Industry · Collection Centres
DPDPA Compliance for Collection Centres in India
A collection centre is not “just the sample counter.” It is the point where identity, phone number, referring doctor and clinical suspicion are all captured together — and under DPDPA 2023, that makes it accountable in its own right. The DPDP Rules were notified on 13 November 2025; substantive obligations commence 13 May 2027. Health data carries no separate tier. It is personal data, with the same duties attached.
Last reviewed: 19 August 2026
What DPDPA compliance risks do collection centres face?
Collection centres hold requisition slips, patient phone numbers, Aadhaar or ID shown at the counter, home-collection app records, and WhatsApp report delivery threads — then push everything to the parent lab through a franchise LIS handoff. Fiduciary or processor turns on who set the purpose: the referring hospital, the parent lab, or the centre itself for walk-ins. The real exposure is Section 8(2) contracts missing partway down that chain, while Section 8(1) holds the fiduciary liable for processing on its behalf irrespective of any agreement to the contrary.
What should collection centres prepare first for DPDPA compliance?
- Map fiduciary vs processor per referral source — walk-ins are yours; hospital and parent-lab panels often are not.
- Put written Section 8(2) contracts on the LIS, home-collection app, SMS/WhatsApp gateway and cloud backup.
- Stop treating WhatsApp report delivery as a front-desk habit — a wrong-number send is a personal data breach.
- Issue a Section 5 notice at the counter; do not hide it in the franchise SOP.
- Name owners for all four breach lanes before a Saturday LIS outage forces the question.
Frequently asked questions
Is the collection centre a Data Fiduciary or a Data Processor?
It depends on who determined the purpose, and one centre is usually both across different flows. For walk-in patients the centre collects, prices and books the test itself — it is a Data Fiduciary. For samples drawn under a hospital's or parent lab's instruction, where that entity set the purpose and the panel, the centre acts as a Data Processor for that flow. Map it per referral source rather than declaring a single status for the business.
Our LIS vendor and the parent lab handle the data after handoff. Does liability leave us?
No. Section 8(1) makes a Data Fiduciary responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary. A clause shifting responsibility to the vendor does not displace that. The practical answer is Section 8(2): a valid written contract with the LIS provider, the home-collection app, the SMS/WhatsApp gateway and the cloud backup, each with purpose limitation, no onward sub-processing without approval, a breach notification window shorter than your own, and deletion on exit. Never treat downstream data as though it stops being personal data once it leaves your counter.
What happens if the centre's system or the LIS is compromised?
Four lanes run cumulatively, not as alternatives. CERT-In requires reporting a reportable cyber incident within 6 hours of noticing it. Rule 7(1) requires intimating affected Data Principals without delay. Rule 7(2)(a) requires an initial intimation to the Data Protection Board without delay. Rule 7(2)(b) requires a detailed report to the Board within 72 hours, covering the events and circumstances, likely consequences, mitigation taken and your contact details. Misdirected WhatsApp reports count — a report sent to the wrong number is a personal data breach, not a front-desk error. Name an owner and a backup for each lane in writing before you need them. Failure of reasonable security safeguards under Section 8(5) carries a penalty of up to ₹250 crore.
Do we need an annual DPDPA audit and DPIA?
Only if the Central Government notifies you as a Significant Data Fiduciary. Rule 13's annual data protection impact assessment, independent audit and algorithmic due-diligence duties attach to notified SDFs — not to every collection centre or franchise. Everything else applies to you regardless of size: Section 5 notice at the counter, per-purpose consent, processor contracts, breach reporting, erasure, and a published grievance contact. Note one earlier date if you plan to route consent through a Consent Manager: Rule 4 registration commences 13 November 2026, ahead of the 13 May 2027 substantive deadline.
Map the handoff before the franchise agreement does it for you
Most centres discover their gap in the handoff — a franchise agreement that covers revenue share and turnaround time, but says nothing about purpose limitation, sub-processing or breach notification windows. A 30-minute discovery call maps your counter, app, WhatsApp and LIS flows against the actual sections and shows you where the contract chain breaks.
Book a 30-minute DPDPA discovery call
Free Gap Analysis
Bring your franchise agreement and one WhatsApp report thread. No deck.
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.