The Digital Personal Data Protection Act, 2023 does not have a small-practice exemption. If you hold patient information digitally — and a WhatsApp group of case photographs counts — you are a data fiduciary with obligations you probably have not been briefed on.
The four duties that actually bite
- Purpose limitation: collect what you need for care, and use it for that.
- Notice and consent: patients should know what you hold and why.
- Access and correction: they can ask to see it and to fix it.
- Breach notification: if data is exposed, there is a clock, and it is short.
Where practices are most exposed
In our experience it is rarely the clinical system. It is the informal layer around it: radiographs on a personal phone, a patient list in a spreadsheet emailed to a locum, treatment photographs in a professional group chat with no consent recorded. Those are the artefacts that create liability, and none of them is difficult to fix.
The compliance risk in a small clinic is almost never the software. It is the workarounds people build because the software was too slow to use.
What good software carries for you
Consent captured against the visit it belongs to. An access log you can actually produce. Export and correction as buttons rather than support tickets. Encrypted storage so that a lost phone is an inconvenience, not a notifiable incident. If your system does these by default, most of your obligations are met by using it normally — which is the point.
A ten-minute starting checklist
- Move clinical photographs off personal galleries and into the patient record.
- Stop sharing patient lists over email and chat.
- Record consent for treatment and for photography separately.
- Know who at your clinic can see what, and check it matches what you intended.
