NEWS ANALYSIS • 4 mins
DPDP Act 2023 Consent Paradox Creates Litigation Risks For Healthtech Legal Teams
A recent analysis highlights the operational tension surrounding consent under the DPDP Act 2023. General Counsels in healthcare must update patient intake workflows and vendor contracts to align with the Rules 2025 and mitigate regulator enforcement risks.
Last updated:
What happened
Author Rajlaxmi Singh published an analysis in the Daily Pioneer critiquing the practical application of consent under the Digital Personal Data Protection Act, 2023. The article notes that the 2017 Supreme Court judgment in KS Puttaswamy v. Union of India established privacy as an intrinsic dimension of human dignity. Despite this constitutional foundation, Singh asserts that the law's treatment of consent creates an unresolved tension between individual autonomy and administrative practicality. The author warns that without proper operational mechanisms, consent risks becoming largely ceremonial and managed by exception.
Does the DPDP Act apply here?
This analysis evaluates the core applicability of the Digital Personal Data Protection Act, 2023, which governs digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. For a General Counsel at a healthcare provider or healthtech platform, this means every digital patient record, consultation log, and prescription flow falls under the purview of the Act. Section 3 of the Act confirms it applies to data collected in digital form or in non-digital form and digitised subsequently. The law exempts only personal or domestic processing, and data made publicly available by the individual.
Legal implications under DPDP
Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Singh highlights the tension between obtaining meaningful consent and administrative realities. To address this, the DPDP Rules, 2025 introduce operational specifics requiring itemised notices that detail the personal data collected and the specific purpose of processing. This establishes clear baseline requirements for transparency and purpose limitation. Additionally, healthtech companies must note that cross-border transfers of digital personal data to foreign cloud vendors are generally permitted unless the Central Government restricts transfer to notified countries or territories. Legal teams must ensure vendor agreements reflect these purpose limitations to control liability allocation.
Could this happen to you
For a Legal Head in a healthtech enterprise, treating patient consent as a ceremonial checkbox presents an immediate litigation risk. If a clinic's intake process relies on bundled consent without clear opt-ins, it fails the itemised notice standard established by the Rules, 2025. In the event of a regulatory audit or an incident, the Data Protection Board of India (DPBI) will scrutinise your consent artifacts and demand evidence of legal basis. Furthermore, if a breach occurs, you are required to provide intimation to affected Data Principals without delay and a detailed report to the DPBI within 72 hours. Your defensibility depends on mapped patient data flows and strict limitation of liability clauses in your vendor contracts.
What companies should do in the next 30 days
1. General Counsels must audit existing patient intake flows to confirm consent is the primary basis for processing, except where Section 7 legitimate uses apply, documenting this review to minimize outside counsel spend. 2. Compliance leads should draft updated itemised notices aligned with the DPDP Rules, 2025, detailing data types and processing purposes for clinic deployment. 3. Legal teams must review contracts with cloud hosting vendors, ensuring indemnities protect the healthcare provider and confirm the 72-hour breach reporting workflow is defined. 4. IT and legal departments must collaborate to map patient data flows to prepare for potential Significant Data Fiduciary (SDF) designation, creating a defensible architecture for future regulator engagement.
What to watch
The author notes that India's privacy framework will require further maturation through legislative revision and judicial interpretation. Courts will likely clarify the acceptable boundaries between administrative practicality and constitutional privacy rights over the coming years. General Counsels should closely monitor early DPBI enforcement trends regarding itemised notices and breach responses to adjust their regulator defensibility strategies. Exactly 282 days remain until the 13 May 2027 hard compliance deadline. Assess your current defensibility and health-grade privacy posture by running a confidential evaluation at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to all patient data in our clinic?
Yes. The Act covers digital personal data processed within India, and processing outside India connected to offering goods or services to Data Principals in India. This includes digitized patient health records, appointment histories, and consultation logs.
Do we always need consent to process health data under DPDP?
No, but consent is the primary basis for processing, except where Section 7 legitimate uses apply. While medical emergencies may fall under legitimate uses, routine healthtech operations and elective procedures require clear, verifiable consent accompanied by an itemised notice.
What happens if our cloud vendor suffers a data breach?
Under the DPDP Rules, 2025, you must provide intimation to affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours. General Counsels must ensure vendor contracts include strict indemnities and liability allocation to cover this risk.
Can we transfer patient records to foreign servers?
Yes. Cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. Legal teams must ensure vendor agreements clearly outline purpose limitations and data handling obligations.
Are healthtech companies automatically Significant Data Fiduciaries?
No. The DPDP Act 2023 relies on the government to notify Significant Data Fiduciaries based on factors like data volume and risk to electoral democracy or public order. However, the volume and sensitive nature of health records make large health platforms highly likely candidates for SDF designation, which requires additional audits.
ComplyDP