Consortia for Advocacy in Rural Health Enhancement
Partner with us
HomeLegalData Protection
Legal · Data protection

Health data and the DPDP Act 2023

The position on health data, including the parts that are not yet settled.

Principles

Five

  1. Purpose limitation

    Data is collected for care and for the programme it was collected under, and not repurposed silently.

  2. Data minimisation

    The emergency view is deliberately small. The full record is no larger than the care requires.

  3. Residency

    Health data is held in India.

  4. Security

    End-to-end encryption in transit and at rest, with audit of every read and write.

  5. Rights

    Access, correction, withdrawal of consent and erasure, subject to any statutory retention that applies to medical records.

Not yet settled

Stated openly

The fiduciary position and operating entity

Which entity operates the service determines the data fiduciary position, the residency obligation and the notification duties. This requires counsel rather than engineering, and it is a hard gate before real patient data is entered into any environment. Field testing is conducted on synthetic records with no identifiers until it is closed.

Breach

What we do

  1. Detect

    Audit-log monitoring, anomaly alerting and support intake.

  2. Contain and assess

    Scope established and exposure closed.

  3. Notify

    The Data Protection Board and affected individuals within the statutory period; where we are processor, immediately the clinic that is fiduciary.

  4. Review

    Post-incident, with remediation tracked to closure.

Read the full register.

Every item, with its gate.