Skip to content

The NNWA journal

Most independent practices hold health information about dozens of people in a personal phone gallery and a spreadsheet. That is the problem in one sentence, and fixing it takes an afternoon.

How should a nutritionist store client records in India?

This is general guidance, not legal advice. The Digital Personal Data Protection Act 2023 and the Rules made under it govern personal data in India, and the text is published by the Ministry of Electronics and Information Technology at meity.gov.in. Have your own arrangements reviewed if you hold records at any scale.

Published
Reading time
5 min
Written by
Neha Mohan SinhaM.Sc Nutrition · PhD Scholar · Command Hospital
Reviewed by
Dr. Sucharita SenguptaMSc Food Science & Nutrition · PG Certificate in Diabetes Education · Doctoral Scholar
Last reviewed
Written byNeha Mohan Sinha, Clinical Nutritionist & Lead MentorM.Sc Nutrition · PhD Scholar · Command Hospital
Reviewed byDr. Sucharita Sengupta, Mentor-in-ChiefMSc Food Science & Nutrition · PG Certificate in Diabetes Education · Doctoral Scholar

Last reviewed on 29 September 2026.

NNWA publishes the name and qualifications of everyone who writes and checks its material. You can see the full teaching team on the faculty page.

The underlying idea is simpler than the legislation. You hold information people gave you for a purpose. Keep what that purpose needs, keep it somewhere only you can reach, keep it no longer than necessary, and be able to hand it back or delete it when asked.

What a practice actually holds

More than practitioners realise once they list it. Intake forms with medical history and medication. Consultation notes. Diet plans. Measurements over time. Photographs, often in a phone gallery alongside everything else. Payment records. Message threads on whatever app the client uses.

That last category is the one people forget. A year of consultation detail sitting in a messaging app is a record, whatever it feels like, and it is usually the least protected thing in the practice.

The four habits that do most of the work

One place, not five

Pick a single store for client files and use it consistently. Scattered records are the root cause of almost every failure here, because you cannot protect, produce or delete what you cannot find.

Access control that is real

A password on the device is the minimum. Anything holding health information should not be reachable by whoever picks up your phone. If a family member uses the same laptop, client records need their own account or their own encrypted folder.

Separate identity from detail where you can

For anything you use in study, supervision or a portfolio, strip the name and contact details and refer to the person by a reference. The clinical detail is what makes a case useful; the identity is what makes it a risk. There is more on this in building a portfolio with no clients yet.

A backup you have actually tested

A single copy is not a record, it is a hope. Whatever you use, restore one file from it once so you know the backup works. Practitioners discover otherwise at the worst possible moment.

How long to keep things

There is no single answer that fits every practice, and anybody offering a confident number without knowing your circumstances is guessing. What matters is that you have a stated period and that you apply it, rather than keeping everything forever by default.

Think about it in two parts. Clinical notes have a reason to persist: a client returning after two years benefits from you having their history. Payment records have their own retention logic driven by tax rather than by health. Marketing consent is different again and should lapse rather than persist.

Write down the period for each category, put a recurring reminder in your calendar to review, and actually delete when the review says so. A retention policy nobody executes is a document rather than a practice.

When somebody asks for their data, or for deletion

This will happen, and the first time is much easier if you have thought about it once.

Be able to produce what you hold about one person in a reasonable time. That is a direct consequence of the one place habit: a practitioner with organised files can do it in ten minutes, and a practitioner with records across four apps cannot do it at all.

For deletion, the practical complication is that some records cannot simply vanish, because tax and accounting obligations attach to payment history. The workable answer is usually to delete the clinical file and retain the minimum financial record, and to say that clearly to the client rather than either refusing or over promising.

Photographs deserve their own rule

Before and after images are the most sensitive thing most practices hold and the most casually stored. They should be in the client store rather than the camera roll, they should have been consented to separately, and any use in marketing needs its own explicit permission that names where they will appear.

The separate consent for this is covered in a client consent form under the DPDP Act.

If you use software

Most practitioners eventually adopt something. Two questions are worth asking any provider: where the data is held, and what happens to it if you stop paying. The second is the one people never ask and the one that strands records.

The one risk people underestimate

Not a breach by somebody malicious. A device that is lost, shared or repaired. A phone handed to a shop with a year of client photographs on it, or a laptop used by a relative who opens the wrong folder, accounts for far more real exposure in small practices than anything dramatic.

That is why device level protection matters more than sophisticated tooling. A passcode, a separate account for practice work, and photographs kept out of the general gallery deal with the ordinary failure modes, which are the ones that actually happen.

What to do if something does go wrong

Do not improvise. Write down what happened and when you noticed. Work out whose data was affected and what exactly was exposed. Take the obvious immediate steps, such as changing credentials or remotely wiping a device. Then take advice about whether anybody needs to be told, because notification obligations depend on circumstances a page cannot assess.

The instinct to say nothing and hope is the one that turns a contained problem into a serious one.

The honest summary

One place, access controlled, backed up and tested. Collect only what the work needs and say why. Write down a retention period for each category and act on it. Keep photographs out of the general gallery and consent to them separately. Be able to produce or delete one person's file on request. That is the whole of it, and it is an afternoon rather than a project.

Sources and further reading

Want to do this work, not just read about it?

The programmes teach the whole method (assessment, diet charting, reading a blood report and running a consultation) in English and Hindi, with mentors beside you.

Enquire on WhatsAppOnline now · we reply 24x7Register
Online now · we reply 24x7