Industry · Diagnostic Labs

DPDPA Compliance for Diagnostic Labs in India

Diagnostic labs capture identity, phone, Aadhaar, symptoms and results at the counter, then push reports out by WhatsApp link within hours. Under the DPDP Act 2023 all of it is personal data, and routine testing runs on Section 6 consent — not the narrow medical-emergency legitimate use. The compliance date is 13 May 2027. NABL and Clinical Establishments retention duties continue alongside.

Last reviewed: 30 July 2026

What DPDPA compliance risks do diagnostic labs face?

The exposure isn't the report, it's the plumbing around it. Unauthenticated WhatsApp and SMS report links, guessable URLs, patient databases living inside an LIS vendor's cloud on no written contract. Then the onward flows: samples outsourced to reference labs, results pushed to referring doctors, corporate health-camp results handed to employers, disclosures to insurance TPAs — each needing its own itemised purpose. DPDPA has no separate sensitive-data tier, so an HIV or pregnancy result carries the same legal standard as a phone number, and far greater harm.

What should diagnostic labs prepare first for DPDPA compliance?

  • Itemise Section 6 consent at registration — diagnosis, marketing, research, referring-doctor disclosure are separate asks.
  • Authenticate and expire report-delivery links (Rule 6(1)(a) names encryption, obfuscation, masking and virtual tokens as minimum safeguards); stop using shared consumer WhatsApp as a records system.
  • Put written processor contracts on LIS, cloud, courier, billing, and reference labs.
  • Map corporate health-camp disclosures — patient consent is required before results go to an employer.
  • Align retention/erasure with NABL and Clinical Establishments duties plus DPDPA purpose limitation.

Frequently asked questions

We're a healthcare provider. Isn't health data covered by a legitimate use instead of consent?

Only in a genuine emergency. Section 7 legitimate uses are a closed list: they cover a medical emergency involving a threat to life or an immediate threat to health where the patient cannot consent, and measures during an epidemic or public-health threat. Routine OPD testing, walk-ins, home collection, health packages and corporate camps are none of those — they run on Section 6 consent, which must be itemised by purpose, in plain language, in English or any Eighth Schedule language, and as easy to withdraw as to give. Diagnosis, marketing, research use of de-identified data and disclosure to a referring doctor are separate asks, not one bundled tick-box at the counter. For patients under 18, Section 9 is the default — but Rule 12 read with the Fourth Schedule (Part A) disapplies Section 9(1) and 9(3) for a clinical establishment, mental health establishment or healthcare professional where processing is restricted to providing health services to the child to the extent necessary to protect her health (and separately for allied healthcare professionals implementing a treatment or referral plan). Marketing, research reuse and tracking outside that clinical purpose still need the full Section 9 treatment.

We send reports over WhatsApp and SMS links. Is that a problem?

It's the single most common failure we find. Section 8(5) obliges you to maintain reasonable security safeguards regardless of how the data leaked, and a report URL that opens for anyone who has the link — no OTP, no date-of-birth check, no expiry, and often a sequential patient ID that can be incremented — is not a safeguard. Same for the shared front-desk WhatsApp Web session, reports mailed as unencrypted PDFs, and the phlebotomist's personal phone holding a month of collection lists. Fixing this is usually cheap: authenticate the link, expire it, randomise identifiers, and stop using consumer messaging accounts as a records system.

Our LIS runs on a vendor's cloud, we outsource specialised tests to a reference lab, and we share results with referring doctors. Who is liable?

The lab is the Data Fiduciary and liability stays with you. Your LIS provider, cloud host, billing gateway and courier are Data Processors — they may process patient data only under a valid written contract with you, specifying purpose, security obligations and deletion on exit. You cannot contract that liability away. Reference labs need looking at carefully: if one is processing strictly on your instructions it is a processor, but if it uses the sample or result for its own purposes it becomes a fiduciary in its own right and needs its own lawful ground. Two things labs routinely miss: the referring doctor is also a Data Principal — their name, registration number, contact details and referral volumes are personal data being processed for incentive and MIS reporting, and they have access and correction rights over it — and disclosing an employee's health-camp results to their employer is a disclosure to a third party that needs the patient's own itemised consent, not the employer's.

If our patient database is breached, what do we report — and do we need annual audits and a DPO?

Two clocks start at detection and both must be met; they are cumulative, not alternatives. CERT-In requires reporting of covered cyber incidents within 6 hours. Separately under DPDPA, you must intimate every affected patient without delay (Rule 7(1)), give the Board an initial description without delay (Rule 7(2)(a)), and file detailed particulars within 72 hours (Rule 7(2)(b)). Failure to maintain reasonable security safeguards attracts up to ₹250 crore, and failure to give the required breach intimation is assessed separately at up to ₹200 crore — one incident can expose you under both heads. On audits: the heavier Rule 13 obligations — annual DPIA, independent data audit, algorithmic due diligence and an India-based Data Protection Officer — bind Significant Data Fiduciaries only, and SDF status is conferred by Central Government notification, not triggered automatically by patient volume. Every lab still owes the baseline duties: valid consent, purpose limitation, erasure once the purpose and statutory retention period end (subject to Rule 6(e)'s one-year floor for access logs and related personal data used as a security safeguard), security safeguards, breach notification, and a working grievance channel with a named contact published on your website and reports.

Official sources

We'll trace one patient journey through your lab

A 30-minute call: registration to report delivery. We look at what your front desk actually collects and on what notice, how reports leave your building, who your LIS and reference-lab contracts make liable, and how long records sit after the clinical purpose ends. You leave with a written gap list mapped to Section 6, the security safeguards duty and your NABL retention obligations — whether or not you work with us.

Book a demo call Free Gap Analysis

Bring your registration form and one report-delivery link. No deck.

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.