DPDPA for Insurance
Insurance processes the most intimate personal data in Indian financial services. Diagnosis codes. Discharge summaries. Driving behaviour. Family history. It does so under a statute that contains no category of sensitive personal data at all.
The absence of a sensitive data category is not a lower standard. It is the removal of a label from data that has not become any less intimate.
How DPDPA applies to insurers in India
DPDPA applies to every insurer, reinsurer, broker, corporate agent, third party administrator, web aggregator and InsurTech platform that processes digital personal data in India. There is no revenue threshold and no size threshold.
The Act contains no category of sensitive personal data. One standard applies to health records, driving telematics and a mobile number alike. Section 33(2) then directs the Board to weigh the type and nature of the personal data affected when fixing a penalty, which restores gravity at the enforcement stage.
The operational difficulty in insurance is not the notice. It is the chain. One claim moves through a hospital, a TPA, a surveyor, a repricing engine and a bank, and each participant must hold a lawful basis or a Section 8(2) contract.
Substantive obligations commence on 13 May 2027. The claims chain takes longer than that to redesign.
DPDPA Exposure by Insurance Sub Sector
Life Insurers
Regulator: IRDAI- ›Proposal stage medical questionnaires and tele underwriting recordings
- ›Persistency and lapse prediction models built on policyholder behaviour
- ›Nominee, assignee and beneficiary data processed without their own consent
- ›Long tenure retention against the erasure obligation in Section 8(7) and Rule 8
- ›Agency force access to policyholder records across a distribution network
Health Insurers and TPAs
Regulator: IRDAI- ›Diagnosis codes, discharge summaries and hospital bills flowing through the claims chain
- ›Third party administrator status as processor and the Section 8(2) contract that must bind it
- ›Fraud, waste and abuse analytics performed on medical records without a separate lawful basis
- ›Network hospital portals as an uncontrolled access surface
- ›Family floater policies where one proposer consents for several Data Principals
General Insurers
Regulator: IRDAI- ›Motor telematics and driving behaviour scores collected from devices and applications
- ›Surveyor and investigator reports containing third party personal data
- ›Garage and workshop networks receiving customer contact data
- ›Geolocation captured in claims applications for accident verification
- ›Retention of rejected claims files and the purpose justification for holding them
Brokers, Corporate Agents and Web Aggregators
Regulator: IRDAI- ›Prospect data collected for comparison and then monetised as leads
- ›Fiduciary status in their own right rather than processor status
- ›Bundled consent across quote, callback and marketing on a single screen
- ›Call recording and outbound telesales scripts as a consent record
- ›Onward sale of unconverted prospect data, which no notice usually discloses
Reinsurers and Cross Border Cession
Regulator: IRDAI- ›Cession bordereaux carrying identified claims data outside India
- ›Section 16 permissive default read with any higher restriction in other law
- ›Restriction ready drafting so a future notification does not break the treaty
- ›Foreign reinsurance branch and service company access to Indian claims systems
- ›Audit and actuarial review by a group entity located outside India
InsurTech and Distribution Platforms
Regulator: IRDAI- ›Software as a service platforms holding insurer data across multiple tenants
- ›Model training on policyholder and claims data without a stated purpose
- ›Wearable and lifestyle data collected for wellness and used for pricing
- ›Application software development kits transmitting device data to third parties
- ›Chat and voice assistants recording health disclosures
Eight Obligations That Reshape an Insurance Book
No Sensitive Category, Higher Gravity
DPDPA has no sensitive personal data class. Insurers read that as relief. Section 33(2) directs the Board to weigh the type and nature of the personal data affected when fixing a penalty. The class disappeared. The exposure did not.
Section 33(2)The Claims Chain Is a Processor Chain
One claim touches a hospital, a TPA, a surveyor, an investigator, a repricing engine and a bank. Every hop needs a lawful basis, and every processor needs a contract that satisfies Section 8(2).
Section 8(2)Consent Given by Someone Else
Family floater, group and employer funded policies collect data about people who never met the insurer. The proposer consents. The insured members are separate Data Principals with their own rights.
Section 6, Section 11Children in Group and Family Cover
Dependent children under group and floater policies bring Section 9 into an insurer's core book. Verifiable parental consent, no behavioural monitoring and no targeted advertising, subject to the exemptions in the Fourth Schedule.
Section 9, Rule 10Erasure Against Statutory Retention
Section 8(7) with Rule 8 requires erasure once the purpose is served. Insurance, tax and anti money laundering law require retention. Reconciliation is a documented retention register mapped to the source of each obligation.
Section 8(7), Rule 8Four Notification Tracks, One Incident
A breach in a claims platform triggers intimation to affected Data Principals and the Board without delay with a detailed report inside 72 hours under Rule 7, alongside CERT-In reporting and the insurer's own regulatory reporting.
Section 8(6), Rule 7Rights Response Inside 90 Days
Rule 14 sets the outer limit for responding to a Data Principal request. A claims book with paper files and legacy systems cannot produce a full summary of processing inside that window without redesign.
Section 11, Rule 14Significant Data Fiduciary Exposure
Volume of personal data, sensitivity of the data and risk to Data Principals are among the factors on which the Central Government may notify a Data Fiduciary as Significant under Section 10. Large health books sit squarely inside that description.
Section 10, Rule 13One Claim, Traced End to End
Pick one settled health claim from last year. Now list every entity that held the diagnosis code. The hospital. The TPA. The repricing vendor. The investigator. The analytics platform. The reinsurer.
For each of them, produce the lawful basis and the contract that satisfies Section 8(2). Then produce the retention justification for the copy each of them still holds.
Very few insurers in India can complete that exercise today. It is not a technology gap. It is an accountability gap that no platform can close.
The Board will not ask for your privacy policy. It will ask for the chain.
Related DPDPA Resources
DPDPA for BFSI
Sector convergence overview
DPDPA for Healthcare
Provider side obligations
Health Data Privacy
Processing standards
Processor Agreements
Section 8(2) drafting
Cross Border Transfers
Section 16 framework
Children's Data
Section 9 and Rule 10
Significant Data Fiduciary
Section 10 and Rule 13
Breach Response
Rule 7 staged intimation
Insurance Specific DPDPA Advisory
AMLEGALS maps the claims and distribution chain, fixes processor status for every participant, rebuilds the proposal and claims notice, and reconciles erasure against sectoral retention.
Our data privacy counsel will reach out within one working day.
What insurers and boards are asking
Does DPDPA treat health data as sensitive personal data?
No. The Act creates no category of sensitive personal data and applies one standard to all digital personal data. That is not relief. Section 33(2) requires the Board to weigh the nature, gravity and duration of the breach and the type and nature of the personal data affected. Health data raises gravity without needing a separate statutory class.
Can an insurer rely on Section 7 legitimate uses for underwriting?
Only partly. Section 7 covers specified legitimate uses including compliance with law and processing to respond to a medical emergency involving a threat to life or immediate health. Ordinary underwriting, risk scoring, persistency modelling, cross selling and renewal marketing are commercial purposes chosen by the insurer. Those need consent under Section 6 preceded by an itemised notice under Section 5.
Is a third party administrator a processor or a fiduciary?
A TPA adjudicating claims under the insurer's instructions is a Data Processor and must be engaged under a valid contract as required by Section 8(2), with the insurer remaining accountable to the Data Principal. Where the TPA decides its own analytics, retention or onward use, it determines means and becomes a Data Fiduciary for that processing. The contractual label does not settle it.
Are transfers of policyholder data to a foreign reinsurer permitted?
Section 16 permits transfer outside India except to a country or territory restricted by the Central Government by notification, and it preserves any higher restriction imposed by another law in force. The practical instruction is to paper reinsurance treaties, cession data flows and shared claims systems with restriction ready terms so that a future notification does not break an existing treaty.
How does DPDPA affect claims fraud analytics?
Fraud analytics on medical records is processing, and it needs a lawful basis of its own. Where it is performed under a statutory or regulatory obligation, that basis must be identified and documented. Where it is performed as a commercial loss control measure, consent and an itemised notice are required, and the notice must actually disclose that claims data will be profiled.
What does Section 9 mean for family floater and group health policies?
Dependent children are Data Principals. Section 9 requires verifiable parental consent before processing a child's personal data and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 prescribes the manner of obtaining verifiable parental consent and the Fourth Schedule sets out exempted classes and purposes, including certain health and safety related processing.
Will insurers be notified as Significant Data Fiduciaries?
Section 10 leaves that to the Central Government, on factors that include the volume and sensitivity of personal data processed and the risk to the rights of Data Principals. Nobody can promise an outcome. The prudent position for a large health or life book is to build the Rule 13 obligations, namely the annual Data Protection Impact Assessment, the annual audit, algorithmic due diligence and a Data Protection Officer based in India, before notification rather than after it.
What should an insurer do before 13 May 2027?
Four things in order. Map the claims and distribution chain and fix processor status for every participant. Rebuild the proposal and claims notice to satisfy Section 5. Segregate statutory processing from commercial processing of the same data. Build the retention register that reconciles Rule 8 erasure against sectoral retention obligations.
