or Meta CAPI.
ICG's Beacon CAPI implementation for DPDP compliance: Beacon sends hashed, anonymised identifiers (hashed phone and email) to Meta CAPI and Google Enhanced Conversions — not raw personal data. The hashing process is one-way and cannot be reversed by Meta or Google to identify the individual. ICG's Data Processing Note for Beacon deployments documents this data flow for DPDP audit purposes.
WhatsApp Marketing
WhatsApp Broadcast to opted-in patients: requires explicit opt-in consent as described above. ICG's Beacon WhatsApp system maintains separate consent flags for transactional messages (appointment reminders — covered by appointment scheduling consent) and marketing messages (health campaigns, service promotions — require explicit opt-in).
WhatsApp messages containing health-specific content (a message that includes the patient's name and references their condition) is sensitive personal data processing — requires the highest level of consent documentation.
Patient Testimonials
Patient testimonials are health data. DPDP consent for patient testimonials must specify:
- The specific content being used (the video, the quote)
- The platforms on which it will appear (clinic website, Instagram, YouTube, Google My Business)
- The duration of use
- The right of withdrawal (how the patient can request removal)
ICG's patient testimonial consent form (included in the Hawk post-consultation follow-up sequence) collects all four elements in a single WhatsApp-based consent flow — digital consent, timestamped, stored in the CRM against the patient record.
CRM and Lead Management
Every lead record in the CRM is personal data under DPDP. Healthcare-specific lead records (including condition of interest, enquiry source, notes from follow-up calls) are sensitive personal data. CRM providers used by ICG clients (LeadSquared, HubSpot, Zoho) are data processors — Data Processing Agreements are in place with all three.
ICG's Hawk CRM protocol:
- Re-engagement messages to leads older than 90 days include a DPDP re-consent option: "We noticed you enquired with us a while back. If you'd still like information, reply YES — otherwise reply STOP and we won't contact you again."
- Lead records older than 24 months with no interaction are flagged for deletion or anonymisation in the monthly CRM health check.
The 90-day DPDP compliance roadmap
Month 1 — Audit: Map every patient data collection touchpoint (WhatsApp, website form, reception registration, CRM, EMR, ad platforms). Document what data is collected at each touchpoint, for what purpose, and what consent is currently obtained. Identify gaps against DPDP requirements.
Month 2 — Implement: Update WhatsApp 4-Bot with DPDP-compliant consent message. Update website lead forms with explicit, specific consent checkboxes. Update reception registration form with DPDP consent. Implement CRM access controls (role-based, no shared passwords). Draft data retention policy. Update patient testimonial consent process.
Month 3 — Document and train: Create Privacy Notice (what data is collected, why, retention period, patient rights — post on website). Train all staff on DPDP obligations (especially: what staff cannot do with patient data, how to handle patient data deletion requests). Implement breach response protocol.
DPDP penalties
The Data Protection Board (to be established under DPDP Act implementation) will have authority to impose financial penalties:
- Failure to implement adequate security safeguards: up to ₹250 crore
- Failure to notify the Board of a data breach: up to ₹200 crore
- Violation of processing children's data provisions: up to ₹200 crore
- General violations: up to ₹50 crore
For small clinics, the immediate enforcement risk is lower than for large hospital chains — but the regulatory expectation is compliance, and the gap between expectation and reality increases legal exposure over time.
FAQ
Q1: Does DPDP Act apply to handwritten patient records? DPDP Act covers "digital personal data." Handwritten records not digitised are not directly covered. Any digitisation (scanning, EMR entry) brings the data within DPDP scope immediately.
Q2: Is Google Analytics DPDP-compliant for healthcare websites? GA4 uses anonymised identifiers and does not require cookie consent for non-personal data collection in most configurations. Healthcare websites should: (a) implement GA4 in cookieless mode where possible, (b) ensure their Privacy Notice mentions Google Analytics data collection, (c) avoid using GA4 custom dimensions to store patient-identifiable information (name, phone, health condition). ICG's standard GA4 configuration for healthcare clients is DPDP-appropriate — ask for the configuration documentation at engagement start.
Q3: What happens if a patient requests deletion of their data from our CRM? Honour the request within a reasonable timeframe (DPDP Act does not specify a precise timeframe — 30 days is the standard adopted in similar regulations). Exception: data you are legally required to retain (minimum CEA retention for clinical records). Marketing data (CRM lead records, WhatsApp opt-in lists) that exceeds the clinical retention requirement must be deleted on request.
Q4: Is it DPDP-compliant to send a post-consultation WhatsApp asking for a Google review? Yes. A review request message sent to a patient who has provided their WhatsApp number for appointment purposes (and consented to appointment-related communication) falls within the legitimate appointment-related communication scope. The review request does not collect new personal data and does not involve health-specific personal data — it simply requests a public review. No additional DPDP consent is required for this specific message type.
Q5: Does DPDP apply to international patients visiting India for treatment? Yes. International patients whose personal data is collected and processed in India by an Indian healthcare provider are covered by DPDP Act 2023. Apply the same consent and protection standards to international patient data as to domestic patient data.
Compliance note: This article reflects DPDP Act 2023 compliance guidance for healthcare marketing. It is not legal advice. Consult a data protection lawyer for specific legal guidance.
Book a free 30-minute Brand & Growth Diagnostic.
It's a working session, not a sales pitch — you leave with a written root-cause analysis you can act on, whether or not you engage ICG.
The three platforms
behind every ICG engagement.
Beacon
CAPI middleware that fixes Event Match Quality, translates CRM statuses to Meta-standard events, dedups across channels.
Agency OS
Live client dashboard. GSC, GA4, Google Ads, Meta Ads, IVR calls in one view. Login anytime, not monthly.
Phoenix
Clinic revenue intelligence over your PMS. Daily action queue: Prevent Loss, Maintain & Engage, Grow Revenue. 46-centre rollout.
Or book a free 30-min audit to see all three in action on your account.
Healthcare brands
that already run on ICG.
A representative slice of the 150+ healthcare brands ICG has delivered for across India. Most engagements remain under NDA.
What ICG clients say · on video.
"Scale up of organic channels and business consulting. ICG has absolute domain authority in their field."
"Working with ICG transformed how we acquire IVF patients in Gurgaon. They understand the fertility journey from inquiry to consult..."
"What Ichelon accomplished — they got all my ideas and worked over 3-4 months to create an amazing, super-customised website."
Need help operationalising this?
Every ICG service is healthcare-only, NMC + DPDP-aware, and built around the patient-research patterns that drive Indian healthcare growth in 2026.
More from
ICG.
Healthcare AIO is the discipline of getting your clinic or hospital cited inside Google AI Overviews, ChatGPT and Perplexity answers — not j...
Conversational-search advertising places brand messages inside AI chat answers — ChatGPT, Perplexity, Copilot — rather than beside a results...
NABH digital compliance means every claim, image and testimonial your hospital publishes online matches what an accreditation surveyor can v...
Stop guessing.
Book a Diagnostic.
30 minutes. Free. With the AI-powered healthcare-only marketing agency 150+ brands already run on. No slides, no pitch, no hard close.
Meta Catalyst IQ Master Dashboard showing account-level KPIs, spend, CPQL and campaign health for a healthcare Meta Ads account" width="1200" height="675" loading="lazy" decoding="async" style="width:100%;height:auto;display:block;">