A metal padlock on an old wooden door

Privacy-safe remarketing in healthcare (DPDP lens)

15 min read

The healthcare remarketing India hospitals can run is narrower than agencies suggest: Google’s health personalised advertising policy blocks customer lists, website visitor lists and lookalikes for health ads, and DPDP consent duties phase in through 2027. Focus on search-led return visits, consented follow-up and owned channels, and audit every tag. This is not legal advice.

In most industries, remarketing is the first thing a performance team switches on: show ads to people who visited the site, upload the customer list, build lookalikes. In healthcare, that playbook runs into two walls. Google’s own policy already blocks most of it for health ads, and India’s data protection law is phasing in obligations that make the rest a consent question. The healthcare remarketing India teams can run today is narrower, and more interesting, than the version most agencies pitch.

This article looks at advertising audiences specifically: what is off the table, what remains, and how to set up tags, consent and governance so that you are not relying on luck. The wider consent design for hospital marketing is in consent under DPDP: what changes for hospital marketing, and the full paid programme sits in the complete guide to Google Ads for doctors in India.

A note before we start: this is an operator’s reading of platform policy and published law, not legal advice. Take specific decisions with your legal counsel and privacy lead.

What Google’s health policy already rules out

Google treats health as a sensitive interest category. Under its health in personalised advertising policy, advertisers promoting products or services related to physical or mental health conditions, treatments, procedures and medical devices cannot use advertiser-curated audiences. That covers Customer Match, your data segments (the lists built from website and app visitors), lookalike segments and audience expansion.

What remains allowed are predefined Google audiences, such as in-market and affinity segments, demographics with exceptions, life events and location targeting, plus custom segments within limits. The policy also says users under 18 should not receive personalised health ads.

In plain terms: the classic “visited the knee replacement page, now follow them around the internet” campaign is not something a hospital should be running on Google for health services. If an agency proposes it, ask them to show you the policy basis. Other ad platforms have their own health rules, which change often, so check each platform’s current policy before assuming anything carries over.

Where the DPDP framework stands in September 2026

The Digital Personal Data Protection Act, 2023 is being brought into force in phases through the DPDP Rules, 2025, notified in the Gazette on 13 November 2025 and announced by the government in a PIB release with an 18-month phased compliance period. The Rules published by MeitY set out the phasing in Rule 1:

  • From publication (November 2025): definitions and the provisions setting up the Data Protection Board.
  • One year after publication (November 2026): the rule on registration and obligations of consent managers.
  • Eighteen months after publication (May 2027): the operational rules, including notice to data principals, security safeguards, breach intimation and retention.

There were press reports earlier this year that MeitY was consulting on shortening that timeline. At the time of writing I could not find a notified amendment, so check the Gazette before you plan around the dates above.

Three provisions of the DPDP Act matter most for patient data advertising once the main obligations apply. Consent must be “free, specific, informed, unconditional and unambiguous with a clear affirmative action” (Section 6(1)). Withdrawing consent must be comparable in ease to giving it (Section 6(4)). And a data fiduciary shall not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children (Section 9(3)), where a child is anyone under eighteen.

The phasing is not a reason to wait. Tag audits, consent redesign and vendor contracts take months in a hospital, and a practice built now does not need rebuilding in 2027.

Remarketing options, sorted by risk

TechniqueGoogle policy for health adsDPDP considerationMy view
Website visitor lists (your data segments)Not allowedTracking-based; needs consentDo not use for health services
Customer Match with patient or enquiry listsNot allowedSharing identifiers with a platform; needs specific consentDo not use for health services
Lookalikes and audience expansionNot allowedBuilt from your dataDo not use for health services
Predefined Google audiences and locationAllowedNo hospital data sharedFine for awareness and launches
Search and contextual targetingAllowedNo hospital data sharedThe backbone of re-capture
Owned channels (WhatsApp, SMS, email) to consented contactsNot an ad audienceNeeds purpose-specific consent and easy opt-outThe most useful “remarketing” you have

What privacy-safe healthcare remarketing India teams can still do

Once you drop lists and pixels, the job changes from following people to being there when they come back. That is less precise, and in my experience it is not much less effective for a hospital, because patients who researched a doctor usually return through search.

  • Own the return search. A well-run brand campaign and strong doctor and specialty pages catch people when they come back to book. Returning patients search the hospital or doctor name; make sure you appear, with the right landing page.
  • Follow up on the enquiry, not the visit. Someone who submitted a form or called has a relationship with you. With consent for that purpose, a callback, a WhatsApp reminder about the slot they asked for or a note with directions is service, not surveillance.
  • Re-engage patients through owned channels. Patients who consented to hear from you can receive relevant, non-clinical reminders. My approach is in re-engaging lapsed patients without being intrusive.
  • Use Google’s audiences for reach, not recall. For a launch or a package, predefined audiences and location targeting can build awareness without any hospital data leaving your systems.
  • Invite a return with content. A newsletter or a WhatsApp channel people choose to join is a consented audience you own.

Performance Max needs particular care here, because its usual audience signals are built from customer data. I cover that in Performance Max for healthcare: when it works.

Consent that covers advertising measurement

Even without remarketing, most paid programmes share some personal data with ad platforms, usually through enhanced conversions for leads, where a hashed email or phone number is sent to Google to measure which ads produced appointments. The mechanics are in call tracking and offline conversion import for hospitals. The privacy point is that this is a distinct purpose, and the notice at the point of collection should say so plainly.

A workable pattern on an appointment form:

  1. A clear notice explaining that details will be used to arrange the appointment, which is the core purpose.
  2. A separate, unticked option to receive health information and offers from the hospital.
  3. A plain sentence on measurement: that contact details may be shared in hashed form with advertising platforms to measure which ads led to appointments, with a link to the privacy notice.
  4. A visible way to withdraw consent that is as easy as giving it, such as a link in every message and an option on WhatsApp.

Whether measurement needs its own consent or can rely on a disclosed purpose is exactly the kind of question to settle with counsel. What I would not do is bury it.

Put limits on enquiry follow-up too. Someone who asked for a cardiology slot consented to hear about that slot, not to a year of messages about every department. Define how long the follow-up purpose lasts, how many attempts the desk makes, and when an unconverted enquiry moves out of active follow-up. Write it into the CRM rules so it does not depend on each agent’s judgement.

Tags, pixels and what they leak

The quietest privacy failures in healthcare advertising are technical. A page URL containing a condition name, passed to every tag on the page. A page title like “Book an appointment for a fertility consultation” sent as an event parameter. A third-party chat widget that records everything typed into it. A pixel firing on a confirmation page that includes the doctor’s specialty.

Audit every tag on your appointment and specialty pages. Keep health information out of URLs, query strings, event names and custom parameters. Make your cookie and consent banner actually control which tags fire, and test that it does. Remove pixels from platforms you no longer advertise on; they keep collecting data long after the campaign ends.

The simplest protection is to collect less in the first place. An ad landing page should ask only for what the booking needs, as I argue in landing pages for doctor consultation ads. Data you never collect cannot leak, cannot be misused by a vendor and never needs a retention decision.

Paediatric pages deserve their own review. Given Section 9(3), I would not run any tracking-based advertising aimed at children, and I would design paediatric campaigns around parents as the audience, using search and contextual placements. The marketing logic is in paediatrics and the parent as the real customer.

Measuring the effect of switching remarketing off

Agencies sometimes resist these changes by pointing to the conversions remarketing campaigns report. Treat those numbers with care. Remarketing audiences are made of people who already knew you, and many of them would have come back anyway. The conversions a remarketing campaign claims are not the conversions it caused.

The fair measure is the change in total honoured appointments for the affected service lines after the change, compared with a period before, and, if you run several units, compared with units where nothing changed yet. Watch brand search volume and brand campaign conversions as well: if returning patients are finding you through search, that is where the demand shows up. In my experience the drop, if any, is smaller than the remarketing reports implied, and the savings are real.

Who owns this inside a hospital

Privacy-safe advertising fails when it belongs to nobody. Marketing owns the campaigns, IT owns the website, an agency owns the tags, a vendor owns the chat widget, and legal sees none of it until something goes wrong.

A simple ownership model works: marketing maintains a register of every tag, audience and data flow; the privacy lead or data protection officer signs off on any new flow; IT controls tag deployment; legal reviews notices and vendor contracts. Agencies and vendors that handle patient data should have data processing terms that say what they can do with it and when they delete it. The hospital CRM readiness checklist includes many of the same data questions, and is a useful companion.

A privacy audit for healthcare remarketing in India

  1. List every audience in every ad account and remove any advertiser-curated audience used for health services.
  2. List every tag and pixel on the website and landing pages, with its owner and purpose.
  3. Check URLs, page titles and event parameters for health information and remove it.
  4. Test that the consent banner actually blocks non-essential tags until the visitor agrees.
  5. Rewrite form notices so each purpose is separate and plainly described.
  6. Confirm withdrawal works across WhatsApp, SMS, email and the CRM.
  7. Review agency and vendor contracts for data processing terms.
  8. Review paediatric campaigns and pages for any tracking-based targeting.
  9. Repeat the audit after every site rebuild and at least twice a year.

What to tell the board

The honest message is that hospital advertising now gives up some precision for trust and compliance, and that the trade is worth it. Google’s policy already prevents the most intrusive techniques for health ads. The DPDP framework adds consent, purpose and withdrawal duties that are phasing in through 2027. The hospitals that do well will be the ones whose patients choose to stay in touch, not the ones with the biggest pixel audiences.

Put a date on the audit, a name on the tag register and a line in the budget for consent redesign. That is a more defensible position than any retargeting lift figure an agency can show you.

Questions people ask

What does healthcare remarketing in India look like today?

It is mostly search-led and consent-led. Google’s health personalised advertising policy stops health advertisers using customer lists, website visitor lists and lookalikes, so the work shifts to owning brand and doctor searches, following up enquiries with consent, re-engaging consented patients on owned channels, and using Google’s predefined audiences and location targeting for reach without sharing hospital data.

Is retargeting website visitors allowed for hospital ads on Google?

For ads promoting health conditions, treatments or procedures, Google’s policy does not allow advertiser-curated audiences, which include your data segments built from website visitors, Customer Match and lookalikes. Predefined Google audiences and location targeting remain available. Check how your specific ads are classified, and do not try to run the same lists through another campaign type.

When do DPDP obligations actually apply to hospital marketing?

The DPDP Rules, 2025 were notified in November 2025 with phased commencement. Consent manager provisions follow one year after publication, and the main operational rules, including notice requirements, follow eighteen months after publication, which points to May 2027. Check the Gazette for any amendment. This is general information, not legal advice; confirm specifics with counsel.

Why should the CEO invest in this before the deadlines?

Because the work takes time in a hospital. Tag audits, consent redesign across forms and WhatsApp, CRM changes and vendor contract reviews each involve several teams. Doing it early spreads cost, avoids a rushed rebuild before the deadline, and reduces the risk of a public complaint in the meantime. Patients also notice when a hospital handles their data carefully.

Does losing remarketing hurt performance?

It removes one tool, but for hospitals the loss is smaller than in retail. Patients who research a doctor usually come back through search, so a strong brand campaign and good landing pages capture much of the return journey. Enquiry follow-up and consented owned channels do the rest. Measure cost per honoured appointment before and after to see the real effect.

What should compliance check on appointment forms?

That each purpose is described separately and plainly, that marketing consent is optional and unticked, that any sharing of hashed data with ad platforms for measurement is disclosed, that the privacy notice is linked, and that withdrawal is as easy as giving consent. Compliance should also check that forms do not collect health details the booking does not need.

What does IT need to do about tags and pixels?

Maintain a register of every tag with an owner and purpose, keep health information out of URLs and event parameters, make sure the consent banner actually blocks non-essential tags, and remove pixels from platforms no longer in use. IT should also control who can publish tags, so agencies cannot add tracking without review.

Can we upload our patient list to Google for Customer Match?

Not for ads promoting health services, under Google’s health in personalised advertising policy. Beyond the platform rule, uploading patient identifiers to an ad platform raises consent and purpose questions under the DPDP framework. Use consented owned channels such as WhatsApp, SMS and email to stay in touch with existing patients instead.

What about paediatric services and children’s data?

The DPDP Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children, where a child is anyone under eighteen. Google’s policy also excludes users under 18 from personalised health ads. Design paediatric campaigns for parents, using search and contextual placements, and review paediatric pages for any tracking-based targeting.

What should we require from our agency on privacy?

Written data processing terms, a list of every tag and audience they have created, no advertiser-curated audiences for health services, no uploads of patient data without sign-off from your privacy lead, and prompt removal of tags they no longer need. Ask for a privacy section in the monthly report showing any changes to tags, audiences or data flows.

Is enhanced conversions for leads a form of remarketing?

No. It is measurement: hashed contact details are matched to ad interactions to show which ads produced appointments. It does not build an audience for targeting. It is still a sharing of personal data with an ad platform, so disclose it plainly in your notice and settle with counsel whether it needs separate consent in your setup.

How long does a privacy audit of our advertising take?

For a single hospital or clinic with one website, the first audit can usually be done in a few weeks, most of it spent finding tag owners and agreeing fixes. Multi-unit groups with several agencies and legacy microsites take longer. Plan fixes as a short project, then repeat the audit after each site rebuild and at least twice a year.

Who should own privacy-safe advertising inside a hospital?

Marketing should own the register of tags, audiences and data flows, because it creates most of them. The privacy lead or data protection officer approves new flows, IT controls tag deployment and legal reviews notices and vendor contracts. Without a named owner, responsibility falls between the agency, IT and marketing, and problems surface only after a complaint.

Free download

Get the Hospital Digital Growth Audit

A 25-point self-assessment across AI operations, growth & CRM, launches, leadership, and PR. Confirm your email and it arrives in your inbox, along with the full Tools & Checklists set. Occasional notes after; unsubscribe anytime.

Read my takes first in Google Search