Back to BlogITH

DPDP 2023: What It Means for Indian Therapists' Session Notes

2 August 2026

This is a general explainer, not legal advice. The DPDP Act's subordinate rules have continued to evolve since the Act was passed, and how they apply to your specific practice can depend on details a blog post can't account for. If compliance decisions carry real weight for your practice, have them reviewed by someone qualified to advise on Indian data protection law.

Every session note you write contains personal data — usually a lot of it, and usually the sensitive kind. If you practice in India, the law that now governs how you're expected to handle that data is the Digital Personal Data Protection Act, 2023 (DPDP Act). Most explainers of it are written for e-commerce companies and ad-tech platforms. Here's what it actually means for a therapy practice specifically.

The basic shape of the law

DPDP Act 2023 is India's first comprehensive data protection statute. It defines three roles that matter for almost everything else in the Act:

  • Data Principal — the individual the data is about. In your practice, that's your patient.
  • Data Fiduciary — whoever decides why and how personal data gets processed. This is the party the Act holds primarily accountable.
  • Data Processor — anyone who processes data on behalf of a fiduciary, following their instructions.

The part that surprises a lot of practitioners: when it comes to your patients' clinical information, you are the data fiduciary — not whatever software you use. A practice-management tool, an EHR, a notes app — those are typically data processors, acting on your instructions. The compliance obligation sits with you, the practitioner, first. Your software vendor should be helping you meet it, not carrying it for you.

What the Act actually requires

Stripped to the parts most relevant to a therapy practice:

Consent has to be real consent. The Act requires consent to be free, specific, informed, and given through a clear affirmative action — not a pre-ticked box, not something buried in a general intake form's fine print. It also has to be specific to a purpose, which matters here: agreeing to have a session recorded is a different consent from agreeing to have that recording processed by an AI tool. If your intake process treats those as one checkbox, that's worth separating.

Your patients have rights over their own data. Under the Act, a data principal can ask to know what data you hold about them, request correction, and request erasure — subject to what you're legally required to retain (clinical records often have their own retention requirements independent of DPDP). Your practice needs a real way to respond to that kind of request, not just a policy that says you will.

Breaches have to be reported. If patient data is compromised, the Act requires notifying the Data Protection Board of India and the affected individuals. This is a real operational obligation, not boilerplate — it means knowing quickly if something's gone wrong, which in practice depends heavily on whether your tools log and monitor access at all.

"Reasonable security safeguards" is a real legal requirement, not just good practice. The Act doesn't spell out a specific technical checklist, but encryption, access controls, and limiting who can see what are the baseline anyone would point to.

One thing that might surprise you

Earlier drafts of India's data protection law (going back to 2019) had a distinct "sensitive personal data" category — health information included — with extra rules on top of the general ones. The Act as actually passed in 2023 dropped that tiered structure. All personal data is governed by the same core obligations, without a separate, stricter tier specifically for health data.

That doesn't mean mental health records should be treated casually — the professional and ethical obligations around therapy notes don't come from DPDP in the first place, and they don't go away. It just means DPDP itself doesn't hand you a special "this is health data, do more" checklist the way some other frameworks do. The baseline requirements — real consent, security safeguards, honoring access/correction/erasure requests — are what apply, and they apply to everything.

What to actually check in your own practice

A few concrete questions worth asking, whether you're evaluating a new tool or reviewing what you already use:

  • Is recording consent tracked separately from AI-processing consent, with a record of when and how each was given?
  • Do you have an actual process for a patient asking "what data do you have on me, and can you delete what's not legally required to keep"? Not a policy stating you support this — an actual process.
  • Is patient data encrypted at rest, not only in transit? "Encrypted" in a privacy policy sometimes only means the connection is HTTPS — ask specifically.
  • If something went wrong, would you know? Access logging and breach-detection aren't glamorous, but they're what make the breach-notification requirement something you can actually meet rather than something you'd only find out about from someone else.

None of this is about picking the "most compliant-sounding" software. It's about being able to answer these questions honestly for your own practice, regardless of which tools you use to run it.

Want to try Kith in your own practice?

Free to start — no card required.

Get started free