What must a diagnostic lab owner do for DPDPA compliance?
- Rebuild the registration consent into itemised purposes. Routine testing is not a medical emergency. Section 7 legitimate uses are a closed list, and the health-related ones cover a medical emergency involving a threat to life or an immediate threat to health where the patient cannot consent, and measures during an epidemic or public-health threat. Walk-ins, home collection, health packages, pre-employment screening and corporate camps are none of those — they run on Section 6 consent. Your notice must meet Rule 3: an itemised description of the personal data, the specified purposes and a specific description of the services enabled, in clear plain language, presented independently of your other terms, in English or any Eighth Schedule language, with a link or means to withdraw as easily as consent was given. Split into separate choices: diagnosis and report to the patient; disclosure to the referring doctor; disclosure to an employer or TPA; marketing and health-package outreach; research use. One signature covering all six is not itemised consent. Owner: you + front-desk lead. Artefact: versioned form, version logged against each registration.
- Fix report delivery — this is the single most common failure. A report URL that opens for anyone holding the link is not a safeguard. Rule 6(1)(a) names the expected measures explicitly: encryption, obfuscation, masking, or virtual tokens mapped to the personal data. Concretely: authenticate the link (OTP or date-of-birth plus reference), expire it, and replace sequential or guessable patient IDs with random tokens — if an ID can be incremented to reach another patient's report, assume it already has been. Then close the adjacent leaks: the shared front-desk WhatsApp Web session that any staffer can open, reports emailed as unencrypted PDFs, and the phlebotomist's personal phone holding a month of collection lists and home-visit addresses. Consumer messaging accounts are not a records system. This item is cheap and it is what a regulator or a journalist will test first.
-
Handle paediatric testing correctly — and do not over-apply Section 9. Most compliance guidance errs the other way here, over-applying Section 9 to routine paediatric testing. Rule 12 read with Fourth Schedule Part A(1) disapplies both Section 9(1) and Section 9(3) for a Data Fiduciary that is a clinical establishment — which includes a laboratory offering pathological or diagnostic services under the Clinical Establishments (Registration and Regulation) Act, 2010 — where processing is restricted to provision of health services to the child, to the extent necessary for the protection of her health. Part A(2) does the same for allied healthcare professionals implementing a treatment or referral plan. So you do not need Rule 10 verifiable parental consent as a precondition to running a clinically indicated test on a minor.
What the carve-out does not touch, where full Section 9 applies: marketing or health-package outreach involving a child, adding paediatric patients to remarketing or campaign lists, research use of identifiable child data, disclosure to a school or employer, and any behavioural tracking or targeted advertising directed at a child under Section 9(3). Build the flow so the clinical path runs clean and the non-clinical uses require verified parental consent under Rule 10 — adult, identifiable, verified by reliable identity and age details you hold, details voluntarily provided, or a virtual token from an authorised entity including a Digital Locker service provider. Handle patients with disability who have a lawful guardian under Rule 11 separately: verify the guardian was appointed by a court, a designated authority under s.15 of the RPwD Act 2016, or a local level committee under s.13 of the National Trust Act 1999.
- Put written processor contracts on the LIS and everything around it — and characterise reference labs deliberately. Your LIS provider, cloud host, billing gateway, courier, home-collection app and SMS/WhatsApp gateway are Data Processors and may process patient data only under a valid written contract; Rule 6(1)(f) requires appropriate security provisions in it. Add purpose limits, sub-processing consent, deletion on exit, and an incident-escalation SLA in hours — their delay consumes your clocks. Most lab tech runs on a click-through plan with no such contract, which is a straightforward gap to close. Reference labs need a decision, not an assumption. If one processes strictly on your instructions for your patient's test, it is a processor. If it retains the sample or result for its own validation, panel development or research, it becomes a Data Fiduciary in its own right with its own lawful ground — and your notice must name that disclosure. Write down which one each is. Liability for a processor's failure stays with you and cannot be contracted away.
- Stop corporate health-camp results going to the employer on the employer's say-so. The employer commissioned the camp; the employee is the Data Principal. Disclosing an individual's results to their HR or occupational-health team is a third-party disclosure requiring that patient's own itemised consent, captured at the camp, not the employer's contract with you. Practical fix: give the employer aggregate and anonymised fitness outcomes by default, and route individual results to the individual — with a separate, defaulted-off consent if they want them shared. This is also the flow most likely to produce a complaint, because the harm is immediate and personal.
- Treat the referring doctor as a Data Principal too. Name, registration number, contact details, referral volumes and any incentive or payout data are personal data you process for MIS and commercial purposes. Doctors have access and correction rights over it, and they are increasingly aware of that. Include them in your notice, your retention map and your rights workflow — most labs have never considered this and it surfaces awkwardly in a panel dispute.
- Enforce access control inside the lab. Rule 6(1)(b) requires appropriate measures to control access to the computer resources used, and Rule 6(1)(c) requires visibility on who accessed personal data through logs, monitoring and review, to enable detection and investigation of unauthorised access. In practice: role-based access so a billing clerk cannot open pathology results, no shared "reception" or "lab" logins, immediate deprovisioning when staff resign, and audit logs that record who viewed which report. If everyone can see everything, you are processing beyond the purpose the patient consented to and you have no safeguard to point at.
- Build a retention map with the statutory floor in it — in both directions. Map each data class to its basis and period: registration and identity data, reports and images, requisition forms, invoices, and NABL and Clinical Establishments record-keeping duties, plus ICMR requirements where you do research work. Erase once the purpose and any statutory retention period end. But note the floors that cut the other way: Rule 6(1)(e) requires retaining access logs and personal data for one year as a security safeguard, and Rule 8(3) sets a one-year minimum for personal data, associated traffic data and processing logs. "Delete everything on request" is wrong; so is a decade of walk-in registrations, old home-collection address lists, and enquiry data that never converted.
- Publish the contact person and stand up the rights machinery. Rule 9 requires prominently publishing on your website or app the business contact information of the person able to answer questions about processing — and mentioning it in every response to a rights request. Put it on your website, on the registration form, and in the report footer, since the report is the document patients actually keep. Rule 14(1) requires publishing the means by which a patient makes a request and any identifier you need (your CRF or patient ID). Rule 14(3) requires responding within a period not exceeding ninety days. Rule 14(4) requires supporting nomination. Name a real person with a monitored inbox, not a generic address.
- Rehearse a breach on paper, and check where the data physically sits. Four obligations run in parallel and are cumulative, not alternatives: CERT-In within 6 hours of noticing; Rule 7(1) intimation to each affected patient without delay; Rule 7(2)(a) initial intimation to the Data Protection Board without delay; Rule 7(2)(b) detailed report to the Board within 72 hours. Most playbooks have only the 72-hour filing — the Board gets two. Rule 7(1) prescribes the patient notice contents: nature, extent and timing, consequences relevant to them, mitigation implemented, safety steps they can take, and business contact information for someone who can respond. Pre-draft it. Run the scenario as LIS ransomware on a Saturday, and a second one as an exposed report URL being enumerated. Separately, Rule 15 applies to every Data Fiduciary transferring personal data outside India, subject to requirements the Central Government may specify — so if your LIS is hosted offshore, or you use teleradiology or telepathology reporting from abroad, inventory those transfers now.