Checklist · Diagnostic Lab Owner

DPDPA Checklist for Diagnostic Lab Owners

Substantive DPDPA obligations commence 13 May 2027. For a lab the exposure is rarely the report itself — it is the link that delivers it, the LIS contract nobody signed, and a counter taking one signature for six purposes. NABL and Clinical Establishments duties continue alongside. Ten items to own personally.

Last reviewed: 30 July 2026

What must a diagnostic lab owner do for DPDPA compliance?

  1. Rebuild the registration consent into itemised purposes. Routine testing is not a medical emergency. Section 7 legitimate uses are a closed list, and the health-related ones cover a medical emergency involving a threat to life or an immediate threat to health where the patient cannot consent, and measures during an epidemic or public-health threat. Walk-ins, home collection, health packages, pre-employment screening and corporate camps are none of those — they run on Section 6 consent. Your notice must meet Rule 3: an itemised description of the personal data, the specified purposes and a specific description of the services enabled, in clear plain language, presented independently of your other terms, in English or any Eighth Schedule language, with a link or means to withdraw as easily as consent was given. Split into separate choices: diagnosis and report to the patient; disclosure to the referring doctor; disclosure to an employer or TPA; marketing and health-package outreach; research use. One signature covering all six is not itemised consent. Owner: you + front-desk lead. Artefact: versioned form, version logged against each registration.
  2. Fix report delivery — this is the single most common failure. A report URL that opens for anyone holding the link is not a safeguard. Rule 6(1)(a) names the expected measures explicitly: encryption, obfuscation, masking, or virtual tokens mapped to the personal data. Concretely: authenticate the link (OTP or date-of-birth plus reference), expire it, and replace sequential or guessable patient IDs with random tokens — if an ID can be incremented to reach another patient's report, assume it already has been. Then close the adjacent leaks: the shared front-desk WhatsApp Web session that any staffer can open, reports emailed as unencrypted PDFs, and the phlebotomist's personal phone holding a month of collection lists and home-visit addresses. Consumer messaging accounts are not a records system. This item is cheap and it is what a regulator or a journalist will test first.
  3. Handle paediatric testing correctly — and do not over-apply Section 9. Most compliance guidance errs the other way here, over-applying Section 9 to routine paediatric testing. Rule 12 read with Fourth Schedule Part A(1) disapplies both Section 9(1) and Section 9(3) for a Data Fiduciary that is a clinical establishment — which includes a laboratory offering pathological or diagnostic services under the Clinical Establishments (Registration and Regulation) Act, 2010 — where processing is restricted to provision of health services to the child, to the extent necessary for the protection of her health. Part A(2) does the same for allied healthcare professionals implementing a treatment or referral plan. So you do not need Rule 10 verifiable parental consent as a precondition to running a clinically indicated test on a minor.

    What the carve-out does not touch, where full Section 9 applies: marketing or health-package outreach involving a child, adding paediatric patients to remarketing or campaign lists, research use of identifiable child data, disclosure to a school or employer, and any behavioural tracking or targeted advertising directed at a child under Section 9(3). Build the flow so the clinical path runs clean and the non-clinical uses require verified parental consent under Rule 10 — adult, identifiable, verified by reliable identity and age details you hold, details voluntarily provided, or a virtual token from an authorised entity including a Digital Locker service provider. Handle patients with disability who have a lawful guardian under Rule 11 separately: verify the guardian was appointed by a court, a designated authority under s.15 of the RPwD Act 2016, or a local level committee under s.13 of the National Trust Act 1999.

  4. Put written processor contracts on the LIS and everything around it — and characterise reference labs deliberately. Your LIS provider, cloud host, billing gateway, courier, home-collection app and SMS/WhatsApp gateway are Data Processors and may process patient data only under a valid written contract; Rule 6(1)(f) requires appropriate security provisions in it. Add purpose limits, sub-processing consent, deletion on exit, and an incident-escalation SLA in hours — their delay consumes your clocks. Most lab tech runs on a click-through plan with no such contract, which is a straightforward gap to close. Reference labs need a decision, not an assumption. If one processes strictly on your instructions for your patient's test, it is a processor. If it retains the sample or result for its own validation, panel development or research, it becomes a Data Fiduciary in its own right with its own lawful ground — and your notice must name that disclosure. Write down which one each is. Liability for a processor's failure stays with you and cannot be contracted away.
  5. Stop corporate health-camp results going to the employer on the employer's say-so. The employer commissioned the camp; the employee is the Data Principal. Disclosing an individual's results to their HR or occupational-health team is a third-party disclosure requiring that patient's own itemised consent, captured at the camp, not the employer's contract with you. Practical fix: give the employer aggregate and anonymised fitness outcomes by default, and route individual results to the individual — with a separate, defaulted-off consent if they want them shared. This is also the flow most likely to produce a complaint, because the harm is immediate and personal.
  6. Treat the referring doctor as a Data Principal too. Name, registration number, contact details, referral volumes and any incentive or payout data are personal data you process for MIS and commercial purposes. Doctors have access and correction rights over it, and they are increasingly aware of that. Include them in your notice, your retention map and your rights workflow — most labs have never considered this and it surfaces awkwardly in a panel dispute.
  7. Enforce access control inside the lab. Rule 6(1)(b) requires appropriate measures to control access to the computer resources used, and Rule 6(1)(c) requires visibility on who accessed personal data through logs, monitoring and review, to enable detection and investigation of unauthorised access. In practice: role-based access so a billing clerk cannot open pathology results, no shared "reception" or "lab" logins, immediate deprovisioning when staff resign, and audit logs that record who viewed which report. If everyone can see everything, you are processing beyond the purpose the patient consented to and you have no safeguard to point at.
  8. Build a retention map with the statutory floor in it — in both directions. Map each data class to its basis and period: registration and identity data, reports and images, requisition forms, invoices, and NABL and Clinical Establishments record-keeping duties, plus ICMR requirements where you do research work. Erase once the purpose and any statutory retention period end. But note the floors that cut the other way: Rule 6(1)(e) requires retaining access logs and personal data for one year as a security safeguard, and Rule 8(3) sets a one-year minimum for personal data, associated traffic data and processing logs. "Delete everything on request" is wrong; so is a decade of walk-in registrations, old home-collection address lists, and enquiry data that never converted.
  9. Publish the contact person and stand up the rights machinery. Rule 9 requires prominently publishing on your website or app the business contact information of the person able to answer questions about processing — and mentioning it in every response to a rights request. Put it on your website, on the registration form, and in the report footer, since the report is the document patients actually keep. Rule 14(1) requires publishing the means by which a patient makes a request and any identifier you need (your CRF or patient ID). Rule 14(3) requires responding within a period not exceeding ninety days. Rule 14(4) requires supporting nomination. Name a real person with a monitored inbox, not a generic address.
  10. Rehearse a breach on paper, and check where the data physically sits. Four obligations run in parallel and are cumulative, not alternatives: CERT-In within 6 hours of noticing; Rule 7(1) intimation to each affected patient without delay; Rule 7(2)(a) initial intimation to the Data Protection Board without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. Most playbooks have only the 72-hour filing — the Board gets two. Rule 7(1) prescribes the patient notice contents: nature, extent and timing, consequences relevant to them, mitigation implemented, safety steps they can take, and business contact information for someone who can respond. Pre-draft it. Run the scenario as LIS ransomware on a Saturday, and a second one as an exposed report URL being enumerated. Separately, Rule 15 applies to every Data Fiduciary transferring personal data outside India, subject to requirements the Central Government may specify — so if your LIS is hosted offshore, or you use teleradiology or telepathology reporting from abroad, inventory those transfers now.

Frequently asked questions

A ten-year-old comes in for a blood test. Do we need verifiable parental consent before we can run it?

Not for the clinical processing itself. Rule 12 read with Fourth Schedule Part A(1) disapplies both Section 9(1) and Section 9(3) for a clinical establishment — which covers a diagnostic laboratory — where processing is restricted to providing health services to the child to the extent necessary for the protection of her health. Registering the child, running the indicated test, generating and releasing the report to the accompanying parent or guardian, and retaining it as a clinical record all sit inside that carve-out. Part A(2) extends the same relief to allied healthcare professionals implementing a recommended treatment or referral plan.

The carve-out is purpose-bound, and everything outside the clinical purpose snaps back to full Section 9: adding the child or the family to marketing and health-package lists, sending promotional SMS or WhatsApp, using identifiable paediatric data for research or panel development, disclosing to a school, and any behavioural tracking or targeted advertising directed at a child. Those need Rule 10 verifiable parental consent — due diligence that the consenting individual is an identifiable adult, verified by reliable identity and age details you already hold, details voluntarily provided, or a virtual token issued by an authorised entity including a Digital Locker service provider. Two related points: a child is anyone under 18, so this covers teenagers, and consent shifts to the patient on their eighteenth birthday; and patients with disability who have a lawful guardian go down the separate Rule 11 route, which turns on court, designated-authority or local-level-committee appointment rather than parenthood.

Our LIS is on a vendor's cloud, we send specialised tests to a reference lab, and we share results with referring doctors, TPAs and corporate clients. Who carries the liability?

The lab does, as Data Fiduciary, and it cannot be contracted away. Sort your counterparties into three groups. Processors — LIS, cloud host, billing gateway, courier, home-collection app, messaging gateway — act only on your instructions and only under a valid written contract specifying purpose, security obligations, sub-processing limits and deletion on exit, with security provisions required by Rule 6(1)(f). Fiduciaries in their own right — insurers and TPAs processing a claim for their own purposes, a reference lab reusing the sample or result for its own ends — have their own lawful ground, which means the disclosure to them is a third-party disclosure needing the patient's itemised consent, and the volume you send matters as much as the consent. Data Principals you had not thought about — the referring doctor, whose registration details, contact information and referral volumes you process for MIS and incentives, with access and correction rights attached; and the individual employee at a corporate camp, whose results cannot go to their employer on the employer's authority alone.

Also worth stating internally: DPDPA has no separate "sensitive personal data" tier. An HIV result, a pregnancy test, a psychiatric referral and a mobile number all sit under one legal standard. The difference is the harm, not the rule — which should drive your access controls and your report-delivery design even though it does not change which law applies.

If our LIS is breached or a report link is scraped, what do we report, what does it cost, and do we need a DPO and an annual audit?

Report on all four lanes: CERT-In at 6 hours, patients without delay under Rule 7(1), the Board without delay under Rule 7(2)(a), and the Board again in detail at 72 hours under Rule 7(2)(b). The obligation is yours even when the breach originated at your LIS vendor or cloud host — which is why their contract needs an alert SLA measured in hours. Two scoping points labs get wrong: ransomware that locks your LIS is a personal data breach even with no confirmed exfiltration, because loss of access counts; and an unauthenticated report URL being enumerated, or a misconfigured storage bucket, is a breach with no attacker in the ordinary sense — "nothing was stolen" is not an exemption from notifying.

On exposure, two separate heads under the Schedule, assessed independently, so one incident can attract both: up to ₹250 crore for failure to take reasonable security safeguards under Section 8(5), and up to ₹200 crore for failure to give the required breach intimation under Section 8(6). If children's data is involved and the failure touches the Section 9 obligations, that is a further head at up to ₹200 crore. These are statutory ceilings, not expected fines — the Board sets quantum on the facts, weighing the nature, gravity and duration of the breach, the type of personal data affected, whether the conduct was repetitive, and the mitigation you undertook and how promptly. That is the entire argument for items 2, 4, 7 and 10 being worth more than a policy document.

On governance: Rule 13 — annual DPIA and independent audit, algorithmic due diligence, an India-based Data Protection Officer, and the localisation restriction — binds Significant Data Fiduciaries only. SDF status is conferred by Central Government notification under Section 10, assessed on volume and sensitivity of data and risk to Data Principals' rights, and is not triggered automatically by sample volume, number of collection centres or turnover. No lab becomes an SDF by growing. You still owe the full baseline regardless: valid consent, purpose limitation, accuracy, erasure subject to lawful retention, security safeguards, breach notification, and the Rule 9 named contact person — which is required of every Data Fiduciary whether or not a DPO is.

Official sources

We'll trace one patient journey through your lab

A 30-minute call: registration to report delivery. We look at what your front desk actually collects and on what notice, how reports leave your building, who your LIS and reference-lab contracts make liable, and how long records sit after the clinical purpose ends. You leave with a written gap list mapped to Section 6, the security safeguards duty and your NABL retention obligations — whether or not you work with us.

Book a demo call Free Gap Analysis

Bring your registration form and one report-delivery link. No deck.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.