Chapter 33 — Healthcare, Education and Child-Facing Services Sector Playbook
1. Do not replace the patient with the guardian
Healthcare and education need careful identity and authority decisions, but not because every patient or learner lacks capacity. Adults commonly exercise their own rights. A child, an adult in a medical emergency and a person with a legally appointed guardian are different situations. Conflating them can deprive an adult of control while giving an unverified relative access to someone else’s records.
Under s2(j), the Data Principal is the individual to whom the data relates, including a parent/lawful guardian in the child case and a lawful guardian acting for the covered disability case. Section 9(1) expressly concerns a person with disability who has a lawful guardian. It is not a rule that every disabled patient must be represented (ACT:73–79,386–391).[1] The subject remains the person whose records are being processed. The proposed case service stores acting person, subject, authority and scope separately; it does not overwrite the child or patient’s identity with the representative’s account ID.
These cases assume the retained core commencement schedule remains unchanged: the relevant core duties and rights are scheduled for 13 May 2027, rather than already operating at the research date (COMM:19,49–59).[2] The Rules’ corresponding delayed tranche and corrected publication wording are read together (RULES:1005–1010; CORR:25–38).[3][4] Care, safeguarding and existing professional obligations do not wait for that date. This chapter addresses a bounded DPDP decision overlay, not the full clinical, education, medical-record or professional-consent regime.
The central tension remains useful: a service may want to learn from a patient’s or child’s behaviour to improve its offering, while protection requirements restrict that processing. Helpful intent is not a substitute for authority. Equally, an undifferentiated “no monitoring anywhere” policy misses conditional exceptions actually present in the Rules. The implementer’s task is to establish which branch applies and to keep the permitted activity inside it.
2. Three child requirements, followed by a separate exception check
Section 9 separates verifiable parental consent, likely detrimental effects on a child’s well-being, and tracking/behavioural-monitoring/targeted-advertising restrictions. Relief under s9(4)/(5) concerns (1)/(3), not the detrimental-effect bar in (2) (ACT:386–403).[1] Consent alone therefore cannot authorise an otherwise prohibited behavioural profile. A profile lasting only for a lesson is still processing; deleting it at logout does not establish that it was not monitoring.
Rule 10 provides identifiable-adult identity/age due-diligence routes and illustrations, including reliable details already held or voluntarily supplied details or authorised tokens. Rule 11 requires due diligence on lawful appointment for its covered guardian case. Neither prescribes indiscriminate collection of a child’s Aadhaar or a relative’s biometrics (RULES:1173–1267).[3] The proposed verification design uses the prescribed routes while avoiding unnecessary raw-document copies. An adult credential is one piece of evidence, not conclusive proof of disputed parentage or unrestricted representative authority.
For a guardian-initiated rights request, first resolve the relationship and scope. Then evaluate the particular right: ss11/12 concern prior-consent processing, including s7(a); nomination under s14 is not the same as present guardianship (ACT:441–495).[1] The proposed service can accept a request without prematurely returning records. Conflicting authority claims lead to restricted investigation and an explained status, not silent account reassignment. Immediate care and the minimum authorised clinical information flow must be assessed separately from a disputed broad record export.
3. Read the Fourth Schedule before granting relief
Rule 12 refers to Fourth Schedule Part A classes and Part B purposes, subject to their stated conditions. It is not a universal “health and education” exemption (RULES:1269–1275).[3] The following summaries are paraphrases; the retained text and its definitions control.
| Exception candidate | Actual boundary | Recommended owner/control |
|---|---|---|
| Part A1: clinical/mental-health establishment or healthcare professional | Health services to the child to the extent necessary to protect her health | Clinical/legal owner confirms class and necessary care scope; excludes advertising |
| Part A2: allied healthcare professional | Necessary support for that professional’s recommended treatment/referral plan | Record the plan and professional role; refuse unrelated engagement analytics |
| Part A3: educational institution | Tracking/behavioural monitoring for its educational activities or safety of enrolled children | Education owner confirms institutional status and purpose; no blanket commercial reuse |
| Part A4: individual entrusted with children in crèche/day care | Tracking/monitoring in the children’s safety interests | Safeguarding owner bounds audience and access |
| Part A5: engaged child transport fiduciary | Safety-related location tracking during travel to/from the institution/crèche/centre | Transport owner bounds route and journey, not continuous family surveillance |
These conditions and the schedule definitions are retained at RULES:1682–1765; the corrigendum fixes definition lettering and punctuation on the relevant page rather than expanding the exemptions (CORR:36–38).[3][4] An institution of learning imparting education, including vocational education, is the schedule’s educational definition. A commercial business is not excluded simply because it charges fees, but an “edtech” label alone does not establish that definition or the relevant activity conditions.
Part B separately covers its listed legal-function, State-benefit, email-account, real-time safety-location, harmful-content-prevention and age-confirmation purposes with necessity restrictions. For example, safety-location relief is not marketing-location relief, and age confirmation is not permission to retain verification data as an advertising feature (RULES:1719–1746).[3] A release workpaper must identify the exact part and row rather than say “r12 applies.” The relief does not itself establish every other lawful-processing condition or remove s9(2).
4. Educational monitoring allowed narrowly, commercial reuse refused
CASE-103 / ENT-103 is a hypothetical educational institution, separate from the Company’s lending business. SUB-004 is an enrolled child. The institution proposes lesson-progress monitoring for its educational activities, with no targeted advertising. DEC-003 conditionally accepts the Part A3 exception analysis under the stipulated class and purpose facts. It still requires a lawful underlying processing decision, suitable safeguards and no likely detrimental effect; an exemption from parental-consent requirements is not an unrestricted exemption from DPDP.
The operational recommendation is to store only the signals justified for the lesson or safety purpose, limit who can inspect them, define review and retention, and keep commercial analytics out of the same access path. The hypothetical institution chooses an appropriate recorded processing ground rather than treating the exception as a third ground alongside consent and s7. If it relies on consent, that consent must actually exist and meet its conditions; the exception’s role is to resolve the separate monitoring restriction.
Now change only the supplier’s purpose. A lesson provider wants the progress profile for its own cross-client product. That is not automatically the institution’s educational monitoring. The decision pack refuses the proposed independent reuse because neither its role/ground nor an applicable child exception has been established. A parent token and short-lived storage do not cure the missing analysis. If a standalone service actually meets the educational-institution definition, it can be assessed on those facts, but the author does not award every app that status.
The original adaptive-learning example claimed measured classification accuracy and a passing build-time SDK control without execution evidence. Those claims are withdrawn. The supplied local tests check stipulated exception predicates, including rejection when the class is unestablished, purpose is advertising or the well-being condition fails. They do not test an adaptive model, clinical safety, age estimation or a device’s network traffic. A real launch needs observed configuration, network and access evidence.
This distinction avoids two poor outcomes. One team should not disable necessary educational monitoring merely because it overlooked the schedule; another should not sell children’s learning signals because it found the word “education” there. Both decisions require the scope record that the old narrative lacked.
5. Emergency grounds are s7(f), s7(g) and s7(h)
The relevant clauses are separate and have different triggers. Section 7(f) concerns responding to a medical emergency involving a threat to life or an immediate threat to health of the principal or another individual. Section 7(g) concerns measures to provide treatment or health services during an epidemic, outbreak or other public-health threat. Section 7(h) concerns safety, assistance or services during disaster or public-order breakdown, with the statutory disaster definition reference (ACT:316–325).[1] There is no “s7(1)(e)” medical-emergency branch. Section 7(e) concerns qualifying judgments, decrees and orders (ACT:313–315).[1]
The text of s7(f) does not make unconsciousness an express prerequisite. Nor does s7(g) expressly require a formal declaration before its stated facts can apply. Those facts must nevertheless be established; an operational alert is not automatically the legal trigger. A software keyword match does not certify a medical emergency, and the book supplies no clinically validated symptom rule.
Routine telehealth onboarding has no blanket emergency exemption. It requires a separately established applicable ground, such as valid consent or a factually matched legitimate use. If the routine purpose changes, updating a database record is not obtaining a new affirmative consent. The clinical workflow may need immediate action, but its data handling should still identify the permitted emergency purpose, necessary categories, recipient and accountable actor.
An author-recommended emergency authorisation object replaces the former unrestricted emergency_mode=true bypass. It binds the subject, clause, factual assessment, data categories, recipients, authorised operations, start/review/end state and decision-maker. The trusted clinical/operational authority supplies the facts; the fixture’s Boolean inputs merely stand for those reviewed facts. A user-supplied flag must not confer emergency access in production.
6. Mid-consult handoff without an invented breach
CASE-102 / ENT-102 is a fictional clinical establishment. An adult patient begins a routine consultation under a recorded care authority. During the encounter, an appropriately responsible clinician identifies facts indicating an immediate health threat and requests a bounded emergency handoff. This is a stipulated scenario, not an instruction to diagnose symptoms or delay urgent care for a software workflow.
PUR-012 uses s7(f) for the necessary response. DEC-007 identifies the receiving emergency-care team, permitted clinical summary and relevant observations. It does not unlock the full video archive, marketing SDKs or every external analytics partner. The proposed system records the actual disclosure and the authority relied upon, maintaining a distinction between what was requested and what was transmitted.
The receiving clinician may determine independent care purposes and therefore require a separate fiduciary role assessment; a recipient outside the original network is not necessarily a processor. DPDP roles follow purpose/means and acting on behalf, not network membership (ACT:65–81).[1] The case records this relationship rather than assuming a consent hash transfers the original provider’s entire authority.
An authorised clinical disclosure is not automatically a personal-data breach. Section 2(u) requires the specified unauthorised processing or accidental events compromising confidentiality, integrity or availability; s8(6) is triggered by a personal-data breach, not geography or organisational separation alone (ACT:115–118,348–350).[1]
The corrected specimen therefore records breach=false under its reviewed authorised-disclosure facts and does not prepare a Board notice just because the recipient is external.
Change the facts: the package is sent to an unauthorised recipient and confidentiality is compromised. That branch is classified as a breach in the hypothetical fixture. When r7 is operative, initial Board and affected-person information is without delay after awareness, with the separate detailed-update rule; other applicable incident duties run on their own triggers (RULES:1112–1139).[3] The emergency ground does not immunise the misdelivery. Conversely, suspicion requiring investigation should be recorded honestly rather than replaced with an invented completed diagnosis or notification result.
7. End the emergency use, not necessarily every retained record
The prior universal “under thirty minutes” duration is removed. A real emergency may last longer, and a false alarm may end sooner. The author-recommended gate expires or is reviewed according to documented clinical/operational conditions. Renewed authority requires renewed facts and scope; it is not an immortal session bit.
When the emergency ends, the emergency-specific active-use authority ends. Continued care needs an existing authority that actually covers the activity or a newly established ground. A consent record cannot be silently edited to create an additional purpose. If the original routine-consult scope still covers an activity, record why; otherwise seek the appropriate fresh authority without representing a clerical update as consent (ACT:206–218,316–325).[1]
Retention is a different question. Section 8(7) carries a lawful-retention qualification; the post-commencement Rules include the separate r8(3) processing/data/log minimum and r6 security-purpose layer. The illustration must not require instant deletion of the emergency record merely because the immediate clinical trigger has ceased (ACT:351–359; RULES:1101–1106,1153–1166).[1][3] The recommended archive state limits access to established care, legal or security purposes and prevents renewed marketing or product training. Applicable professional and record-specific law still needs actual instrument mapping before a disposal date is approved.
The decision pack includes five distinct branches: a false-positive alert with no reviewed emergency facts; a valid emergency with a permitted recipient; a request exceeding the permitted data; an ended emergency with no continued-care authority; and a retained restricted record whose storage does not authorise active reuse. These are designed failure cases, not signs that the same decision can simply be retried until it passes.
For a child needing care, check the appropriate health exception rather than automatically requiring a retail-style signup. Part A1 may apply to the stipulated clinical establishment and necessary protective health services. It affects s9(1)/(3), not every other duty. The case still requires its care/emergency ground and well-being assessment. A hospital marketing offer built from that child’s diagnosis is outside the scoped health-service exception and is refused (RULES:1691–1694; ACT:386–403).[1][3]
8. Ecosystems do not settle legal roles
An ABDM connection, a school-board contract or a healthcare procurement standard can add relevant obligations. It does not by itself register a statutory DPDP Consent Manager or prove that the provider’s processing is lawful. Section 6(9) concerns Board registration of Consent Managers; it is not a generic badge for a health consent interface (ACT:258–268).[1] No ABDM or state education mandate is asserted in this chapter without a retained instrument. The overlay deliberately marks those entity/ecosystem requirements as unassessed, not approved or absent.
A real programme should identify the professional/service category, participating legal entities, geographic jurisdiction, applicable record classes and contractual ecosystem terms. Where a current authoritative instrument is needed for a particular proposed integration, the release remains blocked on that decision. That is different from leaving the available DPDP Rule 12 text unread. The latter gap is closed here; the former facts cannot be invented for an unspecified hospital or school.
Keep operational responsibilities distinct. Clinical staff establish and review care facts. Privacy/legal staff assess the authority and exception scope. Engineering implements bounded access and preserves evidence of actual execution. Security classifies possible incidents and runs the applicable notification tracks. A DPO cannot make an unvalidated symptom classifier clinically safe by signing the data map, and a clinician’s emergency judgment does not authorise unrelated advertising.
9. Workpaper and exercise
out/sector/Q06_DECISIONS.json contains the educational exception, its failed commercial-reuse branch and emergency/retention specimens. out/sector/README.md gives the local fixture command and evidence limits. The chapter does not deliver a clinical engine, an SDK audit or a complete health-sector compliance pack. Its contribution is a usable decision structure backed by the retained primary provisions, including corrected definitions and commencement.
For an exercise, hold the data and system constant while changing the actor and purpose: adult patient requesting routine care; child receiving necessary health services from a qualifying establishment; school monitoring enrolled pupils for safety; commercial supplier requesting the same profile for advertising. Identify the ground, exception if any, representative authority, recipient role, allowed operations and archive state. Then introduce an accidental external misdelivery. A defensible answer must change the breach classification only when the facts justify it, not whenever information crosses a network boundary.
The remaining work for a real entity is clinical validation, institutional-status evidence, applicable health/education instruments, record-specific retention and actual technical tests. No statutory percentage or successful deployment is supplied to conceal those prerequisites. Chapter 34 takes the same method to employment and global services, where the error is often assuming that an organisational relationship supplies unlimited authority.
Source locator key
Ranges above are physical newline lines, starting at 1; PDF form feeds do not add lines. Full source URLs follow. The retained text and hashes are indexed in out/remediation/Q06/source-index.json.
- ACT:
research/legal/evidence/01_dpdp_act_2023_gazette.txt. - COMM:
research/legal/evidence/02_gsr_843e_commencement.txt. - RULES:
research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt. - CORR:
research/legal/evidence/06_gsr_892e_corrigendum.txt.
Sources
[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — ACT [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — COMM [3] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — RULES [4] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — CORR
Contents · Reader guide and citation conventions · Artifact index