What is DPDP Act?

The Digital Personal Data Protection Act, 2023 is India’s data protection law. With the DPDP Rules notified in November 2025, it governs how organisations collect, use, store and share digital personal data, and requires clear notice, valid consent and reasonable security safeguards.

Why it matters for hospitals

Hospital marketing runs on personal data: enquiry forms, call recordings, WhatsApp chats, CRM records and ad audiences. Penalties under the Act reach up to ₹250 crore for failing to take reasonable security safeguards, so data practices are now a board-level risk, not a back-office detail.

How to put it into practice

  • Map every place marketing collects personal data and the purpose for each.
  • Give a clear notice and capture specific consent before marketing use.
  • Keep a consent record you can produce on request, and honour withdrawal quickly.
  • Limit retention and access, and agree data terms with agencies and vendors.

The common mistake

Assuming a privacy policy link is enough. The Act expects notice and consent at the point of collection, in plain language.

An illustrative example

A hospital rebuilds its enquiry form with a short notice, an unticked marketing consent box and a stored consent log. Its remarketing audiences now include only patients who agreed. (Composite example, not a specific hospital.)

Further reading

Part of the healthcare growth and digital glossary. Last reviewed 3 October 2026.

Free download

Get the Hospital Digital Growth Audit

A 25-point self-assessment across AI operations, growth & CRM, launches, leadership, and PR. Confirm your email and it arrives in your inbox, along with the full Tools & Checklists set. Occasional notes after; unsubscribe anytime.