DPDPAcademyKnow the law. Prove it.
Home/Implementation/Healthcare
Fourth Schedule · § 38(1)

Health Data Lost Its Special Status.

The SPDI Rules singled out medical records and physical and mental health condition for heightened protection. The DPDP Act abandons the category entirely - and then carves healthcare out of the children's provisions so that consent cannot gate a child's treatment.

Implementation guide

Covers: hospitals, clinics, diagnostic labs, telemedicine, pharmacies, mental health services.

Why this sector is treated differently

Two changes define healthcare's position, and they pull in opposite directions.

The first is a reduction in sector-specific treatment. Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, physical and mental health condition and medical records were sensitive personal data, attracting a heavier standard than ordinary personal information. The DPDP Act abandons that category. It regulates all digital personal data at a single standard, and a hospital's obligations in respect of a diagnosis are, on the face of the Act, the obligations it has in respect of a phone number. This surprises people, and it is genuinely what the statute does.

The second runs the other way, and it exists because the first would otherwise be dangerous. Section 9(1) requires verifiable parental consent before processing a child's personal data. Applied literally to a hospital, that would make parental consent a precondition of treating a child - including a child brought in unconscious, and including a sixteen-year-old seeking mental health support. Section 9(4) anticipated the problem by allowing classes and purposes to be prescribed as exempt, and rule 12 with the Fourth Schedule does exactly that: Part A begins with clinical establishments, mental health establishments and healthcare professionals, where the processing is restricted to providing health services to the child.

Add section 38(1) - the Act is in addition to and not in derogation of any other law - and the shape becomes clear. Clinical establishment law, medical records retention, professional confidentiality obligations and the digital health frameworks all survive untouched. The DPDP Act is a new layer, not a replacement.

HealthcareFourth Schedule · § 38(1)The personal data you holdTreat a patient§ 74 systems touch it§ 38(1)Treat a child§ 9(4)3 systems touch it§ 8(7)Communicate withpatients§ 63 systems touch it§ 8(7)Answer a rightsrequest§ 113 systems touch it§ 8(7)Part Aclasses exempt from § 9(1) and 9(3)18age below which § 9 engagesNonespecial category for health data
One body of personal data, 4 activities, 4 different answers to when it has to go. That is why the table below has a row per activity rather than per data type.Download as PNG
Part Aclasses exempt from § 9(1) and 9(3)rule 12
18age below which § 9 engages§ 2(f)
Nonespecial category for health data§ 3

What you actually process

One row per activity, not per data type. Lawful basis and erasure attach to a purpose, so the same phone number can sit in three rows below with three different answers.

Processing activities, their lawful basis and when the data must be erased
ActivityLawful basisWhen it must go
Treat a patientName and contact, Presenting complaint, Diagnosis, Prescriptions, Next of kin§ 7Certain legitimate uses, not consent. Section 7 covers responding to a medical emergency involving a threat to life or an immediate threat to health, and taking measures during an epidemic or outbreak. Consent is a poor basis for care a patient cannot meaningfully decline.§ 38(1)Clinical establishment rules and professional obligations set the periods, and section 8(7) carves out retention required by law. Those periods come from statutes outside this Act; confirm them there rather than assuming a number.
Treat a childThe child's clinical data, Parent or guardian contact§ 9(4)Section 9(4) allows classes and purposes to be prescribed as exempt, and rule 12 with Part A of the Fourth Schedule does so - beginning with clinical establishments, mental health establishments and healthcare professionals, where processing is restricted to providing health services to the child.§ 8(7)As for any patient record, governed by the retention the law requires.
Communicate with patientsPhone, Email, Appointment history, Condition, where campaigns are targeted§ 6Outreach beyond care is ordinary processing needing ordinary consent, specific to that purpose. It does not inherit the basis that supports treatment.§ 8(7)Erase on withdrawal. Ancillary systems, not the medical record, are usually where retention quietly becomes indefinite.
Answer a rights requestWhatever the patient asks about, across clinical and ancillary systems§ 11Access to a summary of what is processed and with whom it has been shared, with correction and erasure under section 12.§ 8(7)Keep what proves compliance, no more.

The data flow, and where it breaks

Each lane follows one activity through the actors and systems that touch the data. The failure mode sits on the hop where it happens, rather than in a list somewhere else on the page.

Treat a patient

Provide health services to the person in front of you

  1. ReceptionRegisters the patient§ 5Fails when: Consent forms used as the basis for treatment, creating a right to withdraw that you cannot honour mid-care
  2. ClinicianRecords history, diagnosis and plan§ 7Fails when: Section 7 legitimate uses never mapped, so everything is grounded in consent by default
  3. Clinical recordStores the encounter§ 38(1)Fails when: Clinical records law treated as displaced by the Act rather than surviving alongside it
  4. Lab or imagingReceives the order and returns results§ 8(2)Fails when: Referral partners engaged with no processing terms

Treat a child

Provide health services to a patient under eighteen

  1. ReceptionIdentifies the patient as a child§ 9(1)Fails when: Parental consent treated as a precondition of care, which would gate an emergency
  2. ClinicianDelivers carerule 12Fails when: The Fourth Schedule exemption assumed to cover everything the hospital does with the child's data
  3. Clinical recordStores the encounterFails when: Child records flowing into feedback, marketing or research systems where the exemption does not reach

Communicate with patients

Appointment reminders, feedback requests and health campaigns

  1. Appointment systemExports the contact listFails when: Clinical data reused for outreach on the basis given for treatment
  2. Messaging vendorSends the reminder or campaign§ 8(2)Fails when: Health information sent over consumer messaging with no processing contract and no recipient verification
  3. Feedback platformCollects responses§ 8(2)Fails when: A third-party tool holding patient identity outside the clinical estate

Answer a rights request

Discharge Chapter III duties

  1. Published contactReceives the request§ 8(9)Fails when: No published contact, so requests arrive at a ward and stop there
  2. Identity checkConfirms the requesterFails when: Records released to a family member who is not the Data Principal or a lawful guardian
  3. Systems sweepFinds the data§ 11Fails when: Ancillary systems missed, so the response describes the medical record only

The provisions that apply

Fourth Schedule

Section 9 switched off for clinical care

Rule 12 with Part A of the Fourth Schedule exempts defined classes of Data Fiduciary from sections 9(1) and 9(3) - beginning with clinical establishments, mental health establishments and healthcare professionals, where processing is restricted to providing health services to the child. Part B lists exempt purposes. Check the Schedule for your exact class rather than assuming the exemption reaches all of your processing.

§ 38(1)

Existing medical law survives intact

The provisions of this Act shall be in addition to and not in derogation of any other law for the time being in force. Records retention under clinical establishment rules, professional confidentiality duties and sectoral digital health requirements continue to apply. Where a retention period conflicts with an erasure duty, section 8(7)'s "unless retention is necessary for compliance with any law" is the reconciling clause.

No sensitive category

One standard for all personal data

The Act contains no equivalent of the SPDI Rules' sensitive personal data list. Health condition and medical records are personal data, protected at the same standard as everything else. Practically, the heightened handling that health data deserves now has to be justified as reasonable security safeguards under section 8(5) and as good clinical practice, rather than as a statutory tier.

§ 7

Legitimate uses, including medical emergency

Section 7 sets out the certain legitimate uses for which personal data may be processed without consent. These include responding to a medical emergency involving a threat to life or an immediate threat to health, and taking measures to provide medical treatment or health services during an epidemic or outbreak of disease. Consent is not the only lawful basis available to a clinician.

What to do about it

  1. Map each processing purpose to a basis that is not consent

    Treatment, emergency response and statutory records are better grounded in section 7 legitimate uses and in the laws section 38(1) preserves than in consent. Consent that a patient can withdraw is a poor foundation for a clinical record you are legally required to keep, and mapping this properly avoids promising a right you cannot honour.

  2. Confirm your class in the Fourth Schedule

    The exemption is class-and-purpose bound, and it is restricted to providing health services to the child. A hospital's marketing list, patient app engagement analytics and research use are not health services to the child, and section 9 applies to them in full.

  3. Reconcile retention schedules before erasure duties bite

    Set out, per record type, the law that requires retention and for how long. What that exercise does not cover is what section 8(7) requires you to erase. Most hospitals find the gap is in ancillary systems - appointment reminders, feedback platforms, marketing - rather than in the medical record itself.

  4. Do not rely on the old sensitive-data tiering

    If your controls were designed around the SPDI categories, the classification layer no longer maps to the statute. Keep the stronger controls - they are defensible as reasonable security safeguards - but stop describing the legal basis in SPDI terms, because a regulator reading your policy will notice.

Sequence the work

The same controls as above, in the order they are worth doing. Each names the evidence you would put in front of an auditor, because a control you cannot evidence is a control you cannot prove you had.

Phase 01

Build the foundation

Get the lawful basis and the roles right. Everything else assumes these are settled.

  • Treat a patientMap each processing purpose to a basis that is not consent wherever the law already supplies one, and reserve consent for what a patient can genuinely refuse.Evidence: A purpose-to-basis map per record type, and the clinical policy that implements it.
  • Treat a childConfirm your class against the Schedule text, and treat the exemption as bounded by that purpose. Marketing, engagement analytics and research are not health services to the child.Evidence: The class determination in writing, and a boundary showing which systems child data may and may not enter.
Phase 02

Operationalise it

Turn the basis into systems that run without anyone remembering to run them.

  • Communicate with patientsSeparate operational reminders from marketing, and keep condition-derived targeting out of any channel you cannot verify the recipient on.Evidence: Separate consent records for outreach, and a vendor register with processing terms for each.
Phase 03

Keep it honest

Prove it still works, and answer the people whose data it is.

  • Answer a rights requestOne published channel, an identity standard proportionate to the sensitivity, and a sweep list naming every system including the ancillary ones.Evidence: Request log with timestamps, and the sweep list under version control.

Section and Schedule references above point at the statute itself. Read them in context in the full text of the Act, or against the MeitY publication. This is an educational summary, not legal advice for your organisation.

Healthcare

Healthcare: common questions

Is health data sensitive personal data under the DPDP Act?

No. The Act has no sensitive personal data category at all. The SPDI Rules, 2011 did have one, covering medical records and physical and mental health condition, but the DPDP Act regulates all digital personal data at a single standard. Stronger safeguards for health data remain sound practice and are defensible under section 8(5), but they are no longer a separate statutory tier.

Do we need parental consent before treating a child?

Rule 12 with Part A of the Fourth Schedule exempts clinical establishments, mental health establishments and healthcare professionals from sections 9(1) and 9(3) where the processing is restricted to providing health services to the child. That is what prevents section 9 from gating treatment. The exemption is bounded by that purpose, so processing beyond the provision of health services is not covered.

Does the DPDP Act override clinical records retention rules?

No. Section 38(1) makes the Act additional to, and not in derogation of, other laws in force. Section 8(7) then carves retention required by law out of the erasure duty. The two provisions read together mean statutory medical records retention continues, and the DPDP erasure obligation applies to what those laws do not require you to keep.

Know this well enough to prove it

The certification is a free, graded 15-question exam covering the Act end to end, not just this sector. Pass mark is 70%.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against Healthcare implementation guide. Educational information, not legal advice.

Review standards and attribution →