
The DPDP Act: what Indian therapists actually need to do
Consent, storage and breach duties translated from legal text into practice steps.
Priya Raghavan
Practice Operations Lead
India's Digital Personal Data Protection Act applies to therapy records the moment they exist digitally, which, for almost every practice, is now. The obligations are lighter than they sound, but they are specific.
- Consent must be specific, informed and withdrawable.
- Collect the minimum, keep it only as long as clinically required.
- Know your vendor's storage location and breach process before signing.
Consent is a record, not a conversation
Verbal agreement at intake is not evidence. A timestamped digital consent attached to the client record is, and it takes seconds to capture.
Collect less
Every extra field is a liability with no clinical return. Review your intake form and delete anything you have never used in a session.
Retention and erasure
Define how long closed files are held and what happens after. Clients can ask for erasure; a practice that cannot answer quickly has a policy gap, not a software gap.
Questions for your software vendor
Where is the data stored? Who internally can access it? What is the breach notification timeline? Can you export everything if you leave?
DPDP compliance is mostly good clinical hygiene written down. Most of the work is choosing tools that already handle it for you.

