Checklist · Collection Centre Manager
DPDPA Checklist for Collection Centre Managers
A collection centre handles health data at its most exposed point — walk-in registration, sample tubes, home visits, WhatsApp reports. Under the DPDP Act, 2023 the lab is usually the Data Fiduciary and the centre manager runs the collection point. Franchise centres carry extra risk. This checklist covers what to fix before 13 May 2027.
Last reviewed: 13 August 2026
What must a collection centre manager do for DPDPA compliance?
- Settle who the Data Fiduciary is, in writing, if you're a franchise or partner centre. The lab brand usually decides the purpose and means, so the lab is the Fiduciary and the franchise centre a Processor. That must be a contract clause, not an assumption. Section 8(2) requires a valid contract before a processor handles data on the fiduciary's behalf, and the lab stays liable for your failures. Minimum terms: process only on lab instruction, no local copies retained after upload, no onward sharing without lab authorisation, security provisions under Rule 6(1)(f), and incident notification measured in hours. If you run an independent centre serving multiple labs, you are the Fiduciary for your own registration data — don't assume the lab's compliance covers you.
- Strip the registration form to what the test actually needs. Name, age, sex, contact, referring doctor and the test panel are defensible. Occupation, marital status, full address for an in-centre walk-in, Aadhaar number, and a mandatory alternate contact usually are not. Section 6(1) confines consent to data necessary for the specified purpose. Aadhaar is not required to run a blood test — ABHA is voluntary under ABDM, and refusing a patient for declining either is indefensible. Walk-ins, home collection and health packages run on Section 6 consent, not a medical-emergency legitimate use.
- Separate the consent for report delivery, marketing and research. Patients consent to testing. That does not cover pushing them health-package offers, sharing panel results with a corporate wellness client, or contributing samples and data to a research or pharma tie-up. Take each as a separate, refusable consent at registration under Rule 3, and never make any of them a condition of getting the test done. One signature covering all six purposes is not itemised consent.
- Fix report delivery — the unauthenticated link is your biggest exposure. A report link sent over WhatsApp or SMS that opens without authentication means anyone holding the phone, or anyone who guesses an adjacent URL, reads the report. Require OTP or date-of-birth verification at open, set link expiry, replace sequential patient IDs with random tokens, and never put the test name in the SMS body — "your report is ready", not "your HIV ELISA report is ready." This is cheap, and it is what a regulator or a journalist will test first.
- Get patient data off personal phones. Phlebotomists photographing requisition slips, saving patient numbers to personal contacts, or forwarding reports from their own WhatsApp is the most common real-world failure at collection centres. Issue centre-owned devices or an app with no local image storage, ban camera capture of forms, and run an exit routine when a phlebotomist resigns — you cannot wipe a device you don't own, and Section 8(5) makes that gap your reasonable-security failure.
- Redesign the front desk so the last patient isn't visible to the next. Open registers listing name, age and test, screens angled toward the queue, and printed tube labels sitting on the counter are all disclosures you never had consent for. Practical fixes: token numbers instead of names called out, a screen privacy filter, tubes moved to a closed rack immediately, and the collection cubicle out of CCTV coverage entirely — cameras belong at the entrance and the sample handover point, never where a patient undresses or a sample is drawn.
- Apply the extra rules that specific tests carry, because DPDPA is not the whole picture. DPDPA 2023 has no separate "sensitive personal data" tier — health data sits under the same rules as everything else. Sectoral law still adds duties on top. The HIV/AIDS (Prevention and Control) Act, 2017 requires informed consent and confidentiality for HIV testing and restricts disclosure. The PCPNDT Act governs any prenatal diagnostic work, including Form F records and an absolute bar on sex determination. Train front-desk staff that these results are never discussed at the counter and never given to the person who paid, unless that person is the patient.
- Handle paediatric draws correctly — and do not over-apply Section 9. Rule 12 read with Fourth Schedule Part A(1) disapplies both Section 9(1) and Section 9(3) for a clinical establishment — which covers a diagnostic laboratory — where processing is restricted to providing health services to the child to the extent necessary for the protection of her health. You do not need Rule 10 verifiable parental consent as a precondition to running a clinically indicated test on a minor. What the carve-out does not touch: marketing or health-package outreach involving a child, research use of identifiable paediatric data, disclosure to a school, and targeted advertising directed at a child. Those snap back to full Section 9. For elderly patients whose relatives arrange the test, the patient is still the Data Principal; a son booking his mother's test does not become entitled to her report. Section 14 nomination is the correct route rather than informal family access.
- Write down the retention rule for slips, samples and local copies. Section 8(7) requires erasure once the purpose is served, unless Indian law requires retention. Clinical establishment rules and NABL accreditation impose their own record-retention periods — get the exact figure applicable to your lab's accreditation and state rules from your quality manager and write it down. Then handle what nobody handles: paper requisition slips in the drawer, the local desktop's scan folder, the register from 2019, and residual samples after the retention window. Note the floors: Rule 6(1)(e) and Rule 8(3) set a one-year minimum for certain logs and related personal data. Physical destruction needs a logged shredding routine, not a bin.
- Know your vendor chain and your breach clock before you need them. List everyone who touches the data: LIS/HIS vendor, the courier moving samples, the SMS and WhatsApp gateway, the report-hosting cloud and its region, the home-collection app. You need that list to answer a Section 11 access request and to act inside the clock if one is breached. Four lanes run cumulatively: CERT-In within 6 hours of noticing; Rule 7(1) affected patients without delay; Rule 7(2)(a) Board initial intimation without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. Escalate to the parent lab in hours, not "promptly". Print it and put it next to the centre phone. Separately, if the LIS is hosted offshore, inventory that transfer under Rule 15.
Frequently asked questions
Can we share results directly with the referring doctor?
Where the doctor ordered the test as part of the patient's care, sharing the result back is within the purpose the patient came for — say so plainly in the notice at registration so it isn't a surprise. What that does not cover is the commercial layer: sending a doctor a monthly list of patients they referred, sharing panel data for the doctor's own research, or any arrangement where patient data flows as part of a referral incentive. That's a new purpose needing separate itemised consent. Keep the clinical channel and the commercial channel completely apart.
A family member is asking for a patient's report at the counter. What do we do?
Default to no. The Data Principal is the patient, and the person who paid, booked or drove them has no automatic entitlement. The clean routes are: the patient authorises collection at registration and you record it; the patient nominates someone under Section 14; or, for a child, the verified parent or guardian collects. Anything else — a spouse, an adult child, an employer who arranged a corporate camp — needs the patient's own authorisation. Give the front desk a scripted refusal line rather than leaving it to judgement under pressure.
What does a breach at a collection centre actually cost?
The penalty slabs are separate entries in the Schedule and are assessed independently: up to ₹250 crore for failing reasonable security safeguards under Section 8(5), and up to ₹200 crore for failing to notify a breach under Section 8(6). Report on all four lanes: CERT-In within 6 hours of noticing; Rule 7(1) patient intimation without delay; Rule 7(2)(a) Board initial intimation without delay; Rule 7(2)(b) detailed Board report within 72 hours. For a franchise centre the practical consequence often lands sooner than any Board order — the lab's contract will carry indemnity and termination rights. Rule 13 audit obligations apply only to Significant Data Fiduciaries; a single centre is very unlikely to be in scope. That is not a reason to skip the rest.
We'll trace one patient from this centre to the mother lab
A 30-minute call: registration to report delivery. We look at what your front desk actually collects and on what notice, how reports leave the centre, who the franchise contract makes liable, and how long slips sit after the sample is sent. You leave with a written gap list — whether or not you work with us.
Book a demo call
Free Gap Analysis
Bring your registration form and one report-delivery link. No deck.
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.