DPDP Act 2023 Compliance for Insurance & InsurTech Companies in India (2026 Guide)
Why Insurance Data Protection Is Different
Insurance is one of the few sectors where a single customer touchpoint — buying a health or life policy — generates financial data, medical history, family and nominee details, occupation and income data, and in many cases biometric or video KYC data, all in one proposal form. Under the DPDP Act 2023, none of this is legally classified as “sensitive” personal data the way GDPR treats health data, but the practical risk profile is exactly what you’d expect from sensitive data: a leaked underwriting file can expose someone’s pre-existing medical conditions, income bracket, and family structure in a single document.
On top of this, insurers rarely process this data alone. A typical policy touches the insurer, a broker or corporate agent, a third-party administrator (TPA) for claims, possibly a reinsurer, and increasingly an InsurTech distribution platform or comparison aggregator — each one a separate Data Fiduciary or Data Processor relationship that needs its own contractual and security treatment.
Many insurers and brokers still treat DPDP compliance as “we already do IRDAI cybersecurity” — but the two regimes have different regulators, different notification timelines, and different individual-rights obligations. Being IRDAI-compliant does not automatically make you DPDP-compliant, and vice versa.
7 Core DPDP Obligations for Insurance & InsurTech
1. Consent for Proposal Form Data
Consent for the personal data collected on a proposal form (health history, income, nominee details) must be specific to insurance underwriting and claims purposes — not bundled with generic marketing consent for cross-sell of other financial products. See our Consent definition for the exact statutory standard.
2. Notice at the Point of Sale
Whether sold through an agent, broker, bancassurance channel, or a direct InsurTech app, the Data Principal must receive a clear notice describing what data is collected and why, before or at the point consent is captured — not buried in the policy wording delivered after purchase.
3. Purpose Limitation Across the Distribution Chain
Data shared with a broker for policy issuance cannot be reused by that broker for unrelated marketing without fresh consent. Each hand-off in the distribution chain needs its own documented purpose.
4. Data Processing Agreements With Every Intermediary
Brokers, TPAs, reinsurers, InsurTech platforms, and any vendor processing policyholder data on the insurer’s behalf need a Data Processing Agreement under Section 8, defining scope, security obligations, and data return/deletion on termination.
5. Rights Requests From Policyholders and Nominees
Policyholders (and in claim scenarios, nominees) can request access, correction, or erasure of their data. Erasure requests need careful handling — insurers typically have a “legitimate use” basis under Section 7 to retain policy and claims records for the statutory retention period even after a deletion request, but this must be documented, not assumed.
6. Security Safeguards for Health and Financial Data
Section 8(5)’s “reasonable security safeguards” standard applies on top of, not instead of, IRDAI’s specific encryption and access control requirements — see the overlap section below.
7. Grievance Redressal Aligned With IRDAI’s Existing Channels
Most insurers already run an IRDAI-mandated grievance redressal mechanism (Integrated Grievance Management System). Your DPDP Grievance Officer function should be integrated with this existing channel rather than creating a confusing second complaints process for policyholders.
DPDP Act vs IRDAI Information & Cyber Security Guidelines, 2023
IRDAI notified its Information and Cyber Security Guidelines in 2023, replacing the earlier 2017 guidelines, with a March 2025 update specifically addressing cyber incident and crisis preparedness. These guidelines apply not only to insurers but to brokers, corporate agents, web aggregators, TPAs, insurance marketing firms, insurance repositories, and Insurance Self-Network Platforms — effectively the entire InsurTech and intermediary ecosystem.
| Requirement | DPDP Act 2023 | IRDAI Cyber Security Guidelines 2023 |
|---|---|---|
| Regulator | Data Protection Board of India | IRDAI + CERT-In |
| Breach notification timeline | Without delay to DPBI, detailed report typically expected promptly thereafter | Within 6 hours to IRDAI and CERT-In for cyber incidents |
| Governance role required | DPO (mandatory only for Significant Data Fiduciaries) | Chief Information Security Officer (CISO), reporting to MD/CEO or via CRO |
| Log retention | Not specified; “reasonable” standard | 180-day rolling ICT and application log retention |
| Security testing | Not prescriptive; DPIA for Significant Data Fiduciaries | Periodic VAPT and annual audit, submitted to IRDAI within 90 days of fiscal year-end |
| Encryption | “Reasonable security safeguards” (Section 8(5)) | Encryption at rest, in transit, and backup; FIPS 140-2 preferred for hardware keys |
| Individual rights | Access, correction, erasure, grievance, nomination | Not an individual-rights framework — focused on institutional security controls |
The practical implication: an insurer that builds its security programme around IRDAI’s 2023 guidelines already has most of the technical controls DPDP’s “reasonable security safeguards” standard expects. What’s usually missing is the individual-rights layer — consent capture, notice, access/correction/erasure workflows, and DPA coverage across the intermediary chain — which IRDAI’s guidelines don’t address at all.
The Insurance Data-Sharing Chain
A single policy can pass personal data through several hands, each with a distinct DPDP role:
Every arrow in this chain needs either a documented consent/notice trail or a Data Processing Agreement. This is the single most common gap our assessments find in insurance and InsurTech clients — broker and TPA contracts that predate the DPDP Act and were never updated with data protection clauses.
Dual Breach Notification: DPBI + IRDAI/CERT-In
Insurance is one of the few sectors in India where a single cyber incident can trigger two parallel, independently-timed regulatory notification obligations:
- To the Data Protection Board of India: under Rule 7 of the DPDP Rules 2025, with no materiality threshold — every breach requires notification, plus individual notice to affected policyholders.
- To IRDAI and CERT-In: within 6 hours of the cyber incident, per IRDAI’s March 2025 update to the 2023 Cyber Security Guidelines, followed by a documented Cyber Crisis Management Plan response.
A 6-hour IRDAI/CERT-In clock and a “without delay” DPBI clock running in parallel means your incident response plan needs pre-built notification templates and a single internal escalation path that feeds both regulators — not two separate, uncoordinated response processes built after the fact.
Penalties & Enforcement Risk
Under the DPDP Act, the Data Protection Board of India can impose penalties of up to ₹250 crore per violation, with the highest penalty tier specifically tied to failure to implement reasonable security safeguards leading to a breach. See our full DPDP penalties guide for the complete tier structure. Separately, IRDAI has its own enforcement powers under the Insurance Act and can act against regulated entities and intermediaries for cyber security guideline non-compliance, independent of any DPDP action.
15-Point DPDP Readiness Checklist for Insurers & InsurTechs
- Proposal form consent language is specific to underwriting/claims, not bundled with cross-sell marketing consent
- Notice is delivered at point of sale across every channel (agent, broker, bancassurance, app)
- Data Processing Agreements are in place with every broker, TPA, and reinsurer touching policyholder data
- InsurTech distribution and comparison platforms have documented Data Fiduciary vs Processor status
- A Grievance Officer function exists and is integrated with your existing IRDAI grievance channel
- Access, correction, and erasure request workflows are documented and tested
- Retention basis for policy/claims records post-erasure-request is documented under Section 7
- CISO is appointed and reports to MD/CEO or via CRO, per IRDAI 2023 guidelines
- ICT and application logs are retained for a rolling 180 days
- Annual VAPT is scheduled and audit reports are filed with IRDAI within 90 days of fiscal year-end
- Encryption is applied at rest, in transit, and in backup, with FIPS 140-2 hardware keys where feasible
- A joint incident response plan covers both the 6-hour IRDAI/CERT-In clock and DPBI notification
- Cross-border data flows to reinsurers or offshore InsurTech infrastructure are mapped and assessed
- Employee and agent training covers both DPDP consent principles and IRDAI security policy
- A DPIA has been considered for any AI-based underwriting, fraud detection, or claims automation model
Our Methodology
We assess insurers, brokers, TPAs, and InsurTech platforms against both the DPDP Act and IRDAI’s Information and Cyber Security Guidelines in a single engagement, rather than treating them as separate projects that duplicate evidence-gathering. A typical engagement covers:
- Data flow mapping across the full distribution chain — agents, brokers, TPAs, reinsurers, InsurTech platforms
- Gap assessment against both DPDP obligations and IRDAI’s 2023 guidelines side by side
- Contract review of existing broker, TPA, and vendor agreements for missing data protection clauses
- Remediation roadmap prioritised by risk and regulatory exposure, not a generic checklist
- Implementation support for consent flows, notices, DPAs, and incident response templates
We work with organisations across financial services, including insurance distribution — our client roster spans SaaS, e-commerce, healthcare, and financial services companies including Renewbuy. See our case studies for documented client outcomes.
Get Your Insurance DPDP + IRDAI Gap Assessment
One assessment, two regulatory frameworks mapped together — written, RAG-scored report in 5 business days.
Book My Free Assessment →Frequently Asked Questions
Does being IRDAI cyber security compliant automatically make an insurer DPDP compliant?
No. IRDAI’s Information and Cyber Security Guidelines 2023 focus on institutional security controls — encryption, CISO governance, log retention, VAPT — while the DPDP Act adds an individual-rights layer: consent, notice, access, correction, and erasure. An insurer can be fully IRDAI-compliant and still have significant DPDP gaps, particularly around consent language and Data Processing Agreements with brokers and TPAs.
Do brokers and TPAs need to comply with the DPDP Act separately from the insurer?
Yes. Depending on the relationship, a broker or TPA may be an independent Data Fiduciary (if it decides its own purposes for processing) or a Data Processor acting on the insurer’s instructions. Either way, IRDAI’s Cyber Security Guidelines already apply directly to brokers, corporate agents, TPAs, and web aggregators, and DPDP obligations apply on top based on their specific data-handling role.
What happens if a data breach affects both policyholder personal data and IRDAI-regulated systems?
Both notification obligations apply in parallel: IRDAI and CERT-In must be notified within 6 hours per the March 2025 update to the 2023 Cyber Security Guidelines, while the Data Protection Board of India must also be notified without delay under the DPDP Rules 2025, with individual notice to affected policyholders. These are two separate regulatory relationships, not a single combined filing.
Is health data collected during insurance underwriting treated as “sensitive” under the DPDP Act?
No. Unlike GDPR, the DPDP Act does not create a separate “sensitive personal data” category with heightened default obligations. All personal data, including health underwriting data, is subject to the same uniform standard. In practice, though, IRDAI’s guidelines and general prudence still call for treating health and financial underwriting data with the highest level of security controls available.
Can an insurer refuse a policyholder’s erasure request for claims records?
In most cases, yes, for records the insurer is legally required to retain — typically relying on the “legitimate uses” basis under Section 7 for compliance with law or contractual retention requirements. This must be documented as a specific policy decision, not simply assumed, and the policyholder should still receive a clear response explaining the retention basis rather than being ignored.
Related Resources
- DPDP Act for BFSI, NBFC & Fintech
- DPDP Act Compliance Checklist India 2026
- DPDP Act Glossary of Key Terms
- DPDP Act Penalties India 2026
- Data Processing Agreement Under DPDP Act
- DPIA Under DPDP Act — When & How
- DPDP Act Compliance Services
- Virtual CISO Services India
- ISO 27001 Consultant India — Cost, Timeline & Checklist
- SOC 2 Compliance India — Readiness & Cost