MileEvo
Back to Resources

Clinic Operations & Scaling

DPDP Act Compliance for Healthcare SaaS in India

A plain-language guide to what the DPDP Act means for therapy centers and the software they use — sensitive children’s data, consent, and practical safeguards.

Anup TiwaryBy Anup Tiwary8 min readUpdated 18 July 2026

India's Digital Personal Data Protection Act, 2023 sets the rules for how organisations handle personal data, with the DPDP Rules, 2025 adding implementation detail. For a pediatric therapy center, this is not a back-office concern — you process some of the most sensitive data there is: children's health information. This guide explains, in plain language, what that means for your center and the software you choose.

This is general guidance, not legal advice. The DPDP Act's substantive obligations commence in phases under the 2025 Rules rather than all at once, and interpretation continues to evolve. Confirm your specific obligations and timelines with a qualified professional before relying on any summary, including this one.

Why therapy centers are squarely in scope

A therapy center collects names, contact details, diagnoses, assessments, session notes, and often identifiers like UDID or Aadhaar linkage. Health data is sensitive, and data about children carries heightened protection. Under the DPDP framework, a center acting on this data is a Data Fiduciary — the entity that decides why and how personal data is processed — with corresponding responsibilities.

The principles that matter most

You do not need to memorise the statute to practise well. A handful of principles cover most of what a center must get right:

  1. 1Lawful, consent-based processing. Collect data with clear notice and valid consent. For children, that generally means verifiable parental or guardian consent.
  2. 2Purpose limitation. Use data for the care and administration you collected it for — not for unrelated purposes.
  3. 3Data minimisation. Collect what you actually need, not everything you might one day want.
  4. 4Security safeguards. Protect data with access controls, so only the right people see a child's record.
  5. 5Retention limits. Keep records as long as needed for care and compliance, then dispose of them responsibly.
  6. 6Accountability. Be able to show how data is handled — an audit trail matters.

Practical safeguards for your center

  • Get consent properly at intake, and record it. Capture guardian consent for children explicitly rather than assuming it.
  • Stop using personal devices for clinical data. Notes and parent messages on therapists' personal WhatsApp and laptops are a real exposure — centralise them in a controlled system.
  • Use role-based access so a therapist sees their caseload, an admin sees operations, and nobody sees more than they need.
  • Prefer India data residency. Keeping data hosted in India simplifies compliance and is increasingly expected.
  • Keep an audit trail of who accessed and changed records.

These are the same practices that support RCI-aligned record-keeping — good data protection and good clinical documentation reinforce each other.

What to look for in your software

Your practice software is where most of this is won or lost. Choose a platform that provides:

  • Access controls and role-based permissions
  • India data residency
  • An audit trail
  • Secure, centralised storage that replaces personal-device workflows

MileEvo is built for Indian pediatric therapy centers with these in mind. See our DPDP readiness page for how the platform approaches data protection, and the guide to scaling a center for where compliance fits as you grow.

The takeaway

DPDP compliance is not a one-time checkbox; it is a way of running the center that protects the families who trust you with their children's data. The good news is that the practices it requires — consent, minimisation, access control, and centralised records — are also just good operations.

Related reading