Patient data leaving a lab rarely stays on one server. Franchise counters, the LIS, the report app and the referring hospital each take a copy — and Section 8 decides who is accountable for each one.

TL;DR

  • A DPDPA data processor India arrangement is defined by who decides the purpose, not by who sends the invoice. Section 8(2) of the Digital Personal Data Protection Act, 2023 permits a Data Fiduciary to involve a processor for any activity related to offering of goods or services to Data Principals only under a valid contract.
  • A franchise collection centre operating under your brand is almost always processing on your instructions. Section 8(1) makes the lab responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary.
  • Hospital sharing is usually not a processor handoff. Sending a report to a referring hospital or doctor is typically a disclosure to another Data Fiduciary, which triggers the Section 8(3) accuracy and completeness duty instead.
  • Section 8(7) requires the lab to cause its Data Processor to erase personal data on consent withdrawal or purpose expiry, unless retention is necessary for compliance with any law for the time being in force. Deletion that stops at your own database is not compliance. Reconcile that clock with Clinical Establishments and NABL/ISO 15189 retention before you automate deletion.
  • Breaches run a cumulative dual clock: CERT-In 6 hours under the 28 April 2022 directions, plus a 72-hour detailed report to the Data Protection Board under Rule 7 of the DPDP Rules, 2025. Vendor SLAs must be shorter than both.
  • Substantive obligations bite by 13 May 2027. Failure of Section 8(5) reasonable security safeguards carries a penalty up to ₹250 crore; failure to notify a breach under Section 8(6) carries up to ₹200 crore.

What does a DPDPA data processor India arrangement mean for a diagnostic lab?

Under the DPDPA, a processor relationship exists whenever another entity processes patient personal data on your instructions, for your purpose. That is the whole test. Section 2(k) defines a Data Processor as a person who processes personal data on behalf of a Data Fiduciary; Section 2(i) defines the Data Fiduciary as the person who alone or with others determines the purpose and means of processing. Ownership of the server, size of the vendor and direction of payment are all irrelevant.

This matters for labs because the pillar problem — DPDPA compliance for diagnostic labs — is a chain problem. This article goes one level down into the chain itself: the franchise counter, the LIS instance, the hospital feed, and the contract that is supposed to hold them together.

Two errors show up repeatedly in lab audits. The first is treating every counterparty as a processor, including hospitals and referring clinicians who plainly determine their own purposes. The second is treating no one as a processor because “they’re a partner, not a vendor”. Both produce the same outcome: no Section 8(2) instrument, and no way to evidence instructions when the Board asks.

Who is the Data Fiduciary vs Data Processor in a franchise, LIS or hospital chain?

ArrangementWho determines the purposeLab’s roleCounterparty’s roleInstrument required
Franchise collection centre under lab brandLabData FiduciaryData ProcessorSection 8(2) contract or data addendum to franchise agreement
Independent collection centre with its own patient contractCentre, for registration; lab, for testingBoth, by purposeBoth, by purposeDual instrument: processor terms plus disclosure terms
LIS, cloud host, courier, report-delivery appLabData FiduciaryData ProcessorSection 8(2) contract with field-level scoping
Hospital sends samples under its own patient consentHospitalData ProcessorData FiduciaryProcessor terms from the hospital, accepted by the lab
Lab returns the report to the referring hospital or doctorEach party, separatelyData FiduciaryData FiduciaryDisclosure terms; Section 8(3) accuracy duty applies
Lab markets health packages to hospital-referred patientsLabData Fiduciary—Fresh Section 5 notice and Section 6 consent

DPDPA data processor India role map for diagnostic labs across franchise centres, LIS vendors and hospitals

Row four and row six are the ones that get labs into trouble. When a hospital instructs you to run a panel, you are a processor for that panel — which means no independent reuse of those patient records at all. The moment your growth team pulls those same numbers into a recall campaign, the purpose changed, you became a Data Fiduciary, and you now need your own notice and consent. There is no version of this where the hospital’s consent covers your marketing.

What must a Section 8(2) processor agreement for labs actually say?

Section 8(2) permits a Data Fiduciary to involve a Data Processor for any activity related to offering of goods or services to Data Principals only under a valid contract. It does not enumerate clauses. The enumeration comes from the obligations you still carry: Section 8(4) technical and organisational measures, Section 8(5) reasonable security safeguards — including processing on your behalf by a Data Processor — Section 8(6) breach intimation, Section 8(7) erasure, Section 8(10) grievance redressal, and Sections 11–12 rights fulfilment. When a hospital sends you samples, that Section 8(2) duty sits with the hospital as Data Fiduciary; when you engage an LIS, it sits with you.

ClauseWhat it must actually sayFailure mode if missing
Scope of instructionsNamed purposes and the exact field set — patient ID, panel, result values, phone — not “patient data”Vendor stores full identifiers it never needed; breach blast radius multiplies
Reuse and analytics barNo independent use, no de-identified model training, no aggregate resale without written instructionLIS vendor builds a product on your patient base
Sub-processor disclosureNamed sub-processors, prior notice of change, flow-down of the same termsReport app silently routes PDFs through an unvetted CDN
Security commitmentsEncryption at rest and in transit, role-based access, log retention, offboarding of leaversSection 8(5) exposure sits with you; penalty up to ₹250 crore
Incident escalation clockNotification to the lab in hours, not “promptly” — sized to beat CERT-In’s 6 hoursYou miss the 6-hour CERT-In direction and the 72-hour Board report
Erasure and return on exitDeletion certificate, defined format for return, no residual copies in backups beyond a stated windowSection 8(7) erasure never propagates; franchise exits with the patient database
Audit and evidence rightsRight to access logs, access records and consent state on requestNothing to hand counsel or the Board except assertions
Rights supportVendor must assist with access, correction and erasure requests inside your SLAYou miss rights-request timelines under Sections 11–12

Section 8(2) contract chain from diagnostic lab to franchise centre, LIS vendor and sub-processors under DPDPA

The practical shortcut most labs need is a single data processing addendum that attaches to every franchise agreement, LIS licence and courier contract already in force, rather than renegotiating each one. Add a signed field-scoping annexure per vendor, because that annexure is what makes the addendum enforceable in practice.

How should labs handle hospital sharing and referral report handoffs?

Treat a report handoff as a disclosure, not a transfer of responsibility.

When you send a result to a referring hospital, TPA or clinician who will use it for their own purpose, that recipient is an independent Data Fiduciary. Section 8(3) requires you to ensure the data is complete, accurate and consistent when it is disclosed to another Data Fiduciary or used to make a decision affecting the patient. A wrong phone number attached to a positive result is now a compliance failure, not only a service failure.

Three operational consequences follow:

  1. Name the recipient class in the Section 5 notice. “Shared with your referring doctor and, where applicable, the hospital that ordered the test” is specific. “Shared with partners” is not.
  2. Scope the payload. A referring doctor needs the panel and result. They rarely need the patient’s Aadhaar number, address, or full billing history. Ship the minimum viable field set through the integration.
  3. Log the handoff. Every outbound report needs a record of who received it, which fields, on what date, and under which consent state — which is the same record you will need at hour six of a breach. The hospital-side view of this chain is covered in DPDP consent in hospitals: why it cannot live only inside your HIS.

One more point worth stating plainly: a report does not stop being personal data when it leaves your building. Tokenised, courier-carried, or sitting in a hospital’s HIS, it remains personal data, and your duties attach to what you disclosed and how.

Why does architecture beat a folder of signed PDFs?

Because a contract allocates responsibility; it does not produce evidence. When the Board asks which patients were affected, which fields the LIS vendor held, and whether a withdrawal from March actually reached the franchise counter, a signed PDF answers none of it.

Three architectural components do. A sealed PII vault keeps identifiers out of vendor-facing systems entirely, so the LIS, the report app and the franchise dashboard operate on tokens — which shrinks both the field set in your Section 8(2) annexure and the blast radius of a vendor breach. Cryptographically immutable consent records let you show what a specific patient was shown, on what date, for which purpose, and when they withdrew — the difference between claiming a lawful basis and proving one under Section 6. An evidentiary-grade audit trail shows which fields moved to which processor, who accessed a report, and whether a Section 8(7) erasure instruction executed downstream.

Note what this is not: mandatory Rule 13 audits and DPIAs under the DPDP Rules, 2025 apply to Significant Data Fiduciaries notified under Section 10, not to every lab. Most labs are not SDFs. Every lab still owes Section 8 in full, and Section 8 is what processor failures breach. See the Privigo healthcare solutions page for how this maps to a lab rollout.

Who owns processor governance before 13 May 2027?

AreaOwnerStatus
Processor inventory: every franchise, LIS, courier, app, cloud, TPA feedIT + Quality Manager☐
Role classification (Fiduciary / Processor / dual) per counterpartyLegal☐
Section 8(2) addendum executed across all live contractsFranchise HQ / Legal☐
Field-scoping annexure per processorLIS Owner / IT☐
Sub-processor register and change-notice trackingIT☐
Vendor incident SLA shorter than CERT-In 6 hoursIT (named on-call)☐
Section 8(7) erasure propagation and deletion certificatesQuality Manager☐
Hospital and referral disclosure log with consent stateQuality Manager☐
Exit runbook: data return, deletion proof, access revocationFranchise HQ / IT☐

Closing

Three things worth doing this month:

  1. Classify every counterparty by purpose, not by contract type. Run the list from the governance table above and mark each as Fiduciary, Processor, or dual. Most labs discover at least one hospital feed and one franchise centre sitting in the wrong column.
  2. Issue one Section 8(2) addendum plus a per-vendor field annexure, rather than reopening every commercial agreement. Start with the LIS and the report-delivery app, since they hold the widest field set.
  3. Test erasure propagation end to end. Withdraw consent for one test patient and time how long it takes to get written deletion confirmation from the LIS vendor, the report app and the franchise counter — and log where Clinical Establishments or NABL/ISO 15189 retention still blocks deletion.

Book a 30-minute call with Privigo to map your processor chain, field scoping and consent evidence against Section 8 before 13 May 2027.

Sources

  1. Ministry of Electronics and Information Technology — The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023): https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  2. MeitY — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), notified 13 November 2025: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
  3. Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025, 14 November 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
  4. Press Information Bureau — DPDP Rules, 2025 Notified (explainer document): https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
  5. CERT-In — Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
  6. CERT-In — Directions and FAQs landing page: https://www.cert-in.org.in/Directions70B.jsp

FAQ

Is a franchise collection centre a Data Processor under the DPDPA?

Yes, in most franchise models. If the centre collects patient data under your brand, on your instructions, for your diagnostic purpose, it is a Data Processor and Section 8(2) requires the engagement to sit under a valid contract. A pre-2023 commercial franchise agreement with no data clauses does not satisfy that.

Does a diagnostic lab need a written contract with its LIS vendor under the DPDPA?

Yes. Section 8(2) permits a Data Fiduciary to involve a Data Processor only under a valid contract. For an LIS, cloud host, courier or report-delivery app, that contract must scope the fields processed, bar independent reuse, fix an incident escalation clock and cover erasure under Section 8(7).

Can a lab reuse hospital-referred patient data for its own health packages?

No, not on the hospital’s consent. When you process samples on a hospital’s instructions you are a Data Processor for that purpose. Marketing to those patients is a new purpose that makes you a Data Fiduciary, requiring your own Section 5 notice and separate Section 6 consent.

Is the lab liable if its LIS vendor or franchise partner causes the breach?

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary, in respect of any processing undertaken on its behalf by a Data Processor. The CERT-In 6-hour and Section 8(6) Board intimation duties remain yours, and Section 8(5) security failures carry penalties up to ₹250 crore.

This article is general information on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Diagnostic labs also remain subject to Clinical Establishments legislation, NABL/ISO 15189 requirements and applicable state medical records rules. Consult qualified counsel before acting on any part of it.