AMLEGALS — Strategic Lawyering

Data Minimisation in Insurance Underwriting Under DPDPA

Data Minimisation in Insurance Underwriting Under DPDPA

What you never collected can never leak.

The scene

The motor proposal form asked for marital status, education and employer. Underwriting used none of them. They had been added in 2009 for a cross-sell programme that closed in 2011.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

More data improves pricing.

Only data necessary for the specified purpose can be covered by consent.

Justify each field with a pricing or regulatory need.

Forms are set by regulators.

Regulators set minimums; insurers add the rest.

Remove what you added.

The field audit

For each field: who uses it, for what, and since when. Fields with no user go first.

Monday morning

01 Print your longest proposal form.

02 Cross out fields no one can justify.

03 Ship the shorter form.

Questions, answered plainly

Does DPDPA require data minimisation? +

Section 6 limits consent to personal data necessary for the specified purpose, and Section 8(7) requires erasure when the purpose is served. Together they require collecting and keeping only what is needed.

Can insurers collect data for future cross-selling? +

Collecting data for an unspecified future purpose is hard to reconcile with DPDPA's purpose-specific consent. Cross-selling should be a separate, notified purpose with its own consent.

Sector · Insurance Your agent's phone is part of your data estate. Read →

Insurance · Deep dive Five copies before the policy issues. Read →

Insurance · Deep dive The claims file is the most sensitive file you own. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).