Compliance 8 min read Published 6 August 2026 Updated 6 August 2026

DPDPA Act 2023: What Every Clinic Website Must Do to Stay Compliant

India's data protection law is now enforceable: the DPDP Rules were notified in November 2025, with core obligations phasing in over 12–18 months. Consent notices, patient-photo workflows, 72-hour breach reporting, penalties up to ₹250 crore — here is the checklist your clinic website needs before the deadlines arrive.

Angelin Celena Chief Technology Officer, Baptist Digitek · Chromepet, Chennai
Clinic staff reviewing a patient consent form on a tablet in a modern consultation room

Your clinic's website collects personal data the moment a patient types a name into an enquiry form. Under the DPDPA, that makes your clinic a Data Fiduciary — with legal duties attached. Most clinic websites in India were built before this law had teeth. Now it does, and there is a date on the calendar.

This is not legal advice — for that, speak to your lawyer. It is a practical translation of what the Act and the new Rules mean for the website itself: the forms, the photos, the booking flow, the cookie banner.

What is the DPDPA, and why does it suddenly matter in 2026?

The Digital Personal Data Protection Act was passed in August 2023, but it sat waiting for its operating manual. That manual — the DPDP Rules, 2025 — was notified on 14 November 2025, and it switched the law from theory to timeline:

  • Immediately in force: the Data Protection Board (the regulator that hears complaints and levies penalties) and core definitions.
  • By ~November 2026 (12 months): the Consent Manager framework — registered intermediaries through which users can manage consent.
  • By ~May 2027 (18 months): the obligations that touch your website directly — consent notices, purpose limitation, data-retention and erasure workflows, children's data safeguards, and security requirements.

Eighteen months sounds generous. It is not. Clinics that treat this as a 2027 problem will be re-building forms, galleries and data flows in a rush. Clinics that fix the website now are simply done.

What counts as personal data on a clinic website?

More than most clinic owners expect. Under the Act, personal data is any data about an identifiable individual, processed digitally. On a typical aesthetic or dermatology clinic site, that includes:

  • Name, phone and email from enquiry and booking forms
  • WhatsApp numbers captured through click-to-chat flows
  • Before/after photographs — identifiable images of patients
  • Appointment details, treatment interests, uploaded reports
  • Cookies and analytics identifiers that track individual visitors

The photographs deserve their own sentence: a before/after gallery is a database of identifiable health-related images, published to the open internet. It is the single highest-risk feature on an aesthetic clinic's website — and the most valuable. The law does not say remove it; it says run it on real consent.

What does valid consent look like under the DPDP Rules?

The Rules require notices in clear, plain language that state what is collected and why — and consent that is as easy to withdraw as it was to give. For a clinic website, that translates to four concrete features:

  1. A consent notice at every collection point. Each form states, in one or two plain sentences, what the data is for. "We use these details only to contact you about your appointment" beats a linked 4,000-word policy.
  2. Purpose limitation you actually honour. Data collected for booking cannot quietly become a marketing list. Separate opt-ins for separate purposes.
  3. Withdrawal that works. A patient must be able to withdraw consent — including for published photos — through a route as simple as the one that captured it. A monitored email address and a stated takedown window on the website is the minimum.
  4. Records. When a patient asks "what did I agree to, and when?", the clinic must be able to answer.

What about patient photos — can clinics still show before/after galleries?

Yes — with a consent workflow behind them. The framework that keeps a gallery both persuasive and lawful:

  • Written, specific consent for website publication — separate from consent for treatment, and separate again from social-media use.
  • A retention and takedown rule: state how long images stay published and remove them within a defined window when consent is withdrawn.
  • Minimum identifiability: crop and frame to show the result, not the person, wherever the treatment allows.
  • No children's images in marketing galleries. For anyone under 18, the Rules require verifiable parental consent for data processing — and marketing use of minors' clinical photos is a risk no clinic should take.

A full consent-workflow guide for galleries is coming next on this blog — it deserves its own article, and it gets one.

What security does the law expect from a clinic website?

The Rules name their expectations: encryption, access controls, monitoring, and logs retained for one year, with verified backups. For a clinic website, the practical checklist is short:

  • HTTPS everywhere — no form should ever submit over plain HTTP.
  • Encrypted storage for anything patients submit; no patient data in spreadsheets attached to shared inboxes.
  • Access control: the fewest possible people able to see enquiries; no shared logins.
  • Vendor hygiene: your hosting, forms and analytics providers process patient data on your behalf — a breach at a vendor is still your breach notice.

And the clause that changes behaviour: if personal data is breached, the clinic must notify affected users without delay and the Data Protection Board within 72 hours. A clinic that has never rehearsed that scenario should — once — so the first rehearsal is not the real thing.

What happens if a clinic ignores this?

The Act provides penalties up to ₹250 crore per instance for failures such as inadequate security safeguards. No one expects a neighbourhood clinic to face the maximum — penalties are calibrated to severity. But the complaint mechanism is the real exposure: any patient can approach the Data Protection Board, and an unhappy patient whose photo stayed online after a takedown request now has a regulator to write to. The reputational cost arrives long before any fine does.

The 10-point DPDPA checklist for clinic websites

  1. HTTPS across the entire site, forms included
  2. Plain-language consent notice at every data-collection point
  3. Separate opt-in for marketing vs. appointment communication
  4. Cookie/consent banner that defaults to "denied" until accepted
  5. Written, specific, revocable consent behind every published patient photo
  6. Stated takedown route and window for photo/data removal
  7. No minors' images in marketing content; verifiable parental consent for any under-18 data
  8. Data-retention rule: delete enquiries you no longer need
  9. Access limited to named people; vendors reviewed
  10. A one-page breach-response plan naming who informs patients and the Board within 72 hours

A website that clears this list is not just compliant — it is more trustworthy to every patient who visits, which is the quiet commercial upside of the whole exercise. Compliance and conversion are the same project here: the clinic that shows its consent workflow is the clinic patients believe. (It's one of the seven elements every clinic website needs — and yes, doing it properly is part of what a good clinic website costs.)

WhatsApp us if you'd like a DPDPA review of your current clinic website — first conversations are always free.

Frequently asked questions

Does DPDPA apply to a small single-doctor clinic?

Yes. The Act applies to any entity processing digital personal data in India, regardless of size. Obligations scale with risk, but consent, security and breach duties apply to a single-chair clinic as much as a hospital chain.

Is a WhatsApp-based booking flow a compliance problem?

No — WhatsApp booking is fine, but the website must still show a plain-language notice at the point where the number is captured, and chat records containing patient details need the same care as form data: limited access, no unnecessary retention.

Do we have to take down our existing before/after gallery?

Not if consent is in order. Audit the gallery: keep images with written, specific consent for website use; obtain fresh consent or remove the rest; publish a takedown contact. That converts your riskiest page into a compliant one.

What is the actual deadline for clinic websites?

The DPDP Rules were notified on 14 November 2025 with phased effect: consent-manager provisions at 12 months, and the core website-facing obligations — notices, retention, children's safeguards, security — at 18 months, i.e. around May 2027. Building compliance now avoids a 2027 scramble.

Who enforces DPDPA, and what are the penalties?

The Data Protection Board of India hears complaints and imposes penalties — up to ₹250 crore per instance for serious failures like inadequate security safeguards, calibrated to severity. Patients can complain directly to the Board.