DPDP Act Compliance & Data Anonymization

Last updated: 20 May 2026

1. Scope

Vedamrita Healthcare Private Limited processes personal data within the framework of India's Digital Personal Data Protection Act, 2023 (DPDP). This page summarises our anonymisation protocol, role-mapping and grievance redressal mechanism for this research portal and the Swasthyarath HMS production environment.

2. Role Mapping

  • Data Fiduciary: Vedamrita Healthcare Private Limited — determines purpose and means of processing.
  • Data Processor: Cloud infrastructure partners under documented Data Processing Agreements (DPA).
  • Data Principal: Patients (via partner hospitals), clinicians and career applicants.
  • Data Protection Officer (DPO): Reachable at research@vedamrita.com.

3. Anonymisation Pipeline

Patient data flowing into the Vedamrita research stack passes through a three-stage pipeline:

  1. De-identification at source: the Swasthyarath HMS strips 18 direct identifiers (name, ABHA-ID, phone, address, biometric template, MRN, etc.) before any data leaves the OPD database.
  2. K-anonymity transform (k≥5): quasi-identifiers (age, pin-code, dosha-profile) are generalised so that every tuple is indistinguishable from at least four others in the research extract.
  3. Differential-privacy noise injection on aggregated outputs before they leave the secure analytics enclave, with epsilon budget reviewed quarterly.

4. Consent Architecture

The Swasthyarath HMS issues granular consent receipts (purpose, data category, retention window) at OPD intake. Consent can be withdrawn at any time via the HMS or by email to the DPO; downstream pipelines reconcile withdrawal within 7 days.

5. Data Localisation

All identifiable data is stored on infrastructure located within India. Cross-border transfers, if any, are limited to countries notified by the Central Government under Section 16 of the DPDP Act.

6. Breach Notification

In the event of a personal-data breach, the DPO will notify the Data Protection Board of India and affected Data Principals within 72 hours, in line with the timeline anticipated under the DPDP Rules.

7. Rights of the Data Principal

  • Access & portability of personal data.
  • Correction, erasure or restriction of processing.
  • Withdrawal of consent without penalty.
  • Grievance redressal — first via the DPO; escalation to the Data Protection Board of India.

8. Audit & Accountability

We maintain a Record of Processing Activities (ROPA), conduct annual third-party security audits (ISO 27001) and run twice-yearly DPDP-compliance reviews led by external counsel.

9. Reach the DPO

Data Protection Officer · Vedamrita Healthcare Private Limited
Hisar - Tohana Rd, near MRF Agency, Barwala, Haryana 125121
research@vedamrita.com