Patient data leaving a lab rarely stays on one server. Franchise counters, the LIS, the report app and the referring hospital each take a copy — and Section 8 decides who is accountable for each one.
TL;DR
- A DPDPA data processor India arrangement is defined by who decides the purpose, not by who sends the invoice. Section 8(2) of the Digital Personal Data Protection Act, 2023 permits a Data Fiduciary to involve a processor for any activity related to offering of goods or services to Data Principals only under a valid contract.
- A franchise collection centre operating under your brand is almost always processing on your instructions. Section 8(1) makes the lab responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary.
- Hospital sharing is usually not a processor handoff. Sending a report to a referring hospital or doctor is typically a disclosure to another Data Fiduciary, which triggers the Section 8(3) accuracy and completeness duty instead.
- Section 8(7) requires the lab to cause its Data Processor to erase personal data on consent withdrawal or purpose expiry, unless retention is necessary for compliance with any law for the time being in force. Deletion that stops at your own database is not compliance. Reconcile that clock with Clinical Establishments and NABL/ISO 15189 retention before you automate deletion.
- Breaches run a cumulative dual clock: CERT-In 6 hours under the 28 April 2022 directions, plus a 72-hour detailed report to the Data Protection Board under Rule 7 of the DPDP Rules, 2025. Vendor SLAs must be shorter than both.
- Substantive obligations bite by 13 May 2027. Failure of Section 8(5) reasonable security safeguards carries a penalty up to ₹250 crore; failure to notify a breach under Section 8(6) carries up to ₹200 crore.
What does a DPDPA data processor India arrangement mean for a diagnostic lab?
Under the DPDPA, a processor relationship exists whenever another entity processes patient personal data on your instructions, for your purpose. That is the whole test. Section 2(k) defines a Data Processor as a person who processes personal data on behalf of a Data Fiduciary; Section 2(i) defines the Data Fiduciary as the person who alone or with others determines the purpose and means of processing. Ownership of the server, size of the vendor and direction of payment are all irrelevant.
This matters for labs because the pillar problem — DPDPA compliance for diagnostic labs — is a chain problem. This article goes one level down into the chain itself: the franchise counter, the LIS instance, the hospital feed, and the contract that is supposed to hold them together.
Two errors show up repeatedly in lab audits. The first is treating every counterparty as a processor, including hospitals and referring clinicians who plainly determine their own purposes. The second is treating no one as a processor because “they’re a partner, not a vendor”. Both produce the same outcome: no Section 8(2) instrument, and no way to evidence instructions when the Board asks.
Who is the Data Fiduciary vs Data Processor in a franchise, LIS or hospital chain?
| Arrangement | Who determines the purpose | Lab’s role | Counterparty’s role | Instrument required |
|---|---|---|---|---|
| Franchise collection centre under lab brand | Lab | Data Fiduciary | Data Processor | Section 8(2) contract or data addendum to franchise agreement |
| Independent collection centre with its own patient contract | Centre, for registration; lab, for testing | Both, by purpose | Both, by purpose | Dual instrument: processor terms plus disclosure terms |
| LIS, cloud host, courier, report-delivery app | Lab | Data Fiduciary | Data Processor | Section 8(2) contract with field-level scoping |
| Hospital sends samples under its own patient consent | Hospital | Data Processor | Data Fiduciary | Processor terms from the hospital, accepted by the lab |
| Lab returns the report to the referring hospital or doctor | Each party, separately | Data Fiduciary | Data Fiduciary | Disclosure terms; Section 8(3) accuracy duty applies |
| Lab markets health packages to hospital-referred patients | Lab | Data Fiduciary | — | Fresh Section 5 notice and Section 6 consent |
Row four and row six are the ones that get labs into trouble. When a hospital instructs you to run a panel, you are a processor for that panel — which means no independent reuse of those patient records at all. The moment your growth team pulls those same numbers into a recall campaign, the purpose changed, you became a Data Fiduciary, and you now need your own notice and consent. There is no version of this where the hospital’s consent covers your marketing.
What must a Section 8(2) processor agreement for labs actually say?
Section 8(2) permits a Data Fiduciary to involve a Data Processor for any activity related to offering of goods or services to Data Principals only under a valid contract. It does not enumerate clauses. The enumeration comes from the obligations you still carry: Section 8(4) technical and organisational measures, Section 8(5) reasonable security safeguards — including processing on your behalf by a Data Processor — Section 8(6) breach intimation, Section 8(7) erasure, Section 8(10) grievance redressal, and Sections 11–12 rights fulfilment. When a hospital sends you samples, that Section 8(2) duty sits with the hospital as Data Fiduciary; when you engage an LIS, it sits with you.
| Clause | What it must actually say | Failure mode if missing |
|---|---|---|
| Scope of instructions | Named purposes and the exact field set — patient ID, panel, result values, phone — not “patient data” | Vendor stores full identifiers it never needed; breach blast radius multiplies |
| Reuse and analytics bar | No independent use, no de-identified model training, no aggregate resale without written instruction | LIS vendor builds a product on your patient base |
| Sub-processor disclosure | Named sub-processors, prior notice of change, flow-down of the same terms | Report app silently routes PDFs through an unvetted CDN |
| Security commitments | Encryption at rest and in transit, role-based access, log retention, offboarding of leavers | Section 8(5) exposure sits with you; penalty up to ₹250 crore |
| Incident escalation clock | Notification to the lab in hours, not “promptly” — sized to beat CERT-In’s 6 hours | You miss the 6-hour CERT-In direction and the 72-hour Board report |
| Erasure and return on exit | Deletion certificate, defined format for return, no residual copies in backups beyond a stated window | Section 8(7) erasure never propagates; franchise exits with the patient database |
| Audit and evidence rights | Right to access logs, access records and consent state on request | Nothing to hand counsel or the Board except assertions |
| Rights support | Vendor must assist with access, correction and erasure requests inside your SLA | You miss rights-request timelines under Sections 11–12 |
The practical shortcut most labs need is a single data processing addendum that attaches to every franchise agreement, LIS licence and courier contract already in force, rather than renegotiating each one. Add a signed field-scoping annexure per vendor, because that annexure is what makes the addendum enforceable in practice.
How should labs handle hospital sharing and referral report handoffs?
Treat a report handoff as a disclosure, not a transfer of responsibility.
When you send a result to a referring hospital, TPA or clinician who will use it for their own purpose, that recipient is an independent Data Fiduciary. Section 8(3) requires you to ensure the data is complete, accurate and consistent when it is disclosed to another Data Fiduciary or used to make a decision affecting the patient. A wrong phone number attached to a positive result is now a compliance failure, not only a service failure.
Three operational consequences follow:
- Name the recipient class in the Section 5 notice. “Shared with your referring doctor and, where applicable, the hospital that ordered the test” is specific. “Shared with partners” is not.
- Scope the payload. A referring doctor needs the panel and result. They rarely need the patient’s Aadhaar number, address, or full billing history. Ship the minimum viable field set through the integration.
- Log the handoff. Every outbound report needs a record of who received it, which fields, on what date, and under which consent state — which is the same record you will need at hour six of a breach. The hospital-side view of this chain is covered in DPDP consent in hospitals: why it cannot live only inside your HIS.
One more point worth stating plainly: a report does not stop being personal data when it leaves your building. Tokenised, courier-carried, or sitting in a hospital’s HIS, it remains personal data, and your duties attach to what you disclosed and how.
Why does architecture beat a folder of signed PDFs?
Because a contract allocates responsibility; it does not produce evidence. When the Board asks which patients were affected, which fields the LIS vendor held, and whether a withdrawal from March actually reached the franchise counter, a signed PDF answers none of it.
Three architectural components do. A sealed PII vault keeps identifiers out of vendor-facing systems entirely, so the LIS, the report app and the franchise dashboard operate on tokens — which shrinks both the field set in your Section 8(2) annexure and the blast radius of a vendor breach. Cryptographically immutable consent records let you show what a specific patient was shown, on what date, for which purpose, and when they withdrew — the difference between claiming a lawful basis and proving one under Section 6. An evidentiary-grade audit trail shows which fields moved to which processor, who accessed a report, and whether a Section 8(7) erasure instruction executed downstream.
Note what this is not: mandatory Rule 13 audits and DPIAs under the DPDP Rules, 2025 apply to Significant Data Fiduciaries notified under Section 10, not to every lab. Most labs are not SDFs. Every lab still owes Section 8 in full, and Section 8 is what processor failures breach. See the Privigo healthcare solutions page for how this maps to a lab rollout.
Who owns processor governance before 13 May 2027?
| Area | Owner | Status |
|---|---|---|
| Processor inventory: every franchise, LIS, courier, app, cloud, TPA feed | IT + Quality Manager | ☐ |
| Role classification (Fiduciary / Processor / dual) per counterparty | Legal | ☐ |
| Section 8(2) addendum executed across all live contracts | Franchise HQ / Legal | ☐ |
| Field-scoping annexure per processor | LIS Owner / IT | ☐ |
| Sub-processor register and change-notice tracking | IT | ☐ |
| Vendor incident SLA shorter than CERT-In 6 hours | IT (named on-call) | ☐ |
| Section 8(7) erasure propagation and deletion certificates | Quality Manager | ☐ |
| Hospital and referral disclosure log with consent state | Quality Manager | ☐ |
| Exit runbook: data return, deletion proof, access revocation | Franchise HQ / IT | ☐ |
Closing
Three things worth doing this month:
- Classify every counterparty by purpose, not by contract type. Run the list from the governance table above and mark each as Fiduciary, Processor, or dual. Most labs discover at least one hospital feed and one franchise centre sitting in the wrong column.
- Issue one Section 8(2) addendum plus a per-vendor field annexure, rather than reopening every commercial agreement. Start with the LIS and the report-delivery app, since they hold the widest field set.
- Test erasure propagation end to end. Withdraw consent for one test patient and time how long it takes to get written deletion confirmation from the LIS vendor, the report app and the franchise counter — and log where Clinical Establishments or NABL/ISO 15189 retention still blocks deletion.
Book a 30-minute call with Privigo to map your processor chain, field scoping and consent evidence against Section 8 before 13 May 2027.
Sources
- Ministry of Electronics and Information Technology — The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023): https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- MeitY — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), notified 13 November 2025: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025, 14 November 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
- Press Information Bureau — DPDP Rules, 2025 Notified (explainer document): https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
- CERT-In — Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- CERT-In — Directions and FAQs landing page: https://www.cert-in.org.in/Directions70B.jsp
FAQ
Is a franchise collection centre a Data Processor under the DPDPA?
Yes, in most franchise models. If the centre collects patient data under your brand, on your instructions, for your diagnostic purpose, it is a Data Processor and Section 8(2) requires the engagement to sit under a valid contract. A pre-2023 commercial franchise agreement with no data clauses does not satisfy that.
Does a diagnostic lab need a written contract with its LIS vendor under the DPDPA?
Yes. Section 8(2) permits a Data Fiduciary to involve a Data Processor only under a valid contract. For an LIS, cloud host, courier or report-delivery app, that contract must scope the fields processed, bar independent reuse, fix an incident escalation clock and cover erasure under Section 8(7).
Can a lab reuse hospital-referred patient data for its own health packages?
No, not on the hospital’s consent. When you process samples on a hospital’s instructions you are a Data Processor for that purpose. Marketing to those patients is a new purpose that makes you a Data Fiduciary, requiring your own Section 5 notice and separate Section 6 consent.
Is the lab liable if its LIS vendor or franchise partner causes the breach?
Yes. Section 8(1) makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary, in respect of any processing undertaken on its behalf by a Data Processor. The CERT-In 6-hour and Section 8(6) Board intimation duties remain yours, and Section 8(5) security failures carry penalties up to ₹250 crore.
This article is general information on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Diagnostic labs also remain subject to Clinical Establishments legislation, NABL/ISO 15189 requirements and applicable state medical records rules. Consult qualified counsel before acting on any part of it.

