DPDPA diagnostic labs exposure sits in the chain, not the analyser room — franchise counters, LIS vendors, courier handoffs and WhatsApp report threads that move patient data every day.
TL;DR
- DPDPA diagnostic labs exposure is rarely about the lab’s own server. It is about the franchise, collection-centre, hospital and app chain that patient data travels through every day.
- The lab is the Data Fiduciary. The LIS vendor, report app, courier and cloud host are usually Data Processors, and Section 8(2) requires each engagement to sit under a valid contract.
- Section 5 notice plus Section 6 consent — free, specific, informed, unconditional, unambiguous, by clear affirmative action — must cover phlebotomy, home collection, WhatsApp report delivery and referral sharing separately.
- The Digital Personal Data Protection Act, 2023 does not carry forward the old “sensitive personal data” tier. Labs are regulated because of purpose limitation, notice, consent and processor arrangements — not because of a category label.
- Breaches run a dual clock: CERT-In 6 hours under the 28 April 2022 directions, plus DPB intimation within 72 hours under Rule 7 of the DPDP Rules, 2025. Both apply.
- Substantive obligations bite by 13 May 2027. Maximum penalty is ₹250 crore.
What does DPDPA compliance for diagnostic labs actually cover?
DPDPA diagnostic labs compliance covers every point where patient personal data is collected, stored, shared or delivered — the requisition slip, the phlebotomy room, the LIS, the courier manifest, the hospital handoff, the report PDF and the WhatsApp thread it lands in. The Digital Personal Data Protection Act, 2023 applies to digital personal data, and a test report tied to a name, phone number and patient ID is squarely that.
One misreading is worth killing early. Under the old SPDI Rules, health data sat in a “sensitive personal data” bucket with its own rules. The DPDPA does not retain that tier. Your obligations do not come from a label; they come from Section 4 (lawful purpose), Section 5 (notice), Section 6 (consent), Section 8 (fiduciary duties, security, processor contracts, breach intimation) and the DPDP Rules, 2025. Nothing you hold stops being personal data because it moved downstream to a partner.
Is a diagnostic lab a Data Fiduciary or a Data Processor?
Both roles show up in a single lab’s day, so the answer depends on who determines the purpose.
| Scenario | Lab’s role | What it means operationally |
|---|---|---|
| Walk-in patient books a test directly | Data Fiduciary | Lab owns notice, consent, rights requests, breach duty |
| Home collection booked on lab’s own app | Data Fiduciary | Same, plus consent for location and phlebotomist visit |
| Hospital sends samples under its own patient contract | Usually Data Processor for the hospital | Process only on documented instructions; no independent reuse |
| Franchise collection centre operating under lab brand | Lab is Fiduciary; centre acts on instructions | Contract, training and access control are the lab’s problem |
| Lab engages LIS, cloud, courier, report-delivery app | Lab is Fiduciary; vendor is Processor | Section 8(2) valid contract required for each |
The trap is the third row. Many labs assume that because the hospital “owns” the patient, the lab carries no duty. It does — a processor still owes security safeguards, must stay inside instructions, and must escalate incidents. And where the lab markets its own health packages to those same patients, it has stopped being a processor and become a fiduciary for that purpose.
What patient data do labs hold, and how should each category be handled?
| Data category | Typical source | Common weak point | Required handling |
|---|---|---|---|
| Name, age, sex, patient ID | Requisition / front desk | Reused across franchise branches without control | Purpose-limited; access on role basis |
| Mobile number and email | Registration, report delivery | Bulk-exported for marketing campaigns | Separate Section 6 consent for any promotional use |
| Aadhaar-linked or other government ID | KYC at counter, insurance claims | Photocopies in registers and open drives | Collect only if a purpose requires it; encrypt; retention clock |
| Test results and report PDFs | LIS, analyser interfaces | Shared drives, unrestricted print/export | Encrypted at rest; export logged; no ad-hoc forwarding |
| Home-collection address and geolocation | App, call centre | Sits in phlebotomist’s personal phone | Delete after fulfilment; app-controlled, not personal device |
| Referral doctor mapping and commissions | Business team | Result data attached to commercial reporting | Strip identifiers; report on volumes, not patients |
| Vendor-shared fields (LIS, app, courier) | Integrations, APIs | No contract, no field-level scoping | Contract under Section 8(2); minimum viable field set |
How do notice and consent work across phlebotomy, home collection and WhatsApp reports?
Section 5 requires a notice that itemises the personal data being collected, the purpose, how the patient exercises their rights, and how to complain to the Data Protection Board. Section 6 requires consent that is free, specific, informed, unconditional and unambiguous, signalled by clear affirmative action, and limited to the data necessary for the stated purpose.
For a lab, “specific” is the operative word. These are distinct purposes and need distinct handling:
- Diagnostic processing itself — running the test, generating and storing the report.
- Home collection — address, live location, phlebotomist visit, sample chain of custody.
- Report delivery channel — WhatsApp, SMS, email or a patient app, each named.
- Sharing with a referring doctor or hospital — who receives it, and what fields.
- Health-package marketing and recall reminders — a separate purpose, separately refusable.
A patient who declines marketing must still get their test. Bundling refusal into service denial breaks the “free” and “unconditional” limbs of Section 6. Consent withdrawal has to be as easy as giving it, and it must actually propagate — including to the vendor holding a copy.
Why are franchise networks and LIS vendors the biggest exposure?
Because that is where evidence goes missing. A typical mid-size lab often runs dozens of collection points it does not directly employ, one or two LIS instances, a courier partner, a report-delivery app and a cloud host — and often has a signed contract with none of them beyond a commercial franchise agreement written before 2023.
Section 8(2) is unambiguous: a Data Fiduciary may engage a Data Processor only under a valid contract. In practice that means each vendor and franchise arrangement needs documented instructions on what may be processed, a bar on independent reuse, security and access commitments, sub-processor disclosure, an incident escalation clock that lets you meet your own deadlines, and deletion or return on exit. When a franchise partner leaves, the patient database should not leave with them.
What does breach readiness look like for a lab?
Two clocks run at once, and they are cumulative, not alternatives.
| Clock | Trigger | Deadline | Basis |
|---|---|---|---|
| CERT-In | Detection of a reportable cyber incident, including data breach or leak | 6 hours | Directions dated 28 April 2022 under Section 70B(6), IT Act, 2000 |
| Data Protection Board | Personal data breach | Intimation without delay to affected patients; 72 hours for detailed report to the Board | Section 8(6), DPDPA read with Rule 7, DPDP Rules, 2025 |
Six hours is a shift, not a project. That means a named on-call owner, a pre-drafted CERT-In format, vendor escalation SLAs that are shorter than yours, and logs good enough to tell the Board which patients and which fields were affected — not a rough estimate.
What does defensible lab architecture look like?
The failure mode is policy-PDF theatre: a privacy notice on the website, a consent checkbox nobody logs, and a folder of unsigned vendor agreements. None of that survives a Board inquiry, because none of it is evidence.
Three components change that. A sealed PII vault keeps identifiers out of operational systems, so the LIS, dashboards and analytics work on tokens rather than names. Cryptographically immutable consent records let you prove what a specific patient saw and agreed to on a specific date, and when they withdrew — the difference between asserting compliance and demonstrating it. An evidentiary-grade audit trail shows who accessed which report, which fields went to which vendor, and how a deletion request propagated. Those three things are what you hand to counsel at hour six, not a policy document.
Who owns what in a lab compliance rollout?
| Area | Owner | Status |
|---|---|---|
| Section 5 notice and Section 6 consent capture at all touchpoints | Quality Manager | ☐ |
| LIS configuration, access roles, export controls | LIS Owner / IT | ☐ |
| Collection-centre training, physical records, register hygiene | Collection-Centre Operator | ☐ |
| Franchise contracts, addenda, sub-processor disclosure | Franchise HQ / Legal | ☐ |
| Vendor inventory and Section 8(2) contracts | IT + Legal | ☐ |
| Retention schedule and erasure on withdrawal | Quality Manager | ☐ |
| Breach runbook, CERT-In 6-hour + DPB 72-hour drill | IT (with named on-call) | ☐ |
| Patient rights desk (access, correction, grievance) | Quality Manager | ☐ |
For the hospital-side view of the same chain, see DPDP consent in hospitals: why it cannot live only inside your HIS. For sector-specific rollout patterns, see the Privigo healthcare solutions page and Privigo pricing.
Closing
Three things worth doing this month:
- Inventory every place patient data leaves the lab — franchise centres, LIS, courier, report app, hospital feeds, referral reports — and mark which have a Section 8(2) contract. Most labs find the list is longer than the contract folder.
- Rewrite consent as five separate purposes, not one signature block, and confirm withdrawal actually reaches your vendors.
- Run a 6-hour breach drill with the LIS vendor in the room, and time how long it takes to answer “which patients, which fields”.
Book a 30-minute call with Privigo to walk your lab’s data flow, vendor chain and consent architecture against DPDPA obligations before 13 May 2027.
Sources
- Ministry of Electronics and Information Technology — The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023): https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- MeitY — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), notified 13 November 2025: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025, 14 November 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
- Press Information Bureau — DPDP Rules, 2025 Notified (explainer document): https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
- CERT-In — Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- CERT-In — Directions and FAQs landing page: https://www.cert-in.org.in/Directions70B.jsp
FAQ
Do diagnostic labs need patient consent under the DPDPA?
Yes, in most cases. Under Section 4, a lab may process personal data only for a lawful purpose for which the patient has given consent under Section 6, or for a permitted legitimate use under Section 7. Section 6 consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and preceded by a Section 5 notice. A generic signature on a requisition form is not enough.
Is our LIS vendor or report app a Data Processor under the DPDPA?
Yes, typically. If a vendor processes patient data on the lab’s instructions and for the lab’s purposes, it is a Data Processor, and Section 8(2) requires the engagement to be under a valid contract. The lab stays accountable to the patient and to the Data Protection Board regardless of what the vendor does.
Can a lab send test reports over WhatsApp under the DPDPA?
Yes, but only on a defensible basis. The Section 5 notice must state report delivery by messaging as a purpose, the patient’s Section 6 consent must be specific to that channel, the number must be verified at registration, and Section 8(5) reasonable security safeguards must apply to the delivery path and any stored copies.
Are diagnostic labs required to run a mandatory DPDPA audit?
No, not by default. Rule 13 of the DPDP Rules, 2025 scopes annual Data Protection Impact Assessments and audits to Significant Data Fiduciaries notified by the Central Government under Section 10. Every other lab still owes Section 8 obligations, including security safeguards, processor contracts and breach reporting.
This article is general information on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Diagnostic labs also remain subject to Clinical Establishments legislation, NABL/ISO 15189 requirements and applicable state medical records rules. Consult qualified counsel before acting on any part of it.
