The DPDP Act for healthcare in India

This series of articles explains how India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 bear on healthcare businesses. It is not legal advice. Where we interpret the law rather than restate it, we say so. Confirm any compliance decision with qualified counsel.

India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) and the Digital Personal Data Protection Rules, 2025 set out how any business may collect and use digital personal data. This guide explains the DPDP Act for healthcare businesses on both sides of the market: private hospitals and clinics that hold patient records, and healthtech companies that build software for them or sell directly to patients. It covers what the law requires, from when, and what each requirement does to the way a healthcare business operates.

The Act and the Rules are short and written in plain language, with worked illustrations. Read them yourself: the Act (Gazette of India), the Rules (MeitY) and the commencement notification (MeitY). This guide explains them; it doesn’t replace them.

The A|P DPDP series for healthcare

This guide sits within A|P’s work on operational excellence for private clinics and hospitals in India and on product-market fit for healthtech startups in India. Each piece in this series takes one consequence of the DPDP Act, and works it through for one kind of reader. Read the one that matches your business.

For healthtech founders

  • Fiduciary or processor? How the DPDP Act reads your healthtech business model
  • Selling to Indian hospitals after the DPDP Act
  • Patient communication on WhatsApp, voice and apps under the DPDP Act

For hospital and clinic owners

  • Where patient data actually lives in an Indian private hospital
  • Consent or “voluntarily provided”? Designing patient intake under the DPDP Act
  • Your existing patient database under the DPDP Act

For the go-to-market side of building healthtech in India, see A|P’s guide to go-to-market strategy for healthtech startups in India. And for an overall review of the Act, continue reading below.

When does the DPDP Act apply to healthcare businesses?

The DPDP Act applies in three phases set by MeitY’s G.S.R. 843(E) of 13 November 2025.

  • Definitions and the Data Protection Board took effect on that date.
  • Consent Manager registration opens on 13 November 2026.
  • Every duty a hospital or healthtech company owes, every patient right, and the Board’s power to inquire and penalise start on 13 May 2027.
FromWhat comes into forceWhat it means for a healthcare business
13 November 2025Definitions (s.2), the Data Protection Board (ss.18–26), how the Act sits with other laws (s.38), rule-making powers (ss.40–43). Rules 1, 2 and 17–21.The vocabulary and the regulator exist. No new duty on a hospital or healthtech company yet.
13 November 2026Consent Manager registration (s.6(9), Rule 4) and the Board’s power over Consent Managers (s.27(1)(d)).Companies that want to operate as Consent Managers can apply to register.
13 May 2027Scope (s.3), every duty of a data fiduciary (ss.4–10), patients’ rights and duties (ss.11–15), cross-border transfers and exemptions (ss.16–17), the Board’s inquiries and penalties (ss.27–34), blocking (s.37), and removal of IT Act s.43A (s.44(2)). Rules 3, 5–16, 22 and 23.Notices, consent, security, breach reporting, retention, rights handling and penalties all become enforceable.

The notification is dated 13 November 2025, so this guide treats the main deadline as 13 May 2027. The Data Protection Board was established on the same date by G.S.R. 844(E), with its head office in the National Capital Region. It legally exists today, but its inquiry and penalty powers start only on 13 May 2027.

The eighteen-month window is the planning horizon for any healthcare business.

What law governs health data until 13 May 2027?

Until 13 May 2027, health data held by a body corporate is governed by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the SPDI Rules), made under section 43A of the IT Act. Section 44(2) of the DPDP Act removes section 43A only from 13 May 2027. A hospital or healthtech company that is a body corporate is still under the 2011 regime in 2026.

Section 43A of the Information Technology Act, 2000 defines a body corporate as “any company and includes a firm, sole proprietorship or other association of individuals engaged in commercial or professional activities”. On that wording, a doctor’s sole-proprietor clinic is a body corporate. A|P’s reading, not settled law; confirm with counsel.

The SPDI Rules classify “physical, physiological and mental health condition” and “medical records and history” as sensitive personal data (rule 3). For a body corporate, as the IT Act defines it, they require:

  • written consent, by letter, fax or email, before collecting sensitive personal data, stating the purpose (rule 5(1));
  • a published privacy policy (rule 4);
  • no retention for longer than the lawful purpose or another law requires (rule 5(4));
  • a named Grievance Officer who resolves grievances within one month (rule 5(9));
  • prior permission before disclosing the data to a third party, unless the contract allows it or the law requires it (rule 6);
  • transfer, in India or abroad, only to a recipient that ensures the same level of data protection, and only where the transfer is necessary for a lawful contract or the person has consented (rule 7);
  • a documented information security programme, with IS/ISO/IEC 27001 deemed to comply (rule 8).

The change in May 2027 is from a short regime built around written consent and ISO certification to a fuller one with itemised notices, breach reporting to every affected patient, published rights processes and penalties of up to ₹250 crore.

Who is who under the DPDP Act in a healthcare business?

The DPDP Act assigns duties by role, not by industry.

  • The data fiduciary decides why and how personal data is processed (s.2(i)) and carries the obligations in Chapter II of the Act (ss.4–10).
  • The data processor processes data on a fiduciary’s behalf (s.2(k)).
  • The patient is the data principal. For a child, the term includes the parent or lawful guardian, and for a person with disability, their lawful guardian (s.2(j)).
RoleDefinition in the ActTypical healthcare example
Data principalThe individual the data relates to, including a child’s parent or a lawful guardian (s.2(j))The patient, or a parent registering a child at a paediatric OPD (outpatient department, which treats patients without admitting them, as distinct from the IPD or inpatient department, which admits them for indoor care)
Data fiduciaryAny person who, alone or with others, determines the purpose and means of processing (s.2(i))A private hospital or clinic for its patients; a direct-to-patient health app for its users
Data processorAny person who processes personal data on behalf of a data fiduciary (s.2(k))A hospital information system vendor, an outsourced cloud host, a messaging provider acting on the hospital’s instructions
Consent ManagerA person registered with the Board who lets a data principal give, manage, review and withdraw consent through an interoperable platform (s.2(g))Optional for patients; and no hospital or healthtech company is required to use one
Significant Data FiduciaryA fiduciary or class the government notifies on factors including the volume and sensitivity of data (s.10(1))None notified as of 4 October 2026
Data Protection Board of IndiaThe regulator that inquires into breaches and imposes penalties (ss.18, 27)Established 13 November 2025; inquiry powers from 13 May 2027

Does a healthtech company count as a fiduciary or a processor?

A healthtech company can be both, in different data flows.

  • A software vendor that processes a hospital’s patient records only on the hospital’s instructions acts as a processor for that data.
  • The same company is a fiduciary for its own users, its staff accounts and its marketing leads.
  • If the company reuses hospital patient data for purposes it decides itself, such as product analytics or model training, it determines the purpose of that processing, which makes it a fiduciary in s.2(i). A|P’s reading, not settled law; confirm with counsel.

The distinction decides where liability sits. The Act makes the fiduciary responsible for compliance “irrespective of any agreement to the contrary”, including for processing done on its behalf (s.8(1)), and allows it to use a processor “only under a valid contract” (s.8(2)). A processor’s obligations therefore reach it mainly through the contract it signs with the fiduciary. A|P’s reading, not settled law; confirm with counsel.

Is health data a special category under the DPDP Act?

No. The DPDP Act has no separate category for health, so the baseline duties are the same for a patient record as for a shopping list. Sensitivity specific to healthcare exists in two places:

  • It is a named factor when the government designates Significant Data Fiduciaries (s.10(1)(a)),
  • and “the type and nature of the personal data affected” is a factor when the Board sets a penalty (s.33(2)(b)).

What data does the DPDP Act cover?

The DPDP Act covers digital personal data: data about an identifiable individual, collected in digital form or collected on paper and digitised later (s.3(a)). A paper OPD register stays outside the Act until it is scanned or typed into a system. A hospital information system, a lab portal, a spreadsheet of discharge follow-ups and a WhatsApp message containing a report are all inside it. A|P’s reading, not settled law; confirm with counsel.

The Act also reaches processing outside India when it relates to offering goods or services to people in India (s.3(b)). It does not apply to data an individual processes for personal or domestic purposes, or to data the individual has made publicly available (s.3(c)).

On what legal grounds can a healthcare business process personal data?

From 13 May 2027, a healthcare business may process personal data only for a lawful purpose, and only on one of two grounds:

  1. the person’s consent,
  2. or one of the “certain legitimate uses” listed in section 7 (s.4).

Every purpose a hospital or healthtech company has for patient data, from treatment to reminders to marketing, needs one of the above two.

What makes consent valid?

From 13 May 2027, consent must be “free, specific, informed, unconditional and unambiguous with a clear affirmative action”, and limited to the data necessary for the stated purpose (s.6(1)).

As an example, the Act’s own illustration is a telemedicine app that asks for access to the patient’s phone contacts. This consent is invalid, because the contact list isn’t needed for the telemedicine app to achieve its stated purpose (caring for patients remotely using telecommunications and digital technology). Three further rules shape how consent works in practice:

  1. Notice first. Every consent request must be accompanied or preceded by a notice (s.5(1)). The patient must be able to read the notice and the consent request in English or any language in the Eighth Schedule to the Constitution (ss.5(3), 6(3)). Further, under Rule 3,
    1. the notice must be understandable on its own,
    2. give an itemised description of the data,
    3. state the specific purposes,
    4. and give a link to the business’s website or app through which the patient can withdraw consent, exercise their rights and complain to the Board.
  2. Withdrawal as easy as giving. A patient can withdraw consent at any time, and withdrawing must be as easy as consenting was (s.6(4)). The fiduciary must then stop processing within a reasonable time and make its processors stop too (s.6(6)).
  3. The burden of proof sits with the business. If consent is questioned in a proceeding, the fiduciary must prove that it gave notice and that consent was given as the Act requires (s.6(10)).

Consent given before the Act commenced remains usable. However, the fiduciary must send the patient a notice “as soon as it is reasonably practicable”, and may continue processing until the patient withdraws (s.5(2)). For a hospital with years of digitised patient records, this may be a significant re-notice exercise on their existing patient list. A|P’s reading, not settled law; confirm with counsel.

When can a hospital process data without consent?

Section 7 lists nine legitimate uses that need no consent. Five matter most to healthcare:

  • Data voluntarily provided for a specified purpose that the person hasn’t objected to (s.7(a)). The Act’s illustration is a pharmacy customer who gives her phone number to receive a payment receipt.
  • A medical emergency involving a threat to the life or an immediate threat to the health of the patient or anyone else (s.7(f)).
  • Medical treatment or health services during an epidemic, an outbreak of disease or any other threat to public health (s.7(g)).
  • Safety and assistance during a disaster or a breakdown of public order (s.7(h)).
  • Employment purposes, including a hospital’s own staff records (s.7(i)).

Whether routine OPD and IPD care can rest on s.7(a), rather than on consent, is the most consequential open question for hospitals. The Act’s illustration is a pharmacy receipt, not clinical care but a routine OP check up or IP case where a patient provides their personal details should also be covered under s.7(a) in a similar vein. A|P’s reading, not settled law; confirm with counsel.

Either way, patients keep their rights to access, correction and erasure over data provided under s.7(a) (ss.11(1), 12(1)). So this does mean that a hospital or a healthtech business need to build a robust way to track all they know about a particular patient.

What does a data fiduciary in healthcare have to do?

From 13 May 2027, a hospital or healthtech company acting as a data fiduciary carries nine standing obligations under section 8 and Rule 8(3), made specific by the Rules. These obligations are where compliance work, cost and operating changes concentrate.

ObligationSourceWhat it requires
Responsibility for processorss.8(1)–(2)The fiduciary is responsible for its processors’ processing, whatever the contract says, and may engage them only under a valid contract
Accuracys.8(3)Data used to make a decision about the person, or shared with another fiduciary, must be complete, accurate and consistent
Security safeguardss.8(5); Rule 6At minimum: encryption, obfuscation, masking or tokenisation; access control; access logs with monitoring and review; backups for continuity; keeping logs and data for one year to detect and investigate unauthorised access; security clauses in processor contracts; and organisational measures
Breach intimations.8(6); Rule 7Tell each affected person without delay, through their user account or registered contact, what happened, the likely consequences, the mitigation and whom to contact. Tell the Board without delay, then give it a detailed report within 72 hours
Erasures.8(7)–(8); Rule 8Erase data when consent is withdrawn or the purpose is no longer served, unless another law requires retention, and make processors erase too
Minimum retentionRule 8(3)Keep personal data, traffic data and processing logs for at least one year from the processing, then erase them unless another law requires longer
Contact persons.8(9); Rule 9Publish, prominently on the website or app, the business contact of a person who can answer questions about processing, and include it in every response to a rights request
Grievance redressals.8(10); Rule 14(3)Run an effective grievance mechanism and publish a response period of no more than ninety days
Organisational measuress.8(4)Put in place technical and organisational measures to make the Act and Rules work in practice

A|P’s guide to NABH digital health accreditation for hospitals covers how NABH’s Digital Health Standard for Hospitals assesses access control, which may serve as a practical benchmark for the access-control and logging minimums in Rule 6. NABH, the National Accreditation Board for Hospitals & Healthcare Providers, is a constituent board of the Quality Council of India that accredits hospitals and other healthcare providers.

Two details matter for healthcare specifically:

  1. First, the Rules set an inactivity period after which data is deemed no longer needed only for large e-commerce, online gaming and social media platforms (Rule 8(1) and the Third Schedule). Healthcare is not on that list, so each hospital and healthtech company has to decide for itself when “the specified purpose is no longer being served”. A|P’s reading, not settled law; confirm with counsel.
  2. Second, the breach duty in Rule 7 has no size threshold. A personal data breach includes “accidental disclosure” (s.2(u)), so a lab report sent to the wrong WhatsApp number is reportable to the patient and to the Board. A|P’s reading, not settled law; confirm with counsel.

What rights do patients have under the DPDP Act?

From 13 May 2027, patients have four rights against a hospital or healthtech company that holds their data, and the business must publish on its website or app how to exercise them (Rule 14(1)).

  1. Access (s.11). A summary of the personal data being processed and the processing activities, plus the identities of every other fiduciary and processor the data has been shared with, and a description of what was shared. Sharing with authorities authorised by law to investigate offences is excluded (s.11(2)).
  2. Correction and erasure (s.12). Correction, completion and updating of data. Erasure on request, unless retention is needed for the specified purpose or required by law.
  3. Grievance redressal (s.13). A readily available grievance process. The patient must use it before approaching the Board (s.13(3)).
  4. Nomination (s.14). A nominee who can exercise these rights if the patient dies or loses capacity.

Patients have duties too, including not filing false or frivolous complaints (s.15), with a penalty of up to ₹10,000.

The access right has an operational consequence. A hospital can’t name everyone it shares a patient’s data with unless it knows: TPAs (third party administrators, companies registered with the insurance regulator IRDAI and engaged by insurers to provide health services) and insurers, outsourced labs, referral doctors, the software vendors behind its systems. The data principle’s (patient’s) right effectively requires every data fiduciary (hospital) to keep a current map of its data flows. A|P’s reading, not settled law; confirm with counsel.

How does the DPDP Act treat children’s data and guardians?

From 13 May 2027, a fiduciary must obtain verifiable consent from a parent before processing the data of a child, meaning anyone under 18 (ss.2(f), 9(1)), checking under Rule 10 that the parent is an identifiable adult. It may not process data in a way likely to harm the child’s well-being (s.9(2)), and may not track, behaviourally monitor or target advertising at children (s.9(3)).

Healthcare providers have a narrow exemption from the parental-consent and tracking rules (Rule 12 and the Fourth Schedule). It covers four classes of fiduciary, and only where processing is restricted to providing health services to the child “to the extent necessary for the protection of her health”:

A healthtech platform is not one of the four classes. Whether a platform processing children’s data on a hospital’s behalf can rely on the hospital’s exemption is unsettled. A|P’s reading, not settled law; confirm with counsel. The exemption also never covers the ban on harmful processing in s.9(2).

For patients with a disability who cannot take legally binding decisions, consent comes from a lawful guardian. The fiduciary must verify that a court, a designated authority or a local level committee appointed that guardian (Rule 11). A relative who accompanies the patient is not automatically a lawful guardian. A|P’s reading, not settled law; confirm with counsel.

What extra duties apply to a Significant Data Fiduciary?

The government may designate any fiduciary or class of fiduciaries as Significant Data Fiduciaries, weighing factors that include the volume and sensitivity of data processed (s.10(1)). From 13 May 2027, a designated fiduciary must appoint a Data Protection Officer based in India and an independent data auditor, and run periodic Data Protection Impact Assessments and audits (s.10(2)). Rule 13 adds:

  • a Data Protection Impact Assessment and an audit every twelve months, with significant observations reported to the Board;
  • due diligence that its algorithmic software does not pose a risk to patients’ rights;
  • keeping within India any personal data the government specifies on a committee’s recommendation.

As of 4 October 2026, we found no notification designating any Significant Data Fiduciary. Large hospital chains and health platforms processing data at scale should plan as though designation is possible, because sensitivity is a named factor. A|P’s reading, not settled law; confirm with counsel.

Do healthcare businesses need a Consent Manager?

No. The Act says a patient “may” give, manage, review or withdraw consent through a Consent Manager (s.6(7)). It does not oblige a hospital or healthtech company to use one. A|P’s reading, not settled law; confirm with counsel. From 13 November 2026, companies can apply to register as Consent Managers under Rule 4. The First Schedule sets a high bar:

  • an Indian company with a net worth of at least ₹2 crore;
  • independent certification of its platform;
  • unable to read the personal data passing through it;
  • acting in a fiduciary capacity towards the patient;
  • free of conflicts of interest with the businesses that hold the data;
  • consent records kept for at least seven years.

The conflict-of-interest rules matter for healthtech founders. A company that serves hospitals as a vendor would find it hard to also act as the Consent Manager for those hospitals’ patients. A|P’s reading, not settled law; confirm with counsel.

Can health data be stored or processed outside India?

Yes, within limits that change on 13 May 2027. From that date, section 16 applies: data may go abroad unless the government notifies a country to which transfers are restricted (s.16(1)), and Rule 15 lets it set requirements on making data available to a foreign State. As of 4 October 2026, we found no such notification.

Until 13 May 2027, a body corporate may transfer sensitive personal data, in India or abroad, only to a recipient that ensures the same level of data protection (as would have been applicable to the data in India), and only where the transfer is necessary for a lawful contract with the person or the person has consented (SPDI rule 7). For a hospital or healthtech company using a cloud host, that points to a hosting contract that commits the host to the same level of protection. A|P’s reading, not settled law; confirm with counsel.

From 13 May 2027, sector laws that impose stricter limits still apply (s.16(2)), and a Significant Data Fiduciary may also be required to keep specified data in India (Rule 13(4)).

Which DPDP exemptions matter to healthcare?

Three exemptions are relevant to healthcare businesses:

  • Research, archiving and statistics (s.17(2)(b); Rule 16). The Act does not apply to processing necessary for these purposes if the data is not used to take a decision about a specific person and the processing meets the standards in the Second Schedule: lawful, limited to necessary data, accurate, retained only as needed, secure, and with clear accountability.
  • Data of people outside India processed under a foreign contract (s.17(1)(d)). Most fiduciary duties and patient rights do not apply when an Indian business processes the data of people outside India under a contract with a person outside India. This is relevant to Indian teams serving overseas healthcare clients, however, privacy laws of those countries may apply in such cases.
  • Startups (s.17(3)). The government may exempt notified fiduciaries, “including startups”, from notice, accuracy, erasure, Significant Data Fiduciary and access obligations. As of 4 October 2026, we found no such notification. The government’s 3 December 2025 Lok Sabha reply refers to this power as a “simplified compliance framework for start-ups”; it is not an exemption in force.

What are the penalties, and who enforces them?

From 13 May 2027, the Data Protection Board can inquire into breaches and impose monetary penalties of up to the amounts set in the Schedule to the Act. Penalties are credited to the Consolidated Fund of India (s.34), and appeals go to the Telecom Disputes Settlement and Appellate Tribunal within sixty days (s.29).

BreachMaximum penalty
Failure to take reasonable security safeguards (s.8(5))₹250 crore
Failure to notify the Board or affected people of a breach (s.8(6))₹200 crore
Breach of the obligations on children’s data (s.9)₹200 crore
Breach of Significant Data Fiduciary obligations (s.10)₹150 crore
Breach of any other provision of the Act or Rules₹50 crore
Breach of a data principal’s duties (s.15)₹10,000

When setting a penalty, the Board weighs the nature, gravity and duration of the breach, the type of data affected, repetition, any gain made, mitigation, proportionality and the likely impact on the business (s.33(2)). After penalties in two or more instances, the government may, on the Board’s reference, block public access to a fiduciary’s digital service (s.37). The Act gives the patient no route to compensation, and civil courts cannot hear matters the Board is empowered to decide (s.39). A|P’s reading, not settled law; confirm with counsel.

How does the DPDP Act sit alongside healthcare laws?

The DPDP Act adds to other laws rather than replacing them, and prevails where it conflicts with them (s.38). A hospital’s existing record-keeping and confidentiality obligations continue. The Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 require doctors to keep indoor-patient records for three years from the start of treatment (reg. 1.3.1). They also require records to be issued within 72 hours of a request (reg. 1.3.2), and a doctor not to disclose a patient’s secrets except in specified circumstances (reg. 7.14).

The erasure duty gives way where “retention is necessary for compliance with any law” (s.8(7)), so a three-year retention requirement for IPD records overrides a patient’s erasure request during that period. The 2002 Regulations say nothing about OPD records. That leaves each hospital to set and justify its own retention period for outpatient data. A|P’s reading, not settled law; confirm with counsel.

Reading builds understanding. Deciding what it means for your hospital or healthtech business is a different problem — book a 20-minute call if you’d rather talk it through than work it out alone.

What should a hospital or healthtech company do before 13 May 2027?

Until that date, the 2011 Rules still require a body corporate to obtain written consent before collecting health data (rule 5(1)) and to resolve grievances within one month (rule 5(9)). Seven steps cover most of the distance on DPDP compliance for hospitals and healthtech companies, and none of them needs outside help to start:

  1. Map every flow of patient data and your role in it. List where data is collected, stored and sent, and mark each flow fiduciary or processor. The access right in s.11 makes this list necessary anyway. A|P’s reading, not settled law; confirm with counsel.
  2. Name the legal ground for each purpose. Treatment, reminders, research, marketing and sharing each need consent or a section 7 legitimate use. Purposes without a ground are the ones to fix or stop.
  3. Rewrite notices to the Rule 3 standard. Use an itemised data list, specific purposes, and a working link for withdrawal, rights and complaints, available in the languages patients actually use.
  4. Set a security baseline against Rule 6. Cover encryption or masking, access control, access logs kept for a year, and backups. Write the same requirements into every processor contract.
  5. Write a breach runbook. Decide who tells affected patients, through which channel, and who files the Board report within 72 hours. Rehearse it on a misdirected-report scenario.
  6. Write a retention schedule. Split IPD records, OPD records, billing data, marketing lists and logs. Set each period between the one-year floor in Rule 8(3) and the limits other laws impose.
  7. Plan the re-notice for existing patients. From 13 May 2027, section 5(2) requires a notice to everyone whose consent predates the Act. That makes it the step to sequence and budget for.

Frequently asked questions about the DPDP Act for healthcare

When does the DPDP Act apply to hospitals?

The DPDP Act’s duties apply to hospitals from 13 May 2027, under MeitY’s commencement notification G.S.R. 843(E). Until then, health data held by a body corporate is governed by the IT Act’s 2011 SPDI Rules, which treat medical records and health conditions as sensitive personal data requiring written consent.

Is a healthtech company a data fiduciary or a data processor under the DPDP Act?

A healthtech company can be both, depending on the data flow. It acts as a processor when it handles a hospital’s patient data only on the hospital’s instructions. It acts as a fiduciary for its own users, and for any patient data it uses for purposes it decides itself. A|P’s reading, not settled law; confirm with counsel.

Do hospitals need consent to treat patients under the DPDP Act?

The Act does not settle this explicitly. Section 7(a) allows processing of data a person voluntarily provides for a specified purpose without separate consent, and s.7(f) covers medical emergencies. Whether routine care can rely on s.7(a) is an open question to take to counsel. Either way, from 13 May 2027 the hospital must give a notice that meets Rule 3. A|P’s reading, not settled law; confirm with counsel.

How quickly must a hospital report a data breach under the DPDP Rules 2025?

A hospital must inform each affected patient and the Data Protection Board without delay, and give the Board a detailed report within 72 hours of becoming aware of the breach (Rule 7). The Board can allow more time on a written request. The duty applies from 13 May 2027.

Ready to find a growth partner for your healthcare business?

Reading builds understanding. Deciding what it means for your business is a different problem — book a 60-minute discovery call if you’d rather talk it through than work it out alone.