DPDP 3.3.2 : DPDP and Blockchain – Case Study 2 – Meera’s Story

She withdrew consent. The blockchain remembered anyway.

Meera consented to her medical data being stored on a hospital’s blockchain network. Three years later, she withdrew that consent and asked for her records to be removed.

The hospital recorded her withdrawal correctly. However, her personal data had already been distributed across six network nodes. Those nodes — each holding a copy — were not instructed to delete anything.

Under Section 6(4) of the DPDP Act, 2023, withdrawal of consent must be as easy as giving it. Under Section 8(1), the Data Fiduciary must cease all processing upon withdrawal. Under Section 8(2), every entity processing personal data on the Data Fiduciary’s behalf — effectively, every node — must operate under a written contract limiting processing to the specified purpose.

Meera’s hospital had a consent withdrawal mechanism. However, they had no node governance framework. That gap is the compliance failure.

IS Audit 3.0 Study material of  ICAI (Module 6) flags precisely this risk: not all data on a distributed ledger should be accessible to others, and interoperability between chains creates additional exposure that is often overlooked in deployment planning.

Three things organisations deploying blockchain for sensitive personal data must do:

→ Map every node as a potential Data Processor. Execute written contracts under Section 8(2) before deployment.
→ Design consent withdrawal to trigger cascading deletion or encryption-key revocation across all nodes simultaneously.
→ Never write raw personal data to the chain. Use pseudonymous identifiers on-chain, with personal data in a governed, erasable off-chain repository.

Meera’s hospital is rebuilding its architecture. Consequently, the cost is now far higher than it would have been at design stage.

The DPDP Act compliance deadline is 13 May 2027. Node governance is not optional.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.3.2 : DPDP and Blockchain – Case Study 2 – Meera’s Story

Leave a Reply