We are linked to ABDM. How does its consent fit with DPDP?
Short answer: Both apply; align the wording
ABDM uses a consent manager and consent artefacts to share health records between providers. That consent covers ABDM sharing. You still need your own DPDP notice for what you collect, and your own safeguards, retention and grievance process. The two should use the same plain language so patients are not confused.
What the law says
Section 5 and 6 for your own notice and consent; ABDM's policy for ABDM sharing.
Section 5 · Rule 3: When you ask for consent, give a clear notice that stands on its own: what data, for what purpose, how to withdraw consent, how to use the rights and how to complain to the Data Protection Board. For data collected before the Act, a notice is due as soon as reasonably practicable.
Section 6: Consent must be free, specific, informed, unconditional and unambiguous, given by a clear action, limited to the data needed for the purpose, and as easy to withdraw as it was to give.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Steps
Map what goes through ABDM and what does not.
Align notices with ABDM screens.
Log ABDM consent requests.
Keep safeguards on the gateway.
Train front desk on ABHA linking.
Evidence to keep
Flow map
Aligned notices
Gateway logs
Common mistakes
Assuming ABDM consent covers everything
ABHA linking without explanation
Gateway with weak access
From each seat
DPO / Privacy lead: Align the wording.
CIO / IT head: Map the ABDM interfaces.
Operations head: Front desk explains ABHA linking.
What a good answer from management sounds like
“ABDM flows are mapped, notices agree, and the gateway is secured.” Effort and time: Light to medium.