Insurance runs on personal data: proposal forms, KYC, medical history, claims documents, bank details and nominee information. Insurers, brokers, corporate agents, web aggregators and TPAs all handle this data, and each is a Data Fiduciary or Data Processor under the Digital Personal Data Protection Act 2023.
How DPDP applies to insurance
- Many hands on one policy: a single health policy can involve an aggregator, an agent, the insurer, a TPA and a network hospital. Who is the Fiduciary and who is the Processor must be clear for each flow, and written into contracts.
- Health and claims data: medical records gathered for underwriting and claims deserve the strongest safeguards, as a breach can attract penalties of up to ₹250 crore.
- Regulatory retention: where insurance regulation or other law requires records to be kept, that continues to apply. DPDP erasure duties apply once no such requirement remains.
- Nominees and dependants: policies carry personal data of nominees and family members who never signed anything. Notice and lawful basis must cover them too.
Gaps commonly found in insurance
- Lead data from aggregators and call centres reused for cross-selling without fresh consent
- Proposal forms bundling consent for underwriting, marketing and data sharing
- Agents and POSPs storing customer documents on personal phones and messaging apps
- Claims documents shared between TPAs, hospitals and investigators by email with no controls
- Lapsed-policy and rejected-proposal data kept with no documented retention basis
- No mechanism to honour consent withdrawal across the insurer and its intermediaries
Priorities before May 2027
- Map data flows across the distribution chain, the insurer, TPAs and hospitals.
- Define Fiduciary and Processor roles for each flow, and update contracts to match.
- Separate consent for underwriting, servicing, marketing and data sharing.
- Give agents and POSPs secure tools so customer documents stay off personal devices.
- Set retention rules that reconcile regulatory requirements with DPDP erasure.
See DPDP Rules 2025 explained for the timeline, and the DPDP audit checklist for a full self-assessment.
