AMLEGALS — Strategic Lawyering

DPDPA for Insurers, Brokers and TPAs

DPDPA for Insurers, Brokers and TPAs

The policy is yours. The proposal form is on someone's WhatsApp.

The scene

The proposal form was filled in at a customer's home, photographed by the agent, sent to a branch group chat, uploaded by an assistant, and emailed to underwriting. Five copies before the policy was issued. One company controlled one of them.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Agents are regulated separately.

Agent licensing is not a data processing contract.

Govern agents' data handling as processing on your behalf.

Claims data is the TPA's responsibility.

TPAs process for you; their failure is your exposure.

Contract, audit and rehearse with every TPA.

We need everything for underwriting.

Section 6 limits consent to data necessary for the purpose.

Collect for the risk, not for the file.

After the claim closes

Claims files carry diagnoses, bank details and family information. Retention should follow the law and the limitation period, then end.

The full Insurance briefing 3 deep dives

Deep dive 01 →

Five copies before the policy issues.

The agent carries your brand and your liability in the same bag.

Deep dive 02 →

The claims file is the most sensitive file you own.

The Act has no ‘sensitive’ label. The Board will know sensitive when it sees it.

Deep dive 03 →

Collect for the risk, not for the file.

What you never collected can never leak.

Monday morning

01 Trace one proposal form from home visit to policy issue.

02 Count the copies.

03 Close the channel with the most copies first.

Questions, answered plainly

Are insurance agents and brokers Data Processors under DPDPA? +

When they collect and handle customer data on behalf of an insurer, they generally act as Data Processors, and the insurer remains responsible. Some brokers may act as independent fiduciaries for their own purposes.

Can insurers keep claims data indefinitely under DPDPA? +

No. Data should be erased once its purpose is served, unless retention is required by law. Insurers should align retention with regulatory requirements and limitation periods.

Sector · HR & Staffing The candidate you never hired is still your Data Principal. Read →

Sector · Hospitality & Travel Guests check out. Their passports stay. Read →

Sector · Gaming Your fastest-growing segment may legally be children. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).