Sector reference
DPDP for Hospitals and Healthcare
- What is processed
- Registration and treatment information the hospital genuinely needs in order to care for you. For a child, a clinical establishment, a mental health establishment or a healthcare professional may handle her health information as far as is necessary to protect her health, and an allied healthcare professional may do so to carry out a treatment or referral plan that has already been recommended.
Why it is allowed, and when
Two things are running here. Treating someone in a medical emergency, where life is threatened or health is under immediate threat, does not wait for consent, and neither does acting during an epidemic or another threat to public health. Separately, the usual requirement to get a parent's consent for a child is relaxed for health, but only within the narrow limits above.
Where the permission stops
Both child health exceptions are capped at what is necessary to protect that child's health. They do not authorise marketing, unrelated sharing or profiling. Anything past the cap needs a reason of its own.
Questions people actually ask
Can a hospital process my child's health data without going through the usual parental consent process?
In defined situations, yes. Clinical establishments, mental health establishments and healthcare professionals can handle a child's health information outside the usual consent process, but only as far as is necessary to protect the child's health.
Allied healthcare professionals have a narrower version of the same allowance, for carrying out a treatment or referral plan that has already been recommended.
Can they keep my records after treatment is over?
Only while there is still a live reason, or while another law requires it. Medical record rules often set their own periods and those apply. Once neither holds, the records should be deleted.
What if I was treated in an emergency and never gave formal consent?
That is expressly allowed. Treating someone in a medical emergency, where life is threatened or health is under immediate threat, is one of the situations where nobody has to be asked first. So is acting during an epidemic or another threat to public health.
It covers the emergency, not everything after it. Once you are stable, the ordinary rules resume for anything else the hospital wants to do with your information.
Can the hospital send my reports over WhatsApp?
No particular app is banned. What the law requires is that the hospital protects your information with reasonable security safeguards, and puts real measures in place rather than assuming things are fine.
That turns it into a practical question. Sending a report to a number nobody checked, or into a group, is exactly how this goes wrong. If it does go wrong it is a breach, and the hospital has to tell you and the Data Protection Board about it.
My employer paid for my health checkup. Can they see the results?
Paying for it does not make it their information. The findings are about you, so you are the person the law protects here, and the hospital or lab holding them answers to you.
An employer can normally be told what it needs to run the benefit it arranged, such as whether you attended. Your actual results are a different purpose, and it needs a reason of its own. There is no situation on the law's short list that covers an employer reading your medical findings, so in practice that means your specific agreement rather than a line buried in the health check package.
Agreement asked for by your own employer is also hard to call freely given, which is a problem for whoever is relying on it.
What people get wrong
You consented at registration, so we can share your records with our insurance or diagnostics partner.
Agreeing at registration covers your treatment. Passing your records to a commercial partner is a different purpose, and it needs a reason of its own.
You were treated in an emergency, so the emergency provision covers everything we do with your data now.
The emergency allowance covers responding to the threat to life, or the immediate threat to health. Once that has passed, the ordinary rules resume for anything further.
We are a hospital, so we never need parental consent for a child's data.
The child health exceptions are capped at what is necessary to protect that particular child's health. Billing analytics, marketing, research and passing data to outside companies all sit outside the cap, and each needs a parent's verifiable consent.
Related questions
- Do I need parental consent for users under 18?
- What is legitimate use under Section 7?
- How long can I keep personal data?
This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.