Insurance companies in India process highly sensitive personal data — health history, financial status, nominee details, and biometric information. The DPDP Act 2023 applies fully alongside IRDAI sector regulations. Policyholders are Data Principals with rights to access their personal data, correct inaccuracies, and withdraw consent for non-essential processing.
DPDP + IRDAI dual compliance for insurance — policyholder consent, claims data protection, intermediary DPA, and breach notification.
Insurance companies collect personal data across the entire policy lifecycle: proposal stage (identity, health, financial), underwriting (medical reports, credit data), claim stage (injury/death records, treatment details), and renewal (updated health and financial data). Each stage requires DPDP-compliant consent.
Proposal Stage Consent: The proposal form must include a separate DPDP consent notice (not buried in terms and conditions) covering: data collected, purpose (underwriting, claims, regulatory reporting), third parties who will receive data (reinsurers, TPAs, surveyors), retention period, and policyholder rights. The consent must be obtained before any data is collected or submitted to underwriting.
Health Data Consent: Medical reports, test results, and health history shared in proposals and claims are likely to be classified as sensitive personal data. Enhanced consent — specific, separate, and clearly informed — is required. Bulk health data sharing with reinsurers requires a separate consent event unless disclosed at the point of proposal.
Claims Stage Consent: Claims processing often requires new data collection not covered by the original proposal consent (police reports, hospital bills, forensic reports, employer salary details). Issue a supplementary consent notice at the point of each new data collection event during claims.
IRDAI has issued multiple data-related circulars and master circulars over the past decade. The DPDP Act 2023 adds a comprehensive privacy layer. Key overlap and divergence areas:
Areas of Convergence: (a) Customer disclosure obligations — IRDAI product disclosure requirements overlap with DPDP notice obligations. Meeting DPDP notice standards typically satisfies IRDAI disclosure rules. (b) Data security — IRDAI cyber security guidelines align with DPDP S.8 security safeguards. ISO 27001 or equivalent implementation serves both. (c) Data retention — IRDAI mandates record retention for regulatory purposes; DPDP adds a minimisation overlay for data beyond regulatory retention periods.
Areas of Divergence: (a) Consent withdrawal — DPDP gives policyholders the right to withdraw consent for non-essential processing. IRDAI-mandated data uses (claims verification, fraud detection, regulatory reporting) are not affected by withdrawal. Document the legal basis for each processing activity clearly. (b) Third-party sharing — DPDP requires disclosure of all third-party data recipients at the time of consent; many IRDAI-mandated sharing relationships (IRDAI repositories, government databases) need to be explicitly listed in the consent notice.
Action Items from Gap Analysis: Update proposal form consent notices to list all third-party recipients. Implement a policyholder rights portal for access and correction requests. Review intermediary contracts for DPDP compliance clauses. Train claims staff on handling policyholder data rights requests during claims processing.
Insurance companies occupy a uniquely data-intensive position: they collect health data, financial data, nominee details, and in some cases biometric data — all in the course of a single policyholder relationship. The DPDP Act 2023 applies to all of this processing alongside IRDAI sector requirements.
IRDAI has been proactive about cyber security, but the DPDP Act introduces new obligations around consent specificity, data principal rights, and third-party data sharing disclosure that IRDAI circulars do not fully address. Insurance companies need a unified compliance programme that addresses both regulatory frameworks.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.