Pharmaceutical companies conducting clinical trials, HCP data programmes, and patient support initiatives in India must comply with the DPDP Act 2023. Clinical trial participant data is sensitive personal data requiring enhanced protection. DCGI guidelines and DPDP obligations both apply.
DPDP compliance for pharma and life sciences — clinical trial consent, patient data, CRO vendor DPAs, and DCGI-DPDP gap analysis.
Clinical trial participants are Data Principals under the DPDP Act 2023 with full data rights — including the right to access their trial data and in some cases withdraw from data processing (distinct from trial withdrawal). The existing Informed Consent Form (ICF) process under CDSCO/DCGI guidelines and DPDP consent requirements overlap but are not identical.
DPDP-Specific ICF Additions: The standard CDSCO ICF covers medical procedure consent adequately, but DPDP requires additional data-specific disclosures not always included: (a) specific data types collected and how they will be processed, (b) which third parties will receive data (sponsor, CRO, regulatory agencies, international data sharing), (c) countries to which data may be transferred, (d) data retention period beyond trial end, (e) participant rights: access, correction, data rights grievance mechanism.
Electronic Consent (eConsent): DPDP supports digital consent — eConsent platforms used in clinical trials can serve both CDSCO and DPDP consent requirements if designed correctly. The platform must: log timestamp and IP of consent, version the consent form, support re-consent notifications when the form changes, and provide a downloadable copy to the participant.
Withdraw from Data Processing vs Trial Withdrawal: A participant who withdraws consent for data processing does not automatically withdraw from the trial (if they wish to continue). And a participant who withdraws from the trial may still have their existing data used in aggregate, anonymised research — this distinction must be clearly explained in the ICF.
Healthcare Professional (HCP) data programmes — doctor databases, medical representative visit logs, conference speaker engagements, consultant lists — constitute personal data processing under DPDP. HCPs are Data Principals with DPDP rights regardless of their professional status.
HCP Consent Requirements: Building a doctor database for field force detailing, sending product samples, or medical education communications requires DPDP-compliant consent from each HCP. Purchased or scraped doctor lists (from MCI/NMC registries, hospital websites) do not carry DPDP consent — re-consent campaigns are needed for any existing lists built without explicit opt-in.
CRM Data Governance: Medical CRM platforms storing HCP visit notes, prescription data, and engagement histories are personal data systems under DPDP. Access controls must limit CRM access to the relevant field team. HCPs who request access to their CRM profile or request deletion must receive a response within 30 days.
HCP Speaker / Consultant Engagements: Financial transfers to HCPs for speaking, consulting, or advisory roles require data processing (bank details, tax details, contractual data). This processing must be covered by a separate data notice at the time of contract engagement.
India is the world's second-largest clinical trial country by trial count. As DPDP Act enforcement approaches, pharmaceutical companies conducting trials in India must integrate DPDP data privacy obligations into their existing CDSCO/ICH-GCP compliance frameworks. The two sets of requirements are largely compatible but require deliberate integration.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.