Health data, and an Act with no sensitive category
28 August 2026
Health data is personal data under the DPDP Act, with no sensitive category. What hospitals and diagnostics chains must change before 13 May 2027.
The DPDP Act does not create a special category for health data. Unlike the GDPR, there is no Article 9 equivalent listing sensitive data with a higher bar. Everything is personal data, and the same consent standard applies to a diagnostic report as to a newsletter signup.
That sounds like relief. It is not. The absence of a sensitive category means health providers get no separate lawful basis to fall back on, and the general standard — free, specific, informed, unconditional, unambiguous, under Sec. 6(1) — has to carry a clinical relationship it was not obviously designed for.
Where the exposure concentrates
Consent taken at the counter. Registration desks collect identity, contact and clinical information under time pressure, often on paper, often on behalf of someone who is unwell. A notice under Sec. 5 has to be delivered before that consent, in a language the patient can choose, and the record has to show which notice was shown.
Third parties who are not obviously third parties. Labs, imaging centres, insurers, teleconsult platforms and billing processors each receive personal data. Each transfer needs a purpose the patient was actually noticed about.
Retention. Clinical records are held for years under other law, and the Act permits that where a law requires it. What it does not permit is holding everything else on the same schedule because it sits in the same system.
The withdrawal problem
Sec. 6(4) requires withdrawal to be as easy as giving consent was. In a hospital that means a patient who consented at a desk can withdraw without returning to that desk. Most provider systems have no route for this at all, and building one late means retrofitting it across every downstream system that already received the data.