Featured Articles

DPDP Compliance in 2026: Sensitive Data Is Everywhere — Are Healthcare & Hospitality Ready to Manage the Risk? A Practical Compliance Guide

Article: DPDP Compliance

DPDP Compliance in 2026: Sensitive Data Is Everywhere — Are Healthcare & Hospitality Ready to Manage the Risk? A Practical Compliance Guide

Is your organisation prepared for the New Data Privacy Landscape?

As companies are increasingly adopting digital technologies, the collection and use of personal data have become the most integral parts of their day- to-day operations.

1. Why Are Healthcare and Hospitality Among the Sectors Facing Higher Data-Privacy Risk?

While the nature of operations in these two sectors is very different, both operate in environments where personal data is closely connected to the delivery of their core services.

Hospital sector faces particularly high exposure because of the nature of the associated information. Patient information can include medical histories, diagnoses, prescriptions, diagnostic findings, treatment details, insurance information and other highly personal information.The sector also involves multiple clinical, administrative and external stakeholders, making privacy and security an important consideration throughout the patient-care environment.

However, hotel sector depends on interconnected booking channels, property-management systems, payment platforms, CRM solutions, loyalty programmes and other technology-enabled services.Guest information can therefore become part of a broader digital ecosystem extending across the various stages of the guest experience.

The risk profile of the two sectors is therefore different, but both have one important characteristic in common: personal data is deeply embedded in their everyday operations and service-delivery processes.

2. What Is the DPDP Act and Why Does It Matter?

The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes India's framework for processing digital personal data. An organisation that determines the purpose and means of processing personal data generally acts as a Data Fiduciary, while the individual to whom the data relates is the Data Principal.

The framework focuses on responsible data handling throughout its lifecycle.

DPDP Principle What It Means for Organisations
Consent & Transparency Individuals should understand relevant processing and consent where consent is the applicable basis.
Purpose Limitation Data should be collected and used for specified purposes.
Data Minimisation Only data necessary for the relevant purpose should be processed.
Accuracy Personal data should be accurate and updated where required.
Storage Limitation Data should not be retained indefinitely when the purpose or applicable requirement no longer justifies retention.
Security Safeguards Appropriate technical and organisational measures should protect personal data.
Accountability Organisations should be able to demonstrate how their data-protection responsibilities are being managed.

The Act also provides specified rights to Data Principals and establishes obligations relating to personal-data breaches, Data Processors and, where applicable, Significant Data Fiduciaries.

3. DPDP Compliance: Why Should Healthcare Organisations Pay Attention?

Healthcare organisations handle personal information across a highly interconnected patient-data lifecycle:

Registration → Consultation → Diagnostics → Treatment → Pharmacy → Billing → Insurance → Discharge → Follow-up

A single patient journey may involve doctors, nurses, administrative teams, laboratories, pharmacies, insurers, TPAs, specialists, cloud platforms and technology vendors.

The challenge is therefore not simply securing one hospital database. It is maintaining appropriate governance as information moves across the entire ecosystem.

4. What Should Hospitals Review?

i. Map Every Patient-Data Flow

Hospitals should identify:

  • What patient data is collected
  • Where it is stored
  • Which systems process it
  • Who can access it
  • Which third parties receive it
  • How long different categories are retained

A useful starting point is to map OPD, IPD, ICU, OT, laboratory, radiology, pharmacy, billing, insurance, referral and digital-health systems.

ii. Review Consent and Other Applicable Processing Grounds

Consent is an important part of the DPDP framework, but it is not the only basis recognised by the Act. Specified legitimate uses also exist in defined circumstances.

For example, processing required for healthcare delivery may need to be considered differently from optional promotional communication.

Hospitals should document the purpose and applicable basis for significant processing activities rather than treating every use of patient information as identical.

iii. Control Third-Party Data Sharing

  • Insurance TPAs: For claims processing, with appropriate contractual arrangements and consent where consent is the applicable basis.
  • Labs / Imaging Centres: For healthcare delivery, with appropriate privacy-notice coverage and vendor security assessment.
  • Referral Specialists: For continuity of care, with the applicable processing basis and governance arrangements where the specialist is a separate entity.
  • Government / Public Authorities: Where disclosure is required by applicable law, with the legal requirement and scope of disclosure documented.
  • Police / Medico-Legal Authorities: Where legally required, with disclosures restricted to the required scope and appropriately documented.
  • HIS / EMR / Cloud Vendors: Where acting as Data Processors, with appropriate contractual, security, access and incident-management requirements.
  • Research / Clinical Trial Sponsors: With the applicable consent, purpose, ethical and regulatory requirements appropriately addressed.
  • Marketing / CRM Agencies: For optional marketing activities, with appropriate consent where required and mechanisms to honour withdrawal.

Key point: Third-party sharing should be purpose-driven, documented, controlled and periodically reviewed, rather than treated as a routine operational activity.

iv. Implement Reasonable Security Safeguards

The DPDP Rules specify security measures covering areas such as encryption, access control, monitoring, logging and backups.

For hospitals, practical safeguards may include:

  • Role-based and least-privilege access
  • Multi-factor authentication
  • Encryption at rest and in transit
  • Audit logging of patient-record access
  • VAPT and security testing
  • Endpoint protection
  • Network segmentation
  • Vendor security assessments
  • Physical protection of relevant infrastructure
  • Tested backup and ransomware-recovery mechanisms

The objective is not simply to deploy security tools, but to establish safeguards appropriate to the organisation's risk and processing environment.

v. Prepare for Patient Rights

Hospitals may need to locate information across HIS, EMR, laboratory, radiology, billing, insurance and other systems when responding to applicable Data Principal requests.

A defined workflow should therefore cover request receipt, identity verification, data discovery, review, response, correction or erasure where applicable, and record-keeping.

vi. Address Retention and Erasure

Healthcare records may need to be retained because of applicable legal, regulatory, contractual or operational requirements.

Therefore, DPDP readiness does not mean “delete everything after a fixed period.”

Hospitals should instead establish a documented retention schedule that identifies why particular information must be retained, when it can be deleted and how controlled erasure will be performed.

5. DPDP Compliance: Why Should Hotels Pay Attention?

Hotels also operate through a continuous guest-data lifecycle:

Search → Booking → Identity Verification → Check-in → Stay → Guest Services → Payment → Check-out → Loyalty/Post-Stay Communication

Guest information may move through websites, booking engines, OTAs, PMS, CRM, payment gateways, loyalty platforms, Wi-Fi systems and communication tools.

FHRAI has specifically advised hospitality establishments to pay attention to DPDP responsibilities, including notices, SOPs, vendor compliance and related obligations.

6. What Should Hotels Review?

i. Understand What Guest Data Is Being Collected

This may include:

  • Name and contact information
  • Identity information
  • Booking and stay details
  • Payment-related information
  • Loyalty-programme information
  • Guest preferences
  • Feedback and communication history

Hotels should assess whether each category is necessary for the relevant purpose.

ii. Review Booking and Check-In Processes

Privacy considerations should be incorporated into website forms, booking engines, registration processes and other collection points.

Privacy notices should explain relevant processing in a clear and understandable manner, consistent with the requirements of the applicable DPDP framework.

iii. Manage OTA and Vendor Relationships

Hotels frequently depend on:

  • Online Travel Agencies
  • Booking platforms
  • PMS providers
  • Payment gateways
  • CRM platforms
  • Loyalty-programme providers
  • Cloud and managed-service providers

Hotels should map these relationships, understand the flow of personal data and establish appropriate contractual, security and governance arrangements.

iv. Govern Personalisation and Marketing

Guest preferences can help hotels provide personalised services. However, the organisation should distinguish between information required to deliver a service and information used for optional marketing or personalisation.

Marketing communication, loyalty programmes and other optional activities should have appropriate transparency and consent mechanisms where consent is the applicable basis.

v. Secure Hotel Technology

Important systems such as PMS, booking engines, CRM and payment environments should be protected through appropriate access controls, authentication, monitoring, encryption and security testing.

A compromise of one connected platform can potentially affect multiple stages of the guest-data lifecycle.

7. What Happens When a Personal-Data Breach Occurs?

A data breach could involve ransomware, unauthorised employee access, a compromised account, a lost device, a misconfigured cloud environment or a third-party security incident.

Organisations should follow a defined process:

Detect → Contain → Assess → Notify → Recover → Review

The DPDP Rules require Data Fiduciaries to notify affected Data Principals without delay and inform the Data Protection Board of India without delay, followed by specified detailed information within the prescribed framework.

Organisations should therefore have:

  • A documented incident-response plan
  • Clear escalation responsibilities
  • Breach assessment procedures
  • Notification templates
  • Evidence-preservation procedures
  • Root-cause analysis
  • Recovery procedures
  • Periodic incident-response testing

Healthcare organisations should also consider their obligations under other applicable frameworks, while hotels should consider requirements relevant to their payment, technology and operational ecosystems.

8. What Are Significant Data Fiduciary Obligations?

Not every large hospital, hotel or hotel chain automatically becomes a Significant Data Fiduciary (SDF).

The Act provides for designation based on specified factors and circumstances. Where an organisation is designated an SDF, additional obligations can include:

  • Appointment of a Data Protection Officer
  • Appointment of an independent data auditor
  • Periodic data-protection impact assessments
  • Periodic audits
  • Additional governance and compliance requirements

Organisations should therefore assess their circumstances rather than assuming that organisational size alone determines SDF status.

9. DPDP Penalties: What's at Stake?

The DPDP Act provides for significant financial penalties, with the Schedule allowing penalties of up to ₹250 crore for certain breaches, including failure to take reasonable security safeguards to prevent personal-data breaches.

However, this is a statutory maximum, not an automatic penalty for every incident.

For organisations, the wider concern is therefore not simply the amount of a potential penalty. It is whether they can demonstrate appropriate governance, security safeguards, processes and accountability.

10. What Are the Major DPDP Compliance Challenges?

i. Fragmented Data

Personal data may be distributed across multiple applications, departments and locations.

What to do: Create a data inventory and map significant data flows.

ii. Legacy Systems

Older systems may lack modern access controls, logging or deletion capabilities.

What to do: Assess legacy-system risks and establish a prioritised remediation plan.

iii. Third-Party Dependency

Hospitals and hotels depend heavily on external technology and service providers.

What to do: Conduct vendor assessments and establish appropriate contractual controls.

iv. Employee Access

Too much access can create unnecessary exposure.

What to do: Implement role-based access, least privilege and periodic access reviews.

v. Retention Management

Keeping data indefinitely increases governance complexity.

What to do: Establish purpose- and requirement-driven retention schedules.

vi. Rights and Grievances

Requests can be difficult when data exists in multiple systems.

What to do: Establish a centralised workflow with defined ownership.

vii. Breach Readiness

Organisations may have security tools but no tested response process.

What to do: Conduct tabletop exercises and regularly test incident-response procedures.

viii. Lack of Awareness

Employees remain an important part of the data-protection environment.

What to do: Provide role-specific privacy and security awareness training.

11. 15-Point Hospital DPDP Compliance Checklist

Is your hospital prepared to:

  1. Map patient data across clinical and administrative systems?
  2. Identify purposes for significant processing activities?
  3. Maintain appropriate privacy notices?
  4. Manage consent where consent is the applicable basis?
  5. Document specified legitimate uses where relied upon?
  6. Handle applicable patient rights and grievances?
  7. Map Data Processors and other third parties?
  8. Maintain appropriate contractual arrangements?
  9. Implement role-based access controls?
  10. Enable logging and monitoring of sensitive access?
  11. Implement MFA, encryption and appropriate security safeguards?
  12. Test applications and infrastructure for vulnerabilities?
  13. Maintain backup and ransomware-recovery capabilities?
  14. Establish retention and controlled-erasure procedures?
  15. Maintain and test a documented breach-response process?

12. 15-Point Hotel DPDP Compliance Checklist

Is your hotel prepared to:

  1. Map guest data from booking to post-stay communication?
  2. Review website and booking-engine collection points?
  3. Maintain appropriate privacy notices?
  4. Review consent for optional marketing and loyalty activities?
  5. Map OTAs, PMS, CRM and payment providers?
  6. Review vendor contracts and security responsibilities?
  7. Control employee and contractor access?
  8. Implement MFA for critical systems?
  9. Protect guest information through encryption and monitoring?
  10. Conduct appropriate security assessments?
  11. Establish guest-rights and grievance workflows?
  12. Define retention and deletion requirements?
  13. Review guest-preference and personalisation practices?
  14. Maintain a documented breach-response process?
  15. Conduct periodic privacy, security and vendor reviews?

13. How Should an Organisation Start Its DPDP Compliance Journey?

Trying to address every issue simultaneously can make compliance difficult to manage.

A structured approach is more practical:

  • Step 1 – Identify: Understand what personal data the organisation holds.
  • Step 2 – Map: Trace where the data comes from, where it goes and who can access it.
  • Step 3 – Assess: Review purposes, notices, rights, security, vendors, retention and governance.
  • Step 4 – Remediate: Prioritise and address identified gaps.
  • Step 5 – Implement: Establish policies, procedures and technical controls.
  • Step 6 – Test: Test access controls, rights workflows and breach response.
  • Step 7 – Monitor: Conduct periodic reviews and update the framework as operations change.

The DPDP framework is being implemented through a phased timeline. The main operational provisions under the Act are scheduled to commence 18 months after the November 2025 commencement notification, making the preparation period important for organisations.

14. Is a Privacy Policy Enough for DPDP Compliance?

No.

A privacy policy is only one part of the overall framework.

Effective readiness requires alignment between:

Policy → Process → People → Technology → Third Parties → Evidence

An organisation should be able to demonstrate not only what its policy says, but also how those requirements work in practice.

15. What Does DPDP Readiness Look Like?

A DPDP-ready organisation should be able to answer:

  • What personal data do we process?
  • Why do we process it?
  • Where is it stored?
  • Who can access it?
  • Which third parties receive it?
  • What safeguards protect it?
  • How long do we retain it?
  • How do we handle applicable rights?
  • What happens when a breach occurs?
  • Who is accountable?
  • Can we demonstrate that these controls actually operate?

For hospitals, this means understanding the patient-data lifecycle.

For hotels, it means understanding the guest-data lifecycle.

Conclusion

The DPDP framework brings data protection into the broader organisational conversation around governance, technology, security and accountability.

For healthcare and hospitality organisations, compliance is not simply about understanding the legislation or preparing a privacy policy. It requires organisations to understand how personal data moves through their operations, establish appropriate controls, manage third-party relationships, protect information, respond to applicable rights and maintain evidence of their processes.

As organisations continue to digitise their operations, DPDP readiness should therefore be viewed as an ongoing process of understanding, governing and protecting personal data throughout its lifecycle!

Featured Articles

Commentary and detailed discussion on Cyber Security issues, trends, business growth, digital innovation, jobs, and entrepreneurship.

Have any query?

Feel free to contact us at