A pharmacy in Banjara Hills, Hyderabad keeps a WhatsApp group with 340 regular customers. Every month, the staff broadcasts a refill reminder listing medicine names, dosages, and the customer's first name. It feels like good service. Under the Digital Personal Data Protection Act 2023 (DPDPA 2023), it is an unlicensed disclosure of health-related personal data — and the penalty starts at ₹50 crore per violation category.
Most pharmacy owners we visit have never heard of DPDPA 2023 in the context of their daily billing workflow. They know GST. They know Schedule H registers. But patient data? That's something hospitals worry about, right? Wrong. The DPDPA pharmacy obligation applies to any entity that "processes" personal data of Indian citizens — and every time your billing software saves a customer's name, phone number, and prescription item together, you are processing personal data under the Act.
If you keep running your pharmacy the way you ran it in 2022, you are accumulating a liability that no amount of good customer relationships will neutralize. Here is what that liability looks like in practice.
Your WhatsApp Billing Workflow Is a Compliance Violation Waiting to Be Enforced
Walk into almost any neighborhood pharmacy in Pune or Surat and you will find the same workflow: a customer calls, asks for their "usual medicines," the counter staff pulls up the last bill on the screen or checks a notebook, reads the items back, and sends the invoice photo on WhatsApp. Fast, friendly, and almost certainly a DPDPA violation.
Under DPDPA 2023, transmitting identifiable health data (name + medicine name = health-adjacent personal data) over a non-consented, non-secured channel qualifies as unauthorized processing. The Act requires a lawful basis for every processing activity — and "we always did it this way" is not a lawful basis. The Data Protection Board, once fully constituted, can impose penalties up to ₹250 crore for repeated or egregious violations, with the base tier starting at ₹50 crore.
The more immediate risk is not a regulator walking in tomorrow. It is that one customer complaint to the Board — perhaps after a dispute, perhaps from a competitor — triggers a notice that requires you to produce:
- A record of what personal data you hold
- The consent basis under which you collected it
- Proof that you notified customers of their rights
Most pharmacy software running on local desktops today cannot produce any of these three documents. That is not a technology gap — it is a legal exposure.
Your Schedule H/H1 Register Probably Has a Data Retention Problem Too
Rule 65 of the Drugs and Cosmetics Rules requires pharmacies to maintain a Schedule H1 register for three years, recording the prescriber's name, patient's name, quantity dispensed, and date. This is a legal mandate. Violating it carries fines of ₹1 lakh to ₹10 lakh under Section 27 of the Drugs and Cosmetics Act, and in serious cases, license cancellation.
Here is the intersection point that most pharmacy owners miss: the same register that D&C Rules require you to keep for three years is also a dataset of personal health information governed by DPDPA 2023. You cannot delete it early (D&C compliance), but you must also limit who accesses it, secure it against breach, and be able to respond to a data subject request within a defined period (DPDPA compliance). These two obligations are not in conflict — but they require a system that can satisfy both simultaneously.
A paper register satisfies D&C Rules barely. It satisfies DPDPA 2023 not at all — there is no audit log of who opened it, no encryption, no breach-detection mechanism.
Customer Data Scattered Across Three Systems Means You Cannot Respond to a Legal Notice
A pharmacist in Thane described their setup to us last quarter: billing on one desktop software, customer phone numbers in a separate Excel file for the loyalty program, and prescription images saved in a WhatsApp folder on the owner's personal phone. Three data stores, zero unified consent record, no data map.
When DPDPA enforcement becomes active, a Data Subject Access Request (DSAR) requires you to tell a customer exactly what data you hold about them and where. If that data is across three systems — one of which is a personal WhatsApp account — you have a problem that no lawyer can fix quickly. You simply do not know what you have.
The cost here is not just a fine. It is the operational time required to respond. Industry estimates for mid-size businesses suggest responding to a single regulatory data inquiry can consume 40-80 hours of staff time when records are unstructured. For a pharmacy running on thin margins, 80 hours of the owner's time at any reasonable opportunity cost is a meaningful rupee figure — before legal fees.
What Compliant Patient Data Management Actually Looks Like Day-to-Day
The after-state is not complicated. It is boring in exactly the right way.
Before: Customer data lives in four places. Consent was never collected. The Schedule H1 register is a physical book locked in a drawer. Staff share prescription photos on personal phones.
After: Every bill created in the pharmacy system captures a standardized consent acknowledgment at point of sale. The Schedule H1 register auto-populates from billing data, is timestamped, and is stored in a system with a full access audit log. Prescription images are attached to the bill record inside the pharmacy system — not on anyone's phone. When a customer asks "what data do you have about me," the answer takes ninety seconds to generate.
The data map exists. The consent record exists. The retention timeline is enforced by the software, not by a person remembering to shred a notebook. A D&C inspector and a DPDPA inquiry can both be answered from the same system, the same afternoon. That is what compliance looks like when the tooling is built for it.
How Pharmacies Running Nesayo Are Handling This Right Now
One chemist in Rajkot told us that before switching to Nesayo, their Schedule H1 register was always two weeks behind — the counter staff would batch-fill it on Sunday evenings from memory and billing receipts. Since the auto Schedule H1 register feature went live in Nesayo, every Schedule H dispensing event writes to the register at the moment of billing. No Sunday catch-up session. No gaps. The register is current to the last transaction, exportable for inspection, and tied to the bill record that holds the scanned prescription image from Claude Vision prescription scan.
The DPDPA pharmacy angle: because Nesayo's billing database is the single record of truth for customer data, there is no Excel sidecar file, no WhatsApp folder problem. Voice billing in 10 Indian languages means counter staff do not need to type patient details into a separate system — the bill and the register entry are one action. The Payment Advisor AI agent (part of the AI Employee plan, priced at ₹999 per month as of 2026-07-27; see current pricing at nesayo.com/pricing) flags unusual payment patterns, but it does not export raw customer health data to any external channel. Billing is free forever — that is not a trial, it is the base product (confirmed at nesayo.com/pricing as of 2026-07-27). The paid AI plans starting at ₹399 per month (Starter plan, as of 2026-07-27, nesayo.com/pricing) add the five AI agents but the compliance-critical features — auto Schedule H1 register, prescription image attachment, audit-logged access — are in the free billing layer.
The Morning Briefing agent delivers a 6 AM summary of any compliance-sensitive inventory items: Schedule H1 medicines nearing expiry, pending register entries, and stock that has crossed the 30-day expiry bucket via Expiry Guard. By the time the shutter opens, the owner already knows if there is a gap. That is a fundamentally different posture than discovering a three-month-old register gap during an inspection.
The Choice in Front of You Is Straightforward
Pharmacies that do nothing will not face a regulator tomorrow. Enforcement of DPDPA 2023 is ramping up, not instant. But every month of inaction is another month of WhatsApp prescription sharing, another month of paper registers with no audit trail, another month of customer data living in places you cannot account for. When the notice arrives — from a customer complaint, a competitor tip-off, or a routine inspection — the time to build a compliant system is not that afternoon. The pharmacies that respond to a DPDPA inquiry in ninety minutes are the ones that built the system before they needed it.
Spend 20 minutes at nesayo.com/demo — real pharmacy data is pre-loaded, no signup required. Filter the Schedule H1 register view, pull a sample data map, and see exactly what your current expiry and compliance queue would look like if it were managed automatically. The demo does not require your business data. It will show you the gap between where you are and where the regulation requires you to be.
---
FAQ
Won't migrating my existing billing data take weeks and risk losing years of records?
Nesayo accepts a CSV export from most desktop billing software — including the formats Marg and PharmAssist typically produce (per publicly listed export options on their respective websites as of April 2026). Most pharmacies we have onboarded have their historical bill data visible in Nesayo within one working day. Your existing data does not disappear; it imports into the same database structure that generates the Schedule H1 register going forward. We do not delete the source files — we ask you to keep them as a backup for the 3-year D&C retention period.
What if my internet goes down during billing hours?
Nesayo runs as a Progressive Web App (PWA) with offline billing capability. Bills created during an outage sync automatically when connectivity returns. The Schedule H1 register entries sync in the same batch, so there is no manual reconciliation step after an outage. For pharmacies in areas with inconsistent connectivity — common in tier-2 cities across Maharashtra and Gujarat — the offline mode has been the deciding factor in several adoptions.
Can I actually trust AI to handle something as sensitive as patient data compliance?
The AI agents in Nesayo — Morning Briefing, Expiry Guard, Refill Radar, Stock Sense, Payment Advisor — operate on your billing and inventory data inside the platform. They surface alerts and draft actions for your approval; they do not autonomously share patient data with external systems or channels. The compliance-critical data handling — register generation, prescription image storage, audit logging — is deterministic software logic, not AI inference. The AI layer adds operational intelligence on top of a compliant data foundation, not instead of one.