Free diagnostic · Pharma

How ready is your pharma company for DPDP Law Compliance?

Pharma companies handle personal data across clinical trials, pharmacovigilance, patient-support programmes, healthcare-professional engagement, digital platforms, employment and complex vendor networks. A weakness in any one of these areas can create organisation-wide privacy and operational risk.

Under the DPDP Act, failure to implement reasonable security safeguards can attract a monetary penalty of up to ₹250 crore, while failure to notify a personal data breach can attract up to ₹200 crore. This assessment helps identify the areas requiring immediate attention.

15 questions About 5 minutes Instant score
Assessment progress 0 of 15 answered
Data mapping
01 Have you mapped the digital personal data processed across clinical trials, pharmacovigilance, patient-support programmes, medical affairs, product enquiries, commercial activities, HR and digital platforms?
02 For each major processing activity, have you documented its purpose, the categories of people and personal data involved, and the applicable DPDP processing ground?
03 Have you identified which personal data can be deleted and which must be kept for pharmacovigilance, clinical trials or other legal requirements?
Consent
04 Do your privacy notices clearly explain what personal data is collected, why it is processed, how rights may be exercised and how the organisation may be contacted?
05 Where you rely on consent, can you show who consented, when, how, and for what purpose?
06 Can individuals withdraw consent as easily as they gave it, with the withdrawal communicated to every relevant internal system, CRO, vendor and other processor?
Individual rights
07 Do you have an operational process for receiving, verifying, tracking and responding to requests for access, correction, updating, erasure and grievance redressal?
08 Have you identified processing involving children or persons with lawful guardians and implemented the necessary age, guardian-consent and restricted-processing controls?
Third parties
09 Have you identified every processor and service provider handling personal data, including CROs, laboratories, technology platforms, cloud providers, recruitment partners and patient-support vendors?
10 Do your processor contracts contain appropriate instructions, confidentiality, security, breach-escalation, deletion, audit and cooperation obligations?
11 Do you know where personal data is stored, accessed and processed, including transfers to global affiliates, research partners, safety databases and service providers outside India?
Retention
12 Have you defined and implemented retention periods, legal holds and secure deletion rules for each major data category and system?
Security
13 Have you implemented risk-appropriate technical and organisational safeguards for health data, clinical data, safety reports, employee information and other personal data?
14 Do you have a tested process for detecting, escalating, investigating and responding to personal data breaches, including incidents originating with CROs and other processors?
Governance
15 Can the responsible clinical, pharmacovigilance, medical, commercial, HR, IT and legal teams produce current evidence of these controls if senior management or the Data Protection Board asks for it today?
Ready to see your result? Your answers are used only to calculate this assessment.

Need help with your DPDP compliance journey?

This is an indicative self-assessment based on the answers provided. It is not legal advice, certification or a determination of compliance.