For insurers, brokers, web aggregators and TPAs
DPDP compliance for insurance
Insurance runs on sensitive data moving between customers, agents, brokers, hospitals and TPAs. The DPDP Act asks you to explain each flow, collect only what the policy needs and answer customers’ requests. ConsentKit handles the consent and rights layer across your channels.
- Health and claims data
- Minimise and protect
- Agents and brokers
- Map every flow
- Full compliance
- 13 May 2027
Suraksha Insurance asks for your consent
Choose how we may use your details. You can change this anytime.
Where the DPDP Act touches a policy
Pick a stage to see what you collect, who it goes to and the basis for it.
What changes for insurers on 13 May 2027
IRDAI rules continue. These DPDP duties sit on top.
Clear notice across every channelSections 5 and 6
Direct, agent, broker, bancassurance and aggregator channels all need the customer to see a clear notice.
Notices for web, app and agent tools, with one consent record per customer.
Collect only what the policy needsSection 6(1)
Consent covers data necessary for the purpose. Health questions at quote stage should be limited.
A purpose register mapping each question to underwriting need.
Agents, brokers and TPAs are coveredSection 8
Intermediaries and TPAs processing data for you remain your responsibility.
A partner register, processor contracts and access controls for agent tools.
Customers and nominees have rightsSections 11 to 14
Customers can request access, correction and erasure where law allows, and nominate someone to act for them.
A rights portal that handles nominees and respects IRDAI retention.
Breaches reported in 72 hoursRule 7
Report breaches to the Board and to affected customers, alongside any IRDAI and CERT-In reporting.
A breach workflow producing each report from one incident record.
Large insurers may be Significant Data FiduciariesSection 10 and Rule 13
If notified, you need a DPO in India, annual audits and impact assessments.
Evidence exports for your DPO and auditors.
When the law requires you to keep data
The DPDP Act does not override other laws. Where RBI, PMLA, IRDAI or tax rules require you to collect or keep records, that duty stands, and a customer’s erasure request does not remove it. What changes is that you must be clear about which data you keep for which law, and stop using it for anything else.
This is general guidance, not legal advice. Confirm how it applies to you with your counsel.
A plan across channels
Start with the channels that bring the most data in: agents and aggregators.
Map channels and partners
List every channel, intermediary, TPA, lab and surveyor that handles customer data.
Notices in every journey
Put notices and consent into web, app and agent tools.
Contracts and minimisation
Update partner contracts and trim quote-stage questions.
Rights and breach readiness
Connect rights requests to your grievance desk and rehearse breach reporting.
For every part of the insurance chain
Templates for your role.
Life insurers
Long-term policies and nominee data.
General and health insurers
Claims-heavy, many partners.
Insurance brokers
Customers of many insurers.
Web aggregators
High lead volume and comparison data.
TPAs
Processors for insurers and hospitals.
Corporate agents and banks
Bancassurance consent kept separate from banking.
DPDP compliance for insurance near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions insurers are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Do IRDAI rules override the DPDP Act?
No. Where IRDAI or other laws require you to collect or keep data, that stands. The DPDP Act adds consent, purpose limits, rights and breach duties on top.
Can agents keep customer lists?
Agents act for you when they sell your policies. Give them access through your systems, and remove it when they leave.
Can we share claims data with investigators?
Fraud investigation can be a legitimate need, but limit what investigators see and bind them by contract.
Do nominees need to be told their data is held?
Nominee data is personal data. Your notice should explain how you use it, and the policyholder should tell the nominee.
Can we cross-sell to existing customers?
Only with separate consent for marketing. Renewal reminders for the same policy are a different purpose.
Get every channel ready before May 2027
The readiness check takes about ten minutes and gives you a gap report built for insurance.