This is not legal advice, and answering every line “yes” is not a certification. The section references point at the Digital Personal Data Protection Act, 2023 so that you can go and read the section — they are not a substitute for reading it, and no statutory text, period, penalty or schedule is reproduced anywhere on this page.
No named compliance reviewer has signed this page off yet. Several lines depend on the Rules rather than on the Act, and those are marked for a compliance reviewer where they appear. Take those first.
What this page can be exact about is the other half: what a clinic running MedAppz gets enforced for it, what it merely gets a desk and a clock for, and what no software can do on its behalf. Every one of those sentences names a mechanism in the running product, and the trust centre lists them with their evidence — including an honest list of what MedAppz does not do yet.
What you told the patient before you took anything, and whether you can still produce the version they agreed to.
What happens when a patient asks for their data, asks you to correct it, or asks you to erase it.
The half of the Act that is about deleting, which is the half nobody has a process for.
The Act says “reasonable”; an assessor and a plaintiff will both ask what you actually did.
The obligation that starts on the worst day, when nobody has time to invent a process.
A processor’s mistake is still your obligation, and the list is always longer than a clinic expects.
One line, because getting it wrong is expensive and most clinics never check.
This is not legal advice and it is not a certification. It is a working list, written from the Act’s own structure and from what this product does; the section references have not yet been signed off by a named compliance reviewer, and the lines flagged below are the ones to take to one first.
Everything above stays free and open — this page works without giving us anything. Tell us who you are and the printable version opens right here, on this page, with no email to wait for.