DPDP expects personal data to be erased once the purpose is served. Medical record-keeping expects retention for defined periods. Clinics sit between the two and mostly resolve it by keeping everything indefinitely, which satisfies neither.
The two obligations
Medical records have retention expectations tied to clinical and legal need, and those are not something a marketing policy can override. Marketing data has no such protection and falls squarely under minimisation.
The resolution is separation. A clinical record and a marketing contact record are different things with different lifespans, and most clinic systems store them as one row.
A workable retention split
- Clinical records: retained per medical record-keeping requirements, access restricted by role
- Appointment history: retained while the patient relationship is active, then archived
- Marketing contact data: retained while consent stands, deleted on withdrawal
- Enquiry data from people who never became patients: short retention, months not years
- Marketing analytics: aggregate and discard identifiers
The enquiry pile is where exposure hides
Most clinics hold years of enquiries from people who never booked. There is no clinical basis for keeping them and usually no valid marketing consent either. That pile is pure liability and deleting it costs nothing.
Restrict access by role while you are there
Reception does not need clinical notes. Most small clinic systems grant everyone everything by default, which turns a single compromised account into a full-record breach.
General information, not legal advice. Rules current as of July 2026.