Tools & Checklists · Free template
DPDP consent notice template for hospital marketing
Generate a plain-language consent notice for hospital enquiry forms, WhatsApp flows and follow-up, built around the notice requirements of India’s DPDP Act and Rules.
Template
Build your notice
Timeline
Where the DPDP rules stand
- The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025, with an eighteen-month phased timeline (PIB).
- Provisions on the Data Protection Board took effect first; the consent manager framework follows twelve months after notification, in November 2026; most substantive obligations, including notice and consent, apply from May 2027 (Sansa Legal).
- Maximum penalties run up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to notify a breach (PIB).
Hospitals should not wait for the deadline. Enquiry forms and WhatsApp flows built today will still be running in 2027.
Good practice
How to use the notice
- Show the notice before or at the point of collection, in the language of the form.
- Keep reminders and marketing as separate choices, with marketing unticked by default.
- Record what the patient agreed to, when, and through which form or flow.
- Make withdrawal as easy as giving consent, and honour it across every system.
- Have legal counsel review the final text for your organisation.
More on the marketing side in DPDP consent and hospital marketing and the DPDP Act and a hospital CRM. For WhatsApp, see the WhatsApp consent flow.
FAQ
Questions people ask
In plain language: what personal data is collected, the specific purposes, how to withdraw consent, how to exercise rights, and how to complain to the Data Protection Board.
The Rules were notified on 14 November 2025, and most substantive obligations, including notice and consent, apply from May 2027.
Yes. Separate, unticked choices let patients agree to reminders without agreeing to marketing.
Yes, at any time and as easily as they gave it. Withdrawal must be honoured across all systems.
Up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a breach, among others.
No. It is a starting point for marketing teams. Have legal counsel review the final notice.
