An insurer must obtain free, specific, informed and unambiguous consent from a policyholder before processing their personal data for anything beyond what is strictly necessary to underwrite and service the policy. Under the DPDP Act 2023, consent taken through a proposal form for the contract does not automatically extend to marketing, cross-selling, or sharing with group companies and reinsurers — those need their own consent or a lawful basis. IRDAI norms on policyholder data and outsourcing sit on top of DPDP, so insurers face an overlapping obligation. This checker assesses whether your policyholder consent practices meet the combined IRDAI and DPDP bar.
Insurers face DPDP consent duties layered on top of IRDAI data norms. Check whether your policyholder consent practices meet the combined bar in under 3 minutes.
Insurers in India already operate under IRDAI regulations covering policyholder protection, data localisation of certain records, and outsourcing of functions that touch personal data. The DPDP Act 2023 adds a general-law layer on top: any processing of a policyholder's personal data must rest on valid consent or another lawful basis, consent must be purpose-specific, and the policyholder must be able to withdraw it. Where IRDAI and the DPDP Act both apply, an insurer has to satisfy both — the sector regulator's requirements do not displace the data-protection law.
In practice this means a proposal form that captures a single blanket signature is no longer sufficient for everything an insurer does with the data. Underwriting and policy servicing are core to the contract, but marketing, cross-selling other products, sharing with group companies, feeding analytics models, or passing data to reinsurers and TPAs each need their own specific consent or a clearly stated lawful basis. Niti Bharat helps insurers and intermediaries map every policyholder data flow to the correct basis under the combined IRDAI-DPDP framework.
The highest-risk pattern is bundled consent — one tick-box in a proposal form that purports to authorise underwriting, marketing, sharing with partners and analytics all at once. Under the DPDP Act, consent bundled across unrelated purposes is vulnerable to being treated as not freely given for the secondary purposes, which can invalidate the entire downstream use. The second common gap is undisclosed sharing with reinsurers, TPAs and distribution partners, and the third is the absence of any real withdrawal mechanism.
Because insurance handles financial and often health-related data at scale, an insurer that gets consent wrong faces meaningful penalty exposure under the DPDP Act — up to ₹50 crore for general obligation failures and far higher where a security-safeguard failure leads to a breach. Niti Bharat's fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) are built to rebuild an insurer's consent architecture into a purpose-by-purpose model that stands up to both IRDAI scrutiny and Data Protection Board enforcement expected from around May 2027.
A practical PDF mapping each policyholder data use to the consent or lawful basis it needs, with an IRDAI-DPDP overlap matrix and ready-to-adapt consent-notice wording.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.