Skip to content
Senior Living Kerala

What Data Does the Operator Collect About Me, and Who Has Access to My Medical Records?

India's Digital Personal Data Protection Act, 2023 (DPDP Act) is now in force and applies to any personal data an operator collects about you — including health monitoring records, medication logs, CCTV footage and visitor records. One common misconception worth correcting directly: unlike some older Indian rules and frameworks like the GDPR, the DPDP Act does not create a special "sensitive personal data" category with extra-heightened rules specifically for health data — it applies one uniform consent-and-purpose standard to all personal data, health information included. That still means an operator needs your free, specific, informed and unambiguous consent to collect and use your data, and generally cannot share your medical records with your children or anyone else without that consent, unless a specific legal exception applies.

What the Act actually requires

Under the DPDP Act, an operator collecting your data (medical records, medication administration logs, health monitoring, CCTV in common areas) is a "data fiduciary" and needs your consent — which must be freely given, specific to the purpose, informed, and given through a clear affirmative action — before collecting or using that data for a given purpose. You generally have the right to ask what data is held about you, request correction of inaccurate records, and withdraw consent, subject to the operator's own retention obligations (for example, the 10-year record-retention requirement under Kerala's care-home guidelines, which is a separate, older obligation that continues to apply alongside the DPDP Act).

Sharing your records with family

Because the Act requires consent for a specific purpose, an operator generally shouldn't share your medical records with your adult children or other family members without your consent, unless you've specifically authorised that in advance (for example, naming a family member as someone who can receive health updates) or a recognised legal exception applies. If keeping your children informed matters to you, it's worth explicitly authorising that in writing with the operator — rather than assuming it happens automatically, or assuming it doesn't.

Research gaps

This guide describes the DPDP Act's general framework. The Act's rules (the Digital Personal Data Protection Rules) govern implementation details — such as specific consent-notice formats and data-breach reporting timelines — that were still being finalised/rolled out as this was researched, so operator practices may not yet fully reflect the Act's eventual full implementation. If a specific data-handling practice concerns you, it's worth raising directly with the operator and, if needed, with a lawyer familiar with the current state of DPDP Rules implementation.

This guide is provided for general information and research purposes. It is not legal, tax or financial advice. Rules can depend on the specific type of property, operator, agreement and individual circumstances. Where a decision involves a substantial sum, inheritance, tax or contractual dispute, get advice from a lawyer or chartered accountant who can look at your specific documents.