
As organizations increasingly depend on digital interactions, personal data has become a critical business asset. To protect individuals’ privacy rights and create accountability for how organizations use personal data, the DPDP Act, 2023 was enacted.
What is DPDP Act 2023 and DPDP Rules 2025 for the Pharma Industry
The Digital Personal Data Protection (DPDP) Act, 2023, is India’s primary privacy law governing
the processing of digital personal information. It applies to organizations processing digital
personal information in India, as well as organizations outside India that process such
information in connection with offering goods or services to individuals in India. However, the
DPDP Rules, 2025, provide the operational framework for implementing the Act by prescribing
requirements around consent and governance.
The pharma industry is significantly impacted by the Act as it processes large volumes of
personal data related to healthcare professionals (HCPs), patients, employees, stakeholders,
etc. The one area that deserves particular attention is Healthcare Professional consent.
What Changes with DPDP Rules: Stronger Accountability and Governance
Earlier, pharma companies focused on collecting and utilizing physicians’ details for business
purposes with limited or no transparency on the consent mechanism. The collection of consent
usually happens at a specific interaction point, such as a webinar, a conference, or a website,
etc. These records were often stored across multiple systems with no visibility into data usage.
With the DPDP Act, 2023 and the DPDP Rules, 2025 establishing the framework for consent,
transparency and data governance, pharma entities must have a lawful purpose for collecting
and processing these key details. Permission authorization should be managed throughout its
lifecycle and not as a one-time phenomenon.
Individuals, or HCPs in this context, gain rights to access, correction, and consent withdrawal.
Organizations must provide clear privacy notices and obtain valid approval where required,
utilizing the Consent Manager framework.
Registered Consent Manager and Enterprise Consent Management
The Act provides for a registered Consent Manager, that allows
HCPs to give, manage, review, and withdraw consent through an interoperable platform. This
helps ensure that pharma entities process personal data in accordance with the HCP’s valid
consent, where consent is the basis for processing.
Even when a registered Consent Manager is involved in helping HCPs manage consent across
multiple organizations, pharma companies must maintain their own internal consent-
management capabilities to receive consent signals, maintain auditable records, update CRMs
and engagement platforms, and stop processing upon consent cancellation, ensuring
compliance across the entire doctor's data lifecycle.
The bottleneck for life-science entities is building enterprise consent-management capabilities,
which refer to the internal processes, technology, governance, and controls required to manage
the consent cycle across structures.
Pharma companies will continue to act as Data Fiduciaries under the Act and should be
prepared to demonstrate valid consent, receive consent updates, receive withdrawal requests,
and reflect these changes across internal networks.
HCP Consent Lifecycle: Capture to Withdrawal
Consent Capture
Consent is captured by informing and sharing a clear privacy notice with HCPs that explains
what data is being collected, why it is collected, how it will be used, and how consent can be
withdrawn.
Consent Record
Companies should maintain evidence of who provided consent, the date and time, the channel
through which it was obtained, the privacy notice presented, and the purpose for which consent
was obtained. Relevant channels may include HCP registration, e-detailing, webinars,
conferences and events, email campaigns, digital engagement, and websites or portals. This
creates an auditable consent record.
Consent Management
The requested consent should not sit across multiple systems. Instead, companies should
maintain a central view through which doctors' permissions can be consumed by CRMs, event
platforms, marketing platforms, etc. This will create a consistent experience across all
communications.
Consent Review
Organizations should periodically review consent records and preferences to ensure that
outdated or inconsistent permissions do not continue to drive HCP communications.
Consent Withdrawal
The DPDP requirement gives individuals the choice to withdraw consent. The discontinuation
process should be easy and accessible, just like the onboarding consent process.
The critical part for organizations is to act on the withdrawal across all systems, and non-
adherence may attract compliance risk.
HCP Consent Management Ecosystem and Integration with CRM
Medical companies should build a central consent repository, serving as a single source of truth
for consent records, while allowing doctors to manage communication preferences. They should
also synchronize vendor and agency communications throughout the consent lifecycle. The
system should be able to justify and maintain audit trails as well.
A CRM plays a central role in ensuring that HCP consent is not only captured but also managed
and enforced consistently across all engagement channels.
How Keacyte CRM Can Support Consent Governance
Consent management can be embedded directly into HCP engagement workflows with
Keacyte.
HCP Profile-Level Consent Visibility: Reps can view current consent status, communication
preferences, history, and cancellation records from a single doctor profile.
Single source of truth: It can act as a centralized consent repository for HCP consent details
and maintain a complete audit trail for regulatory adherence.
Omnichannel integration: Consent preferences can be incorporated into email campaigns,
event management platforms, and other digital channels, ensuring communications are aligned
with doctors’ preferences.
Automated consent enforcement: When consent is removed, automated workflows help
companies execute DPDP requirements across business processes.
Consent Reporting and Audit Visibility: Consent dashboards can provide commercial
compliance and legal teams with visibility into consent status, changes withdrawal activity and
audit records.
Conclusion
Where consent is the basis for processing HCP personal data, pharma companies need
mechanisms to capture, manage, and act on that consent throughout its lifecycle. The HCP
consent lifecycle spans notice, capture, recording, management, enforcement, review, and
withdrawal, with consent potentially being managed through an interoperable Consent Manager.
A key challenge for organizations is building enterprise consent-management systems;
however, with the integration of a CRM like Keacyte, companies can create automated
workflows that embed consent-management visibility across all channels while aligning with
compliance requirements.
Sources:
● DPDP Act, 2023 – Ministry of Electronics and Information Technology
● DPDP Rules, 2025 – Ministry of Electronics and Information Technology