Data-principal rights process
This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.
Rights supported
| Right (DPDP Act 2023) | What it means here |
|---|---|
| Access (s.11) | Summary of personal data processed, processing activities, and with whom it was shared |
| Correction, completion, updating (s.12) | Fix demographics or contact details; clinical corrections are made by the practitioner as an amendment (the original is kept, as medical law requires) |
| Erasure (s.12) | Delete data no longer needed — subject to medical-record, tax and legal retention (see below) |
| Nomination (s.14) | Nominate a person to exercise rights on death or incapacity (log as a GRIEVANCE-type request with a note until a dedicated type ships) |
| Grievance redressal (s.13) | Complaint to the provider / our grievance officer, then to the Data Protection Board |
Who handles the request
- Patients → the healthcare provider (Data Fiduciary). The clinic owner handles requests in
Admin → Privacy Requests (
/app/privacy-requests, permission privacy.request.manage, owner only); Achal Technology assists as processor. - Clinic owners/staff (our customers) → Achal Technology grievance officer.
Set up (owner, once)
- Open Admin → Privacy Requests → Settings.
- Enter the grievance officer name, e-mail, phone and address — patients see this on their portal page.
- Review the response times (defaults below) and save.
How a patient raises a request
- In the patient portal open My Privacy (
/patient/privacy). - Read Your rights, choose the request type (Access, Correction, Erasure, Grievance), describe it (up to 2,000 characters) and submit. Up to 5 requests per day.
- The request appears under My requests with its reference (
DPR-yyyymmdd-XXXXXX), status and due date.
Requests received by e-mail, phone, WhatsApp or in person are logged by the owner with Log a request.
Workflow in the staff queue
Statuses: Received → Acknowledged → In progress → Fulfilled / Partially fulfilled / Rejected → Closed.
- Acknowledge within the acknowledgement target (the queue flags Acknowledgement overdue).
- Verify identity before disclosing or changing anything: OTP to the registered phone/e-mail (portal requests are already OTP-verified), guardian verification for minors, nominee proof when applicable. Select Verify identity and note how it was verified.
- Start the work and fulfil:
- Access → Download access package: a JSON file with the patient's demographics and every linked record (appointments, encounters, vitals, diagnoses, allergies, prescriptions, clinical documents, bills, payments, packages…). Share it through a secure channel. The download is recorded in the access log.
- Correction → edit the patient's demographics in the patient record (audited); clinical content is corrected by the practitioner as an amendment/addendum. Then select Fulfil.
- Erasure → Preview erasure plan (nothing changes yet), review it, then Execute erasure and type the request reference to confirm.
- Grievance → investigate, record notes, Fulfil or Reject with reasons.
- Close with closure notes (required) describing the outcome and any reasons for partial refusal. The request record is kept (without unnecessary health data) for audit.
Every action is timestamped with the user and written to the audit log. Overdue requests are flagged in red.
Erasure rules (what "Execute erasure" does)
| Data | Action | Why / until |
|---|---|---|
| Encounters, vitals, diagnoses, allergies, prescriptions, clinical documents, legacy reports, care plans, treatment packages & usage, queue tokens | Restricted — kept, no further processing except legal purposes | Clinical-record retention: at least 3 years after the last record; for minors until age 21 + 3 years if later |
| Bills, payments, credit notes | Retained (never deleted) | CGST Act s.36 — until 6 years after the end of the financial year of the last record |
| Notifications | Deleted | Purpose ended |
| Appointments not completed and not linked to an encounter or bill | Deleted | Not a clinical record |
| Other appointments | Retained with the clinical/tax records | Attached to retained records |
| Patient-portal password and sessions | Deleted (all sessions signed out) | Not needed |
| Patient record | Anonymised ("Erased patient", contact / DOB / address / guardian cleared; UHID kept) only when nothing above is retained; otherwise restricted | Retained records must stay attributable |
| DPDP request records, audit and access logs | Retained | Accountability (DPDP Rules), CERT-In directions |
The patient record is marked restricted (processingRestricted with the request reference and the retention end
date); restricted records are hidden from staff who lack the restricted-records permission, and every access is
audited. The request becomes Fulfilled when the patient was anonymised, otherwise Partially fulfilled (explain the
retained data in the closure notes). Running the erasure again does nothing more.
Not yet automated (handle manually and note it on the request): patient feedback/review entries (stored by phone number) and marketing opt-ins.
Service levels (defaults, configurable)
| Step | Target |
|---|---|
| Acknowledge | within 2 days |
| Fulfil access/correction | within 15 days |
| Fulfil erasure (non-retained data) | within 30 days |
| Grievance resolution | within 30 days (subject to the timeline finally prescribed under the DPDP Rules) |
Due dates are calendar days from receipt (IST).
Medical-retention exceptions to erasure
Erasure does not remove records that the provider must keep by law, including clinical records under medical council/state rules, PCPNDT records, medico-legal case records, and tax invoices under GST law. Such records are restricted from further processing except for legal purposes and are erased when the retention period ends. See the retention policy.
Grievance officer
Each clinic publishes its own grievance officer in Privacy Requests → Settings (shown on the patient portal). Achal Technology's own grievance officer: TBD — to be appointed; contact details will be published in the privacy notice.