DPDP compliance for insurance companies

DPDP compliance for insurance companies
Insurance

DPDP compliance for insurance companies

Insurance companies process health, financial, and personal data at scale — often under regulatory frameworks that predate the DPDP Act. Here is how the two sets of obligations interact.

Quick Answer: Insurance companies are Data Fiduciaries under the DPDP Act for the personal, health, and financial data they collect from policyholders. Health insurance companies process particularly sensitive data. You must obtain explicit, purpose-specific consent before using health data for underwriting, pricing, or profiling beyond what is strictly necessary for the policy. IRDAI's existing data governance requirements and DPDP have significant overlap — build a unified compliance programme rather than treating them separately. SDF designation is a real risk for large insurers. Enforcement deadline: May 2027.

What personal data do insurance companies process under the DPDP Act?

Insurance companies collect: personal identity data (name, DOB, address, PAN, Aadhaar); health data (medical history, pre-existing conditions, diagnostic reports, lifestyle information for health and life insurance); financial data (income, assets, liabilities, existing policies); claims data (incident details, medical reports, police reports for motor claims); nominee and beneficiary information; and usage data for telematics-based motor insurance. This is a comprehensive personal data profile of policyholders and their families.

Does DPDP require explicit consent for insurance underwriting using health data?

The most sensitive DPDP issue for insurers is the use of health and financial data for underwriting and pricing decisions. Policyholders applying for insurance understand their data will be used for underwriting — that is the nature of the product. But using data beyond the disclosed underwriting purpose — for example, sharing health data with pharmaceutical companies, using claims data for marketing to third parties, or building wellness profiles for sale — requires explicit consent beyond the policy application.

How do IRDAI data governance requirements interact with the DPDP Act?

IRDAI's Master Circular on Cybersecurity and IRDAI's data governance guidelines impose obligations on insurers around data security, customer data protection, and incident reporting. These overlap significantly with DPDP but are not identical. Build a unified compliance programme: identify where IRDAI requirements and DPDP requirements align and where they diverge, and design controls that satisfy both. Where they diverge, apply the stricter standard.

How must insurance companies handle health data in claims processing under DPDP?

The claims process generates new health data — medical reports, hospital bills, doctor letters — that insurers must manage carefully. Claims data is sensitive personal data and must be retained only for the period necessary (the claims statute of limitations, plus any additional regulatory requirement), not indefinitely. Access to claims data must be strictly controlled, and it must not be used for purposes beyond the specific claims settlement without consent.

Does DPDP apply to telematics and IoT data used in motor insurance pricing?

Motor insurers using telematics — apps or devices that track driving behaviour — and health insurers partnering with wearable manufacturers are collecting real-time behavioural data. This is personal data, and its use for pricing or discounting requires clear disclosure and consent. The privacy notice for a telematics policy must explain exactly what is tracked, how it affects premiums, and how long it is retained. Policyholders must be able to opt out of telematics without losing the ability to hold the policy (though they may lose the discount).

What DPDP data rights do insurance policyholders have?

Policyholders have the right under DPDP to access the personal data the insurer holds about them, including underwriting data, claims data, and health information collected during the application or claims process. They have the right to correct inaccurate data — which has direct underwriting implications if incorrect health history has led to a higher premium. Build a mechanism for policyholder rights requests that integrates with your underwriting and claims systems, not just your CRM.

Frequently asked questions

Can we use a policyholder's claims history to decline renewal or increase premiums without notifying them?

Using claims history for underwriting is a disclosed purpose for most policies. However, the DPDP Act's transparency requirements mean that any decision significantly affecting the policyholder — denial, non-renewal, material premium increase — should be explainable. If the decision is driven by personal data, the policyholder can request to know what data drove the decision. Ensure your underwriting decisions are documented and explainable.

We share customer data with reinsurers. Do we need DPAs?

If a reinsurer receives personal data about individual policyholders — and most reinsurance arrangements do involve some individual-level data — then yes, a DPA is required. The reinsurer is a Data Processor for that data. Reinsurance contracts often predate DPDP and will need data protection addenda. Most major reinsurers are well aware of GDPR obligations from their European operations and will have DPA templates.

IRDAI requires us to retain certain policy documents for 10 years. Does DPDP conflict with this?

No. Retention of data required by law is a valid lawful basis for continued processing even after the original processing purpose has ended. You can retain policy documents for the IRDAI-mandated period. However, you cannot retain data beyond the statutory period on the basis of a general 'we might need it' policy. Build a retention schedule that maps each data category to the applicable statutory retention period and programmes deletion after it expires.

Align your insurance compliance with DPDP

Niti Bharat advises insurance companies on DPDP compliance alongside IRDAI obligations — consent frameworks for health data, claims data retention, telematics consent, and policyholder rights workflows.

Start Insurance DPDP Assessment
Previous Post Next Post

Get Free DPDP Checklist