How does the DPDP Act apply to clinical trial data in India? Clinical trial participant data is personal data under the DPDP Act 2023, and much of it — health status, diagnoses, genetic and biometric data — also falls under the heightened category the Act references for sensitive processing contexts. Trial sponsors, CROs and investigator sites must layer DPDP obligations (specific and informed consent, purpose limitation, breach notification, data principal rights) on top of existing ICMR ethical guidelines and Good Clinical Practice (GCP) informed consent requirements — the two consent frameworks serve different purposes and must both be satisfied. This kit maps the overlap and gives you the documents to close the DPDP gap without disrupting your existing ethics and GCP processes.
A DPDP compliance kit built for CROs, pharma sponsors and hospital research units — consent mapping, sponsor DPA clauses, anonymisation protocol and breach response for trial data.
GCP informed consent (governed by ICMR National Ethical Guidelines and Schedule Y) establishes a participant's agreement to undergo the trial procedures, risks and interventions — it is an ethics and safety consent, reviewed and approved by the Ethics Committee. DPDP consent is a separate, additional requirement covering how the participant's personal data is collected, used, stored, shared and retained. A signed GCP informed consent form does not automatically satisfy DPDP — the two must be read together, and best practice is a DPDP-specific data processing annexure attached to or referenced within the existing informed consent document, reviewed alongside the main consent form by the Ethics Committee.
Map each existing consent touchpoint (screening, enrolment, sample collection, follow-up visits, long-term data retention post-trial) against DPDP's consent requirements: is it free, specific to each processing purpose, informed in plain language, given unambiguously, and withdrawable? Participant withdrawal from a trial (a GCP right) and withdrawal of DPDP consent for data processing are related but distinct — your SOP must address what happens to already-collected data under each type of withdrawal, since trial data integrity rules may still require retention of already-generated results even after a participant withdraws.
Under DPDP, participants (as Data Principals) retain rights to access information about their data, request correction of inaccurate data, and — subject to trial integrity, regulatory retention obligations and scientific validity requirements — request erasure. Your SOP should specify: the intake channel for a participant rights request (typically the site coordinator or Grievance Officer), the internal triage step to determine whether the request conflicts with GCP data-integrity or regulatory retention requirements, the response template explaining any limitation, and the target response time (align to the Act's 30-day expectation for standard requests).
Critically, document the legal basis for any refusal or partial fulfilment of an erasure request — typically that trial data must be retained per regulatory requirements (Schedule Y, ICH-GCP, and sponsor/regulator retention mandates that can run 15–25 years post-trial). This documented basis is what protects the site or sponsor if a participant later escalates the refusal to the Grievance Officer or the Data Protection Board.
Data categories selected for your kit:
Clinical trial data protection in India sits at the intersection of three frameworks: ICMR's National Ethical Guidelines for Biomedical Research, ICH-GCP standards that most Indian trials follow for global acceptability, and now the DPDP Act 2023 as a horizontal data protection law that applies regardless of sector. Generic privacy policies and consent forms built for consumer apps do not fit clinical research — trial data has long, regulator-mandated retention periods, comes from vulnerable participant populations, often involves paediatric or incapacitated subjects requiring special consent handling, and routinely crosses borders to sponsors and central labs.
CROs and sponsors that operate multi-site, multi-country trials are particularly exposed because a single DPDP gap — an unmapped consent form, an undocumented cross-border transfer, or a breach response process that does not account for the sponsor-CRO-site chain — can affect every active trial simultaneously, not just one site.
The practical path for CROs, sponsors and research hospitals is to layer DPDP requirements onto existing GCP infrastructure rather than rebuilding it: add a DPDP-specific consent annexure rather than replacing the informed consent form, add DPDP clauses to existing sponsor-CRO-site agreements at the next amendment cycle, and extend the existing pharmacovigilance/safety breach escalation process to also trigger the DPB's 72-hour breach notification clock where relevant. This approach gets an organisation to compliance without pausing active trials or requiring Ethics Committee re-approval of already-running studies.
With enforcement expected around May 2027, CROs and research hospitals should treat this as a parallel workstream to their next study start-up, not a one-time retrofit. Niti Bharat runs fixed-price DPDP compliance engagements (Rs 75,000–Rs 3.2 lakh) for healthcare and life-sciences organisations that need this mapped properly against their specific trial portfolio and sponsor relationships.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.