PsychDesk
A padlock beside a laptop representing data privacy
All articles
ComplianceClinical Guide

The DPDP Act: what Indian therapists actually need to do

Consent, storage and breach duties translated from legal text into practice steps.

PR

Priya Raghavan

Practice Operations Lead

27 June 2026 8 min read

India's Digital Personal Data Protection Act applies to therapy records the moment they exist digitally, which, for almost every practice, is now. The obligations are lighter than they sound, but they are specific.

Key takeaways
  • Consent must be specific, informed and withdrawable.
  • Collect the minimum, keep it only as long as clinically required.
  • Know your vendor's storage location and breach process before signing.

Consent is a record, not a conversation

Verbal agreement at intake is not evidence. A timestamped digital consent attached to the client record is, and it takes seconds to capture.

Collect less

Every extra field is a liability with no clinical return. Review your intake form and delete anything you have never used in a session.

Retention and erasure

Define how long closed files are held and what happens after. Clients can ask for erasure; a practice that cannot answer quickly has a policy gap, not a software gap.

Questions for your software vendor

Where is the data stored? Who internally can access it? What is the breach notification timeline? Can you export everything if you leave?

DPDP compliance is mostly good clinical hygiene written down. Most of the work is choosing tools that already handle it for you.

Keep reading

A calm, sunlit therapy space

Ready to simplify your practice?

Start your free trial today. No credit card required, set up your workspace in 10 minutes and see why 200+ mental health professionals trust PsychDesk.

Want the detail first?

Read the product documentation