The DPDP Act applies to every insurance company in India. Insurers must take clear permission before using customer data, keep health records safe, let customers name a nominee for their data rights, and report data leaks.
The DPDP Rules, 2025 have already been notified, and insurers now have a limited window to prepare before most compliance obligations become enforceable. Understanding the DPDP Act for insurance companies and following the DPDP Act Compliance checklist should be a priority.
What Is the DPDP Act?
The Digital Personal Data Protection (DPDP) Act is India’s data privacy law that governs how businesses collect, store, process, and share individuals’ personal data. It gives people more control over their information and requires organizations to handle personal data responsibly, obtain consent where needed, and protect it from misuse or unauthorized access.

Does the DPDP Act Apply to Insurance Companies?
Yes, the DPDP Act applies to Life insurers, health insurers, general insurers, TPAs, brokers, and web aggregators. Depending on factors such as the scale and sensitivity of data processing, certain insurers may be notified as Significant Data Fiduciaries (SDFs) by the Central Government.
If an insurance company is notified as a Significant Data Fiduciary (SDF), it will have additional compliance responsibilities:
- A Data Protection Officer: Based in India and answerable to the board.
- Risk assessments: Before high-risk work like AI-based underwriting or claim scoring.
- A yearly audit: Done by an independent auditor who reports to the Data Protection Board.
Don’t wait for the official announcement. Build for it now.
Simplify Your Compliance & Stay Audit-Ready
Help your team manage controls, risks, and audits with ease
What Changes for Consent in Health Insurance?
Consent can not be taken as a checkbox; it should be made purpose-wise according to the DPDP Act for Insurance Companies:
- Consent collection processes will need to change: Each policy needs specific consent for the data that the product actually uses. Using a single bundled consent for unrelated purposes such as underwriting, marketing, and cross-selling, may not satisfy DPDP consent requirements. The consent notice should clearly explain each purpose for which personal data is collected.
- Your apps change: Consent notices should be written in clear language and made available in English or any language listed in the Eighth Schedule to the Constitution, based on the customer’s preference. Digital journeys need a rebuild for this.
- Saying no becomes easy: If consent took two taps, withdrawal cannot need a branch visit. Once withdrawn, that use of data stops.
One relief for claims teams. In a medical emergency that threatens life, data can be processed without consent.

How Should Insurance Companies Protect Health Data?
Data protection compliance for health insurers is simple:
- Collect less: Collect only the personal data that is necessary for underwriting, claims processing, customer servicing, or any other stated purpose. Avoid collecting information that is not required.
- Know where data lives: Suppose a customer does not renew a policy and asks you to erase their data. You can delete it from every system only if you have a map of where it sits. Build that data inventory first.
- Delete on time: IRDAI regulations require insurers to retain certain records for prescribed periods. Once those legal retention requirements and the original purpose are fulfilled, personal data should be securely deleted in accordance with the DPDP Act.
- Extra care for children: You need verifiable consent from a parent, and tracking children’s behaviour is banned.
Who is Responsible When a TPA or Vendor Leaks Data?
Even when personal data is processed by TPAs or third-party vendors, the insurance company, as the Data Fiduciary, remains accountable for complying with the DPDP Act. This makes strong vendor due diligence, contractual safeguards, and regular security assessments essential.
What Does the DPDP Act Say About Nominees?
Section 14 gives every customer the right to name a person who can use their data rights after death or incapacity.This is not the policy nominee. The policy nominee gets the claim money. The DPDP nominee may exercise the data rights available to the customer after their death or incapacity, subject to the provisions of the Act and applicable procedures. They can be two different people, and you must handle both.
Build three things. A step in onboarding to record the DPDP nominee. An identity check before acting on a nominee’s request. A log of what data the nominee viewed or erased.
What Are the Penalties under the DPDP Act for Insurance Companies?
| Failure | Maximum Fine |
| Weak security that leads to a breach | Rs 250 crore |
| Not reporting a breach | Rs 200 crore |
| Breaking children’s data rules | Rs 200 crore |
| Failing SDF duties | Rs 150 crore |
The Data Protection Board determines penalties after considering the facts and circumstances of each case. Where multiple provisions of the Act are violated, separate penalties may be imposed.
How Can Insurance Companies Comply with the DPDP Act?
- Map every system that holds personal data, including TPA and agent systems.
- Rebuild consent journeys purpose by purpose, in all required languages.
- Fix retention schedules against IRDAI record rules.
- Add DPDP nominee capture to onboarding and servicing.
- Set up breach alerts, reporting workflows, and audit-ready records.
Doing this by hand across millions of policies is not realistic. Platforms like SureGrid automate evidence collection, control mapping, and vendor risk assessments across frameworks like the DPDP Act, ISO 27001, and SOC 2, so your compliance team manages exceptions, not spreadsheets.
Conclusion
The DPDP Act changes how insurance companies collect, use, and delete customer data. The direction is simple. Take purpose-wise consent, protect health records, record the data nominee, and answer for every TPA and vendor that touches your systems.
Although most compliance obligations become enforceable from 13 May 2027, insurers should begin preparing now because updating consent journeys, data governance processes, and vendor agreements can take significant time.
FAQs
Ques: Does the DPDP Act Apply to Insurance Companies in India?
Ans: Yes, the DPDP Act, 2023 applies to all life, health, and general insurance companies in India, along with TPAs, brokers, and web aggregators. Any entity that decides how policyholder data is used is a Data Fiduciary under the Act and must comply fully.
Ques: What Is the Penalty for Insurance Companies Under the DPDP Act?
Ans: The maximum penalty is Rs 250 crore per instance for weak security safeguards that lead to a data breach. Not reporting a breach costs up to Rs 200 crore, children’s data violations up to Rs 200 crore, and Significant Data Fiduciary failures up to Rs 150 crore.
Ques: Is the DPDP Nominee the Same as the Insurance Policy Nominee?
Ans: No, the policy nominee receives the claim money under the Insurance Act. The DPDP nominee, named under Section 14, exercises the customer’s data rights after death or incapacity, such as access, correction, and erasure. They can be two different people, so insurers must record both separately.
Ques: When Do Insurance Companies Need to Comply with the DPDP Act?
Ans: The DPDP Rules were notified in November 2025, and most obligations for insurers apply by May 2027. Consent journey rebuilds, multilingual notices, and vendor contract updates take months, so compliance work should begin now, starting with a full data inventory.
Ques: Can Insurers Use Health Data Without Consent in an Emergency?
Ans: Yes, in one situation. Section 7 of the DPDP Act allows processing personal data without consent to respond to a medical emergency that threatens life. So cashless approval during an emergency admission can proceed. Underwriting, marketing, and cross-selling cannot use this exemption.