Under India’s Digital Personal Data Protection (DPDP) Act, “ownership” is really about roles. The patient is the data principal, with rights over their information. Your clinic is the data fiduciary, responsible for it. Your software vendor is a data processor, handling it on your behalf. A good vendor never locks you in, and you can test that quickly.
General information, not legal advice. Check the current DPDP Act and Rules for your obligations.
It is a question worth two minutes of your attention, because the answer decides whether you could ever leave your current software, hand a patient their records on request, or come through an audit without scrambling. The reassuring part: the law is clearer than it sounds, and checking where you stand is quick. This guide explains the three roles the DPDP Act creates, what each means for you, and a simple test of how much control you really have.
The Three Roles, in Plain Terms
The DPDP Act, 2023 frames personal data through relationships rather than possession:
- Data principal (the patient): the person the data is about. They have rights to access, correct and erase their data, and to raise grievances.
- Data fiduciary (your clinic): whoever decides how and why the data is used. That is you. The Act makes you accountable for protecting it, using it only for the stated purpose, and obtaining proper consent.
- Data processor (your software vendor): processes data on the fiduciary’s instructions. The vendor works for you; it does not get to repurpose your patients’ data.
So no single party simply “owns” the data. The patient holds rights, you hold responsibility, and the vendor holds a duty to process it properly and hand it back on request.
What Patients Can Ask of You
Because patients are data principals, they can reasonably ask to see the data you hold on them, to have errors corrected, and in defined circumstances to have data erased, as well as to raise a grievance if something goes wrong. Your clinic should be able to answer those requests, which in practice means your records need to be organised and exportable rather than scattered.
What the DPDP Act Expects of a Clinic
The Act is built on consent and purpose limitation. In practice that means:
- Consent first: getting free, specific, informed and revocable consent before collecting patient data.
- Plain-language notice: telling patients, in plain language, what you collect and why.
- Purpose limitation: using the data only for that stated purpose, not for unrelated marketing or resale.
- Security and readiness: keeping it secure, and being ready to act on a patient’s request or a breach.
The DPDP Rules that operationalise the Act point to safeguards such as encryption, access controls and audit logging. The Rules were notified in November 2025, with most substantive obligations phasing in by 13 May 2027, so check the current timelines that apply to you. There is also an official regulator, the Data Protection Board of India, and significant penalties for serious violations up to ₹250 crore in the most serious cases which is why this is worth getting right rather than ignoring.
The Two-Minute Check
You can test how much control you really have very quickly:
Can you get all your data out, in a usable format?
Ask how you export your patient list, records and billing whether that is self-serve or provided on request. What matters is a clear, dependable process and no lock-in. The real red flag is a vendor that cannot give you a straight answer.
Read the exit clause.
Your contract should say you can take your data out if you leave, in a usable format, without a penalty. If it is silent or restrictive, ask.
Check consent and security.
Confirm the tool captures patient consent and protects data with encryption and role-based access, so only the right staff see the right records.
If all three pass, you are in control. If any fail, you have work to do before it matters.
Vendor Red Flags
A few signs suggest a vendor sees your data as theirs rather than yours:
- No export, or punitive export terms no way to get your data out at all, or only behind a high fee or an unreasonable delay.
- Vague or missing exit terms on what happens to your data if you leave.
- Unclear storage answers about where and how data is stored and secured.
- Self-serving data terms that allow the vendor to use your patients’ data for its own purposes.
Any one of these is worth a direct conversation before you commit further.
Making Your Clinic More DPDP-Ready
You do not need to become a lawyer overnight. A practical start: use clear consent notices in plain language, collect only the data you actually need, restrict staff access to what each role requires, keep the software and its security up to date, and make sure you can produce or delete a patient’s data when asked. Software with encryption, role-based access and easy export does much of this heavy lifting for you.
Where Medisray Stands
Medisray treats your patient data as yours to take with you, and protects it with encryption and role-based access, on secure hosting. You can read more about how Medisray protects your data. Portability and clear consent are the practical signs of a vendor that respects the fiduciary-processor relationship the law describes. Keeping your records organised and exportable is what makes moving or backing up data straightforward, and our DPDP Act guide for clinics covers the wider duties in more detail.
The bottom line: no one “owns” patient data outright but you carry the responsibility for it, and your software should make that easier, not harder. If you can export everything, your contract lets you leave cleanly, and consent and access are handled properly, you are in a strong position. If not, now is the time to fix it well before a patient request or an audit forces the question.
Frequently Asked Questions
Who owns patient data in India?
The DPDP Act does not frame it as ownership. The patient is the data principal with rights, the clinic is the data fiduciary responsible for the data, and the software vendor processes it on the clinic’s behalf.
What is the DPDP Act 2023?
It is India’s Digital Personal Data Protection Act, which sets rules for how personal data, including health data, is collected, used and protected, built around consent and accountability.
Is a clinic a data fiduciary under the DPDP Act?
Yes. A clinic decides how and why patient data is used, which makes it a data fiduciary, responsible for consent, purpose limitation and security.
What rights do patients have over their health data?
Patients can seek access to their data, correction of errors, erasure in defined cases, and grievance redressal, as data principals under the Act.
Can a software company sell or reuse my patients’ data?
No. As a data processor it should only handle data on your instructions and for the agreed purpose. Check your contract to be certain.
What happens to my data if I leave a software vendor?
That depends on your contract. A good vendor lets you export everything in a usable format without penalty. Confirm the exit clause before signing.
What are the penalties under the DPDP Act?
The Act provides for significant financial penalties for serious violations up to ₹250 crore in the most serious cases adjudicated by the Data Protection Board of India. Treat compliance as worth getting right.
Is storing patient data on the cloud legal in India?
Yes, when done with proper consent and security. Look for encryption, access controls and secure, reputable hosting, and confirm you can export your data.
How do I make my clinic DPDP-ready?
Use plain-language consent, collect only necessary data, restrict staff access by role, keep software and security current, and be able to produce or delete a patient’s data on request.