Legal · Compliance

Digital Personal Data Protection (DPDP) Rules, 2025

This page explains how Vinmayaa Care India Pvt. Ltd. ("Vinmayaa Care", "we", "us", or "our") aligns its data practices with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025.

Effective date: 1 July 2026 Last updated: 29 July 2026
DPDP Act, 2023 DPDP Rules, 2025 Data Protection Board of India
01

About the DPDP Rules, 2025

The Digital Personal Data Protection Rules, 2025 operationalise the Digital Personal Data Protection Act, 2023 — India's first comprehensive law governing digital personal data. Together, the Act and Rules set out a consent-driven, rights-based framework covering how organisations may collect, process, store, and protect personal data, along with obligations around notice, breach reporting, cross-border transfer, and the rights of individuals (referred to as "Data Principals").

The Rules are being rolled out in a phased manner over an 18-month implementation window, and are overseen by the newly constituted Data Protection Board of India.

This page is a plain-language summary of how these rules shape our data practices. It supplements, and should be read alongside, our Privacy Policy.

02

Our role as a Data Fiduciary

Under the DPDP Rules, Vinmayaa Care acts as a Data Fiduciary — the entity that determines the purpose and means of processing personal data. As a provider of home and facility-based eldercare, we process personal and health-related data belonging to our clients, in order to deliver safe, coordinated care.

Where we engage external partners — such as payment processors or diagnostic labs — to process data on our behalf, those partners act as Data Processors under our instructions, and are bound by written confidentiality and data protection obligations.

03

Consent and notice

In line with the Rules, before we collect or process personal data, we provide clients and their families with a clear, itemised notice covering:

  • What personal data is being collected, in plain and specific terms.
  • The specific purpose for which it is being collected (for example, preparing a care plan or processing payment).
  • How to withdraw consent, and how to raise a grievance, with a direct communication link or contact.

Consent is collected separately for each distinct purpose, and is never bundled into a single blanket approval. Clients may withdraw consent for non-essential processing (such as promotional communication) at any time, as easily as it was given.

04

Data retention and erasure

We retain personal and health data only for as long as it is needed for the purpose it was collected, or as required under applicable medical record-keeping and legal obligations. Once the purpose is fulfilled and no legal retention requirement applies, we take steps to erase or anonymise the data within the timelines prescribed under the Rules.

Where a client's account has been inactive for an extended period, we will notify the client or their nominated representative before data is scheduled for erasure, wherever this is required under the Rules.

05

Data breach notification

In the event of a personal data breach, the Rules require Data Fiduciaries to notify both the affected Data Principals and the Data Protection Board of India, describing the nature of the breach, likely consequences, and mitigation steps taken.

StepWhat we do
DetectionInvestigate the scope and cause of the incident immediately upon discovery.
ContainmentTake prompt technical and organisational steps to limit further exposure.
NotificationInform affected clients or families, and the Data Protection Board, within the prescribed timelines.
ReviewConduct an internal review to prevent recurrence.
06

Cross-border data transfer

The DPDP Rules permit the transfer of personal data outside India, subject to conditions that may be prescribed by the Central Government from time to time. Certain categories of sensitive data may additionally be required to be stored within India, as and when notified.

Vinmayaa Care primarily stores and processes client data within India. Where any service provider processes data outside India (for example, a cloud storage partner), we ensure appropriate contractual safeguards are in place.

07

Your rights as a Data Principal

As a Data Principal under the DPDP Rules, you (or your authorised representative) have the following rights in relation to your personal data:

Right to access

Obtain a summary of the personal data we hold about you and how it is being processed.

Right to correction

Request correction of inaccurate or incomplete personal data in your records.

Right to erasure

Request deletion of personal data that is no longer necessary for the purpose it was collected.

Right to withdraw consent

Withdraw consent for any processing that is not essential to delivering your care.

Right to grievance redressal

Raise a complaint with our Data Protection Officer, and escalate to the Data Protection Board if unresolved.

Right to nominate

Nominate another individual to exercise these rights on your behalf, including in the event of incapacity.

We aim to respond to all such requests within the timelines prescribed under the Rules.

08

Children and persons with disabilities

Where a client requires a guardian or lawful representative — including persons with disabilities under a lawful guardianship arrangement — the Rules require verifiable consent from that guardian before processing the individual's personal data. Vinmayaa Care follows this requirement for any client who is unable to provide consent directly, obtaining consent from the nominated next of kin or legal guardian.

09

Grievance redressal and the Data Protection Board

If you have a concern about how your personal data has been handled, you may first raise it with our Data Protection Officer using the contact details in Section 10. We aim to acknowledge and resolve grievances promptly and in good faith.

If a grievance remains unresolved, you may escalate it to the Data Protection Board of India, the independent body established under the DPDP Act to adjudicate data protection complaints, through its online complaints portal.

10

Contact our Data Protection Officer

For any questions about this page, or to exercise your rights as a Data Principal, please reach out:

Vinmayaa Care
Email: info@vinmayaacare.com
Phone: +919611519681 +919535657002
Registered office

This page is intended as a general, plain-language summary and does not constitute legal advice. For the full text of the DPDP Act, 2023 and DPDP Rules, 2025, please refer to the official notifications published by the Ministry of Electronics and Information Technology.

Sujatha Home Care Services
LOADING