DPDP Act Compliance for Therapists in India:
What You Actually Need to Do
.png)
By Mahima Paliwal, Counselling Psychologist
Published 02/08/2026 · Last reviewed 02/08/2026

As a therapist in private practice
If you keep client records on a laptop, a phone, a Google Drive folder or a WhatsApp thread, India’s data protection law reaches your practice. Not your hospital, not your platform. You, as the practitioner who decided what to collect and why.
There is no exemption for solo practice, no exemption for small caseloads, and no exemption for “I only see eight clients a week.”
I run a solo practice myself, and getting this in order took a handful of afternoons rather than a legal budget. What the law asks of an independent counsellor is much narrower than the compliance industry makes it sound.
Key Takeaways:
-
The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The Act’s own commencement notification, G.S.R. 843(E), puts Section 3 and every duty in Chapter II on 13 May 2027, together with the penalties in Section 33 and the Schedule.
-
Until that date, your records are governed by Section 43A of the IT Act, 2000 and the SPDI Rules, 2011. Those rules name mental health condition and medical records among sensitive personal data, so a therapy file sits squarely inside them.
-
The two regimes hand over cleanly. Section 44(2) of the DPDP Act omits Section 43A on the same day DPDP starts applying.
-
The Data Protection Board of India exists in law but had still not been given a Chairperson or Members as of August 2026. Its power to inquire into complaints, Section 27, commences in 2027.
-
HIPAA does not apply to you. Software sold to Indian therapists as "HIPAA compliant" is telling you about a law with no force over your practice.
-
Paper notes come into scope one page at a time. The Act reaches personal data collected in non-digital form and digitised subsequently.
-
Clients under 18 need verifiable parental consent in most cases.
-
A breach means notifying the Board and every affected client. Section 8(6) contains no severity threshold.
What the DPDP Act actually is
The Digital Personal Data Protection Act, 2023 is India’s data protection law. The rules that make it work were notified on 13 November 2025. It covers personal data in digital form. That is the whole of it - no separate category for health data, no separate rulebook for clinics. It works on a simple structure. The person who decides what data to collect and why is the Data Fiduciary. In a solo practice, that is you. Your client is the Data Principal. Any software you use to store or process their data works on your instructions, which means if your cloud spreadsheet leaks, the obligation to report it is yours, not your vendor’s. You can contract with a vendor. You cannot hand over the accountability.
Two scope limits are genuinely useful for therapists:
Digital only.
The Act covers digital personal data, plus physical records that are subsequently digitised. A locked filing cabinet of handwritten process notes that never gets scanned sits outside the Act. The moment you photograph a page to type it up later, or move to a digital record, the whole set comes into scope.
Everyone, regardless of size.
There is no turnover threshold, no headcount threshold and no carve-out for sole proprietors. Enhanced duties such as annual audits, Data Protection Impact Assessments and a designated Data Protection Officer attach only to entities notified as Significant Data Fiduciaries, which a solo practice will not be. The baseline duties apply to you all the same.
The obligations that actually bite in a therapy practice
Consent, split by purpose
Consent has to be free, specific, informed and unambiguous, given by a clear affirmative action, and limited to the data you actually need. A notice sits alongside it, written so it stands on its own, listing what you are collecting and why.
For a practice that means one thing above all. The consent your client gives so you can keep a clinical record is not consent to add them to a newsletter, to feature their anonymised story in a workshop, or to share their details with a supervisor or referral partner. Each purpose needs its own line.
The burden of proof is on you. If a question about consent ever comes up, you have to show that notice was given and consent was obtained. Design the record for that, not for the filing cabinet.
Two small things people miss: the notice has to be available in a language your client can actually read, and you have to publish on your website who a client can contact about their data and how they can make a request or complaint.
Clients under 18 need verifiable parental consent
The general rule is straightforward: you need verifiable parental or guardian consent before processing the personal data of a child, and the law defines a child as anyone under eighteen. There is, however, a carve-out. The DPDP Rules exempt a clinical establishment, mental health establishment or healthcare professional from the child-consent requirement, when the processing is limited to giving the child health services. Allied healthcare professionals get a narrower version of this exemption — it only covers them when they're carrying out a treatment or referral plan that another healthcare professional already wrote. That distinction matters for counsellors, because a self-referred client doesn't come with someone else's treatment plan attached, so the narrower "allied healthcare" exemption may not even be the one to lean on. Whether an independent counsellor counts as a "healthcare professional" in the first place is a question tied to the National Commission for Allied and Healthcare Professions Act, 2021. That Act is itself fairly new, and it isn't fully clear yet how counsellors and counselling psychologists fit into its categories. So as things stand, this is a genuine grey area, not something I'd treat as settled.
At Snowflakes, we don't wait for that to get clarified. We take parental consent as its own step regardless of whether the exemption might end up covering us. At Snowflakes we treat this as its own step rather than a tick box on the adolescent's intake form. We hold the parent's contact number separately from the young person's, call them, explain what we will be recording and why, and take a signed consent from them before the work begins. It costs one phone call. Doing it as a distinct, documented step is also what lets you demonstrate that you verified it, which is the part the Rule actually asks for.
There is a real tension here with clinical practice, where confidentiality from a parent is often what makes the work possible. The law governs the data, not the content of the session. Be deliberate about where that line sits and write it into your intake process rather than improvising it in the moment.
Retention, and the 48-hour erasure notice
Personal data must be erased once the purpose it was collected for is no longer served, including when consent is withdrawn. Before you delete, the Rules require notifying the individual at least 48 hours in advance so they can ask you to preserve it.
For therapists there is a conflict here that nobody has resolved cleanly yet. Your professional obligation to retain a clinical record for a defined period sits against a client's right to have their data erased. The defensible position is a written retention policy, stating how long you keep records after the last session and why, applied consistently. A stated, reasoned retention period is far stronger than an unstated one.
Breach reporting has no severity threshold
If there is a breach, you tell the Board and you tell every affected client. There is no materiality qualifier anywhere in it. Unlike Europe, there is no exception for low-risk breaches. A laptop with unencrypted session notes stolen from a car is reportable. Tell each affected client without delay, in plain language: what happened, what it means for them, what you are doing about it, and who they can contact. Tell the Board without delay too, and give them the detailed account within seventy-two hours.
WhatsApp is the quiet problem
Sending session summaries, homework, assessment information or clinical notes over WhatsApp feels completely normal in Indian practice. From a data-protection perspective, it deserves considerably more thought. When you send clinical information through WhatsApp, you are using a third-party communication platform to process and transmit information that may include highly sensitive personal or health-related data. You do not control the underlying infrastructure, you cannot audit the entire processing environment yourself, and deletion becomes much harder once information has entered a client's or another professional's chat history. That does not mean that every use of WhatsApp is automatically unlawful. It means that WhatsApp is a channel where consent, security, confidentiality and deletion are all harder to demonstrate and control. That makes it a poor place for substantive clinical material.
I have never sent a client homework or a session summary this way. The one time client material has left my practice over WhatsApp was a transfer, when I passed a client's information to the therapist taking over her care. Before I sent anything I took her written consent, naming the channel and naming the person receiving it. That is the standard the Act is asking for, and it is workable. What is not workable is the ambient version, where notes drift into a chat thread over months and nobody has consented to anything in particular.
If you are going to use it, get explicit consent for that channel and keep the substance minimal. It is one of the strongest arguments for keeping clinical material inside a system you actually govern.
Your compliance checklist
1. Write a privacy notice in plain language: what you collect, why, how long you keep it, how a client withdraws consent or asks for erasure. One page. This is already a duty today, not only from 2027.
2. Make sure that notice is available in a language your clients actually read.
3. Publish on your site who to contact about data, and how to make a request or a complaint.
4. Split your consent form into three: consent to the work itself, consent to the clinical record and communications, and consent to any secondary use such as supervision, teaching or anonymised research. Separate ticks, not one blanket signature.
5. Build a parental consent step for clients under 18 that captures the parent’s identity and age, taken separately from the young person’s intake.
6. Write a retention policy: how long after the last session you keep records, and what you are relying on.
7. Inventory where client data actually lives. Laptop, phone, cloud drive, email, WhatsApp, billing app, calendar. Every practitioner I have walked through this has found at least six places, and most were surprised by two of them.
8. Reduce that list. Every location is somewhere you have to secure, report on, and erase from.
9. Turn on the basics: full-disk encryption, device passcode, two-factor authentication on your email and cloud drive, an auto-lock screen.
10. Ask every vendor two questions: where is my client data stored, and do you use it to train models. Get the answer in writing.
11. Write a one-page breach plan covering who you call, what you send the Board and what you tell clients, before you need it.
12. Diarize 13 May 2027, and review this list once in late 2026.
Frequently Asked Questions:
Is the DPDP Act in force right now?
Partly. The Rules were notified on 13 November 2025 and the Data Protection Board is operational, so complaints can already be filed. Penalties commence on 13 November 2027. The substantive obligations become fully enforceable on 13 May 2027.
Does this apply to counsellors and psychologists too, or only clinical practices?
The Act does not distinguish between professional categories. It applies to anyone who decides what personal data to collect and why, and then processes it digitally. A counsellor, a clinical psychologist, a psychotherapist and a psychiatrist in independent practice are all Data Fiduciaries in exactly the same way. RCI registration, clinic registration and the size of your caseload make no difference to whether the law covers you.
Do I need to register anywhere?
No. There is no registration or licensing requirement for an ordinary Data Fiduciary. Registration applies to Consent Managers, a separate category, and that regime opens in November 2026.
Are my paper case notes covered?
Not while they stay on paper. They come into scope the moment they are digitised, whether scanned, photographed, or typed up.
Does storing client data outside India break the law?
Not by default. The Rules use a blacklist model for cross-border transfers rather than mandatory localisation. Keeping data in India is a reasonable choice, not a legal requirement for most practitioners.
Can a client ask me to delete their entire record?
They can ask, and you must have a process for responding. Whether you must delete depends on your stated retention policy and any professional obligation to retain the record, which is exactly why writing that policy down matters.
Can I send session notes to a client on WhatsApp?
Only with consent that names WhatsApp specifically, and even then it is worth avoiding for anything substantive. A general consent to be contacted is not consent for health data to be processed by a third-party messaging platform. If you are transferring a client to another practitioner, take a written consent naming the channel and the recipient before you send anything.
Does HIPAA apply to me?
No. HIPAA is the Health Insurance Portability and Accountability Act, a United States federal law. It governs American healthcare providers, health plans and their business associates. It has no application to a counsellor practising in Pune, Kochi or Guwahati or anywhere in India, and no Indian regulator will ever ask you about it.
This matters commercially, not just pedantically. Much of the practice-management software marketed to Indian therapists advertises HIPAA compliance because the product was built for the US market and the badge was already there. The badge is accurate and irrelevant. The law you are accountable to is the Digital Personal Data Protection Act, 2023, read with the DPDP Rules, 2025. Ask any vendor about that instead.
This is a plain-language summary for practitioners, not legal advice. For a decision with real consequences for your practice, speak to a lawyer.
Last Reviewed: 11/08/2026
.png)