The Hospital Corridor Display Board: A Quiet DPDP Compliance Gap in Indian Healthcare
Authored by Ammu Brigit
A patient is admitted to a hospital. On the corridor outside the ward, a digital display board scrolls through the day’s occupancy list: full name, home address and room number, visible to every visitor, delivery staff member, and passer-by. It is a common sight in Indian hospitals, designed to help families find a relative and to help staff manage a floor. It is also, on closer examination, a useful case study in how the Digital Personal Data Protection Act, 2023 (DPDP Act) apply to everyday operational practices that were never designed with a data protection statute in mind.
This article uses the display-board scenario to unpack a broader compliance question that healthcare providers, hospital administrators will increasingly have to confront.
Does the DPDP Act even apply to a physical display board?
The DPDP Act applies to “digital personal data,” which Section 3 defines to include personal data collected in digital form, and personal data collected in non-digital form that is subsequently digitised. A display board, at first glance, looks like a purely physical arguably outside the Act’s scope.
In practice, however, most hospitals don’t operate this way. Almost every hospital of reasonable scale runs its admissions, bed allocation and ward management through a Hospital Management Information System (HMIS). At admission, the patient’s name, address and room number are entered into the system once. The corridor display then simply pulls this same data from the database in real time. The processing that matters for DPDP purposes is not the board itself but the act of retrieving digital personal data from the HMIS and pushing it to a public-facing output. That is squarely “processing” of “digital personal data” as defined under the Act, performed by the hospital in its capacity as Data Fiduciary.
The narrow exception would be a hospital that still runs an entirely paper-based, non-digitised admissions register and manually chalks names onto a physical board, a practice that is now rare.
Running The Display Through The DPDP Compliance Checklist
Notice and consent: Section 5 requires a Data Fiduciary to give the Data Principal a notice, in clear and plain language, describing the personal data being processed and the purpose of that processing, either at or before the point consent is sought. Section 6 requires that consent be free, specific, informed, unconditional and unambiguous, limited to what is necessary for the stated purpose. Admission paperwork in most hospitals seeks consent for treatment, billing, insurance processing and, occasionally, research or teaching use. It rarely, if ever, discloses that the patient’s name and home address will be displayed on a screen visible to the general public within the hospital premises. Consent obtained for treatment purposes cannot be stretched to cover a separate, undisclosed purpose like public display.
Purpose limitation and data minimisation: Even accepting that a hospital has a legitimate operational need to help visitors and staff locate a patient, the scope of that need is narrow: a name and a room number would ordinarily suffice. The home address adds nothing to the stated operational purpose and is the single hardest element to justify on this fact pattern. Publicly displaying a patient’s residential address alongside their identity and the fact of hospitalisation creates a foreseeable secondary risk from unwanted solicitation to more serious concerns This is precisely the kind of over-collection and over-display that the data-minimisation, which is one of the underlying principle of DPDP is designed to prevent.
The “legitimate uses” exemption: Section 7 carves out specific situations where personal data may be processed without consent i.e., medical emergencies, threats to public health, employment purposes, and a handful of others. A routine, standing wayfinding display for all admitted patients does not fit comfortably within any of these categories. It is not an emergency measure and is not confined to public-health necessity. It is a continuous administrative convenience. Hospitals relying on Section 7 as an implicit justification for this practice are on weak ground and should not treat the exemption as a general-purpose fallback.
Reasonable security safeguards: Section 8(5) obliges a Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches, which the Act defines broadly to include unauthorised disclosure or access. A display visible to anyone physically present in a public corridor including other patients’ visitors, vendors, delivery personnel and members of the public with no legitimate need to know is difficult to reconcile with a “reasonable safeguards” standard. The safeguard obligation is not limited to cyber-hygiene; it extends to how and to whom data is exposed by design.
Why this matters now: the DPDP Rules are no longer theoretical
For hospitals and healthcare institutions, this is the moment to move data-protection compliance from a legal-department slide deck into operational reality and physical, visible practices like corridor displays are exactly the kind of “low-tech” gap that internal audits tend to miss because attention defaults to firewalls, databases and vendor contracts.
None of the above analysis requires hospitals to abandon patient-location displays altogether as the operational need behind the display board is real. What it requires is a re-calibration of what is displayed, on what legal basis, and with what safeguards. Simple, visible things like corridor displays are easy to miss, because compliance reviews usually focus on firewalls, databases and vendor contracts. Keeping this in mind, the following steps are a practical starting point for bringing existing practice in line with the DPDP Act and Rules:
-
Display only what is operationally necessary i.e, an unique number, token number, or first name and last initial, together with the room or bed number.
-
Re-draft admission consent forms to separately and specifically address any public display of patient identifiers, rather than folding it into a general treatment-and-billing consent clause.
-
Where a full-name display is operationally important for identification purposes, obtain explicit, purpose-specific consent at admission and offer an opt-out.
-
Align internal privacy practices with DPDP compliance
-
Extend the same review to adjacent practices that share the same underlying issue such as visitor logs, pharmacy counters that call out patient names and diagnoses, and shared discharge summaries left at nursing stations.