Cross-Border Health-Data Contracts Between India and Singapore: Allocating Risk in a Two-Regime World
Introduction : India and Singapore are two opposite sides of the health data coin: India’s hospitals, labs, and innovators create health data, while its Singapore counterparts host, reinsure, and analyze it. A clinical trial data-management agreement, a hospital-cloud contract, a telemedicine deal, or an insurance-analytic pact, may well contain obligations of India’s Digital Personal Data Protection Act, 2023 (DPDPA) and/or Singapore’s Personal Data Protection Act 2012 (PDPA) : this article focuses on the allocation of consent, security, breach-notification, and retention obligations, discusses the four deal types applicable to both data jurisdictions, and extracts lessons for the contracting parties.
Legal Provisions
India’s DPDPA 2023, and DPDP Rules 2025 - Health data is sensitive personal data, as per repealed SPD Rules and is subject to the DPDPB’s “reasonable security safeguards” (Section 8(5) DPDPA), to be applied “having regard to the risk to the data principal” (Section 8(6) 2020, DPDPA Rules 2025). A data fiduciary or processor must notify the DPDPB “without delay” and provide it with a detailed report on a personal data breach, within 72 hours (Section 8(6) & Rule 7, 2025 DPDP Rules). Further, Section 16 DPDPA, 2023 allows data processing in any territory not specified by the central government as restricted for processing, subject to protection mandated by Rule 15, 2025 DPDP Rules and “more stringent laws” for the sector, while Rule 8(7) obligates erasure of processed data if “the purpose for which the data was processed ceases to exist,” subject to other laws prescribing retention (typically, clinical-establishment and medical-record retention norms).
Singapore’s PDPA 2012
Health data is not explicitly categorized as sensitive information under Singapore’s Personal Data Protection Act (PDPA) 2012. However, the Personal Data Protection Commission (PDPC) requires applying stricter processing limitations to such data. In particular, the collection of health information should be limited to predefined purposes, and its processing should involve enhanced levels of confidentiality and retention control. According to the advisory guidelines issued jointly by the Ministry of Health and the PDPC in September 2023, healthcare sector data controllers must adhere to additional requirements and guidelines, including Cyber and Data Security Guidelines for Healthcare Providers. Under the PDPA, the notification of the PDPC about a personal data breach is mandatory in case of significant harm to the data subject or more than 500 affected persons, and individual notification is required only in the first case, which is less privacy protected compared to India’s data protection law.
Sector-specific laws
India’s Telemedicine Practice Guidelines 2020 stipulate that teleconsultation may be provided only by registered medical practitioners and prohibit cross-border teleconsultation; the Ayushman Bharat Digital Mission stipulates the consent-manager architecture for India’s domestic health-record exchange. By contrast, Singapore’s Healthcare Services Act 2020 (HCSA), which came into force in June 2023, designates teleconsultation as licensable healthcare service under the HCSA: doctors providing healthcare services need to have a license from the Ministry of Health (MOH) and the Singapore Medical Council; overseas doctors are not licensed by the HCSA. The Singapore Standard SS 584 Multi-tier Cloud Security standard to which many Singapore-linked contracts make reference stipulates the security requirements for cloud hosting.
Allocation of Responsibility: Legal Analysis across the Four Deal Types
Research collaborations: An Indian hospital or biobank sharing clinical/genomic data with a Singaporean research organization must decide which entity is the data fiduciary under India’s DPDPA, as responsibility for compliance rests with the fiduciary, even when a foreign processor is used; while Rule 16, 2025 DPDP Rules, 2025, which carves out research from the application of the DPDPA, may reduce the obligation to obtain consent, security, and anonymization must be explicitly bargained for, as the “research-purpose” exception does not apply to clinical-trial data.
Cloud hosting: Where India’s health-record data is hosted on Singapore-linked cloud infrastructure, the Indian entity is likely to be the data fiduciary while the cloud-hosting provider is a processor. While both the DPDP’s proportional-safeguard standard and the SS 584 cloud-security standard are “reasonable security safeguards” under Section 8(5) DPDPA, the contract should stipulate which standard applies, while also clarifying sub-processor transparency and India’s right to audit and inspection even when the data is hosted overseas. While the PDPA permits retention of personal data “as necessary for the purpose for which it was processed,” Section 16(2) DPDPA, 2023, permits adoption of “more stringent laws” applicable to the sector; accordingly, the cloud-hosting contract should not presume that Singapore’s retention norms are adequate when processing Indian records subject to NABH or other retention norms.
Telemedicine: Given India’s absolute prohibition on cross-border teleconsultation (per Telemedicine Practice Guidelines 2020), and the HCSA’s lack of recognition of overseas doctors, a telemedicine contract between India and Singapore must stipulate that the consultation takes place between the patient and a local doctor, with the overseas-based Singaporean doctor serving in a non-clinical capacity (e.g. second opinion or specialist consult with patient’s consent).
Insurance analytics: Re-insurance and analytics firms seeking to aggregate Indian claims and health data with Singapore-based analytics teams for underwriting or fraud-detection purposes should note that processing of health data for analytics purposes often involves a change of purpose, necessitating a separate basis for processing under either the DPDPA or the PDPC’s Advisory Guidelines on Analytics and Research.
Bilateral Conflict between the DPDPA and the PDPA
The primary area of conflict between the DPDPA and the PDPA concerns breach-notification obligations: India’s zero-threshold, individual-notification requirement, coupled with the 72-hour detailed report to the DPB, is far more stringent than the “significant harm” or 500-affected-persons threshold in the PDPA, as well as the three-day timing requirement for notification to the PDPC. Accordingly, a joint incident response and breach-notification clause should adopt the stricter standard (India’s) rather than attempt to reconcile the two.
A second conflict concerns retention obligations: India’s clinical-establishment or NABH norms may require retention of health records beyond the period specified by the PDPA’s limitation of purpose principle, necessitating a retention hierarchy clause in the contract. A third conflict concerns telemedicine licensing regimes, as discussed above. A fourth hypothetical conflict concerns India’s negative-listing regime for data localization under Section 16 of the DPDPA 2023: at present, no jurisdiction is “restricted” for data processing, but should Singapore be added to the negative list, a fallback clause would be necessary to address data-localization requirements or alternate processing arrangements.
Practical Ramifications
For Indian hospitals and health-tech firms, a cloud-hosting, research, or insurance analytics contract with a Singapore-linked counterparty that fails to address these differences, may find itself in a jurisdictional grey zone, as neither Indian nor Singapore lawyers would be aware of the other’s requirements. For Singapore-linked cloud, analytics or research providers, a contract using PDPA-compliant breach-notification and retention clauses, may, in fact, be deficient under the DPDPA. For both, it is far safer to adopt the stricter standard when conflicts arise, rather than attempt to devise a jurisdiction-specific carve-out. By identifying these areas of conflict and stipulating the allocation of responsibility in the contract, the onus of due diligence will shift from the contracting parties to the legal counsels.
Conclusion
Cross-border health-data contracts between India and Singapore typically implicate two data privacy regimes that are broadly similar but conflict on several key issues, primarily concerning breach-notification thresholds and requirements. Given that both the DPDPA and the PDPA impose liability on the controlling entity for ensuring that data protection obligations are met, the allocation of responsibility for capturing, securing, breach-notifying, and retaining health data falls on the contract, rather than leaving it to the goodwill of the contracting parties. Specifying the allocation of these responsibilities at the drafting stage will be considerably less burdensome than untangling them in the aftermath of a data-breach incident.
Essential Health-Data Contract Clauses
- Allocation of roles and liabilities: Specify whether each party is a fiduciary/controller or a processor for each data flow, and identify liabilities that persist post-contract termination.
- Consent architecture: Specify who captures consent on what basis (treatment, research, analytics) and how withdrawal is processed by each party.
- Security-standard baseline: Identify the standard (proportional safeguards, SS 584, or ISO 27001) and require the stricter of the two where they conflict.
- Breach-notification protocol: Default to India’s no-threshold, without-delay/72-hour standard to the DPB for any breach touching Indian data principals, with a joint incident response timeline identifying lead counsel in each jurisdiction.
- Retention and erasure hierarchy: Set retention periods by reference to the longer of DPDP/Section 16(2)-preserved Indian sectoral norms and Singapore’s limitation-of-purpose obligations, with documentation of the legal basis for retention beyond original purpose.
- Cross-border data transfer mechanism: Confirm the basis for transfer of data to Singapore under Section 16 of the DPDP Act, 2023 specify a fallback mechanism for any future government restrictions, and disclose sub-processor obligations.
- Purpose limitation and repurposing: Stipulate requirement of a fresh consent or legitimate-use basis before health data captured for treatment can be used for analytics or research.
- Licensing and jurisdiction for telemedicine: Confirm which jurisdiction’s licensed practitioners undertake clinical consultations, and restrict cross-border data exchange to non-clinical functions.
- Audit and inspection rights: Require the Indian party to retain rights to audit a Singapore processor’s security and retention norms irrespective of the hosting location.
- Regulatory-change cooperation: Oblige both parties to cooperate in good faith to amend the contract if either the DPDPA’s negative list or the PDPA guidance undergoes a material change.
Author :- Shriyaa Zubin, in case of any query, contact us at Global Patent Filing or write back us via email at support@globalpatentfiling.com.
References
- The Digital Personal Data Protection Act, 2023 (India), ss. 6, 8, 16.
- Digital Personal Data Protection Rules, 2025 (India), rr. 7, 8, 14-16.
- Personal Data Protection Act 2012 (Singapore), as amended.
- Personal Data Protection Commission and Ministry of Health (Singapore), Advisory Guidelines for the Healthcare Sector (revised 20 September 2023).
- Healthcare Services Act 2020 (Singapore) and Healthcare Services (General) Regulations 2021.
- Telemedicine Practice Guidelines, 2020 (India), issued by the Board of Governors in supersession of the Medical Council of India.
- Ayushman Bharat Digital Mission, Health Data Management Policy.
- Singapore Standard SS 584: Multi-Tier Cloud Security (MTCS).
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India).
- Christopher Kuner, ‘Regulation of Transborder Data Flows under Data Protection and Privacy Law: Past, Present and Future’ (2011) 187 OECD Digital Economy Papers.
- Paul M Schwartz, ‘Information Privacy in the Cloud’ (2013) 161 University of Pennsylvania Law Review 1623.
- Christopher Kuner, Transborder Data Flows and Data Privacy Law (OUP 2013).