DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Pharma and life-sciences companies process some of the most sensitive personal data that exists — clinical trial records, adverse-event and pharmacovigilance data, patient-support-programme information and research datasets. Under the DPDP Act 2023 this data needs a lawful basis (usually specific consent from the trial participant or patient), strict purpose limitation, strong security safeguards, and controlled sharing with CROs, sites, sponsors and regulators. Sector rules from ICMR, CDSCO and Good Clinical Practice sit alongside the DPDP Act, so pharma companies face an overlapping obligation. This guide assesses your clinical-data protection readiness.

Pharma & Life Sciences Clinical Data Protection Under DPDP

Clinical, pharmacovigilance and patient-programme data is the most sensitive data pharma handles. Check your clinical-data protection readiness against the DPDP Act.

Assess your clinical-data protection readiness

Clinical-data protection checklist for pharma & life sciences

How does the DPDP Act apply on top of GCP, ICMR and CDSCO rules?

Clinical research in India is already governed by Good Clinical Practice guidelines, ICMR ethics norms and CDSCO regulatory requirements, all of which include their own informed-consent and record-keeping rules. The DPDP Act 2023 adds a general data-protection layer: the personal data of trial participants and patients must be processed on a lawful basis, limited to the research or safety purpose, protected by reasonable security safeguards, and not retained beyond what the purpose and regulatory rules require. These regimes are complementary — the DPDP Act does not replace GCP consent, it sits alongside it.

For pharma and life-sciences companies this means the informed-consent form participants sign for a trial should be reviewed against DPDP requirements: is the data-use description specific enough, does it cover secondary research and cross-border transfer to a global sponsor, and can consent be withdrawn without compromising participant safety obligations. Niti Bharat helps sponsors, CROs and patient-programme operators reconcile GCP-based consent with the DPDP Act so a single participant journey satisfies both.

Where do pharma companies most often fall short on clinical data?

The most common gaps are unclear role allocation and weak downstream control. Sponsors, CROs and trial sites frequently have not documented who is the data fiduciary and who is the processor, which leaves accountability ambiguous when a regulator or the Data Protection Board asks. The second recurring gap is cross-border transfer: clinical data routinely moves to a global sponsor or centralised database abroad without a clearly stated lawful basis or participant-facing disclosure. The third is retention — trial and pharmacovigilance data kept indefinitely long after the regulatory retention window has expired.

Because clinical, adverse-event and patient-programme data is among the most sensitive personal data anywhere, a breach or misuse carries severe consequences — DPDP penalties reach up to ₹250 crore where a security-safeguard failure causes a breach. Niti Bharat's fixed-price DPDP engagements (₹75,000–₹3.2 lakh) help life-sciences companies map their clinical data flows, fix role and transfer gaps, and build the documentation a regulator or the Board would expect ahead of enforcement around May 2027.

Get the clinical-data protection toolkit (free)

A PDF covering a clinical-data flow map, a fiduciary-vs-processor allocation matrix for sponsor/CRO/site relationships, and a DPDP-aligned review of GCP informed consent.

Frequently Asked Questions

Does the DPDP Act replace GCP and ICMR informed consent?+
No. GCP and ICMR informed-consent requirements continue to apply, and the DPDP Act's consent and data-protection duties sit alongside them. In practice the trial informed-consent process should be reviewed so that a single consent journey satisfies both the ethics/regulatory requirements and the DPDP standard of specific, informed consent.
Who is the data fiduciary in a sponsor-CRO-site chain?+
It depends on who decides the purpose and means of processing. Typically the sponsor is the data fiduciary and the CRO and sites are processors, but a CRO or site can become a co-fiduciary where it makes independent decisions about the data. The safest approach is to define each party's role explicitly in the contract.
Can we transfer clinical data to a global sponsor abroad?+
Cross-border transfer is common in multinational trials but must rest on a lawful basis, be disclosed to participants, and comply with any transfer restrictions under the DPDP framework. It should be addressed in both the informed-consent documentation and the data-sharing agreements.
How long should clinical trial data be retained?+
Retention should follow the applicable regulatory record-keeping requirements (for example CDSCO and ICMR retention periods for trial records), after which the data should be de-identified or deleted. Keeping identifiable clinical data indefinitely without a retention basis conflicts with the DPDP storage-limitation principle.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Privacy by Design in DevOpsPrivacy Training Metrics GuideProduct DPDP Sprint ChecklistDSAR Process Timeline CheckerSee all Reference & Checklists tools →📝 DPDP for Payment Aggregators📝 How to Implement Data Retention Deletion DPDP