What is DPDP Act?
The Digital Personal Data Protection Act, 2023 is India’s data protection law. With the DPDP Rules notified in November 2025, it governs how organisations collect, use, store and share digital personal data, and requires clear notice, valid consent and reasonable security safeguards.
Why it matters for hospitals
Hospital marketing runs on personal data: enquiry forms, call recordings, WhatsApp chats, CRM records and ad audiences. Penalties under the Act reach up to ₹250 crore for failing to take reasonable security safeguards, so data practices are now a board-level risk, not a back-office detail.
How to put it into practice
- Map every place marketing collects personal data and the purpose for each.
- Give a clear notice and capture specific consent before marketing use.
- Keep a consent record you can produce on request, and honour withdrawal quickly.
- Limit retention and access, and agree data terms with agencies and vendors.
The common mistake
Assuming a privacy policy link is enough. The Act expects notice and consent at the point of collection, in plain language.
An illustrative example
A hospital rebuilds its enquiry form with a short notice, an unticked marketing consent box and a stored consent log. Its remarketing audiences now include only patients who agreed. (Composite example, not a specific hospital.)
Related terms
Further reading
- Attribution in healthcare: what you can know
- What a hospital CRM is actually for
- Hospital digital marketing in India: key statistics 2026
Part of the healthcare growth and digital glossary. Last reviewed 3 October 2026.
