Our resources provide the essential tools, guides, and insights to help your business stay ahead of data privacy regulations. From practical templates to expert articles, we ensure you have everything you need to navigate compliance with confidence.
Table of content
Last Updated: 2026-09-08 ~ DPDP Consultants
The insurance industry is built on personal
data. From the moment a customer requests a quote to the settlement of a claim
years later, insurance operations depend on collecting, assessing, sharing, and
storing vast quantities of personal and financial information. A single life
insurance policy application can require the customer's full name, date of
birth, address, Aadhaar number, PAN, income details, medical history, family
medical history, occupation, lifestyle habits, nominee details, and bank account
information.
What makes insurance uniquely complex from a
data protection perspective is not just the volume or sensitivity of data
collected. It is the number of entities that process this data. A single
insurance transaction can involve the customer, an insurance agent or broker,
the insurer's underwriting team, a Third-Party Administrator (TPA) for health
claims, hospitals and diagnostic centres, reinsurers, and the regulator
(IRDAI). Customer data flows across all these entities, often without the
customer having any visibility into who holds their data, for what purpose, or
for how long.
The Digital Personal Data Protection Act, 2023
(DPDPA) fundamentally changes the rules for this entire ecosystem. Under the
Act, every entity that processes personal data of individuals in India is
accountable. The insurer, the agent, the TPA, the hospital network, and every
technology vendor in the chain must comply with the Act's requirements for
lawful processing, purpose limitation, data minimisation, security safeguards,
and Data Principal rights.
This guide provides a comprehensive analysis of
how the DPDPA applies to the insurance sector, maps the data flows across
agents, TPAs, and insurers, identifies the compliance gaps most insurance
businesses have not addressed, and offers a practical roadmap for achieving
compliance across the entire insurance value chain.
Chapter 2: Personal Data Across the Insurance Lifecycle
Insurance generates personal data at every stage
of the policy lifecycle. Understanding these data flows is the foundation of
DPDPA compliance.
|
Lifecycle Stage |
Personal Data Collected |
Entities Involved |
DPDPA Risk |
|
Lead
Generation |
Name,
phone, email, age, income bracket, browsing behaviour, cookie data |
Agents,
digital platforms, insurers |
High |
|
Proposal / Application |
Full KYC (Aadhaar, PAN), income proof,
medical history, family details, occupation, lifestyle, nominees |
Agents/brokers, insurers (underwriting) |
Very High |
|
Medical
Underwriting |
Health
records, diagnostic reports, pre-existing conditions, BMI, blood reports,
ECG, lifestyle declarations |
Insurers,
TPAs, hospitals, diagnostic labs |
Very
High |
|
Policy Issuance |
Policy details, premium amount, payment
info, bank account/card, auto-debit mandates |
Insurers, payment gateways, banks |
Very High |
|
Policy
Servicing |
Address
changes, nominee updates, fund switches, contact updates, loan requests |
Insurers,
agents, call centres |
High |
|
Claims Processing |
Hospital records, treatment details,
bills, discharge summaries, prescriptions, investigation reports |
TPAs, hospitals, insurers,
investigators |
Very High |
|
Claims
Settlement |
Bank
account for payout, tax details, legal heir documentation, death certificates |
Insurers,
banks, legal teams |
Very
High |
|
Renewal & Retention |
Lapse history, payment patterns, usage
data, cross-sell/upsell targeting, behavioural analytics |
Insurers, agents, marketing teams |
High |
|
Regulatory
Reporting |
Aggregated
and individual policy data, complaint records, audit trails |
Insurers,
IRDAI, reinsurers |
High |
A single health insurance claim can generate
over 30 distinct personal data points flowing across four or more entities. For
an insurer processing lakh of claims annually, the scale of personal data
processing is enormous, resulting in significant compliance exposure.
Chapter 3: Who Is the Data Fiduciary? Mapping Roles Across the Insurance Chain
One of the most critical questions in insurance
DPDPA compliance is: who is the Data Fiduciary, and who is the Data Processor? Incorrect
classification may result in misallocation of responsibilities and create compliance
gaps.
Insurers: The Primary Data
Fiduciary
The insurance company is the primary Data
Fiduciary. It determines the purpose and means of processing customer data.
Whether data is collected through an agent, a digital platform, or a TPA, the
insurer bears ultimate responsibility for ensuring that all processing complies
with the DPDPA. This includes ensuring valid consent is obtained, data is
processed only for specified purposes, security safeguards are implemented,
Data Principal rights are fulfilled, and breaches are notified to the Data
Protection Board and affected individuals.
Agents and Brokers: Data
Fiduciaries or Processors?
Insurance agents and brokers occupy a complex
position. An exclusive agent working on behalf of a single insurer typically
acts as a Data Processor, collecting data on the insurer's behalf and for the
insurer's purposes. However, an independent broker who maintains their own
customer database, uses customer data to recommend products across multiple
insurers, and conducts their own marketing activities is likely a Data
Fiduciary in their own right. The classification depends on who determines the
purpose and means of processing. Many agents and brokers operate in a grey
area, and the DPDPA requires this classification to be explicitly defined in
contractual agreements.
Third-Party Administrators (TPAs)
TPAs process health insurance claims on behalf
of insurers. They receive highly sensitive personal data: hospital records,
treatment details, diagnostic reports, prescriptions, and billing information.
Under the DPDPA, TPAs are typically Data Processors acting on the insurer's
instructions. They handle high volume and sensitivity of data and any compliance
failure by a TPA creates significant statutory liability on the insurer. The
insurer must ensure that every TPA has robust data processing frameworks,
security safeguards, defined retention policies, and breach notification
capabilities.
Hospitals and Network Providers
Hospitals and diagnostic centres that provide
cashless treatment under insurance policies share patient data with TPAs and
insurers. For their own patient records, hospitals are independent Data
Fiduciaries. When sharing data with insurers and TPAs for claims processing,
the relationship is governed by consent and contractual agreements. The data
shared often includes the most sensitive health information which needs to be protected
under the DPDPA.
Reinsurers
Reinsurers receive policy and claims data from
insurers for risk assessment and pricing. While reinsurance data is often
aggregated, individual-level data sharing does occur, particularly for large or
complex claims. Under the DPDPA, reinsurers receiving personal data are Data
Processors (or independent Data Fiduciaries if they determine their own
processing purposes), and the primary insurer must ensure DPDPA compliant data
sharing arrangements.
Chapter 4: Where Standard Insurance Practices Violate the DPDPA
1. Blanket Consent in Proposal
Forms
Insurance proposal forms typically include a
single declaration that bundles consent for underwriting, policy issuance,
claims processing, marketing communications, data sharing with reinsurers,
sharing with group companies, and sharing with third-party partners into one
checkbox. Under the DPDPA, consent must be specifically taken for each purpose.
A customer must be able to give consent for underwriting and policy issuance
while declining to consent for marketing communications and third-party data
sharing. Bundled consent is not valid consent under DPDP Act,2023.
2. Sensitive Medical Data
Collection
Collecting a customer's complete family medical
history for three generations, detailed lifestyle questionnaires covering
alcohol consumption, smoking habits, and exercise patterns, and retaining full
diagnostic reports indefinitely raises high compliance requirement under the
DPDP Act because medical data is considered as highly sensitive data.
3. Agent Data Practices
Insurance agents often maintain personal
customer databases on their own devices, laptops, phones, or cloud drives.
Customer KYC documents, income proofs, and medical reports may be stored in
unsecured formats, shared via WhatsApp or email, or retained indefinitely even
after the insurer-agent relationship ends. Under the DPDPA, the insurer is
responsible for ensuring that agents handling customer data implement adequate
security safeguards and do not retain data beyond the required period.
4. TPA Data Handling Gaps
TPAs process the most sensitive category of
insurance data: health records. Common issues include TPAs retaining claims
data indefinitely for analytics, sharing data with wellness programme partners
without customer consent, inadequate encryption of medical records in transit
and at rest, and lack of defined data deletion processes when the TPA-insurer
contract ends. Every TPA’s data handling gap is the insurer's compliance
liability.
5. Cross-Selling Without Separate
Consent
Insurers frequently use data collected for one
product (motor insurance) to market other products (health insurance, life
insurance) to the same customer. Agents use customer contact details from one
insurer's records to solicit business for another. Under the DPDPA, each
marketing purpose requires its own specific consent. Using data collected for
motor insurance underwriting to send health insurance promotional messages is a
separate processing purpose that requires fresh consent.
6. Indefinite Data Retention
Insurance companies retain customer records for
decades, often well beyond the policy term, claim settlement, or regulatory
requirement. Full proposal forms with KYC documents, medical records, and
financial information remain in insurer databases indefinitely. While IRDAI
mandates certain retention periods for specific records, the DPDPA requires
that personal data be erased when the purpose is fulfilled. Insurance companies
must define and implement retention schedules that balance regulatory requirements
with both IRDAI and DPDPA obligations.
7. Investigator Access to Personal
Data
Insurance companies engage investigation
agencies to verify claims, particularly for large or suspicious claims.
Investigators receive extensive personal data: medical records, hospital visit
details, employment information, and sometimes conduct surveillance. This data
sharing often occurs without the customer's explicit knowledge. Under the
DPDPA, sharing personal data with investigators requires a lawful basis, and
the insurer must ensure that investigators process data only for the specified
investigation purpose and implement appropriate safeguards.
Chapter 5: DPDPA Obligations for the Insurance Sector
Informed, Granular Consent
Insurance customers must receive a clear,
itemised notice at the time of data collection stating what personal data is
being collected, why, who will receive it, and how long it will be retained.
Consent must be obtained separately for underwriting and policy issuance,
claims processing, marketing and cross-selling, data sharing with reinsurers,
data sharing with group companies and partners, and any other distinct
processing purpose. The consent mechanism must allow customers to agree to
essential processing (underwriting, claims) while declining non-essential uses
(marketing, analytics). Consent notices must be available in English and any
other languages mentioned in the 8th Schedule of the Constitution.
Data Minimisation
Collect only the data necessary for the specific
insurance function. If a motor insurance policy requires the vehicle
registration number, driver's licence, and address, it does not need to collect
the customer's medical history. Every data field must be justified against a
documented purpose.
Purpose Limitation Across the
Chain
Data collected for underwriting cannot be
repurposed for marketing without fresh consent. Data collected for claims
processing cannot be used for product development analytics without appropriate
consent or anonymisation. Each entity in the chain, whether insurer, agent,
TPA, or hospital, must process data only for the purpose for which it was
collected and shared.
Data Principal Rights
Insurance customers have the right to access all
data held about them, correct inaccurate information, request deletion of their
data, and file grievances. Fulfilling these rights in insurance is complex
because customer data is distributed across the insurer's core system, agent
records, TPA databases, hospital records, and reinsurer files. The insurer must
be able to integrate a comprehensive response mechanism across all these
entities when a customer exercises their rights.
Security Safeguards
Insurance data, particularly health records,
financial information, and identity documents, requires robust protection. The
DPDPA mandates reasonable security safeguards including encryption of all
customer data at rest and in transit, role-based access controls across insurer
systems, secure data transmission between insurers, agents, and TPAs,
protection of agent-held data on personal devices, regular security assessments
of TPA infrastructure, and secure disposal of physical documents containing
customer data.
Breach Notification
An insurance data breach can expose identity
documents, medical records, financial information, and family details of
thousands or millions of customers. As per the DPDP Act,2023 and DPDP Final
Rules,2025 the insurer must notify the Data Protection Board within 72 hours and
each affected individual within reasonable time. Given the distributed nature
of insurance data, even a breach from the end of a TPA, agent, or technology
vendor needs to be notified by the Insurance company. Insurance companies must
have breach detection and response capabilities covering their entire data
processing chain.
Chapter 6: Compliance Roadmap for the Insurance Sector
Step 1: Map All Data Flows
Conduct a comprehensive data mapping exercise
covering every entity in your insurance ecosystem. Identify every personal data
field collected at each lifecycle stage, which systems store it, which agents
and TPAs receive it, where data crosses organisational boundaries, and where it
crosses national borders. This data map must cover the insurer's core systems,
agent channels (both exclusive and independent), every TPA, hospital and
diagnostic networks, reinsurers, payment processors, and technology vendors.
Step 2: Redesign Consent Framework
Replace blanket proposal form consent with
granular, purpose-specific consent mechanisms. Create separate consent flows
for underwriting, claims processing, marketing, data sharing with reinsurers,
and data sharing with partners. Implement consent capture at every digital
touchpoint: website, mobile app, agent portal, and TPA interface. Ensure
consent withdrawal is as easy as giving consent, and that withdrawal of
marketing consent does not affect essential insurance processing.
Step 3: Secure All Systems
Implement encryption across all systems that
handle customer data: core insurance platforms, agent portals, TPA systems, and
customer-facing apps. Configure role-based access controls so that claims
adjusters cannot access marketing data and marketing teams cannot access
medical records. Establish secure data transmission protocols between insurers
and TPAs. Address the agent device security gap by implementing mobile device
management or restricting customer data to secure agent portals.
Step 4: Execute Vendor Agreements
Audit and renegotiate data processing agreements
with every entity that receives customer data. This includes every TPA, every
hospital in the cashless network, every investigation agency, every technology
vendor, every reinsurer, and every payment processor. Each agreement must
specify DPDPA-compliant data handling obligations, security requirements,
purpose limitation, retention limits, breach notification procedures, and
sub-processor restrictions.
Step 5: Train All Stakeholders
Deliver DPDPA-specific training to every person
who handles customer data. This includes insurance agents and brokers,
underwriting teams, claims processing staff, TPA personnel, call centre agents,
marketing teams, and IT staff managing insurance systems. Training must cover
what constitutes personal data, how to obtain valid consent, how to handle Data
Principal requests, and how to report potential breaches.
Step 6: Implement Ongoing
Monitoring
DPDPA compliance is not a one-time exercise.
Implement automated data retention policies that delete customer records when
their retention period expires. Set up continuous monitoring of data flows
between insurers, agents, and TPAs. Maintain documentation of consent records,
processing activities, vendor assessments, and Data Principal requests. Conduct
periodic compliance audits across the entire insurance value chain. Build and
test breach detection and notification capabilities.
Chapter 7: How DPDP Consultants Can Help
Insurance compliance under the DPDPA requires
specialised expertise that bridges data protection law, insurance operations,
and technology across a complex multi-entity ecosystem. DPDP Consultants
provides end-to-end compliance services tailored to the insurance sector.
DPDPA Gap Assessment
We audit your entire insurance operation,
covering core systems, agent networks, TPA relationships, hospital networks,
reinsurer data sharing, and technology infrastructure, against every DPDPA
requirement. Our assessment maps data flows across the entire value chain and
identifies exactly where compliance gaps exist.
Privacy Framework Implementation
We design and implement an insurance-specific
privacy framework covering customer consent workflows, purpose mapping for
every data touchpoint across the policy lifecycle, data minimisation policies,
retention schedules aligned with both IRDAI and DPDPA requirements, and Data
Principal rights fulfilment mechanisms that work across insurers, agents, and
TPAs.
Consent Management Platform
Our Data Principal Consent Management tool
integrates with your policy administration system, agent portals, and
customer-facing platforms to capture granular, purpose-specific consent at
every touchpoint, manage consent withdrawal, and maintain audit-ready records
that demonstrate compliance.
Grievance Redressal System
Our automated Grievance Redressal platform
handles customer requests for data access, correction, and erasure,
coordinating fulfilment across insurer systems, agent records, and TPA
databases within DPDPA timelines.
DPO as a Service
Our Data Protection Officers provide ongoing
oversight of your insurance data processing, manage agent and TPA compliance,
handle regulatory communications with both IRDAI and the Data Protection Board,
oversee breach response, and ensure continuous DPDPA adherence across your
entire distribution and claims network.
Awareness Programme
We deliver DPDPA awareness training programmes
customised for the insurance sector, covering agents, underwriters, claims
teams, TPA personnel, call centre staff, and IT teams.
Third-Party Assessment
We evaluate every TPA, hospital network partner,
investigation agency, reinsurer, and technology vendor in your ecosystem,
ensuring appropriate data processing agreements and DPDPA-compliant security
safeguards are in place across the entire insurance value chain.
Chapter 8: Frequently Asked Questions (FAQs)
Q: Is the insurer or the agent
responsible for DPDPA compliance?
The insurer, as the primary Data Fiduciary,
bears ultimate responsibility for DPDPA compliance. However, if an agent
independently determines the purpose and means of processing (for example,
maintaining their own customer database for cross-selling), the agent will be a
Co-Data Fiduciary. In all cases, the insurer must ensure that agents processing
data on its behalf comply with the DPDPA through contractual agreements and
oversight.
Q: How does the DPDPA affect
health insurance claims processing through TPAs?
TPAs process highly sensitive health data on
behalf of insurers. The insurer must ensure that the TPA has a DPDPA-compliant
data processing agreement, implements adequate security safeguards for medical
records, retains claims data only as long as necessary, and has breach
notification procedures in place. The customer's consent for claims processing
must specifically cover data sharing with the TPA.
Q: Can insurers use customer data
for cross-selling other insurance products?
Not without separate consent. Data collected for
motor insurance underwriting cannot be used to market health or life insurance
products. Each marketing purpose requires its own specific consent. The
customer must be able to consent to policy servicing while declining cross-sell
communications.
Q: What happens to customer data
when a TPA contract ends?
When an insurer-TPA relationship ends, the
insurer must ensure that the TPA returns or securely deletes all customer data.
The data processing agreement should specify data return or deletion
procedures, timelines, and certification of deletion. Failure to address data
disposition at contract termination creates ongoing compliance risk.
Q: Does the DPDPA require insurers
to delete medical records after claim settlement?
The DPDPA requires data to be erased when the
purpose is fulfilled. However, IRDAI regulations may mandate retention of
claims records for specified periods. Insurers must balance IRDAI retention
requirements with DPDPA obligations. Data that is not required by IRDAI or for any
other regulatory compliance must be deleted once the claims purpose is
fulfilled.
Q: Are insurance aggregator and
comparison websites covered under the DPDPA?
Yes. Insurance aggregator websites
(PolicyBazaar, Coverfox, InsuranceDekho) that collect customer data for
generating quotes, comparing products, and facilitating purchases are Data
Fiduciaries under the DPDPA. They must obtain valid consent, implement security
safeguards, and comply with all Data Principal rights obligations.
Q: How should agents handle
customer data on personal devices?
Agents should not store customer KYC documents,
medical reports, or financial information on personal devices. Insurers should
provide secure agent portals for data collection and submission. Where agents
must use personal devices, mobile device management policies, encryption, and
remote wipe capabilities should be implemented. Customer data must be deleted
from agent devices once transmitted to the insurer.
Q: What are the penalties for
insurance data breaches under the DPDPA?
Penalties under the DPDPA range up to Rs 250
crore depending on the nature and severity of the violation. For insurance
breaches involving Aadhaar, medical records, and financial data of potentially
millions of policyholders, the exposure is severe. Beyond financial penalties,
insurance data breaches erode customer trust and can trigger IRDAI regulatory
action in addition to DPDPA penalties.
Protect Your Policyholders' Data. Comply with the DPDPA.
The insurance sector processes some
of the most sensitive personal data of any industry: identity documents,
medical records, financial information, and family details. The DPDPA holds
every entity in the insurance chain accountable.
DPDP Consultants provides the
expertise and technology to make your insurance operations fully compliant.
From Gap Assessments and Privacy Framework Implementation to Consent
Management, DPO as a Service, and Third-Party Assessments, we cover every aspect
of insurance data protection.
Contact us today:
Website: www.dpdpconsultants.com
Email: info@dpdpconsultants.com
Your policyholders trust you with their most personal
information. The DPDPA says you must earn that trust.
Disclaimer: This
document is prepared by DPDP Consultants for informational purposes only. It
does not constitute legal advice and should not be relied upon as a substitute
for professional legal counsel. The information contained herein is based on
the Digital Personal Data Protection Act, 2023, and publicly available
information about the DPDP Rules as of August 2026. Laws, regulations, and
their interpretations may change. Readers should consult qualified legal
professionals for advice specific to their circumstances. DPDP Consultants
assumes no liability for any actions taken or not taken based on the contents
of this document.