What DPDP Means for Mental Health Practitioners in India
The Digital Personal Data Protection Act creates specific obligations for therapists, psychologists, and psychiatrists in India. Here is what you need to know and what compliance looks like in practice.

What India’s data privacy law requires of therapists, psychologists, and psychiatrists, and what compliance looks like day to day.
Summary
India’s Digital Personal Data Protection Act is now enforceable law, with full compliance mandatory by May 2027. For mental health practitioners, the Act is not a peripheral concern. The data collected in clinical practice, including session notes, diagnoses, intake records, and client correspondence, is classified as sensitive personal data under the Act, attracting heightened obligations. This article explains what the DPDPA requires of mental health practitioners specifically: how consent under the Act differs from therapeutic consent, what data residency means in practice, the six core obligations every Data Fiduciary must meet, and the dual-consent reality for practitioners running digital or hybrid practices. It covers what day-to-day compliance looks like and the penalty framework for non-compliance. The guidance is written for solo practitioners, clinical psychologists, psychiatrists, and clinic-based therapists working in the Indian context.
Table of Contents
- What the DPDP Act Covers
- Why Mental Health Data Gets Heightened Scrutiny
- Consent: What the Act Requires
- Data Residency: Where Your Client Data Lives
- Your Obligations as a Data Fiduciary
- The Dual-Consent Reality for Mental Health Practitioners
- What Compliance Looks Like in Practice
There is a document sitting in the Ministry of Electronics and Information Technology’s gazette that will change how you run your practice. Most therapists in India have not read it. Some have not heard of it.
It is called the Digital Personal Data Protection Act. The reason it matters to you specifically is that mental health records are among the most sensitive personal data the Act recognises. What you collect from clients, how you store it, where it lives, who can access it: all of it falls under this law now.
The obligations that follow are not complex. But they are specific, and they apply to everyone, including a therapist seeing twelve clients a week from a clinic in Pune.
What the DPDP Act Covers
The Digital Personal Data Protection Act (DPDPA) governs all personal data in digital form. It applies to any individual, organisation, or institution, including independent practitioners, that collects and processes personal data of Indian residents.
The Act uses precise language. The person whose data is collected is the Data Principal. The entity that collects and processes it is the Data Fiduciary. As a mental health practitioner, you are the Data Fiduciary. Your clients are Data Principals. That role comes with enforceable obligations.
The DPDP Rules, notified by the Ministry in November 2025, give the Act its operational shape. Full compliance is mandatory by May 13, 2027.
Why Mental Health Data Gets Heightened Scrutiny
The DPDPA defines personal data relating to mental health conditions as sensitive personal data. That classification is deliberate. The legislature identified health information, including psychological and psychiatric data, as a category warranting heightened protection.
Sensitive personal data in the context of mental health practice includes:
- Clinical diagnoses
- Session records and case notes
- Intake forms capturing mental health history
- Medication records (relevant to psychiatrists)
- Communications with clients about their condition
Processing this category of data requires more deliberate systems for consent, security, and retention than would apply to, say, a client’s name and phone number. The Act recognises that a data breach involving mental health records carries consequences for clients that are categorically different from most other kinds of data exposure.
Consent: What the Act Requires
Consent is the primary legal basis for processing personal data under the DPDPA. For mental health practitioners, this creates a specific distinction that most practitioners have not yet thought through.
You already obtain therapeutic consent from clients: consent to treatment, to the therapeutic relationship, to the modalities you use. The DPDPA adds a separate layer: consent to collect, store, and process personal data for the purposes of running your practice.
These two consents are distinct. A client’s agreement to begin therapy is not, by itself, DPDP-compliant consent to data processing.
What DPDP-compliant consent looks like
Consent under the Act must be:
- Free: not bundled with conditions that make treatment contingent on data processing agreement
- Specific: the client must know what data is being collected and why
- Informed: accompanied by a clear consent notice before or at the point of collection
- Unconditional: clients cannot be penalised for withholding consent for non-essential processing
- Unambiguous: given through a clear affirmative action, not implied
The consent notice must be in plain language, available in English or any of the 22 Eighth Schedule languages, and must explain what data is being collected, for what purpose, how rights can be exercised, and how complaints can be raised.
For digital mental health practice, this means your intake flow, your booking system, and your telehealth platform each need a proper consent notice before any data is collected.
Data Residency: Where Your Client Data Lives
The DPDP Rules establish a framework for cross-border data transfers. India operates a negative list model: personal data can be transferred outside India unless the Central Government has expressly prohibited it for a specific jurisdiction or category.
The practical question for most practitioners is where their data is stored right now.
Practitioners using global platforms (general-purpose cloud storage, international telehealth tools, or foreign-hosted practice management software) may find that client records are stored on servers outside India without a specific compliance review having been done. Under the new rules, that is a compliance gap.
Data stored on India-based servers, under Indian data protection law, is the most defensible position. It simplifies compliance, removes cross-border transfer questions, and aligns with what clients would reasonably expect when sharing sensitive information with a practitioner in India.
Your Obligations as a Data Fiduciary
Under the DPDPA, every Data Fiduciary, including sole-practitioner therapy practices, must meet six core obligations.
Give clients a privacy notice before collecting any data. The notice must explain what is collected, why, and how the client can exercise their rights.
Collect only what is genuinely necessary. The Act requires data minimisation. Extended intake forms gathering information unrelated to clinical care are a compliance risk.
Maintain security safeguards appropriate to the data you hold. For mental health data, this means encryption at rest and in transit, access controls limiting who can view records, and secure storage.
Notify affected clients of data breaches without delay, in many cases within 72 hours. A stolen device with client records, an unauthorised login, a system compromise: all trigger this obligation.
Respond to client rights requests. Clients have enforceable rights to access their data, correct inaccuracies, and request erasure. A documented process for handling these requests is required.
Provide a grievance mechanism. Clients must have a way to raise complaints with you directly about how their data is handled.
The Dual-Consent Reality for Mental Health Practitioners
Mental health practice sits at the intersection of two separate consent regimes.
The Mental Healthcare Act, 2017 governs consent to treatment and the rights of persons with mental illness. The DPDPA governs consent to personal data processing. They operate independently. Compliance with one does not satisfy the other.
For telehealth sessions specifically, there are three distinct consent components:
- Consent to treatment (Mental Healthcare Act, 2017)
- Consent to audio/video recording, if applicable (DPDPA)
- Consent to data retention and any data sharing (DPDPA)
Practitioners running digital or hybrid practices, using any combination of online booking, telehealth, and electronic records, need to address all three cleanly. The practitioners most at risk are those who have a single intake form that tries to cover everything and ends up covering nothing adequately.
What Compliance Looks Like in Practice
Compliance with the DPDPA is not a one-time action. It is a set of standing practices.
For a mental health practitioner, day-to-day compliance means:
- Your intake process includes a proper consent notice before any information is collected, separate from the therapeutic agreement
- Your session notes and client records are stored on a secure system with encryption and access controls
- You know where your data is stored, specifically whether it is on India-based servers
- You have a process for responding if a client asks to see, correct, or delete their records
- You have a documented response plan for data breaches, including client notification
- Any third-party tool or platform you use, whether for telehealth, billing, or scheduling, has a privacy notice and processes data consistently with your obligations as the Data Fiduciary
On penalties
The DPDPA’s penalty framework is tiered. Fines for non-compliance are capped at ₹250 crore per breach, with specific violations attracting prescribed penalty ranges. While the threshold for enforcement against a solo practitioner differs from that of a large hospital, the obligations themselves apply equally.
Ignorance of the Act is not a defence. The standard is whether you had reasonable safeguards in place.
On timing
The compliance deadline is May 13, 2027. That is when all substantive obligations become enforceable. The period between now and then is preparation time. Starting early matters, because retrofitting consent flows and data storage into a practice already in motion is harder than building them into the system from the start.
The practitioners who will find this least disruptive are those building on tools designed to meet these requirements from the ground up. Aroha stores client data on India-based servers, applies encryption and role-based access controls, and structures the consent and documentation infrastructure around what the Act requires of practitioners.
If you found this useful, Aroha publishes practical guides like this one for mental health practitioners in India every month. No generic advice, just content written for the realities of Indian practice.
The information in this post is provided for general awareness and is not legal advice. For guidance specific to your practice’s compliance obligations, consult a qualified legal professional.
Related Articles

What Makes Mental Health Software Secure?
A practitioner's guide to what makes mental health software secure; encryption, HIPAA alignment, DPDP readiness, access control, and data residency. The criteria to verify before trusting any tool with client data.

What to Look for in Mental Health Software Built for India
Mental health software built for India keeps client data on Indian servers, is DPDP-ready, and fits how care is practised here. What to look for, and how to tell.

How to Choose Therapy Practice Software in India
A practical framework for choosing practice management software as a therapist in India: security, DPDP compliance, data residency, clinical fit, and the questions to ask before you commit.