India’s DPDPA vs GDPR: Reconciling Cross-Border Health Data
Digital healthcare has dissolved borders for medical expertise. A patient in Mumbai can consult a specialist in Berlin in minutes. But that convenience masks a growing legal problem: India and Europe protect health data using fundamentally different frameworks. For patients and hospitals sending medical information across continents, the gap between these systems creates real vulnerability.

How India and Europe Define Health Data Differently

The difference starts at the definitional level. India’s Digital Personal Data Protection Act, 2023 (DPDPA) treats all personal data uniformly. An email address and a cancer diagnosis receive the same legal protection.

Under DPDPA Section 2(t), any data about an identifiable individual is “personal data.” No distinctions. No categories. This uniformity simplifies compliance but creates a blind spot for sensitive information.

The European Union’s GDPR takes the opposite approach. It broadly defines personal data, then explicitly carves out a separate category: “special categories” of data. Article 9 of GDPR designates healthcare information as special. That label triggers stricter processing rules, higher penalties for breaches, and mandatory consent for processing.

Aspect India (DPDPA) Europe (GDPR)
Health Data Classification Same as all personal data Special category, higher protection
Cross-Border Transfers Negative list (allowed unless blacklisted) Whitelist (allowed only if adequate protection)
Breach Penalties Defined but less severe for health Up to 4% of global revenue for health data
Safeguard Requirements General obligations Standard Contractual Clauses or Binding Corporate Rules required

The Real Risk: A Hospital in Kerala Shows Why This Matters

In March 2026, the gap between these systems became tangible. A leading private hospital in Ernakulum, Kerala suffered a ransomware attack. The cybercriminal group “The Gentlemen” stole 800 GB of sensitive healthcare data and posted it on the dark web.

Under DPDPA, this breach triggered standard data protection protocols. Under GDPR, if any of those patients were European citizens, the hospital would face potential fines reaching millions of dollars, mandatory breach notification within 72 hours, and investigations by multiple data protection authorities.

The asymmetry is stark: India has no special category enforcement for health data. Europe does. A hospital exporting health records to an overseas AI server would face minimal DPDPA friction, but crossing that same data to Europe demands proof of adequate protection and proper safeguards.

How Cross-Border Transfers Actually Work

DPDPA uses what regulators call a “negative list” approach. Section 16 and Rule 15 of the Digital Personal Data Protection Rules, 2025 allow data transfers globally unless the Central Government explicitly blacklists a jurisdiction. This permissiveness suits startups and enables rapid telemedicine expansion. It also creates structural risk.

GDPR operates on the opposite principle: a “whitelist” model. Chapter V, Articles 44 to 50 restrict data from leaving the European Economic Area unless the recipient country offers “adequate” protection. There is no such thing as a default-allowed transfer in GDPR. Every transfer requires explicit justification.

For multinational healthcare platforms, GDPR offers formal pathways: Standard Contractual Clauses (SCCs) for vendor relationships or Binding Corporate Rules (BCRs) for internal transfers. DPDPA has no equivalent mechanism. This creates a compliance puzzle for any telemedicine company serving both Indian and European patients.

The Structural Problem for Indian Patients

Here is the core vulnerability: A patient’s medical records, contact information, and diagnostic images could be sent from India to a server in a country with minimal privacy regulation. Under DPDPA, this is legally permissible. Under GDPR, it would be illegal if that same data belonged to a European patient.

This creates unchecked exposure to foreign surveillance, unauthorized secondary use, or commercial monetization of health profiles. An Indian patient has no mechanism within DPDPA to block this transfer or demand the same protections a European patient receives by default.

The difference is not semantic. It determines whether health data is treated as a commodity or a fundamental right.

What India Must Do

As digital health services expand, India’s regulatory framework faces a test. DPDPA must evolve to distinguish health data from ordinary personal data. This does not require adopting GDPR wholesale. It requires India to recognize that healthcare information demands a different risk profile.

Possible measures include designating health data as a special category requiring explicit consent for cross-border transfer, establishing an “adequate protection” whitelist for receiving countries, or requiring impact assessments before exporting health records internationally.

Without these changes, digital convenience will come at the cost of patient privacy. The Kerala hospital breach is not an outlier. It is a preview of what happens when regulatory frameworks lag behind technology.

Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates