More people touch prescription data than you think — and that's a problem.
A customer buys blood pressure medicine at your pharmacy. You think only you and the pharmacist know. But the cashier saw the name. The delivery boy saw the address. The app company stored the prescription photo. The call centre checked the order. That is six people — before the medicine even reaches the customer. Under the new data law, every one of those hands needs a good reason.
Say a customer orders diabetes medicine on your app. Their name, phone number, address, and prescription photo travel through your billing software, your delivery partner, and maybe a call centre. Each of these is a separate hand. If any one of them misuses the data, the law holds your pharmacy responsible. Even a WhatsApp message to your delivery boy with a customer's address counts. You must know who has access — and why.
List every person and vendor who can see customer prescription details.
Tell delivery staff and cashiers not to share customer health data on WhatsApp.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Every extra hand in the order chain needs a clear reason.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.