A silver padlock close up

DPDP will kill lazy hospital CRM. Good

Last reviewed

4 min read

India’s Digital Personal Data Protection Rules were notified in November 2025 with a phased 18-month runway, and penalties of up to Rs 250 crore for security failures. Hospitals hold some of the most sensitive personal data there is. The law will force a rethink of how patient data flows into marketing, and that is overdue.

What happened

According to the government’s own note, the DPDP Rules 2025 were notified on 14 November 2025, with an 18-month phased window that brings full obligations and penalties into force around May 2027. There have been reports of a proposal to shorten that window, but no formal change has been announced. Penalties go up to Rs 250 crore for failing to take reasonable security safeguards and up to Rs 200 crore for failing to notify breaches or for violations involving children’s data.

A recent Whalesbook explainer on healthcare set out what this means for hospitals: emergency access to data without consent is allowed but must be logged and followed by notice to the patient, children’s records need verifiable parental consent, and data flows between doctors, insurers and labs need to be mapped.

My take

For years, many hospitals treated patient data as a marketing resource that came free with treatment. Phone numbers from registration went into campaign lists. Discharge data triggered promotional messages. Diagnostic records were used to target health check offers. Much of this was done with good intentions, and some of it helped patients. Very little of it was done with clear, specific consent.

DPDP ends that. And I think the industry will be better for it.

Why consent is a brand opportunity

Consent is usually handled by legal teams, written in legal language and presented at the worst possible moment, such as during registration at a busy front desk. Patients sign without reading, and the hospital ends up with consent that is technically valid and practically meaningless.

A better approach treats consent as part of the product:

  • Ask at the right moment. Offer follow-up reminders when a patient is leaving with a prescription, not when they are anxious in a queue.
  • Explain the value in plain words. “We will remind you when your next test is due” gets a very different response from a checkbox about processing personal data.
  • Make choices granular. Let people agree to clinical reminders while declining promotions.
  • Make withdrawal easy. Paradoxically, easy exits increase trust and opt-ins.
  • Show it in the app. A simple privacy dashboard in the patient app signals seriousness.

What most coverage missed

The hospitals that design consent well will end up with smaller but far more valuable databases. Patients who have actively opted in respond better, complain less and stay longer. The hospitals that try to preserve old habits with vague consent will face a steady drip of complaints and, eventually, enforcement.

There is also an organisational point. DPDP forces marketing, IT, legal and clinical teams to agree on who owns patient data and why each use is justified. Many hospitals have never had that conversation. It will be uncomfortable, and it will make their CRM strategy sharper.

What I would do now

  • Map every patient data flow into marketing systems and label the legal basis for each.
  • Separate clinical communications from promotional ones in the CRM.
  • Redesign consent screens in the app, website and front desk with plain language.
  • Log emergency access properly and test the breach notification process before you need it.
  • Retire lists you cannot justify. It will hurt for a quarter and help for years.

What to watch

Watch the first enforcement actions once penalties are live. They will set the tone for the whole sector. Better still, do not wait for them.

Source: Whalesbook; PIB. Figures as reported at the time of writing.

Questions people ask

When do the DPDP Rules come fully into force?

The government notified the Rules on 14 November 2025 with an 18-month phased window, which brings full obligations and penalties into effect around May 2027. A shorter timeline has been proposed but not formally adopted.

What are the penalties under DPDP for hospitals?

Up to Rs 250 crore for failing to take reasonable security safeguards, and up to Rs 200 crore for failing to notify breaches or for violations involving children’s data.

Can hospitals access patient data in an emergency without consent?

Yes, emergency access is allowed, but it should be logged and followed by notice to the patient or guardian.

How should hospitals redesign consent for marketing?

Ask at the right moment, explain the benefit in plain language, separate clinical reminders from promotions, allow granular choices and make withdrawal easy.

Free download

Get the Hospital Digital Growth Audit

A 25-point self-assessment across AI operations, growth & CRM, launches, leadership, and PR. Confirm your email and it arrives in your inbox, along with the full Tools & Checklists set. Occasional notes after; unsubscribe anytime.