DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

An insurer must obtain free, specific, informed and unambiguous consent from a policyholder before processing their personal data for anything beyond what is strictly necessary to underwrite and service the policy. Under the DPDP Act 2023, consent taken through a proposal form for the contract does not automatically extend to marketing, cross-selling, or sharing with group companies and reinsurers — those need their own consent or a lawful basis. IRDAI norms on policyholder data and outsourcing sit on top of DPDP, so insurers face an overlapping obligation. This checker assesses whether your policyholder consent practices meet the combined IRDAI and DPDP bar.

Insurance Policyholder Consent Checker — IRDAI + DPDP Overlap

Insurers face DPDP consent duties layered on top of IRDAI data norms. Check whether your policyholder consent practices meet the combined bar in under 3 minutes.

Check your policyholder consent readiness

Policyholder consent essentials under IRDAI + DPDP

How do IRDAI norms and the DPDP Act overlap for policyholder consent?

Insurers in India already operate under IRDAI regulations covering policyholder protection, data localisation of certain records, and outsourcing of functions that touch personal data. The DPDP Act 2023 adds a general-law layer on top: any processing of a policyholder's personal data must rest on valid consent or another lawful basis, consent must be purpose-specific, and the policyholder must be able to withdraw it. Where IRDAI and the DPDP Act both apply, an insurer has to satisfy both — the sector regulator's requirements do not displace the data-protection law.

In practice this means a proposal form that captures a single blanket signature is no longer sufficient for everything an insurer does with the data. Underwriting and policy servicing are core to the contract, but marketing, cross-selling other products, sharing with group companies, feeding analytics models, or passing data to reinsurers and TPAs each need their own specific consent or a clearly stated lawful basis. Niti Bharat helps insurers and intermediaries map every policyholder data flow to the correct basis under the combined IRDAI-DPDP framework.

What consent mistakes create the most exposure for insurers?

The highest-risk pattern is bundled consent — one tick-box in a proposal form that purports to authorise underwriting, marketing, sharing with partners and analytics all at once. Under the DPDP Act, consent bundled across unrelated purposes is vulnerable to being treated as not freely given for the secondary purposes, which can invalidate the entire downstream use. The second common gap is undisclosed sharing with reinsurers, TPAs and distribution partners, and the third is the absence of any real withdrawal mechanism.

Because insurance handles financial and often health-related data at scale, an insurer that gets consent wrong faces meaningful penalty exposure under the DPDP Act — up to ₹50 crore for general obligation failures and far higher where a security-safeguard failure leads to a breach. Niti Bharat's fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) are built to rebuild an insurer's consent architecture into a purpose-by-purpose model that stands up to both IRDAI scrutiny and Data Protection Board enforcement expected from around May 2027.

Get the insurer consent redesign checklist (free)

A practical PDF mapping each policyholder data use to the consent or lawful basis it needs, with an IRDAI-DPDP overlap matrix and ready-to-adapt consent-notice wording.

Frequently Asked Questions

Does a signed insurance proposal form count as DPDP consent?+
It counts as consent for the processing strictly necessary to underwrite and service that policy, because that is the contractual purpose the policyholder agreed to. It does not automatically extend to marketing, cross-selling, sharing with group companies or reinsurers, or analytics — each of those needs its own specific, informed consent or another lawful basis under the DPDP Act.
Do IRDAI rules override the DPDP Act for insurers?+
No. Where both apply, an insurer must comply with both. IRDAI norms on policyholder protection and outsourcing sit alongside the DPDP Act's consent and security obligations rather than replacing them, so insurers face an overlapping — not an either-or — obligation.
Do we need fresh consent to share policyholder data with a reinsurer or TPA?+
You need a lawful basis and clear disclosure for every recipient. Sharing genuinely necessary to perform the insurance contract may rest on that basis, but the policyholder must be told about it in the notice. Sharing for purposes beyond the contract — such as marketing partnerships — generally needs separate specific consent.
How should a policyholder withdraw consent?+
Withdrawal must be as easy as giving consent was. Insurers should offer a clear channel — for example a self-service option or a request to the Grievance Officer — and, on withdrawal, stop the affected processing and record the request with a date.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
IoT Device Data-Collection & Consent CheckerIRDAI Data Rules + DPDP Gap CheckerIs Your Background-Check Consent DPDP-Adequate? Fr…DPDP Due Diligence Report Generator for M&ASee all Calculators tools →📝 DPDP Penalty Data Breach India📝 DPDP Compliance Cost India