DPDP Rules 2025: A Checklist for Dental Clinics

A pair of hands signing a printed form with a pen

Photo: Unsplash

The Digital Personal Data Protection Act has been law since 2023, but for two years there was nothing to actually do, because the Rules that make it operational had not been issued. That changed in November 2025. The Rules are notified, the Data Protection Board exists, and there is now a date on the calendar.

This is a plain-language summary, not legal advice. It is written for a practice owner trying to work out what to do on Monday morning. For anything consequential, read the official notification and take advice.

The Timeline

The Rules were notified in November 2025 with an eighteen-month phased transition. Broadly:

  • From November 2025: the Data Protection Board is operational and can receive complaints.
  • Around November 2026: the regime opens. Consent Managers must be Indian companies.
  • May 2027: the substantive obligations bite in full. Consent notices, rights handling, retention limits, breach procedures, all of it.

Eighteen months sounds generous. It is not, if the answer to "where is our patient consent recorded" is currently "on the registration form, somewhere in that cupboard".

Where a Dental Clinic Sits

Your clinic is a . You decide why and how patient data is processed. Your patients are Data Principals. Your software vendor, your lab, and your accountant are typically acting on your instructions, which means the obligation to patients stays with you regardless of who is holding the file.

That last point is worth sitting with. Outsourcing the storage does not outsource the responsibility.

The Checklist

1. Give a Real Notice

Not a line at the bottom of the registration form. The Rules expect a standalone, itemised notice in clear language that says what you are collecting, specifically what each item is for, and how the patient can withdraw consent or complain. "For clinic purposes" is not a purpose.

2. Separate Treatment Consent From Marketing Consent

The consent to treat a patient and the consent to send them a recall message on WhatsApp are different things collected for different purposes. Bundling them is the most common mistake, and it is the one most likely to matter for a clinic, because recall messaging is the visible bit a patient can complain about.

3. Make Withdrawal Work

Withdrawing consent has to be as easy as giving it. In practice: when a patient replies "stop", something in your system has to change so the next campaign does not include them. If the only record of that is a note in someone's head, you do not have a process.

4. Decide How Long You Keep Things

Personal data is meant to be kept only as long as the purpose requires. Clinical records have their own retention obligations under medical record-keeping norms, which is a separate question from how long you keep a phone number for marketing. Write down a retention period for each, even a rough one, and know where the old paper registers are.

5. Be Able to Answer a Rights Request

A patient can ask to access, correct, update or erase their personal data, and the Rules set an outer limit of 90 days to respond. Two practical questions follow. Could you produce everything you hold on one named patient? Could you correct a wrong date of birth everywhere it appears, including the backup?

6. Handle Nomination

A patient may nominate someone else to exercise these rights for them, which matters more in healthcare than in most sectors: elderly patients, patients who lose capacity, patients who die mid-treatment plan. You need a way to record a nominee and to honour one.

7. Get Children Right

Processing a child's personal data requires verifiable consent from a parent or guardian. There are limited exemptions for essential purposes including healthcare, so treating a child is not the problem. Adding that child's number to a marketing list is a different matter entirely. Paediatric practices should look at this closely.

8. Have Reasonable Security Safeguards

Individual staff logins rather than one shared password. Access limited to what a role actually needs. Encryption in transit. Backups. A record of who looked at what. Most clinics fail the first item on that list before reaching the interesting ones.

9. Know What You Would Do in a Breach

If patient data leaks, you must promptly inform the affected individuals in plain language, describing the nature of the breach and its likely consequences, and report it to the Data Protection Board, with reporting requirements framed around a 72-hour window. Decide now who makes that call, because you will not want to be designing the process while it is happening.

10. Name a Contact for Grievances

Patients need a published way to raise a complaint with you before they escalate to the Board. A named person and a working email address, on your website and on your notice.

The Three Things Clinics Get Wrong

  • The shared login. One username the whole front desk uses. It defeats access control, makes an audit trail meaningless, and is trivially fixable.
  • Patient conversations on personal phones. Clinical information sitting in a staff member's personal WhatsApp is outside your control and leaves with them.
  • The unexamined old data. The register from 2019 with two thousand phone numbers and no record of what anyone agreed to. Ignoring it is a decision, just not a good one.

What Software Can and Cannot Do for You

Be sceptical of anything sold as "DPDP compliance in a box". Software can give you per-user logins, role-based access, records in one place instead of five, and a defined way to find and correct a patient's data. It cannot write your notice, decide your retention periods, or take responsibility for a decision you made.

Dentomate's own position on data handling is set out on the DPDP page and the security page, including what is built today and what is not.

If you do one thing this quarter, make it the second item on the checklist. Separating treatment consent from marketing consent is a change to a form, it takes an afternoon, and it is the obligation a patient is most likely to notice you failing.

Records in One Place, Not Five

Per-user logins, patient records you can actually find, and conversations that stay with the clinic. Free forever, no card required.