News Analysis • 4 mins
Government Bans Local Aadhaar Storage by CSCs as DPDP Rules 2025 Phased Rollout Advances
MeitY informs Parliament that decentralized CSC operators cannot store Aadhaar or health data, highlighting compliance risks for healthtech enterprises reliant on local partner networks.
Last updated:
What happened
The government recently informed Parliament that Village Level Entrepreneurs operating over 5.8 lakh Common Service Centres are explicitly unauthorized to collect or store citizen data, including Aadhaar and health records. According to a TechObserver report, the Ministry of Electronics and Information Technology outlined a strict three-phase implementation timeline for the Digital Personal Data Protection Rules, 2025, which were notified on 13 November 2025. Phase one focuses on establishing the Data Protection Board of India, comprising a Chairperson and four Members, with recruitment advertisements published in the Employment News on 6 June 2026. Phase two will commence on 13 November 2026, marking the start of Consent Manager registrations.
Does the DPDP Act apply here?
The Digital Personal Data Protection Act, 2023 applies strictly to the processing of digital personal data within India, as outlined in Section 3 of the Act. This includes personal data collected in digital form or digitized subsequently. In the healthcare sector, patient records, diagnostic data, and identity markers like Aadhaar processed by decentralized intake desks or third-party franchise clinics fall firmly under this mandate. The data is not corporate IP or anonymised statistics, meaning the central enterprise remains accountable for how these local nodes handle the information.
Legal implications under DPDP
Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. The government mandate against localized storage at Common Service Centres reinforces the principles of purpose limitation and data minimization. While the DPDP Act 2023 does not create a separate sensitive data category, the high volume and inherent risk associated with processing health and identity data are critical factors when the government designates a Significant Data Fiduciary. Organizations must ensure that any third party collecting data on their behalf does not retain unauthorized local copies, as the central healthtech enterprise bears the ultimate liability for breaches or non-compliance.
Could this happen to you
For a Head of Compliance at a large healthtech enterprise, decentralized data collection is a massive operational risk. Your hospital chain likely relies on local diagnostic centers, franchise clinics, or partner pharmacies to onboard patients. If a local desk operator improperly stores a patient Aadhaar scan or medical history locally instead of pushing it to your central secure server, you face immediate regulatory exposure. In the event of a breach, the DPDP Rules, 2025 require a detailed report to the Data Protection Board within 72 hours, alongside intimation to affected Data Principals without delay. The DPBI would immediately demand your processor contracts, audit trails of local data deletion, and your complete RoPA. Producing health-grade privacy evidence across thousands of decentralized nodes is incredibly difficult without automated data mapping tools.
What companies should do in the next 30 days
1. The Head of Compliance must mandate a comprehensive mapping of patient data flows across all decentralized intake nodes to update the central RoPA.
2. The legal team must review and amend vendor agreements with local collection centers to explicitly prohibit the localized storage of identity and health records.
3. IT operations must implement technical controls to auto-delete local caches at intake kiosks immediately after the data is transmitted to the central server.
4. The compliance office must prepare a regulator-ready evidence pack proving that local nodes do not retain unapproved copies of consent artefacts.
What to watch
Phase two of the Rules rollout begins on 13 November 2026, which will introduce the registration framework for Consent Managers. Organizations should use this window to evaluate how their current patient portals will integrate with these new entities. With the Data Protection Board actively recruiting as of June 2026, early enforcement frameworks are rapidly taking shape. Exactly 267 days remain until the 13 May 2027 hard deadline for full compliance. Healthtech compliance teams can check their readiness for these decentralized risks by running a diagnostic at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act restrict local partner clinics from storing patient health data?
Yes. The government recently clarified that decentralized operators, such as Common Service Centres, cannot store data like Aadhaar or health records locally. The central enterprise remains fully accountable under the Digital Personal Data Protection Act, 2023 for ensuring partner clinics do not retain unauthorized local copies.
What happens if a franchise clinic breaches patient data?
The central healthtech enterprise, acting as the Data Fiduciary, is fully liable for data collected by its processors or decentralized nodes. The DPDP Rules, 2025 require you to submit a detailed report to the Data Protection Board within 72 hours of a breach. You must also provide intimation to affected Data Principals without delay.
When is the deadline to comply with the DPDP Rules 2025?
The rules establish an 18-month transition period spread across three phases. Exactly 267 days remain until the 13 May 2027 hard deadline. It is crucial to start mapping your decentralized data flows and updating your RoPA immediately.
How do we prove compliance across hundreds of decentralized collection centers?
You must build a regulator-ready evidence pack that includes updated vendor contracts, technical logs showing local cache deletion, and a comprehensive RoPA. Without automated data mapping, proving health-grade privacy across decentralized networks is extremely challenging and labor-intensive for a compliance team.
Will the Data Protection Board accept our existing patient intake consent forms?
Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Your existing forms must be updated to meet the specific itemised notice and clear affirmative action standards of the new legislation. You must also maintain reliable, centralized audit trails of these consent artefacts.
ComplyDP