International Journal For Multidisciplinary Research

E-ISSN: 2582-2160   •   Impact Factor: 9.24

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 8, Issue 5 (September-October 2026) Submit your research before last 3 days of October to publish your research paper in the issue of September-October.

Regulatory Divergence in Digital Healthcare: Corporate Governance, Risk Mitigation, and Data Privacy Liabilities for Transnational Telehealth Providers Under the EU GDPR and India's DPDPA

Author(s) Faisal Yaseen, Fouzan Shah
Country India
Abstract Telehealth companies that operate across borders handle sensitive patient data clinical records, biometric information, and behaviour patterns for patients in both the European Union and India. These two regions have very different data protection laws, in terms of how the rules are designed, how they are enforced, and who can be held responsible when something goes wrong. This paper compares the corporate governance duties, risk-management practices, and data privacy liabilities faced by telehealth companies that must follow both the EU's General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDPA), which is now being put into effect through the Digital Personal Data Protection Rules, 2025. The study uses GDPR enforcement records, market data on India's telehealth sector, and a survey of 42 compliance officers at telehealth companies. From this, it builds a simple index comparing how strict each law is, and measures how much compliance risk officers feel across six areas of their work. The findings show that GDPR carries a much higher risk of direct fines and has more experienced regulators enforcing it. DPDPA's biggest risk, by contrast, comes from unclear rules particularly around moving data across borders, reporting data breaches on time, and deciding which companies count as “Significant Data Fiduciaries” (a special category under Indian law). The paper argues that companies whose governance structures are built only around GDPR may still have compliance gaps under DPDPA, which focuses heavily on consent and holds company boards directly accountable. It ends by proposing a three-tier governance framework to help companies meet both sets of rules at once.
Keywords telehealth governance; GDPR compliance; Digital Personal Data Protection Act; cross-border data transfer; healthcare data privacy; regulatory divergence
Published In Volume 8, Issue 5, September-October 2026
Published On 2026-10-06

Share this