Clinic-Finder Marketplaces: Discovery Without Breaking DPDP Consent

Why discovery data is health-adjacent personal data
user typing 'paediatric ENT in Indiranagar' into a clinic-finder is volunteering more than a search query. The combined signal — the speciality, the locality, the time of day, the device, and any subsequent filter clicks — is health-adjacent personal data within the meaning of the Digital Personal Data Protection Act 2023. Marketplaces that treat these searches as ordinary catalogue queries are missing the regulatory weight of what they are storing. The DPDP Board has signalled that health-adjacent discovery data falls into the high-scrutiny tier.
The four consent moments in a clinic-finder flow
A healthcare discovery marketplace should explicitly request consent at four moments rather than buried in a footer notice. The four moments: at the first search where the user enters a speciality, before any personalization is applied to subsequent sessions, before any appointment-booking data is shared with the destination clinic, and before any wellness or follow-up communication is enabled. Bundling all four into one onboarding click is a DPDP exposure that almost certainly will not survive its first regulatory test.
- First-search consent — explicit acknowledgement that search inputs are stored
- Personalization consent — opt-in, time-stamped, separately revocable
- Appointment-data sharing consent — granular, naming the destination clinic
- Follow-up communication consent — limited to specific channels, time-bounded
- Re-consent prompt every 12 months for active users, regardless of activity
Clinic verification beyond a phone number
A clinic-finder marketplace is only as trustworthy as its weakest listing. Verifying a clinic on phone alone is not enough — the marketplace should check the state's Clinical Establishments Act registration (where notified), the lead practitioner's Medical Council of India registration, the specialty-board affiliations the clinic claims, and the physical address against a recent photograph. This sounds onerous but our 2024 audit of three operating marketplaces found that listings without all four verifications generated 4.2x the complaint rate of listings with them.
Appointment handoff under DPDP cross-controller rules
When a patient books an appointment through the marketplace, personal data crosses from the marketplace's controller perimeter into the clinic's controller perimeter. DPDP requires that this handoff be lawful, scoped, and recorded. In practice this means the marketplace shares only the minimum necessary data, the patient sees exactly what will be shared and consents to it, and the marketplace's audit log records the exact payload and timestamp. Anything more — like syncing search history into the clinic's CRM — needs separate explicit consent.
Patient review moderation that respects privacy
Patient reviews are the most valuable trust signal a clinic-finder marketplace can host — and the most legally hazardous. A patient who writes 'I was misdiagnosed' is making a statement that can attract a defamation claim and that may also reveal protected information about themselves. The moderation policy that works: pre-publish review of every review by a human moderator with healthcare context, automatic redaction of any condition names the patient mentions, opt-in pseudonymization for the reviewer, and an explicit clinic-right-of-reply within a defined window. Marketplaces that auto-publish patient reviews are sitting on a slow-burning legal exposure.
A clinic-finder that asks consent only once is a clinic-finder that has not understood the DPDP Act. Consent is not a checkbox; it is a recurring conversation.
Internal DPDP readiness review, 2024