Skip to content
Saaro Health
Trust

Under the DPDP Act, your clinic is the data fiduciary. Saaro is built to make that manageable.

Consent, notice, retention, erasure, breach reporting and grievance handling are obligations on the clinic. Here is what each one means for an OPD, and which parts the product does for you.

  • Consent in the record
  • Hosted in India
  • Audit trail
What the law asks

The Act names three parties. The clinic is the one with the obligations.

The Digital Personal Data Protection Act 2023 uses three terms. The data principal is the person the data is about: your patient. The data fiduciary is whoever decides why and how that data is processed: your clinic. The data processor is whoever processes it on the fiduciary's behalf: Saaro Health, operated by Lumotis Digital Media. The obligations sit with the fiduciary, and the fiduciary stays responsible for what its processors do.

The Act asks for consent that is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and preceded by a notice in plain language stating what data is collected and why. Patients can withdraw consent as easily as they gave it. Processing without consent is allowed for certain legitimate uses, including medical emergencies, but those are exceptions and should be treated as such.

Patients have rights: to know what data you hold, to have it corrected or erased, to a grievance process, and to nominate someone to exercise these rights if they cannot. Children under eighteen need verifiable parental consent. Data must be erased once its purpose is served or consent is withdrawn, unless a law requires you to keep it, which for medical records the clinical establishment and medical council rules generally do for a minimum period.

If a personal data breach happens, the fiduciary must inform the Data Protection Board of India and each affected patient in the form and timeline set by the Rules. Penalties for non-compliance are structured in crores and scale with the seriousness of the failure. The DPDP Rules phase these obligations in over a period running through 2027, so a clinic that starts now has time, but not much of it.

One point of accuracy. The DPDP Act does not create a separate 'sensitive' category; it treats all personal data under one standard. Health information is, however, classed as sensitive personal data under the older IT Act rules, and regulators and courts treat it with heightened care. Practically, clinics should assume health data deserves the strictest handling the Act describes.

Obligations

Every DPDP obligation for a clinic, with who owns it.

Product means Saaro provides the mechanism. Clinic means it is a decision, a document or a behaviour that is yours. Both means the product provides the tool and the clinic operates it.

  1. Give notice before or at collection

    Patients must be told what is collected and why, in plain language. Saaro sends a notice on WhatsApp at registration from your clinic's number, in Hindi or English; the wording is yours to approve.

    Shared
  2. Take and record consent

    Consent is captured as a clear action by the patient, timestamped, and stored against the record with the notice version they saw. Withdrawal is one reply away and is recorded the same way.

    Saaro handles it
  3. Limit processing to the stated purpose

    Data collected for treatment is used for treatment, reminders and billing. Using it for anything else, such as marketing, needs a separate consent that the product asks for separately.

    Shared
  4. Keep data accurate and complete

    Patients can ask for corrections; the front desk edits the record and the change is logged with who made it and when.

    Your clinic
  5. Respond to access, correction and erasure requests

    Saaro exports a patient's full record on request and can erase it, subject to legal retention. The clinic decides what retention law applies and responds to the patient.

    Shared
  6. Retain only as long as needed or required

    Retention periods are set per record type in the workspace. Saaro flags records past the configured period; the clinic confirms deletion or documents the legal reason to keep them.

    Shared
  7. Handle children's data with parental consent

    Paediatric records carry a guardian field and consent is taken from the guardian. Verifying the guardian is the clinic's job at the desk.

    Shared
  8. Report breaches to the Board and to patients

    Lumotis notifies the clinic without undue delay if a breach touches its data, with the details the clinic needs to inform the Board and patients. Filing the report is the fiduciary's obligation.

    Shared
  9. Publish a grievance contact

    Patients need a way to complain. Saaro's notice template includes the clinic's grievance contact; the clinic names the person and responds within the period the Rules allow.

    Your clinic
  10. Bind processors by contract

    A data processing agreement between the clinic and Lumotis sets out purpose, security, sub-processors, breach notice and deletion on termination. It is part of every plan.

    Saaro handles it
In the record

What a patient's consent history looks like on screen.

Consent is not a signed sheet in a file. It is a set of rows in the patient's timeline: the notice that was sent, the reply that gave consent, the purposes it covers, and any withdrawal.

When a patient asks what they agreed to, or a Board officer asks how you know, the answer is a screen the front desk can open in seconds.

  • Notice version and language shown to the patient
  • Consent reply with timestamp and channel
  • Purposes covered, with marketing separate from care
  • Withdrawal and erasure requests with outcome
RRamesh K.58 · M · Consent: care, reminders
  • 09:41DPDP notice sent on WhatsApp (Hindi, v3)Delivered
  • 09:43Consent given for care and remindersConsented
  • 09:43Marketing consent not requestedSkipped
  • Tue 2 SepRecord export requested by patientFulfilled
Mapping

DPDP obligation against the Saaro control.

Obligations summarised from the DPDP Act 2023 and Rules. This is product documentation, not legal advice; counsel should confirm how each applies to your clinic.

DPDP obligationWhat it means for an OPDSaaro control
NoticeTell the patient what is collected and why, before or at collectionWhatsApp notice at registration, versioned, in Hindi or English
ConsentFree, specific, informed, unambiguous, by clear actionReply-based consent stored with timestamp, channel and notice version
WithdrawalAs easy as giving consentOne-word reply stops non-care messaging; recorded on the timeline
Purpose limitationUse data only for the purpose consentedPurposes tracked per patient; flows check consent before sending
Access and correctionGive patients their data; fix errorsFull record export; edits logged with user and time
ErasureDelete when purpose ends unless law requires retentionErase action with legal-hold option and retention flags
ChildrenVerifiable parental consent under eighteenGuardian field on paediatric records; consent taken from guardian
Security safeguardsReasonable measures to prevent breachEncryption in transit and at rest, role-based access, audit trail, backups
Breach notificationInform the Board and affected patientsProcessor notifies clinic without undue delay with incident details
Processor contractBind processors in writingData processing agreement included in every plan
GrievanceGive patients a way to complainClinic contact in the notice; requests logged on the record
Data locationNo statutory localisation, but sectoral care expectedHosted in India, hosting region; sub-processor list published

Swipe to see every tier

Your questions answered.

The things clinics ask first.

Yes, if you decide why and how patient data is processed, which any clinic keeping records does. Size does not exempt you. Saaro is your data processor and is bound to you by a data processing agreement.

No software can do that on its own. Saaro provides the mechanisms: notice, consent capture, purpose tracking, access controls, audit, export and erasure. The clinic still has to name a grievance contact, decide retention, and respond to patients. The checklist on this page shows which is which.

The front desk can record consent given verbally or on paper against the record, with the notice version and the staff member who took it. The audit trail shows it the same way.

Yes, and you must comply unless a law requires retention. Medical council and clinical establishment rules generally require records to be kept for a minimum period. Saaro lets you place a legal hold with the reason recorded, and erases once it lapses.

Lumotis notifies the clinic without undue delay with what happened, what data was affected and what has been done. The clinic, as fiduciary, reports to the Data Protection Board and affected patients in the form and timeline the Rules set. We help you draft it.

The Act is law; the Rules bring obligations into force in phases through 2027. Consent, notice and security expectations are the ones to be ready for first. Counsel can confirm the dates that apply to your clinic.

Related

Keep reading.

See consent captured on a real registration.

Twenty minutes. Notice, consent, withdrawal and export, on your own patient flow.