Black fountain pen resting on a stack of papers and envelopes

Consent under DPDP: what changes for hospital marketing

15 min read

DPDP consent for hospitals means marketing can no longer ride on the patient’s registration. Consent for promotional use has to be separate, specific, informed, given by a clear action and as easy to withdraw as to give. That changes registration forms, WhatsApp opt-ins, ad audience uploads, tracking on condition pages, bought or agency leads, old databases and vendor contracts. The work is operational more than legal.

For years, most hospital marketing in India has run on an assumption nobody wrote down: if a patient gave us their number at registration, we could message them about anything. Health check offers, camp invitations, new specialty launches, festival greetings, all sent to the same list built by the front desk for billing and records.

The Digital Personal Data Protection Act ends that assumption. DPDP consent for hospitals is not a new checkbox on an old form. It changes how data is collected at the desk, what marketing can do with a patient list, how leads from outside partners are handled and what happens when a patient says stop. Most of the change falls on marketing, CRM and the contact centre, not on the legal team.

A caution before I start. I am an operator, not a lawyer. What follows is how I think about the practical implications for a hospital’s growth function. Every hospital should work through its own position with counsel and its privacy lead, particularly on which lawful basis applies to which processing.

What DPDP consent for hospitals actually requires

Under the law, the hospital is a data fiduciary: it decides why and how personal data is processed. Patients are data principals. Agencies, CRM providers, messaging platforms and call centre vendors acting for the hospital are data processors, and the hospital remains responsible for what they do.

Where processing relies on consent, the consent has to be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the data needed for the stated purpose. It has to follow a notice, in clear and plain language, that tells the patient what data is collected and why, how to withdraw and how to complain. The patient must be able to read that notice in English or in one of the languages of the Eighth Schedule, which matters a great deal for hospitals serving regional catchments. Withdrawal must be as easy as giving consent.

The law also recognises certain legitimate uses where consent is not the basis, such as responding to a medical emergency, or processing data a person voluntarily provided for a specific purpose. Your counsel will decide how those apply to clinical care and operations. For marketing, I work on a simple rule: if the message is promotional, assume consent is needed, and make sure you can prove you have it.

Separating care from marketing

The most important design decision is to treat care communication and marketing as different purposes, with different consent and different rules.

Care communication covers appointment confirmations, reminders the doctor asked for, report availability, billing and insurance updates. Patients reasonably expect these, and they support the treatment they sought. Marketing covers health check offers, new service announcements, newsletters, camp invitations and anything designed to generate new demand. Each needs its own consent, recorded separately, withdrawable separately.

This separation protects the useful work. A patient irritated by promotional messages who withdraws consent should not lose the reminder about their review visit. If both run through one undifferentiated list, the hospital has to choose between losing its care channel and ignoring the withdrawal, and it cannot do the second. I made a similar point about post-visit journeys in the context of what healthcare marketing automation actually replaces: automation works only when its purpose is clean.

The registration desk is where consent is won or lost

Most patient data enters a hospital at the registration counter, the appointment call or the online booking form. That is where consent has to be designed.

Pre-ticked boxes and consent buried in the terms of registration will not hold up. A patient must not be required to agree to marketing in order to be registered or treated, because consent that is a condition of service is not freely given. The practical design is a short notice, in the patient’s language, followed by a separate, unticked choice about receiving information on health services and offers, with the channel the patient prefers.

Front desk staff need to be trained to present the choice neutrally. If incentives reward the number of marketing opt-ins, some staff will tick the box for the patient, and the hospital will have a database it cannot defend. I would rather have fewer, genuine consents than a large list built on shortcuts.

Every consent should be stored with the time, the channel, the version of the notice shown and the person or system that captured it, in a system of record that marketing tools read from. This is exactly the kind of foundation I described in what a hospital CRM is actually for. A consent that lives only on paper, or only in a messaging tool, cannot be honoured reliably across channels.

Ad platforms, tracking and the patient list

Some of the most common digital marketing practices are also the most exposed.

Uploading patient phone numbers or emails to ad platforms to build custom or lookalike audiences is processing personal data for a marketing purpose, even when the platform hashes it. It needs a lawful basis the hospital can show. Uploading lists segmented by department or condition is more sensitive still, because the audience itself reveals something about the patient’s health. Many hospitals will decide not to do this at all. Those that do should restrict it to patients who gave marketing consent, avoid condition-based segments and document the decision.

Tracking pixels and tags on the website deserve an audit. A pixel on a page about a specific condition, or on an appointment form for a particular specialty, can send signals about a visitor’s health interest to an advertising platform. Review what fires on which pages, remove tracking from sensitive pages and booking steps unless you are confident of the basis, and put a clear cookie and tracking notice in place. This will make some attribution harder. I think that is an acceptable trade, and the limits of what hospitals can know anyway are in attribution in healthcare.

Children need particular care. The law requires verifiable consent from a parent or guardian before processing a child’s data, and it restricts tracking, behavioural monitoring and targeted advertising directed at children. Paediatric marketing, vaccination reminders and school health programmes should be reviewed with this in mind.

WhatsApp, calls and the contact centre

Messaging and calling are where consent is exercised most often, and where it most often goes wrong.

On WhatsApp, the platform already expects an opt-in before a business sends messages, and it treats utility and marketing templates differently. DPDP raises the bar on what that opt-in has to look like. A patient who messaged the hospital to ask about timings has not agreed to receive health check offers. Build the marketing opt-in as an explicit choice inside the conversation or at registration, record it in the consent record, and make STOP work instantly.

Outbound calling needs the same thinking. Contact centres that call enquiries back are generally acting on the person’s own request. Contact centres that call old patient lists to sell packages are doing marketing, and should only call people with recorded consent, alongside the telecom rules on promotional calls that already apply. Call recordings, which often contain health details, need their own retention period and access controls.

Agents should be trained to recognise and act on withdrawal in conversation. “Please do not call me again about this” is a withdrawal, even if the patient never clicks anything. The agent needs a simple way to record it on the spot, and the system has to act on it across every channel.

Leads you did not collect yourself

Hospitals receive personal data from many places they do not control: lead generation agencies, aggregator platforms, health camps run with partners, corporate tie-ups, insurance desks, referring doctors. Each of these raises the same question: under what consent did this person’s data reach us, and does it cover what we intend to do?

For bought or agency-generated leads, ask for evidence of the notice the person saw and the consent they gave, and make sure it names the hospital or clearly covers it. If the agency cannot show it, do not load the data into your marketing systems. For camps, design the registration form with its own notice and separate marketing choice, rather than collecting names on a sheet and adding them to the database later. For corporate health programmes, agree with the employer who is responsible for which data and what employees were told.

This will reduce lead volumes from some sources. The leads that remain will be cleaner, and the hospital will not inherit someone else’s compliance problem.

Withdrawal, retention and the old database

Withdrawal has to work in practice. A patient who replies STOP on WhatsApp, tells an agent they do not want calls, or clicks unsubscribe in an email should be removed from marketing across every channel, quickly, and the withdrawal should flow to every processor holding their data. That requires one consent record that every tool checks before sending. Test it by withdrawing consent yourself as a patient and seeing what still arrives.

Retention is the less visible change. Data should not be kept for marketing once the purpose is served or consent is withdrawn, subject to other legal requirements for keeping medical and financial records. Marketing copies of patient data, such as exports sitting in spreadsheets, old campaign lists, agency folders and chat histories, need an inventory and a clean-up. The effort involved is almost always underestimated, which is the theme of the data work nobody budgets for.

Then there is the legacy database: years of patient numbers collected before the law, with no record of marketing consent. My view is that the hospital should treat it as care data only, and invite patients to give marketing consent through a clear, low-pressure request during their next genuine interaction, such as a visit, a report delivery or a reminder. Blasting the whole list with a consent request is itself a marketing message and should be discussed with counsel first.

Vendors and processors

Almost every hospital runs marketing through vendors: agencies, CRM and messaging platforms, call centres, analytics tools. Under DPDP, the hospital remains accountable for them.

Contracts should state what data the vendor processes, for what purpose, where it is stored, how long it is kept, what security is in place, how breaches are reported to the hospital and how data is returned or deleted at the end. Access should be limited to what the work needs. Agencies should not hold patient lists on their own drives. Review vendor access when staff change and when contracts end. I have written about managing vendors without becoming their project manager, and data obligations are one area where the hospital cannot delegate oversight.

Breaches are the other reason vendor discipline matters. The hospital must notify the regulator and affected patients in the event of a personal data breach, and a vendor who discovers a problem late, or reports it vaguely, puts the hospital in a very difficult position.

Before the next campaign goes out

Treat DPDP as a programme with an owner, not a policy document. In most hospitals, the privacy or compliance lead owns the framework and the head of digital or CRM owns the operational change, with legal advising and IT delivering the systems. Agree that split explicitly.

Then work through a short sequence. Map every place patient data enters the hospital and every system and vendor that touches it for marketing. Redesign registration and booking forms with a clear notice in the right languages and a separate, unticked marketing choice. Build or configure a single consent record that every marketing tool checks. Audit website tracking and remove pixels from sensitive pages. Stop loading third-party leads without evidence of consent. Review and update vendor contracts. Decide how the legacy database will be treated. Then test withdrawal end to end, as a patient would.

None of this stops a hospital marketing well. It pushes the work towards patients who want to hear from you, through channels you can account for, which is where good marketing should have been anyway. The hospital CRM readiness checklist is a useful place to see how much of the foundation already exists.

Questions people ask

What is DPDP consent for hospitals?

DPDP consent for hospitals refers to how hospitals must obtain, record and honour permission to process patients’ personal data under India’s Digital Personal Data Protection Act. Where consent is the basis, it must be free, specific, informed, unambiguous and given by a clear action, after a plain-language notice, and must be as easy to withdraw as to give. For marketing, it usually needs to be separate from consent for care.

Does DPDP stop hospitals from marketing to patients?

No. It changes how marketing is done. Hospitals can still send promotional messages to patients who have genuinely agreed to receive them, through channels they chose, with an easy way to stop. What changes is the old habit of messaging everyone registered for care. Marketing lists become smaller and cleaner, and each contact needs a consent record the hospital can show.

Do appointment reminders need marketing consent?

Care-related communication such as confirmations, reminders the doctor requested and report updates is a different purpose from marketing, and your counsel will advise on the lawful basis that applies. What matters operationally is keeping these messages free of promotion and separate from marketing consent, so a patient who withdraws from offers still receives the reminders that support their treatment.

Can we upload patient lists to ad platforms?

Uploading phone numbers or emails to build audiences is processing personal data for marketing, even when hashed, and needs a lawful basis you can demonstrate. Condition or department segments are more sensitive because they reveal health information. Many hospitals will avoid this entirely. Those that proceed should limit it to consented patients, avoid condition segments and document the decision with legal sign-off.

What should the registration desk change?

Show a short, clear notice in the patient’s language, then offer a separate, unticked choice about receiving information on services and offers, with a preferred channel. Registration or treatment must not depend on agreeing to marketing. Train staff to present the choice neutrally and avoid incentives that reward opt-in counts. Record the time, channel and notice version for every consent.

What about leads from agencies and aggregators?

Ask for evidence of the notice the person saw and the consent they gave, and check that it covers the hospital and the intended use. If the source cannot provide it, do not load the data into marketing systems. Camps and corporate programmes should use their own compliant registration forms, with a separate marketing choice, rather than sheets added to the database later.

What happens to our old patient database?

Data collected before the law usually lacks a record of marketing consent. A cautious approach is to treat it as care data only and invite patients to opt in to marketing during their next genuine interaction with the hospital. Sending a mass consent request is itself a marketing message, so discuss that route with counsel before using it. Clean up stray marketing copies too.

What does IT need to build?

A single consent record, linked to the patient or lead in the CRM, that every marketing and messaging tool checks before sending, and that updates across channels when a patient withdraws. IT should also support data inventory, access controls, retention and deletion, audit logs and breach detection. A consent stored only inside one messaging tool will not be honoured across the others.

Who should own DPDP compliance in marketing?

Typically the privacy or compliance lead owns the framework, the head of digital or CRM owns the operational change in marketing and patient communication, legal advises on interpretation, and IT delivers systems. Write that split down. Without a named operational owner, forms, vendor contracts and tracking audits drift, and the hospital discovers the gaps only when a complaint or breach arrives.

How does DPDP affect website tracking?

Pixels and tags on condition pages or appointment forms can reveal a visitor’s health interest to advertising platforms. Audit what fires on each page, remove tracking from sensitive pages and booking steps unless the basis is clear, and put a proper tracking notice in place. Some attribution will become harder, but the hospital’s exposure falls considerably.

What about children’s data?

The law requires verifiable consent from a parent or guardian before processing a child’s personal data, and restricts tracking, behavioural monitoring and targeted advertising directed at children. Paediatric departments, vaccination reminders and school health programmes should be reviewed with counsel. Marketing that targets parents about their children’s care needs particular thought about what is collected and how.

How much effort does this take?

More than most hospitals expect, but most of it is one-time redesign followed by routine discipline. Mapping data flows, redesigning forms, building the consent record, auditing tracking and updating vendor contracts can take several months across a group. After that, the effort is in keeping the record accurate, training new staff and testing withdrawal regularly.

What should the board or CEO ask about?

Ask who owns DPDP operationally, whether the hospital can show consent for every marketing contact, how quickly a withdrawal takes effect across channels and vendors, whether vendor contracts cover data obligations, and how a breach would be detected and reported. These questions reveal readiness far better than a policy document, and they are worth asking in every quarterly review.

Free download

Get the Hospital Digital Growth Audit

A 25-point self-assessment across AI operations, growth & CRM, launches, leadership, and PR. Confirm your email and it arrives in your inbox, along with the full Tools & Checklists set. Occasional notes after; unsubscribe anytime.