मुख्य कंटेंट तक स्किप करें

Data-principal rights process

DRAFT — requires legal review

This document is a working draft prepared by the engineering team to describe how the platform is designed to support compliance. It is not legal advice and has not yet been reviewed by counsel. Do not rely on it as a final policy until this banner is removed.

Rights supported​

Right (DPDP Act 2023)What it means here
Access (s.11)Summary of personal data processed, processing activities, and with whom it was shared
Correction, completion, updating (s.12)Fix demographics or contact details; clinical corrections are made by the practitioner as an amendment (the original is kept, as medical law requires)
Erasure (s.12)Delete data no longer needed — subject to medical-record, tax and legal retention (see below)
Nomination (s.14)Nominate a person to exercise rights on death or incapacity (log as a GRIEVANCE-type request with a note until a dedicated type ships)
Grievance redressal (s.13)Complaint to the provider / our grievance officer, then to the Data Protection Board

Who handles the request​

  • Patients → the healthcare provider (Data Fiduciary). The clinic owner handles requests in Admin → Privacy Requests (/app/privacy-requests, permission privacy.request.manage, owner only); Achal Technology assists as processor.
  • Clinic owners/staff (our customers) → Achal Technology grievance officer.

Set up (owner, once)​

  1. Open Admin → Privacy Requests → Settings.
  2. Enter the grievance officer name, e-mail, phone and address — patients see this on their portal page.
  3. Review the response times (defaults below) and save.

How a patient raises a request​

  1. In the patient portal open My Privacy (/patient/privacy).
  2. Read Your rights, choose the request type (Access, Correction, Erasure, Grievance), describe it (up to 2,000 characters) and submit. Up to 5 requests per day.
  3. The request appears under My requests with its reference (DPR-yyyymmdd-XXXXXX), status and due date.

Requests received by e-mail, phone, WhatsApp or in person are logged by the owner with Log a request.

Workflow in the staff queue​

Statuses: Received → Acknowledged → In progress → Fulfilled / Partially fulfilled / Rejected → Closed.

  1. Acknowledge within the acknowledgement target (the queue flags Acknowledgement overdue).
  2. Verify identity before disclosing or changing anything: OTP to the registered phone/e-mail (portal requests are already OTP-verified), guardian verification for minors, nominee proof when applicable. Select Verify identity and note how it was verified.
  3. Start the work and fulfil:
    • Access → Download access package: a JSON file with the patient's demographics and every linked record (appointments, encounters, vitals, diagnoses, allergies, prescriptions, clinical documents, bills, payments, packages…). Share it through a secure channel. The download is recorded in the access log.
    • Correction → edit the patient's demographics in the patient record (audited); clinical content is corrected by the practitioner as an amendment/addendum. Then select Fulfil.
    • Erasure → Preview erasure plan (nothing changes yet), review it, then Execute erasure and type the request reference to confirm.
    • Grievance → investigate, record notes, Fulfil or Reject with reasons.
  4. Close with closure notes (required) describing the outcome and any reasons for partial refusal. The request record is kept (without unnecessary health data) for audit.

Every action is timestamped with the user and written to the audit log. Overdue requests are flagged in red.

Erasure rules (what "Execute erasure" does)​

DataActionWhy / until
Encounters, vitals, diagnoses, allergies, prescriptions, clinical documents, legacy reports, care plans, treatment packages & usage, queue tokensRestricted — kept, no further processing except legal purposesClinical-record retention: at least 3 years after the last record; for minors until age 21 + 3 years if later
Bills, payments, credit notesRetained (never deleted)CGST Act s.36 — until 6 years after the end of the financial year of the last record
NotificationsDeletedPurpose ended
Appointments not completed and not linked to an encounter or billDeletedNot a clinical record
Other appointmentsRetained with the clinical/tax recordsAttached to retained records
Patient-portal password and sessionsDeleted (all sessions signed out)Not needed
Patient recordAnonymised ("Erased patient", contact / DOB / address / guardian cleared; UHID kept) only when nothing above is retained; otherwise restrictedRetained records must stay attributable
DPDP request records, audit and access logsRetainedAccountability (DPDP Rules), CERT-In directions

The patient record is marked restricted (processingRestricted with the request reference and the retention end date); restricted records are hidden from staff who lack the restricted-records permission, and every access is audited. The request becomes Fulfilled when the patient was anonymised, otherwise Partially fulfilled (explain the retained data in the closure notes). Running the erasure again does nothing more.

Not yet automated (handle manually and note it on the request): patient feedback/review entries (stored by phone number) and marketing opt-ins.

Service levels (defaults, configurable)​

StepTarget
Acknowledgewithin 2 days
Fulfil access/correctionwithin 15 days
Fulfil erasure (non-retained data)within 30 days
Grievance resolutionwithin 30 days (subject to the timeline finally prescribed under the DPDP Rules)

Due dates are calendar days from receipt (IST).

Medical-retention exceptions to erasure​

Erasure does not remove records that the provider must keep by law, including clinical records under medical council/state rules, PCPNDT records, medico-legal case records, and tax invoices under GST law. Such records are restricted from further processing except for legal purposes and are erased when the retention period ends. See the retention policy.

Grievance officer​

Each clinic publishes its own grievance officer in Privacy Requests → Settings (shown on the patient portal). Achal Technology's own grievance officer: TBD — to be appointed; contact details will be published in the privacy notice.