Clinic Operations & Scaling
DPDP Act Compliance for Healthcare SaaS in India
A plain-language guide to what the DPDP Act means for therapy centers and the software they use — sensitive children’s data, consent, and practical safeguards.
India's Digital Personal Data Protection Act, 2023 sets the rules for how organisations handle personal data, with the DPDP Rules, 2025 adding implementation detail. For a pediatric therapy center, this is not a back-office concern — you process some of the most sensitive data there is: children's health information. This guide explains, in plain language, what that means for your center and the software you choose.
This is general guidance, not legal advice. It was written by the MileEvo editorial team and has not yet been reviewed by a lawyer — a legal review is planned, and we will say so on this page when it has happened. The DPDP Act's substantive obligations commence in phases rather than all at once, and interpretation continues to evolve. Confirm your specific obligations and timelines with a qualified professional before relying on any summary, including this one.
When does this actually apply to my center?
The DPDP Rules, 2025 do not switch on all at once. They were notified in November 2025 and phase in over eighteen months, in three stages:
- 1First, the regulator. The Data Protection Board of India is constituted and begins functioning, along with the appeal procedure. Nothing at this stage changes day-to-day operations at a therapy center.
- 2Then, consent infrastructure. About a year in, the registration and obligations regime for Consent Managers — the intermediaries through which a person can give, manage, and withdraw consent — comes into force.
- 3Finally, the obligations that apply to you. At the eighteen-month mark, notice and consent requirements, security safeguards, breach notification, retention and erasure limits, verifiable guardian consent for children's data, and Data Principal rights (access, correction, and erasure) all become binding.
On the exact dates: we have deliberately not printed them here. The Rules count each phase from the date of publication in the Official Gazette, and widely-published summaries differ by a day on which date that is. Rather than repeat a deadline we have not verified against the notification itself, we describe the sequence. Confirm the exact date that applies to you with a qualified professional — and we will add the dates to this page once we have had them confirmed.
Two things follow from that shape, and centers routinely get both wrong.
First: the children's-data consent rule is not yet in force — and you should behave as if it were. Verifiable parental or guardian consent becomes a binding obligation at the final phase, not today. That is a statement about enforcement dates, not about good practice. A center that starts recording proper guardian consent now will have a clean consent record for its whole caseload by the time the obligation lands; one that waits will be retrofitting consent onto a live caseload of children under deadline pressure, which is materially harder and produces worse records.
Second: eighteen months is not a long runway for the things that are slow. Getting off personal WhatsApp and personal laptops, introducing role-based access, and writing down a retention policy are organisational changes, not switches. The compliance date is when you must be finished, not when you should start.
Why therapy centers are squarely in scope
A therapy center collects names, contact details, diagnoses, assessments, session notes, and often identifiers like UDID or Aadhaar linkage. Health data is sensitive, and data about children carries heightened protection. Under the DPDP framework, a center acting on this data is a Data Fiduciary — the entity that decides why and how personal data is processed — with corresponding responsibilities.
Consent for children's data — what "verifiable" means in practice
Data about a child is treated with extra care under the DPDP framework: processing will generally require verifiable consent from a parent or lawful guardian, not just a general intake signature buried in paperwork. As set out above, this obligation is part of the final phase rather than something already in force — but it is the single hardest thing to retrofit, and it is straightforward to build in from the start. In practice, it means:
- Consent is specific, not a blanket "I agree to your terms" — the parent/guardian should understand what data is collected and why (assessment, session records, progress reporting, billing).
- Consent is recorded, not assumed — keep a timestamped record of what was agreed to, not just a filed form.
- Consent is revisited when purpose changes — if you start using data for something beyond care and administration (for example, a case study or a testimonial), that's a new purpose and needs its own consent, not a stretch of the original intake agreement.
- A worked example: at intake, a center presents a short, plain-language notice — "We collect [name, contact, diagnosis, assessment and session records] to provide therapy services and communicate with you about your child's care. We do not use this data for any other purpose without asking you first." — and records the parent's affirmative consent against that specific notice, not a generic sign-in sheet.
The principles that matter most
You do not need to memorise the statute to practise well. A handful of principles cover most of what a center must get right:
- 1Lawful, consent-based processing. Collect data with clear notice and valid consent. For children, that generally means verifiable parental or guardian consent (see above).
- 2Purpose limitation. Use data for the care and administration you collected it for — not for unrelated purposes. If a use case wasn't in the original notice, it needs its own consent, not an assumption.
- 3Data minimisation. Collect what you actually need, not everything you might one day want. A field on an intake form you never use is a liability, not a convenience.
- 4Security safeguards. Protect data with access controls, so only the right people see a child's record.
- 5Retention limits. Keep records as long as needed for care and compliance, then dispose of them responsibly — see the retention discussion in RCI compliance in clinical documentation for how this interacts with professional record-keeping obligations.
- 6Accountability. Be able to show how data is handled — an audit trail matters, both for DPDP purposes and for demonstrating professional record-keeping standards.
Practical safeguards for your center
- Get consent properly at intake, and record it. Capture guardian consent for children explicitly rather than assuming it.
- Stop using personal devices for clinical data. Notes and parent messages on therapists' personal WhatsApp and laptops are a real exposure — centralise them in a controlled system.
- Use role-based access so a therapist sees their caseload, an admin sees operations, and nobody sees more than they need.
- Prefer India data residency. Keeping data hosted in India simplifies compliance and is increasingly expected.
- Keep an audit trail of who accessed and changed records.
- Write down what you retain and for how long, and don't keep data past that point "just in case" — a documented, followed policy is what accountability actually looks like in practice.
These are the same practices that support RCI-aligned record-keeping — good data protection and good clinical documentation reinforce each other.
What a center should actually be able to produce
Compliance frameworks are easier to act on when you turn them into a short list of artefacts someone could ask you for. If a parent, an auditor, or the Board ever asked, a well-run center should be able to produce:
- The notice you gave. The actual plain-language text a parent was shown at intake — not a description of it from memory, and not a terms page that has since been edited without a version history.
- The consent you recorded against it. Who consented, for which child, to which stated purposes, and when. A signature on a form in a drawer is weak evidence; a timestamped record tied to a specific notice version is strong evidence.
- A list of what you hold and why. Which categories of data the center collects and the purpose each one serves. A field nobody can justify is a field to stop collecting.
- Your retention policy, and evidence you follow it. Written down, with a defined period per record type, and actual disposal happening rather than data accumulating indefinitely "just in case."
- Your access model. Who can see a child's record, and why that set of people is the minimum necessary.
- An access and change log. Who opened or edited a record, and when.
- A breach response you could actually run — who is told, in what order, within what time, and who decides. A plan written after a breach is not a plan.
Most centers already do several of these informally. The work is usually not new practice; it is making existing practice legible and recorded — which is also precisely what makes it survive staff turnover.
What to look for in your software
Your practice software is where most of this is won or lost. Choose a platform that provides:
- Access controls and role-based permissions
- India data residency
- An audit trail
- Explicit, recorded consent capture at intake — not just a checkbox with no record of what was agreed to
- Secure, centralised storage that replaces personal-device workflows
MileEvo is built for Indian pediatric therapy centers with these in mind. See our DPDP readiness page for how the platform approaches data protection, and the guide to scaling a center for where compliance fits as you grow.
The takeaway
DPDP compliance is not a one-time checkbox; it is a way of running the center that protects the families who trust you with their children's data. Building consent, minimisation, access control, and retention discipline in now — ahead of the final compliance deadline — means you are not retrofitting it under pressure later. The good news is that these practices are also just good operations.