DPDP Act 2023 checklist for dental clinics in India
A practical DPDP Act 2023 checklist for Indian dental clinics: notices, consent, WhatsApp, children's records, staff access, breaches, retention and software.
By AvanceZone team · Published 04 Oct 2026 · Updated 04 Oct 2026 · 9 min read
Does the DPDP Act apply to a small dental clinic?
Yes. The Digital Personal Data Protection Act 2023 applies to any person or organisation in India that processes digital personal data, and a dental clinic that keeps patient records in software, on a computer or in WhatsApp is processing digital personal data. There is no exemption for small clinics. In the Act's language the clinic is a data fiduciary, each patient is a data principal, and the software vendor that stores the records for you is a data processor acting on your instructions.
The DPDP Rules, 2025 were notified in November 2025, with most obligations phased in over the following 18 months. Check the current compliance dates with your adviser; the habits below are worth building now in any case, because they are also what patients increasingly expect.
This checklist is practical guidance from the team that builds Dental Software India, not legal advice. For anything specific to your clinic, speak to a lawyer who works with healthcare providers.
The checklist at a glance
| Area | What to do | Evidence to keep |
|---|---|---|
| Notice | Tell patients what data you collect and why, in a language they understand | Registration form or screen wording, dated |
| Consent | Separate consent for treatment records, WhatsApp reminders, marketing and record sharing | Consent log with time, purpose and staff member |
| Minimisation | Collect only what treatment and billing need | Reviewed registration form |
| Access | Role-based access for desk, dentist, consultant and accounts | User list with roles |
| Security | Encryption, backups, two-factor login, no shared passwords | Vendor security summary, backup records |
| Breach | Written plan to notify the Data Protection Board and affected patients | One-page breach procedure |
| Rights | Handle access, correction and erasure requests within a set time | Request register |
| Retention | Keep records as long as clinical and legal duties require, then delete | Retention policy |
1. What should the patient notice say?
A notice is a short, plain statement given at or before the time you collect data. For a dental clinic it should cover what you collect (name, contact, medical history, X-rays, photos, payment details), why (treatment, billing, reminders, legal records), who else sees it (visiting consultants, dental labs, payment gateways, your software vendor), how long you keep it, and how the patient can ask for access, correction or deletion or complain to the Data Protection Board. The Act allows the notice in English or any language in the Eighth Schedule of the Constitution, so offer Tamil, Hindi or your local language alongside English.
2. How should consent work for WhatsApp and marketing?
Consent under the Act must be free, specific, informed, unconditional and unambiguous, and as easy to withdraw as to give. Bundling everything into one signature on the registration form does not meet that standard. Use separate tick boxes for:
- Appointment reminders and recall on WhatsApp or SMS
- Treatment plans and estimates sent on WhatsApp
- Offers, newsletters and festival greetings (marketing)
- Sharing records through ABDM with the patient's ABHA
Treatment itself does not need a separate data-processing consent in the same way, because providing health services to the patient who asked for them is the purpose of collection, but clinical consent for procedures is a separate matter governed by medical ethics and law. If a patient withdraws WhatsApp consent, stop messages promptly and switch to calls. See our guide to WhatsApp recall reminders for consent wording.
3. What about children's dental records?
The Act treats anyone under 18 as a child and generally requires verifiable consent from a parent or lawful guardian before processing a child's data, and it prohibits tracking, behavioural monitoring and targeted advertising directed at children. Dental clinics see many child patients for check-ups, fluoride, sealants and orthodontics. The Rules include an exemption for healthcare providers processing a child's data to the extent needed to provide health services; check its exact scope with your adviser. Practically: record the parent's details and consent on the child's file, send reminders to the parent's number, and never include children in marketing campaigns.
4. Who in the clinic should see what?
Most data leaks in small clinics are not hackers; they are shared logins, a former receptionist who still has access, or a WhatsApp group with patient X-rays in it. Set roles so the front desk sees appointments and billing, dentists see clinical records, visiting consultants see only their own patients, and accounts see ledgers. Remove access the day someone leaves. Keep patient images out of personal phones and group chats; share them through the software or the lab case link instead.
5. What security safeguards are reasonable?
- Data hosted in India with encryption in transit and at rest
- Daily encrypted backups kept in a second location, and a tested restore
- Two-factor login for owners and admins, unique logins for every staff member
- An audit log of who viewed, edited or exported which record
- Updated computers with screen locks at the front desk
Failing to take reasonable security safeguards attracts the Act's highest penalty, up to ₹250 crore. The amount a small clinic would face depends on the circumstances, but the expectation is clear.
6. What happens if there is a data breach?
A personal data breach includes a stolen laptop with patient files, a hacked email account, or records sent to the wrong person. The Act requires the clinic to inform the Data Protection Board and each affected patient. Write a one-page procedure now: who decides it is a breach, who contacts the software vendor, what the patient message says, and where the record of the incident is kept. Ask your vendor how quickly they will tell you about a breach on their side.
7. How long should you keep dental records?
The Act requires deletion once the purpose is served, unless another law requires retention. Clinical records have their own retention expectations under medical council regulations and state clinical-establishment rules, and records may be needed for medico-legal defence. Agree a retention period with your adviser (many clinics keep adult records for several years after the last visit and children's records until well after they turn 18), write it down, and apply it consistently rather than deleting ad hoc.
Your software vendor's retention is separate from yours. In Dental Software India the periods are fixed per data category and are the same on the security page, in the privacy policy and in our FAQs:
| Data category | Purpose | Retention in Dental Software India |
|---|---|---|
| Clinical records (patients, charts, plans, e-consents, notes, images, ledgers, WhatsApp history) | Treatment, billing, follow-up | As long as the clinic account is active; exportable at any time and for 30 days after closing, then erased |
| A single patient's record | Right to erasure | Erased within 30 days of the clinic's request (archiving in the app only hides it) |
| Audit log | Evidence of who did what | Seven years |
| Backups | Disaster recovery | Encrypted nightly, 30-day rolling; erased data leaves backups within 30 days |
| Closed-account data | None after export | Erased from live systems when the 30-day export window ends |
Because your own legal retention period is usually longer than an account's life, export your records before you close an account.
8. What should you ask your dental software vendor?
- Where exactly is data hosted, and is the backup also in India?
- Can roles be restricted per user and per branch, and is there an audit log?
- Does the software store consent separately for each purpose, with time and wording?
- How are deletion and correction requests handled, and is there a record of what was removed?
- Can the clinic export everything at any time, and what happens to data after cancellation?
- How and when will the vendor notify the clinic of a breach?
How Dental Software India supports DPDP compliance
Dental Software India hosts data in India (AWS Mumbai region) with encryption in transit and at rest, nightly encrypted backups kept for 30 days, four roles (owner, admin, staff, viewer; desk-only and consultant-only roles are planned) and an audit log of creates, edits, deletions, plan approvals and payments, kept for seven years. The WhatsApp opt-in is stored on each patient, every plan e-consent keeps the typed name, time, IP and a fingerprint of the exact text agreed, and erasure requests are completed within 30 days and recorded in the audit log. Two-factor login and per-purpose marketing consent records are planned. Read the details on the security and compliance page, our ABDM guide for dental clinics, and the pricing page: these controls are in every plan.
Questions people ask
Is a dental clinic a data fiduciary under the DPDP Act?
Yes. A dental clinic decides why and how patient data is processed, which makes it a data fiduciary under the DPDP Act 2023. The software vendor that stores records is a data processor. Dental Software India acts as a processor on the clinic's instructions and provides consent, access and audit controls.
Do I need consent to send WhatsApp reminders to patients?
Yes. Record a specific, separate consent for WhatsApp reminders, apart from marketing, and stop messages promptly if the patient withdraws it. Meta's policy also requires an opt-in. Dental Software India stores the WhatsApp opt-in on the patient record, and the audit log shows which staff member changed the patient and when; keep your signed registration form for the wording.
What is the penalty for a data breach under the DPDP Act?
Failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore, and failing to notify the Data Protection Board and affected patients of a breach can also be penalised. Actual amounts depend on the circumstances. Encryption, backups, role-based access and a written breach plan are the basics.
Does the DPDP Act replace ABDM rules for dental clinics?
No. The DPDP Act 2023 is a general data-protection law that applies to every clinic, while ABDM is a voluntary health-records framework with its own consent system. A clinic using ABDM must follow both. Dental Software India captures ABHA numbers today; ABDM sharing, with its own consent records, is planned.
Related guides
Best dental software in India 2026: how to choose
How to choose dental software in India in 2026: 10 checks that matter, prices in rupees, and Practo Ray, Clinicia, Dentee, BestoSys and CareStack compared.
How to set up WhatsApp recall reminders for a dental clinic
Step-by-step: set up six-month dental recall and appointment reminders on WhatsApp in India, with templates, timing, Meta message costs and DPDP Act consent.