The Act has no ‘sensitive’ label. The Board will know sensitive when it sees it.
The scene
The TPA's shared drive held two years of discharge summaries, uploaded by hospitals, downloaded by claims staff, emailed to investigators. When a laptop was stolen, nobody could say which summaries were on it.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
The TPA is regulated separately.
Sectoral licensing does not transfer the insurer's DPDPA responsibility.
Contract, audit and rehearse breach response with each TPA.
Health data is treated like other data.
Section 33 lets the Board weigh the type of data when deciding penalty.
Protect health data above the baseline.
The breach drill for claims
Assume a TPA laptop is lost. Who tells you, how fast, and can you list the affected policyholders within 72 hours? Rehearse until the answer is yes.
Monday morning
01 List every place discharge summaries are stored.
02 Check TPA contracts for breach notice times.
03 Run the lost-laptop drill.
Questions, answered plainly
Are TPAs Data Processors for insurers under DPDPA? +
When processing claims data on an insurer's behalf, TPAs generally act as Data Processors. The insurer remains responsible for compliance.
Is health data given extra protection under DPDPA? +
DPDPA does not create a separate category, but the Board considers the type and nature of personal data when determining penalties, so breaches of health data are likely to be viewed seriously.
Sector · Insurance Your agent's phone is part of your data estate. Read →
Insurance · Deep dive Five copies before the policy issues. Read →
Insurance · Deep dive Collect for the risk, not for the file. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).