All articles
Compliance

DPDP Act 2023: what every Indian dental clinic must do (2026 checklist)

12 January 2026 9 min readBy Team Viyora
Legal documents and a stethoscope representing healthcare data compliance

The Digital Personal Data Protection Act, 2023 (DPDP) received Presidential assent in August 2023 and is the first cross-sector personal data law India has ever had. Every dental clinic that stores patient names, phone numbers, X-rays or clinical notes electronically is a Data Fiduciary under this Act. This guide translates the parts that apply to you.

The vocabulary you need

  • Data Principal — the patient whose data you hold.
  • Data Fiduciary — you, the clinic that decides what is done with that data.
  • Data Processor — any vendor that processes data on your behalf (your practice-management software, your accountant, your cloud storage).
  • Personal Data — anything that can identify a Data Principal: name, phone, email, Aadhaar, photograph, X-ray, medical history.

The seven things you must do

  1. Give notice: When you collect data, tell the patient exactly what you'll do with it, for how long, and how they can withdraw consent. A patient-registration form is the right place.
  2. Take consent: Consent must be free, specific, informed and unambiguous. A tick-box on the intake form works; a blanket clause buried in fine print does not.
  3. Purpose limitation: Only use the data for the purpose you told the patient. Sharing a mailing list with a marketing agency without fresh consent is not okay.
  4. Enable rights: Patients can ask you to (a) show them their data, (b) correct it, (c) erase it, and (d) nominate someone to receive it after their death. You must respond within a reasonable time.
  5. Report breaches: If patient data is lost or leaked, you must notify the Data Protection Board of India and the affected patients. Speed matters.
  6. Vet your processors: Your software vendor, your accountant and your backup provider are all processors. You are on the hook for their mistakes if you didn't sign an agreement with them.
  7. Delete when done: When the reason you collected the data ends (e.g. the patient asks for erasure, or your retention period ends), you must delete it — including from backups.

The 'Significant Data Fiduciary' question

The Act allows the Central Government to classify some Data Fiduciaries as 'Significant' based on volume, sensitivity and risk. If you cross the threshold, you'll need to appoint a Data Protection Officer, publish audits, and complete Data Protection Impact Assessments. Most single-location dental clinics will not be classified this way; large multi-city chains may need to be ready.

How Viyora helps you get to compliance

  • Consent capture built into the patient-registration form, with an audit log of when and how consent was given.
  • One-click data export in JSON so you can honour a portability request in under a minute.
  • Record-level erasure that also removes data from encrypted backups within the deletion window.
  • Encrypted-at-rest storage on Indian data centres so nothing leaves the country.
  • A signed Data Fiduciary–Processor agreement at onboarding, so your paperwork with your software vendor is done.

Your 2026 checklist

  1. Update your intake form with a DPDP-style consent block.
  2. Publish a plain-English privacy notice on your clinic's website.
  3. Sign written processor agreements with every vendor that touches patient data.
  4. Establish an internal process for handling access, correction and erasure requests.
  5. Document a breach-response playbook — who calls whom, in what order, within what hours.
  6. If you cross into 'Significant' territory, appoint a Data Protection Officer.

The DPDP Act is not a threat to Indian dentistry — it is a chance to modernise how patient data is handled. Clinics that lean in early will be trusted more, and audited less.

See what Viyora looks like at your clinic.

30-day free trial. No credit card. Full Viyora Copilot, WhatsApp reminders and GST invoicing from day one.

Keep reading