Your go-to hub for Expert Insights,
Publications, and Resources
on
data privacy and compliance

Our resources provide the essential tools, guides, and insights to help your business stay ahead of data privacy regulations. From practical templates to expert articles, we ensure you have everything you need to navigate compliance with confidence.

Last Updated: 2026-09-08 ~ DPDP Consultants

DPDPA in Insurance: Managing Customer Data Across Agents, TPAs & Insurers

DPDPA in insurance sector compliance visual showing data protection across agents, TPAs, and insurers with security shield and data flow icons

Chapter 1: Introduction

The insurance industry is built on personal data. From the moment a customer requests a quote to the settlement of a claim years later, insurance operations depend on collecting, assessing, sharing, and storing vast quantities of personal and financial information. A single life insurance policy application can require the customer's full name, date of birth, address, Aadhaar number, PAN, income details, medical history, family medical history, occupation, lifestyle habits, nominee details, and bank account information.

What makes insurance uniquely complex from a data protection perspective is not just the volume or sensitivity of data collected. It is the number of entities that process this data. A single insurance transaction can involve the customer, an insurance agent or broker, the insurer's underwriting team, a Third-Party Administrator (TPA) for health claims, hospitals and diagnostic centres, reinsurers, and the regulator (IRDAI). Customer data flows across all these entities, often without the customer having any visibility into who holds their data, for what purpose, or for how long.

The Digital Personal Data Protection Act, 2023 (DPDPA) fundamentally changes the rules for this entire ecosystem. Under the Act, every entity that processes personal data of individuals in India is accountable. The insurer, the agent, the TPA, the hospital network, and every technology vendor in the chain must comply with the Act's requirements for lawful processing, purpose limitation, data minimisation, security safeguards, and Data Principal rights.

This guide provides a comprehensive analysis of how the DPDPA applies to the insurance sector, maps the data flows across agents, TPAs, and insurers, identifies the compliance gaps most insurance businesses have not addressed, and offers a practical roadmap for achieving compliance across the entire insurance value chain.


Chapter 2: Personal Data Across the Insurance Lifecycle

Insurance generates personal data at every stage of the policy lifecycle. Understanding these data flows is the foundation of DPDPA compliance.

Lifecycle Stage

Personal Data Collected

Entities Involved

DPDPA Risk

Lead Generation

Name, phone, email, age, income bracket, browsing behaviour, cookie data

Agents, digital platforms, insurers

High

Proposal / Application

Full KYC (Aadhaar, PAN), income proof, medical history, family details, occupation, lifestyle, nominees

Agents/brokers, insurers (underwriting)

Very High

Medical Underwriting

Health records, diagnostic reports, pre-existing conditions, BMI, blood reports, ECG, lifestyle declarations

Insurers, TPAs, hospitals, diagnostic labs

Very High

Policy Issuance

Policy details, premium amount, payment info, bank account/card, auto-debit mandates

Insurers, payment gateways, banks

Very High

Policy Servicing

Address changes, nominee updates, fund switches, contact updates, loan requests

Insurers, agents, call centres

High

Claims Processing

Hospital records, treatment details, bills, discharge summaries, prescriptions, investigation reports

TPAs, hospitals, insurers, investigators

Very High

Claims Settlement

Bank account for payout, tax details, legal heir documentation, death certificates

Insurers, banks, legal teams

Very High

Renewal & Retention

Lapse history, payment patterns, usage data, cross-sell/upsell targeting, behavioural analytics

Insurers, agents, marketing teams

High

Regulatory Reporting

Aggregated and individual policy data, complaint records, audit trails

Insurers, IRDAI, reinsurers

High

 

A single health insurance claim can generate over 30 distinct personal data points flowing across four or more entities. For an insurer processing lakh of claims annually, the scale of personal data processing is enormous, resulting in significant compliance exposure.


Chapter 3: Who Is the Data Fiduciary? Mapping Roles Across the Insurance Chain

One of the most critical questions in insurance DPDPA compliance is: who is the Data Fiduciary, and who is the Data Processor? Incorrect classification may result in misallocation of responsibilities and create compliance gaps.

Insurers: The Primary Data Fiduciary

The insurance company is the primary Data Fiduciary. It determines the purpose and means of processing customer data. Whether data is collected through an agent, a digital platform, or a TPA, the insurer bears ultimate responsibility for ensuring that all processing complies with the DPDPA. This includes ensuring valid consent is obtained, data is processed only for specified purposes, security safeguards are implemented, Data Principal rights are fulfilled, and breaches are notified to the Data Protection Board and affected individuals.

Agents and Brokers: Data Fiduciaries or Processors?

Insurance agents and brokers occupy a complex position. An exclusive agent working on behalf of a single insurer typically acts as a Data Processor, collecting data on the insurer's behalf and for the insurer's purposes. However, an independent broker who maintains their own customer database, uses customer data to recommend products across multiple insurers, and conducts their own marketing activities is likely a Data Fiduciary in their own right. The classification depends on who determines the purpose and means of processing. Many agents and brokers operate in a grey area, and the DPDPA requires this classification to be explicitly defined in contractual agreements.

Third-Party Administrators (TPAs)

TPAs process health insurance claims on behalf of insurers. They receive highly sensitive personal data: hospital records, treatment details, diagnostic reports, prescriptions, and billing information. Under the DPDPA, TPAs are typically Data Processors acting on the insurer's instructions. They handle high volume and sensitivity of data and any compliance failure by a TPA creates significant statutory liability on the insurer. The insurer must ensure that every TPA has robust data processing frameworks, security safeguards, defined retention policies, and breach notification capabilities.

Hospitals and Network Providers

Hospitals and diagnostic centres that provide cashless treatment under insurance policies share patient data with TPAs and insurers. For their own patient records, hospitals are independent Data Fiduciaries. When sharing data with insurers and TPAs for claims processing, the relationship is governed by consent and contractual agreements. The data shared often includes the most sensitive health information which needs to be protected under the DPDPA.

Reinsurers

Reinsurers receive policy and claims data from insurers for risk assessment and pricing. While reinsurance data is often aggregated, individual-level data sharing does occur, particularly for large or complex claims. Under the DPDPA, reinsurers receiving personal data are Data Processors (or independent Data Fiduciaries if they determine their own processing purposes), and the primary insurer must ensure DPDPA compliant data sharing arrangements.


Chapter 4: Where Standard Insurance Practices Violate the DPDPA

1. Blanket Consent in Proposal Forms

Insurance proposal forms typically include a single declaration that bundles consent for underwriting, policy issuance, claims processing, marketing communications, data sharing with reinsurers, sharing with group companies, and sharing with third-party partners into one checkbox. Under the DPDPA, consent must be specifically taken for each purpose. A customer must be able to give consent for underwriting and policy issuance while declining to consent for marketing communications and third-party data sharing. Bundled consent is not valid consent under DPDP Act,2023.

2. Sensitive Medical Data Collection

Collecting a customer's complete family medical history for three generations, detailed lifestyle questionnaires covering alcohol consumption, smoking habits, and exercise patterns, and retaining full diagnostic reports indefinitely raises high compliance requirement under the DPDP Act because medical data is considered as highly sensitive data.

3. Agent Data Practices

Insurance agents often maintain personal customer databases on their own devices, laptops, phones, or cloud drives. Customer KYC documents, income proofs, and medical reports may be stored in unsecured formats, shared via WhatsApp or email, or retained indefinitely even after the insurer-agent relationship ends. Under the DPDPA, the insurer is responsible for ensuring that agents handling customer data implement adequate security safeguards and do not retain data beyond the required period.

4. TPA Data Handling Gaps

TPAs process the most sensitive category of insurance data: health records. Common issues include TPAs retaining claims data indefinitely for analytics, sharing data with wellness programme partners without customer consent, inadequate encryption of medical records in transit and at rest, and lack of defined data deletion processes when the TPA-insurer contract ends. Every TPA’s data handling gap is the insurer's compliance liability.

5. Cross-Selling Without Separate Consent

Insurers frequently use data collected for one product (motor insurance) to market other products (health insurance, life insurance) to the same customer. Agents use customer contact details from one insurer's records to solicit business for another. Under the DPDPA, each marketing purpose requires its own specific consent. Using data collected for motor insurance underwriting to send health insurance promotional messages is a separate processing purpose that requires fresh consent.

6. Indefinite Data Retention

Insurance companies retain customer records for decades, often well beyond the policy term, claim settlement, or regulatory requirement. Full proposal forms with KYC documents, medical records, and financial information remain in insurer databases indefinitely. While IRDAI mandates certain retention periods for specific records, the DPDPA requires that personal data be erased when the purpose is fulfilled. Insurance companies must define and implement retention schedules that balance regulatory requirements with both IRDAI and DPDPA obligations.

7. Investigator Access to Personal Data

Insurance companies engage investigation agencies to verify claims, particularly for large or suspicious claims. Investigators receive extensive personal data: medical records, hospital visit details, employment information, and sometimes conduct surveillance. This data sharing often occurs without the customer's explicit knowledge. Under the DPDPA, sharing personal data with investigators requires a lawful basis, and the insurer must ensure that investigators process data only for the specified investigation purpose and implement appropriate safeguards.


Chapter 5: DPDPA Obligations for the Insurance Sector

Informed, Granular Consent

Insurance customers must receive a clear, itemised notice at the time of data collection stating what personal data is being collected, why, who will receive it, and how long it will be retained. Consent must be obtained separately for underwriting and policy issuance, claims processing, marketing and cross-selling, data sharing with reinsurers, data sharing with group companies and partners, and any other distinct processing purpose. The consent mechanism must allow customers to agree to essential processing (underwriting, claims) while declining non-essential uses (marketing, analytics). Consent notices must be available in English and any other languages mentioned in the 8th Schedule of the Constitution.

Data Minimisation

Collect only the data necessary for the specific insurance function. If a motor insurance policy requires the vehicle registration number, driver's licence, and address, it does not need to collect the customer's medical history. Every data field must be justified against a documented purpose.

Purpose Limitation Across the Chain

Data collected for underwriting cannot be repurposed for marketing without fresh consent. Data collected for claims processing cannot be used for product development analytics without appropriate consent or anonymisation. Each entity in the chain, whether insurer, agent, TPA, or hospital, must process data only for the purpose for which it was collected and shared.

Data Principal Rights

Insurance customers have the right to access all data held about them, correct inaccurate information, request deletion of their data, and file grievances. Fulfilling these rights in insurance is complex because customer data is distributed across the insurer's core system, agent records, TPA databases, hospital records, and reinsurer files. The insurer must be able to integrate a comprehensive response mechanism across all these entities when a customer exercises their rights.

Security Safeguards

Insurance data, particularly health records, financial information, and identity documents, requires robust protection. The DPDPA mandates reasonable security safeguards including encryption of all customer data at rest and in transit, role-based access controls across insurer systems, secure data transmission between insurers, agents, and TPAs, protection of agent-held data on personal devices, regular security assessments of TPA infrastructure, and secure disposal of physical documents containing customer data.

Breach Notification

An insurance data breach can expose identity documents, medical records, financial information, and family details of thousands or millions of customers. As per the DPDP Act,2023 and DPDP Final Rules,2025 the insurer must notify the Data Protection Board within 72 hours and each affected individual within reasonable time. Given the distributed nature of insurance data, even a breach from the end of a TPA, agent, or technology vendor needs to be notified by the Insurance company. Insurance companies must have breach detection and response capabilities covering their entire data processing chain.


Chapter 6: Compliance Roadmap for the Insurance Sector

Step 1: Map All Data Flows

Conduct a comprehensive data mapping exercise covering every entity in your insurance ecosystem. Identify every personal data field collected at each lifecycle stage, which systems store it, which agents and TPAs receive it, where data crosses organisational boundaries, and where it crosses national borders. This data map must cover the insurer's core systems, agent channels (both exclusive and independent), every TPA, hospital and diagnostic networks, reinsurers, payment processors, and technology vendors.

Step 2: Redesign Consent Framework

Replace blanket proposal form consent with granular, purpose-specific consent mechanisms. Create separate consent flows for underwriting, claims processing, marketing, data sharing with reinsurers, and data sharing with partners. Implement consent capture at every digital touchpoint: website, mobile app, agent portal, and TPA interface. Ensure consent withdrawal is as easy as giving consent, and that withdrawal of marketing consent does not affect essential insurance processing.

Step 3: Secure All Systems

Implement encryption across all systems that handle customer data: core insurance platforms, agent portals, TPA systems, and customer-facing apps. Configure role-based access controls so that claims adjusters cannot access marketing data and marketing teams cannot access medical records. Establish secure data transmission protocols between insurers and TPAs. Address the agent device security gap by implementing mobile device management or restricting customer data to secure agent portals.

Step 4: Execute Vendor Agreements

Audit and renegotiate data processing agreements with every entity that receives customer data. This includes every TPA, every hospital in the cashless network, every investigation agency, every technology vendor, every reinsurer, and every payment processor. Each agreement must specify DPDPA-compliant data handling obligations, security requirements, purpose limitation, retention limits, breach notification procedures, and sub-processor restrictions.

Step 5: Train All Stakeholders

Deliver DPDPA-specific training to every person who handles customer data. This includes insurance agents and brokers, underwriting teams, claims processing staff, TPA personnel, call centre agents, marketing teams, and IT staff managing insurance systems. Training must cover what constitutes personal data, how to obtain valid consent, how to handle Data Principal requests, and how to report potential breaches.

Step 6: Implement Ongoing Monitoring

DPDPA compliance is not a one-time exercise. Implement automated data retention policies that delete customer records when their retention period expires. Set up continuous monitoring of data flows between insurers, agents, and TPAs. Maintain documentation of consent records, processing activities, vendor assessments, and Data Principal requests. Conduct periodic compliance audits across the entire insurance value chain. Build and test breach detection and notification capabilities.


Chapter 7: How DPDP Consultants Can Help

Insurance compliance under the DPDPA requires specialised expertise that bridges data protection law, insurance operations, and technology across a complex multi-entity ecosystem. DPDP Consultants provides end-to-end compliance services tailored to the insurance sector.

DPDPA Gap Assessment

We audit your entire insurance operation, covering core systems, agent networks, TPA relationships, hospital networks, reinsurer data sharing, and technology infrastructure, against every DPDPA requirement. Our assessment maps data flows across the entire value chain and identifies exactly where compliance gaps exist.

Privacy Framework Implementation

We design and implement an insurance-specific privacy framework covering customer consent workflows, purpose mapping for every data touchpoint across the policy lifecycle, data minimisation policies, retention schedules aligned with both IRDAI and DPDPA requirements, and Data Principal rights fulfilment mechanisms that work across insurers, agents, and TPAs.

Consent Management Platform

Our Data Principal Consent Management tool integrates with your policy administration system, agent portals, and customer-facing platforms to capture granular, purpose-specific consent at every touchpoint, manage consent withdrawal, and maintain audit-ready records that demonstrate compliance.

Grievance Redressal System

Our automated Grievance Redressal platform handles customer requests for data access, correction, and erasure, coordinating fulfilment across insurer systems, agent records, and TPA databases within DPDPA timelines.

DPO as a Service

Our Data Protection Officers provide ongoing oversight of your insurance data processing, manage agent and TPA compliance, handle regulatory communications with both IRDAI and the Data Protection Board, oversee breach response, and ensure continuous DPDPA adherence across your entire distribution and claims network.

Awareness Programme

We deliver DPDPA awareness training programmes customised for the insurance sector, covering agents, underwriters, claims teams, TPA personnel, call centre staff, and IT teams.

 

Third-Party Assessment

We evaluate every TPA, hospital network partner, investigation agency, reinsurer, and technology vendor in your ecosystem, ensuring appropriate data processing agreements and DPDPA-compliant security safeguards are in place across the entire insurance value chain.


Chapter 8: Frequently Asked Questions (FAQs)

Q: Is the insurer or the agent responsible for DPDPA compliance?

The insurer, as the primary Data Fiduciary, bears ultimate responsibility for DPDPA compliance. However, if an agent independently determines the purpose and means of processing (for example, maintaining their own customer database for cross-selling), the agent will be a Co-Data Fiduciary. In all cases, the insurer must ensure that agents processing data on its behalf comply with the DPDPA through contractual agreements and oversight.

Q: How does the DPDPA affect health insurance claims processing through TPAs?

TPAs process highly sensitive health data on behalf of insurers. The insurer must ensure that the TPA has a DPDPA-compliant data processing agreement, implements adequate security safeguards for medical records, retains claims data only as long as necessary, and has breach notification procedures in place. The customer's consent for claims processing must specifically cover data sharing with the TPA.

Q: Can insurers use customer data for cross-selling other insurance products?

Not without separate consent. Data collected for motor insurance underwriting cannot be used to market health or life insurance products. Each marketing purpose requires its own specific consent. The customer must be able to consent to policy servicing while declining cross-sell communications.

Q: What happens to customer data when a TPA contract ends?

When an insurer-TPA relationship ends, the insurer must ensure that the TPA returns or securely deletes all customer data. The data processing agreement should specify data return or deletion procedures, timelines, and certification of deletion. Failure to address data disposition at contract termination creates ongoing compliance risk.

Q: Does the DPDPA require insurers to delete medical records after claim settlement?

The DPDPA requires data to be erased when the purpose is fulfilled. However, IRDAI regulations may mandate retention of claims records for specified periods. Insurers must balance IRDAI retention requirements with DPDPA obligations. Data that is not required by IRDAI or for any other regulatory compliance must be deleted once the claims purpose is fulfilled.

Q: Are insurance aggregator and comparison websites covered under the DPDPA?

Yes. Insurance aggregator websites (PolicyBazaar, Coverfox, InsuranceDekho) that collect customer data for generating quotes, comparing products, and facilitating purchases are Data Fiduciaries under the DPDPA. They must obtain valid consent, implement security safeguards, and comply with all Data Principal rights obligations.

Q: How should agents handle customer data on personal devices?

Agents should not store customer KYC documents, medical reports, or financial information on personal devices. Insurers should provide secure agent portals for data collection and submission. Where agents must use personal devices, mobile device management policies, encryption, and remote wipe capabilities should be implemented. Customer data must be deleted from agent devices once transmitted to the insurer.

Q: What are the penalties for insurance data breaches under the DPDPA?

Penalties under the DPDPA range up to Rs 250 crore depending on the nature and severity of the violation. For insurance breaches involving Aadhaar, medical records, and financial data of potentially millions of policyholders, the exposure is severe. Beyond financial penalties, insurance data breaches erode customer trust and can trigger IRDAI regulatory action in addition to DPDPA penalties.


 

Protect Your Policyholders' Data. Comply with the DPDPA.

The insurance sector processes some of the most sensitive personal data of any industry: identity documents, medical records, financial information, and family details. The DPDPA holds every entity in the insurance chain accountable.

DPDP Consultants provides the expertise and technology to make your insurance operations fully compliant. From Gap Assessments and Privacy Framework Implementation to Consent Management, DPO as a Service, and Third-Party Assessments, we cover every aspect of insurance data protection.

 

Contact us today:

Website: www.dpdpconsultants.com

Email: info@dpdpconsultants.com

Your policyholders trust you with their most personal information. The DPDPA says you must earn that trust.

 

Disclaimer: This document is prepared by DPDP Consultants for informational purposes only. It does not constitute legal advice and should not be relied upon as a substitute for professional legal counsel. The information contained herein is based on the Digital Personal Data Protection Act, 2023, and publicly available information about the DPDP Rules as of August 2026. Laws, regulations, and their interpretations may change. Readers should consult qualified legal professionals for advice specific to their circumstances. DPDP Consultants assumes no liability for any actions taken or not taken based on the contents of this document.