DPDP Audits

DPDP Compliance for Insurers, Brokers and TPAs

How the DPDP Act 2023 applies to insurers, brokers, agents and TPAs handling policyholder and health data, and where compliance gaps usually sit.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 25 September 2026

Insurance runs on personal data: proposal forms, KYC, medical history, claims documents, bank details and nominee information. Insurers, brokers, corporate agents, web aggregators and TPAs all handle this data, and each is a Data Fiduciary or Data Processor under the Digital Personal Data Protection Act 2023.

How DPDP applies to insurance

Gaps commonly found in insurance

Priorities before May 2027

  1. Map data flows across the distribution chain, the insurer, TPAs and hospitals.
  2. Define Fiduciary and Processor roles for each flow, and update contracts to match.
  3. Separate consent for underwriting, servicing, marketing and data sharing.
  4. Give agents and POSPs secure tools so customer documents stay off personal devices.
  5. Set retention rules that reconcile regulatory requirements with DPDP erasure.

See DPDP Rules 2025 explained for the timeline, and the DPDP audit checklist for a full self-assessment.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.