AMLEGALS — Strategic Lawyering
Insurance — Intimate Data, Single Standard

DPDPA for Insurance

Insurance processes the most intimate personal data in Indian financial services. Diagnosis codes. Discharge summaries. Driving behaviour. Family history. It does so under a statute that contains no category of sensitive personal data at all.

IRDAI OverlayHealth DataClaims ChainReinsurance × Section 166 Sub Sectors

The absence of a sensitive data category is not a lower standard. It is the removal of a label from data that has not become any less intimate.

The Position in One Paragraph

How DPDPA applies to insurers in India

DPDPA applies to every insurer, reinsurer, broker, corporate agent, third party administrator, web aggregator and InsurTech platform that processes digital personal data in India. There is no revenue threshold and no size threshold.

The Act contains no category of sensitive personal data. One standard applies to health records, driving telematics and a mobile number alike. Section 33(2) then directs the Board to weigh the type and nature of the personal data affected when fixing a penalty, which restores gravity at the enforcement stage.

The operational difficulty in insurance is not the notice. It is the chain. One claim moves through a hospital, a TPA, a surveyor, a repricing engine and a bank, and each participant must hold a lawful basis or a Section 8(2) contract.

Substantive obligations commence on 13 May 2027. The claims chain takes longer than that to redesign.

Sub Sector Analysis

DPDPA Exposure by Insurance Sub Sector

Life Insurers

Regulator: IRDAI
  • Proposal stage medical questionnaires and tele underwriting recordings
  • Persistency and lapse prediction models built on policyholder behaviour
  • Nominee, assignee and beneficiary data processed without their own consent
  • Long tenure retention against the erasure obligation in Section 8(7) and Rule 8
  • Agency force access to policyholder records across a distribution network

Health Insurers and TPAs

Regulator: IRDAI
  • Diagnosis codes, discharge summaries and hospital bills flowing through the claims chain
  • Third party administrator status as processor and the Section 8(2) contract that must bind it
  • Fraud, waste and abuse analytics performed on medical records without a separate lawful basis
  • Network hospital portals as an uncontrolled access surface
  • Family floater policies where one proposer consents for several Data Principals

General Insurers

Regulator: IRDAI
  • Motor telematics and driving behaviour scores collected from devices and applications
  • Surveyor and investigator reports containing third party personal data
  • Garage and workshop networks receiving customer contact data
  • Geolocation captured in claims applications for accident verification
  • Retention of rejected claims files and the purpose justification for holding them

Brokers, Corporate Agents and Web Aggregators

Regulator: IRDAI
  • Prospect data collected for comparison and then monetised as leads
  • Fiduciary status in their own right rather than processor status
  • Bundled consent across quote, callback and marketing on a single screen
  • Call recording and outbound telesales scripts as a consent record
  • Onward sale of unconverted prospect data, which no notice usually discloses

Reinsurers and Cross Border Cession

Regulator: IRDAI
  • Cession bordereaux carrying identified claims data outside India
  • Section 16 permissive default read with any higher restriction in other law
  • Restriction ready drafting so a future notification does not break the treaty
  • Foreign reinsurance branch and service company access to Indian claims systems
  • Audit and actuarial review by a group entity located outside India

InsurTech and Distribution Platforms

Regulator: IRDAI
  • Software as a service platforms holding insurer data across multiple tenants
  • Model training on policyholder and claims data without a stated purpose
  • Wearable and lifestyle data collected for wellness and used for pricing
  • Application software development kits transmitting device data to third parties
  • Chat and voice assistants recording health disclosures
Pressure Points

Eight Obligations That Reshape an Insurance Book

No Sensitive Category, Higher Gravity

DPDPA has no sensitive personal data class. Insurers read that as relief. Section 33(2) directs the Board to weigh the type and nature of the personal data affected when fixing a penalty. The class disappeared. The exposure did not.

Section 33(2)

The Claims Chain Is a Processor Chain

One claim touches a hospital, a TPA, a surveyor, an investigator, a repricing engine and a bank. Every hop needs a lawful basis, and every processor needs a contract that satisfies Section 8(2).

Section 8(2)

Consent Given by Someone Else

Family floater, group and employer funded policies collect data about people who never met the insurer. The proposer consents. The insured members are separate Data Principals with their own rights.

Section 6, Section 11

Children in Group and Family Cover

Dependent children under group and floater policies bring Section 9 into an insurer's core book. Verifiable parental consent, no behavioural monitoring and no targeted advertising, subject to the exemptions in the Fourth Schedule.

Section 9, Rule 10

Erasure Against Statutory Retention

Section 8(7) with Rule 8 requires erasure once the purpose is served. Insurance, tax and anti money laundering law require retention. Reconciliation is a documented retention register mapped to the source of each obligation.

Section 8(7), Rule 8

Four Notification Tracks, One Incident

A breach in a claims platform triggers intimation to affected Data Principals and the Board without delay with a detailed report inside 72 hours under Rule 7, alongside CERT-In reporting and the insurer's own regulatory reporting.

Section 8(6), Rule 7

Rights Response Inside 90 Days

Rule 14 sets the outer limit for responding to a Data Principal request. A claims book with paper files and legacy systems cannot produce a full summary of processing inside that window without redesign.

Section 11, Rule 14

Significant Data Fiduciary Exposure

Volume of personal data, sensitivity of the data and risk to Data Principals are among the factors on which the Central Government may notify a Data Fiduciary as Significant under Section 10. Large health books sit squarely inside that description.

Section 10, Rule 13
The Test

One Claim, Traced End to End

Pick one settled health claim from last year. Now list every entity that held the diagnosis code. The hospital. The TPA. The repricing vendor. The investigator. The analytics platform. The reinsurer.

For each of them, produce the lawful basis and the contract that satisfies Section 8(2). Then produce the retention justification for the copy each of them still holds.

Very few insurers in India can complete that exercise today. It is not a technology gap. It is an accountability gap that no platform can close.

The Board will not ask for your privacy policy. It will ask for the chain.

Insurance Specific DPDPA Advisory

AMLEGALS maps the claims and distribution chain, fixes processor status for every participant, rebuilds the proposal and claims notice, and reconciles erasure against sectoral retention.

Request a Confidential Briefing

Our data privacy counsel will reach out within one working day.

Insights & Answers

What insurers and boards are asking

Does DPDPA treat health data as sensitive personal data?

No. The Act creates no category of sensitive personal data and applies one standard to all digital personal data. That is not relief. Section 33(2) requires the Board to weigh the nature, gravity and duration of the breach and the type and nature of the personal data affected. Health data raises gravity without needing a separate statutory class.

Can an insurer rely on Section 7 legitimate uses for underwriting?

Only partly. Section 7 covers specified legitimate uses including compliance with law and processing to respond to a medical emergency involving a threat to life or immediate health. Ordinary underwriting, risk scoring, persistency modelling, cross selling and renewal marketing are commercial purposes chosen by the insurer. Those need consent under Section 6 preceded by an itemised notice under Section 5.

Is a third party administrator a processor or a fiduciary?

A TPA adjudicating claims under the insurer's instructions is a Data Processor and must be engaged under a valid contract as required by Section 8(2), with the insurer remaining accountable to the Data Principal. Where the TPA decides its own analytics, retention or onward use, it determines means and becomes a Data Fiduciary for that processing. The contractual label does not settle it.

Are transfers of policyholder data to a foreign reinsurer permitted?

Section 16 permits transfer outside India except to a country or territory restricted by the Central Government by notification, and it preserves any higher restriction imposed by another law in force. The practical instruction is to paper reinsurance treaties, cession data flows and shared claims systems with restriction ready terms so that a future notification does not break an existing treaty.

How does DPDPA affect claims fraud analytics?

Fraud analytics on medical records is processing, and it needs a lawful basis of its own. Where it is performed under a statutory or regulatory obligation, that basis must be identified and documented. Where it is performed as a commercial loss control measure, consent and an itemised notice are required, and the notice must actually disclose that claims data will be profiled.

What does Section 9 mean for family floater and group health policies?

Dependent children are Data Principals. Section 9 requires verifiable parental consent before processing a child's personal data and prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 prescribes the manner of obtaining verifiable parental consent and the Fourth Schedule sets out exempted classes and purposes, including certain health and safety related processing.

Will insurers be notified as Significant Data Fiduciaries?

Section 10 leaves that to the Central Government, on factors that include the volume and sensitivity of personal data processed and the risk to the rights of Data Principals. Nobody can promise an outcome. The prudent position for a large health or life book is to build the Rule 13 obligations, namely the annual Data Protection Impact Assessment, the annual audit, algorithmic due diligence and a Data Protection Officer based in India, before notification rather than after it.

What should an insurer do before 13 May 2027?

Four things in order. Map the claims and distribution chain and fix processor status for every participant. Rebuild the proposal and claims notice to satisfy Section 5. Segregate statutory processing from commercial processing of the same data. Build the retention register that reconciles Rule 8 erasure against sectoral retention obligations.