DPDP readiness
India's Digital Personal Data Protection Act 2023 places obligations on your center as the data fiduciary — particularly where children's data is concerned. Software cannot discharge those obligations for you. What it can do is give you the records and controls to meet them. This page separates what Lumidor does today from what we are still building.
What Lumidor does today
These are working features you can use from your first week.
- Consent records. Capture parental consent per child and per purpose — therapy services, media, data export, analytics — each recorded against the version of the privacy notice in force at the time, with the date it was given. Consent can be withdrawn or its scope changed, and the change is recorded rather than overwritten.
- A consent history. Every grant, change and withdrawal is written to a separate trail, so you can show not just the current state but how it got there.
- Access, correction and erasure requests. Log a request from a parent, track it against a due date, see what is outstanding, and record who approved it.
- Carrying out an erasure. An administrator can execute an approved erasure request. The child's record is withdrawn from use and the action is written to the audit trail. Clinical records are retained rather than destroyed outright, so your center can apply its own retention policy — that judgement stays with you.
- An audit trail. Actions on records are logged with who did them, at which center, and when.
- Separation between centers, and roles within one. Described on our security page.
Our approach
The following describes how we intend to build, not features you can use today. We would rather tell you that plainly than let a roadmap read like a product.
- Verifiable parental consent. Lumidor records that consent was given and by whom. The Act's standard for verifying that a person is genuinely the child's parent or guardian is a higher bar, and we have not built to it yet. Today, verifying identity remains your center's process; we are working on tooling to support it.
- Grievance handling. The Act expects a route for data principals to raise grievances. We intend to provide this inside Lumidor so complaints are logged and tracked like any other request. It is not available yet.
- Data minimisation by default. We aim to collect only what a therapy center actually needs, and to keep adding controls that let you hold less rather than more.
- Breach notification. If we become aware of a personal data breach affecting your center, we will tell you promptly and with enough detail for you to meet your own notification duties.
Where your data lives
Your data is encrypted in transit and at rest on secure cloud infrastructure. If your center needs a specific answer about hosting location for its own assessment, ask us and we will tell you exactly where your center's data sits.
What stays with your center
You decide what data you collect and why, who on your staff can see it, how long you keep it, and how you verify that the person giving consent is the child's parent or guardian. You are the data fiduciary. Lumidor is the processor acting on your instructions.
Ask us the hard questions
If you are assessing Lumidor for a center that handles children's health data, we are happy to go through any of this in detail. Chat with us on WhatsApp or email hello@lumidor.app.
Lumidor provides tools that support DPDP Act compliance. Compliance obligations rest with each center as data fiduciary. This page is not legal advice.