Article: DPDP Compliance
As companies are increasingly adopting digital technologies, the collection and use of personal data have become the most integral parts of their day- to-day operations.
While the nature of operations in these two sectors is very different, both operate in environments where personal data is closely connected to the delivery of their core services.
Hospital sector faces particularly high exposure because of the nature of the associated information. Patient information can include medical histories, diagnoses, prescriptions, diagnostic findings, treatment details, insurance information and other highly personal information.The sector also involves multiple clinical, administrative and external stakeholders, making privacy and security an important consideration throughout the patient-care environment.
However, hotel sector depends on interconnected booking channels, property-management systems, payment platforms, CRM solutions, loyalty programmes and other technology-enabled services.Guest information can therefore become part of a broader digital ecosystem extending across the various stages of the guest experience.
The risk profile of the two sectors is therefore different, but both have one important characteristic in common: personal data is deeply embedded in their everyday operations and service-delivery processes.
The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes India's framework for processing digital personal data. An organisation that determines the purpose and means of processing personal data generally acts as a Data Fiduciary, while the individual to whom the data relates is the Data Principal.
The framework focuses on responsible data handling throughout its lifecycle.
| DPDP Principle | What It Means for Organisations |
|---|---|
| Consent & Transparency | Individuals should understand relevant processing and consent where consent is the applicable basis. |
| Purpose Limitation | Data should be collected and used for specified purposes. |
| Data Minimisation | Only data necessary for the relevant purpose should be processed. |
| Accuracy | Personal data should be accurate and updated where required. |
| Storage Limitation | Data should not be retained indefinitely when the purpose or applicable requirement no longer justifies retention. |
| Security Safeguards | Appropriate technical and organisational measures should protect personal data. |
| Accountability | Organisations should be able to demonstrate how their data-protection responsibilities are being managed. |
The Act also provides specified rights to Data Principals and establishes obligations relating to personal-data breaches, Data Processors and, where applicable, Significant Data Fiduciaries.
Healthcare organisations handle personal information across a highly interconnected patient-data lifecycle:
Registration → Consultation → Diagnostics → Treatment → Pharmacy → Billing → Insurance → Discharge → Follow-up
A single patient journey may involve doctors, nurses, administrative teams, laboratories, pharmacies, insurers, TPAs, specialists, cloud platforms and technology vendors.
The challenge is therefore not simply securing one hospital database. It is maintaining appropriate governance as information moves across the entire ecosystem.
Hospitals should identify:
A useful starting point is to map OPD, IPD, ICU, OT, laboratory, radiology, pharmacy, billing, insurance, referral and digital-health systems.
Consent is an important part of the DPDP framework, but it is not the only basis recognised by the Act. Specified legitimate uses also exist in defined circumstances.
For example, processing required for healthcare delivery may need to be considered differently from optional promotional communication.
Hospitals should document the purpose and applicable basis for significant processing activities rather than treating every use of patient information as identical.
Key point: Third-party sharing should be purpose-driven, documented, controlled and periodically reviewed, rather than treated as a routine operational activity.
The DPDP Rules specify security measures covering areas such as encryption, access control, monitoring, logging and backups.
For hospitals, practical safeguards may include:
The objective is not simply to deploy security tools, but to establish safeguards appropriate to the organisation's risk and processing environment.
Hospitals may need to locate information across HIS, EMR, laboratory, radiology, billing, insurance and other systems when responding to applicable Data Principal requests.
A defined workflow should therefore cover request receipt, identity verification, data discovery, review, response, correction or erasure where applicable, and record-keeping.
Healthcare records may need to be retained because of applicable legal, regulatory, contractual or operational requirements.
Therefore, DPDP readiness does not mean “delete everything after a fixed period.”
Hospitals should instead establish a documented retention schedule that identifies why particular information must be retained, when it can be deleted and how controlled erasure will be performed.
Hotels also operate through a continuous guest-data lifecycle:
Search → Booking → Identity Verification → Check-in → Stay → Guest Services → Payment → Check-out → Loyalty/Post-Stay Communication
Guest information may move through websites, booking engines, OTAs, PMS, CRM, payment gateways, loyalty platforms, Wi-Fi systems and communication tools.
FHRAI has specifically advised hospitality establishments to pay attention to DPDP responsibilities, including notices, SOPs, vendor compliance and related obligations.
This may include:
Hotels should assess whether each category is necessary for the relevant purpose.
Privacy considerations should be incorporated into website forms, booking engines, registration processes and other collection points.
Privacy notices should explain relevant processing in a clear and understandable manner, consistent with the requirements of the applicable DPDP framework.
Hotels frequently depend on:
Hotels should map these relationships, understand the flow of personal data and establish appropriate contractual, security and governance arrangements.
Guest preferences can help hotels provide personalised services. However, the organisation should distinguish between information required to deliver a service and information used for optional marketing or personalisation.
Marketing communication, loyalty programmes and other optional activities should have appropriate transparency and consent mechanisms where consent is the applicable basis.
Important systems such as PMS, booking engines, CRM and payment environments should be protected through appropriate access controls, authentication, monitoring, encryption and security testing.
A compromise of one connected platform can potentially affect multiple stages of the guest-data lifecycle.
A data breach could involve ransomware, unauthorised employee access, a compromised account, a lost device, a misconfigured cloud environment or a third-party security incident.
Organisations should follow a defined process:
Detect → Contain → Assess → Notify → Recover → Review
The DPDP Rules require Data Fiduciaries to notify affected Data Principals without delay and inform the Data Protection Board of India without delay, followed by specified detailed information within the prescribed framework.
Organisations should therefore have:
Healthcare organisations should also consider their obligations under other applicable frameworks, while hotels should consider requirements relevant to their payment, technology and operational ecosystems.
Not every large hospital, hotel or hotel chain automatically becomes a Significant Data Fiduciary (SDF).
The Act provides for designation based on specified factors and circumstances. Where an organisation is designated an SDF, additional obligations can include:
Organisations should therefore assess their circumstances rather than assuming that organisational size alone determines SDF status.
The DPDP Act provides for significant financial penalties, with the Schedule allowing penalties of up to ₹250 crore for certain breaches, including failure to take reasonable security safeguards to prevent personal-data breaches.
However, this is a statutory maximum, not an automatic penalty for every incident.
For organisations, the wider concern is therefore not simply the amount of a potential penalty. It is whether they can demonstrate appropriate governance, security safeguards, processes and accountability.
Personal data may be distributed across multiple applications, departments and locations.
What to do: Create a data inventory and map significant data flows.
Older systems may lack modern access controls, logging or deletion capabilities.
What to do: Assess legacy-system risks and establish a prioritised remediation plan.
Hospitals and hotels depend heavily on external technology and service providers.
What to do: Conduct vendor assessments and establish appropriate contractual controls.
Too much access can create unnecessary exposure.
What to do: Implement role-based access, least privilege and periodic access reviews.
Keeping data indefinitely increases governance complexity.
What to do: Establish purpose- and requirement-driven retention schedules.
Requests can be difficult when data exists in multiple systems.
What to do: Establish a centralised workflow with defined ownership.
Organisations may have security tools but no tested response process.
What to do: Conduct tabletop exercises and regularly test incident-response procedures.
Employees remain an important part of the data-protection environment.
What to do: Provide role-specific privacy and security awareness training.
Is your hospital prepared to:
Is your hotel prepared to:
Trying to address every issue simultaneously can make compliance difficult to manage.
A structured approach is more practical:
The DPDP framework is being implemented through a phased timeline. The main operational provisions under the Act are scheduled to commence 18 months after the November 2025 commencement notification, making the preparation period important for organisations.
No.
A privacy policy is only one part of the overall framework.
Effective readiness requires alignment between:
Policy → Process → People → Technology → Third Parties → Evidence
An organisation should be able to demonstrate not only what its policy says, but also how those requirements work in practice.
A DPDP-ready organisation should be able to answer:
For hospitals, this means understanding the patient-data lifecycle.
For hotels, it means understanding the guest-data lifecycle.
The DPDP framework brings data protection into the broader organisational conversation around governance, technology, security and accountability.
For healthcare and hospitality organisations, compliance is not simply about understanding the legislation or preparing a privacy policy. It requires organisations to understand how personal data moves through their operations, establish appropriate controls, manage third-party relationships, protect information, respond to applicable rights and maintain evidence of their processes.
As organisations continue to digitise their operations, DPDP readiness should therefore be viewed as an ongoing process of understanding, governing and protecting personal data throughout its lifecycle!