Blog / Compliance

DPDP Act for Clinics: A Practical Checklist for Indian Doctors

By the Careflow team · Published 20 July 2026 · 7 min read

Under India's Digital Personal Data Protection Act (DPDP Act, 2023), a clinic that stores patient details digitally is a data fiduciary: it must collect patient data for a clear purpose, take consent, keep the data secure, and honor requests to correct or erase it. In practice this means moving patient records off personal phones and spreadsheets into systems with access control, consent capture, and audit trails.

This article is general information for clinic operations, not legal advice. For obligations specific to your practice, consult a lawyer familiar with health data.

Who is who under the Act

  • Your clinic is typically the data fiduciary for patient records: it decides why and how patient data is processed.
  • Software vendors that host or process those records on your instructions, such as a clinic management platform, act as data processors and should offer a data processing agreement.
  • Patients are data principals, with rights to access, correction, and erasure of their personal data.

The practical checklist

  1. Consent at registration: tell patients what you collect and why, and record their consent. Digital consent with a timestamp beats a paper form that gets lost.
  2. Purpose limitation: use patient contact details for care-related communication, appointments, invoices, follow-ups, unless the patient has separately agreed to more.
  3. Access control: staff should see patient data only through logged-in accounts, not shared spreadsheets or personal WhatsApp chats.
  4. Storage and isolation: patient records should live in a system where your clinic's data is isolated from anyone else's and encrypted in transit.
  5. Opt-outs: if a patient asks to stop receiving messages, stop, and keep a record of it.
  6. Erasure and correction: have a way to correct wrong entries and delete data when retention is no longer justified.
  7. Vendor diligence: ask your software vendor for their privacy policy, security policy, and a data processing addendum. If they cannot show these, that is your answer.
  8. Grievance channel: patients should have a clear way to raise data concerns, and clinics should know their vendor's grievance contact too.

WhatsApp messaging under DPDP

Messaging patients on WhatsApp is fine when it is care-related and consented, but it should leave an audit trail. Sending records from a doctor's personal WhatsApp mixes patient data into a personal device with no access control. Clinic software that sends via the official WhatsApp Business API keeps messages tied to the patient record, logged, and controllable.

How Careflow supports this

Careflow is built multi-tenant with each clinic's data isolated, supports digital consent capture with PDF export, logs every WhatsApp message, honors patient opt-outs, and publishes its privacy, security, DPDP, and data processing policies openly in its legal center. Your clinic remains the fiduciary; the tooling just makes the duties practical to carry out.

Run your clinic from one app

Patients, appointments, billing, WhatsApp follow-ups, recalls, and reviews. Start free, no card required.

Trust & compliance

How Careflow approaches security and privacy

Controls and policies we document publicly. These are product summaries, not third-party certifications. Open any item for the full policy.

Full documents: Legal center·Privacy·Security·DPDP