Home
DPDP Rules

DPDP Act for Pharmaceutical Companies: Clinical Trials, Pharmacovigilance and Patient Data

Date Published

clinical data management

India runs one of the world's largest pharmaceutical operations: third by production volume, a global hub for clinical trials and bioequivalence studies, and home to the R&D and data hubs of multinational drug makers. Every part of that machine runs on personal data of the most sensitive kind: medical histories, genetic information, diagnostic results, adverse event reports, and long-term health outcomes. India’s DPDP Act, 2023 and DPDP Rules, 2025 create an economy-wide framework for digital personal data. For pharmaceutical companies, this framework sits alongside the New Drugs and Clinical Trials Rules, ICMR ethical requirements, pharmacovigilance obligations and the earlier SPDI framework. Most core DPDP obligations become enforceable on 13 May 2027

The data itself sets the stakes. Health information sits at the top of the sensitivity scale. Although the DPDP Act does not create a separate category of sensitive personal data, the volume, sensitivity and potential harm associated with health, genetic and clinical data can materially increase an organisation’s privacy risk. Pharmaceutical companies rank among the costliest breach victims; IBM’s 2024 India analysis estimated the average cost of a pharmaceutical-sector data breach at ₹221 million, and a trial participant whose data is mishandled can create heightened regulatory, reputational and complaint risk. This guide maps the obligations across the pharma value chain: the trial site, the contract research organisation, the safety database, the patient support programme, and the field force, and flags the three places where the sector's current reading of the law is most likely wrong.

Two Consents, One Participant

The first correction concerns the document every trial already has. Informed consent under the New Drugs and Clinical Trials Rules 2019 and the ICMR ethical guidelines is a form of medical consent: it establishes that a participant understands the procedure, its risks, and its benefits. It does not, by itself, satisfy the DPDP Act. Data processing consent is a separate legal instrument with Informed consent under the New Drugs and Clinical Trials Rules, and ICMR ethical guidelines primarily address participation in the research, including the procedure, potential risks, benefits, and participant rights. It does not automatically establish valid consent for every digital personal-data processing purpose under the DPDP Act. Sponsors should therefore add a clearly distinguishable DPDP notice-and-consent layer within the informed consent form or through a linked document covering the personal data involved, specified purposes, rights, grievance route, and withdrawal. Free, specific, informed, unconditional, unambiguous, tied to stated purposes, accompanied by clear and plain language, with access in English or a relevant Eighth Schedule language - 22 languages 

A sponsor can be fully compliant with the ICMR guidelines and still in breach of the DPDP Act if participants were never told, in DPDP Act terms, what personal data would be processed, for which purposes, where it would travel, and how to exercise their rights. The fix is procedural rather than philosophical: trial documentation needs a data-processing consent layer alongside the medical one, captured as explicit, purpose-mapped consent with an auditable record. A participant should be told what personal data will be processed, the specified purposes, how to withdraw consent, how to exercise DPDP rights, and how to raise a grievance. Sponsors may additionally explain key recipient categories and cross-border flows as a transparency and governance practice. Withdrawal needs equal care, because a participant who withdraws data consent mid-trial triggers questions the protocol must already answer: what happens to data collected so far, what continued processing the law still permits, and how the withdrawal is evidenced.

clinical data management

The Research Exemption Is Narrower Than the Sector Assumes

Much of the industry is planning around Section 17(2)(b), which exempts processing for research, archiving, or statistical purposes from the Act's main obligations. Two constraints make that exemption far narrower than the planning assumes. First, it applies only where processing follows the standards prescribed in the Second Schedule of the DPDP Rules: lawful processing, purpose limitation, data minimisation, accuracy, security safeguards, and accountability, which together amount to most of a compliance programme anyway. Second, and decisively, the exemption does not cover processing used to make decisions specific to an individual data principal.


Clinical trials make participant-specific decisions constantly: enrolment, dosing, continuation, withdrawal for safety. Section 17(2)(b) cannot be relied upon for processing that is used to make decisions specific to an individual participant. Many operational trial activities, including screening, enrolment, dose allocation, safety intervention and continuation decisions, are therefore unlikely to qualify for the exemption. Other research processing may still qualify where it is necessary for research, does not drive participant-specific decisions and is carried out in accordance with the Second Schedule standards. On the plain reading, the conduct of a trial is therefore outside the exemption, and the consent regime applies in full. Where the exemption genuinely works is downstream. The exemption may be particularly relevant to secondary research, statistical analysis and real-world evidence programmes that do not result in participant-specific decisions. Separately, data that has been irreversibly anonymised so that individuals are no longer identifiable may fall outside the definition of personal data. Pseudonymised or coded data that can still be re-linked to a participant should continue to be treated as personal data. That makes data anonymization the highest-value technical control in pharma's DPDP toolkit: done rigorously, “may take a specific dataset outside the Act’s scope, provided the anonymisation is robust, and re-identification is not reasonably possible.” Done sloppily, with re-identifiable keys floating in linked systems, it moves them back in with penalties attached.

The third correction runs in the industry's favour. Adverse event reporting is mandated by the NDCT framework and the Pharmacovigilance Programme of India: investigators report serious adverse events within 24 hours, sponsors report onward to the regulator within statutory timelines, and marketing authorisation holders run continuous drug safety surveillance. Processing personal data to meet those obligations is compliance with law, a legitimate use under Section 7 of the Act, and it does not run on patient consent.

That classification matters in both directions. Pharmacovigilance teams do not need to chase consent for statutory safety reporting, and should not, because a safety system that patients could switch off by withdrawing consent would defeat its purpose, and the law does not require it. But organisations should not assume that every activity labelled "pharmacovigilance" is automatically consent-free. The legitimate use extends only as far as the legal obligation. Activities such as case follow-up beyond statutory requirements, global safety database consolidation, signal detection, long-term surveillance, research, or secondary analytics should each be assessed against their own lawful basis. Where processing goes beyond the applicable statutory obligation, for example, commercial analytics, market research, or promotional targeting, it leaves the Section 7 safe harbour and requires an independently documented lawful basis, which in many cases will be consent. Pharmacovigilance databases therefore need purpose tagging at the record level so statutory processing and discretionary processing never blur, with an audit trail that clearly records the lawful basis supporting each use.


CROs, Sponsors, and the Fiduciary Chain

Indian pharma runs on outsourcing, and the DPDP Act maps onto that structure with clear default roles: the sponsor who determines why and how trial data is processed is the data fiduciary; the contract research organisation processing on the sponsor's instructions is the data processor; and liability for the processor's handling rests with the fiduciary. A contract research organization running site management, data management, and safety operations across dozens of sponsors becomes a concentration of other companies' regulatory risk, which is why CRO contracts now need the same treatment lenders give their agents: purpose-scoped data clauses, security and breach notification duties flowing back without delay, sub-processor controls, and audit rights that are actually exercised.

Cross-border flows add the next layer. Global sponsors consolidate trial and safety data in regional or headquarters systems, and pharma GCCs in India process worldwide datasets. The Act permits cross-border transfers except to countries the government notifies, but the Rules allow additional restrictions for Significant Data Fiduciaries, and health data is exactly the category such restrictions would target. Multinationals should architect for the possibility that specified categories of clinical and health data may one day be required to stay in India, which argues for India-resident primary storage with controlled outbound flows rather than the reverse.

Beyond the Trial: Patient Programmes and the Field Force

The trial is the most regulated data flow in pharma but rarely the largest. Patient support programmes hold ongoing treatment, adherence, and outcomes data collected directly from patients, squarely consent-based and long-lived. Digital therapeutics and companion apps add device and behavioural streams. And the commercial engine holds a data category the sector routinely forgets is regulated: healthcare professionals. Doctors in a field force CRM are data principals like anyone else; prescribing-behaviour profiles, engagement histories, and contact data all need a lawful basis, notices, and hygiene around third-party data purchases. Marketing consent for HCP communication is the unglamorous compliance gap most likely to generate early complaints, because the data principals involved understand the law better than most.

Pediatric research and programmes carry the strictest overlay: anyone under 18 is a child, processing requires verifiable parental consent under Rule 10, and the clinical-establishment exemptions in the Rules are scoped to health services, not to research or commercial programmes. Sponsors running pediatric trials need parent identity verification and consent records built into enrolment, not appended to it.

pharmacovigilance

SDF Status, Retention, and the Breach Clocks

Health data volume and sensitivity make large pharma companies natural candidates for Significant Data Fiduciary designation, which brings an India-based data protection officer, annual impact assessments and audits, and algorithmic review that reaches AI models trained on patient data. Retention runs on two clocks that must be reconciled record by record: the NDCT framework requires trial records kept for five years after completion, and other statutory duties can extend that, while DPDP requires erasure once purpose and legal obligation both lapse. Purpose-tagged retention schedules resolve the apparent conflict; blanket keep-everything archives do not.

Breach duties compound the sector's exposure. A compromised safety database or trial system triggers CERT-In's 6-hour filing, intimation to the Data Protection Board without delay, a detailed report within 72 hours, and notification to affected data principals without delay, with no materiality threshold and penalties stacking to ₹250 crore for failed safeguards plus ₹200 crore for failed notification. Scoping a breach inside 72 hours across EDC systems, safety databases, CRO environments, and CRMs is impossible without a maintained data inventory, which is where incident response tooling earns its place in the pharma stack.

Building the Compliance Programme

The sequence follows the corrections above. Inventory personal data across the estate first: EDC and CTMS platforms, safety databases, patient support systems, HCP CRMs, GCC data lakes, and the laptops of clinical research associates. Classify every flow by lawful basis: consent, legitimate use, or the research exemption, with its Second Schedule conditions documented. Rebuild trial documentation with the data-consent layer and pediatric verification where it applies. Contract the CRO and vendor chain to fiduciary standard. Stand up the SDF layer early, DPO, DPIA cadence, audit and algorithm review, and wire the three breach clocks with templates and named owners.

How Privy Supports DPDP Readiness for Pharmaceutical Enterprises

Privy by IDfy helps pharmaceutical organisations operationalise DPDP controls across consent, data discovery, privacy assessments, third-party governance and incident response.

Its Consent Governance Platform can capture purpose-linked consent, withdrawal and verifiable parental-consent evidence. Data Compass can discover and classify personal data across clinical, safety, patient-support and commercial environments. Privacy-impact-assessment, third-party-risk and incident-management workflows can support high-risk processing reviews, CRO oversight and coordinated breach response.

Together, these capabilities help pharma teams move from policy-level compliance to auditable implementation across the data lifecycle.

Trusted by 50+ organisations | Ranked #1 in the MeitY–NeGD DPDP Innovation Challenge

Meity-NeGD's DPDP Innovation Challenge winner

IDfy won MeitY's DPDP Innovation Challenge and brings 14 years of handling India's most sensitive identity data at a scale of 60 million verifications a month.


best DPDP compliance platforms India

Conclusion

Pharma's DPDP problem is not effort but classification. The sector already runs the most heavily documented consent processes in the economy; the Act asks it to add a second consent layer it has been treating as covered, subtract the consent it never needed for pharmacovigilance, and stop assuming an exemption that excludes the very decisions trials exist to make. The companies that reclassify their data estate in 2026, basis by basis, will find much of the machinery already in place. The ones that wait will discover in May 2027 that ethics-committee compliance and DPDP compliance were never the same thing.

To see how Privy by IDfy operationalises consent, data discovery, and CRO governance for pharmaceutical enterprises, write to shivani@idfy.com for a walkthrough.

FAQs

Can clinical trial consent and DPDP consent be combined into a single form?

Yes. The DPDP Act does not necessarily require a separate physical form. However, the DPDP notice and consent elements should be clearly distinguishable, purpose-specific and capable of being evidenced independently.

Are pseudonymised clinical trial data outside the DPDP Act?

Not necessarily. If the data can be linked back to a participant using a code, key or another dataset, it should continue to be treated as personal data. Only robustly anonymised data that no longer relates to an identifiable individual may fall outside the Act.

Are CROs always Data Processors?

No. A CRO may act as a Data Processor for sponsor-instructed activities, but may become a separate or joint Data Fiduciary when it independently determines the purpose or means of processing.

Does the DPDP Act require pharmaceutical health data to be stored in India?

The current framework does not create a blanket localisation rule for all health data. However, transfers may be restricted to notified countries, and specified personal data processed by Significant Data Fiduciaries may be subject to localisation requirements.

Can consent be withdrawn during a clinical trial?

A participant may withdraw consent for consent-based personal-data processing. However, withdrawal does not invalidate processing already undertaken and does not prevent retention or processing that is required or authorised under another applicable law.

Does informed consent for a clinical trial cover DPDP consent? 

No. Medical informed consent under the NDCT Rules and ICMR guidelines addresses the procedure and its risks. DPDP consent is a separate instrument covering personal data processing: categories, purposes, recipients, rights, and withdrawal, with its own notice and record requirements. Trials need both layers.

Does the research exemption cover clinical trials?

 Not for trial conduct. Section 17(2)(b) exempts research, archiving, and statistical processing that meets the Second Schedule standards, but it excludes processing used to make decisions specific to an individual, and trials make participant-specific decisions throughout. The exemption's real value is in de-identified secondary research and real-world evidence work.

Is patient consent required for adverse event reporting? 

No. Pharmacovigilance obligations under the NDCT framework and PvPI are legal duties, so the processing is a legitimate use under Section 7. Consent re-enters only if the same data is repurposed beyond the statutory obligation, for example into commercial analytics or promotional targeting.

Are doctors' details in a pharma CRM covered by the DPDP Act? 

Yes. Healthcare professionals are data principals, so field force CRMs, prescribing-behaviour profiles, and engagement data need a lawful basis, notices, and consent for marketing communication, the same as any consumer database.

Will pharmaceutical companies be Significant Data Fiduciaries? 

Large pharma companies processing health data at scale fit the designation criteria of volume, sensitivity, and risk of harm. Prudent programmes build the SDF layer now: an India-based DPO, annual DPIAs and audits, and review of algorithmic systems trained on patient data.