Insurance DPDP compliance
the data of people who never became customers.
Underwriting collects health and financial detail from many people who never buy a policy. IRDAI's rules keep policy and claim records; the DPDP Act says erase what no law requires. The gap between the two is the declined proposal, the lapsed quote and the nominee who was never told.
Which laws apply to insurers and intermediaries?
Insurers, foreign reinsurance branches and IRDAI-regulated intermediaries owe the DPDP Act's duties for personal data and IRDAI's Information and Cyber Security Guidelines, 2026 for security. IRDAI's March 2025 circular sets the six-hour incident report, and CERT-In's directions run alongside it.
| Law or rule | What it governs | Notes |
|---|---|---|
| DPDP Act 2023 and Rules 2025 | Notice, consent, purpose, erasure, breach reporting, rights | Applies to proposers, policyholders, nominees, claimants |
| IRDAI Information and Cyber Security Guidelines, 2026 | Governance, CISO, audit, incident reporting, vendors | Replaced the 2023 guidelines on 6 April 2026. See the IRDAI guide |
| IRDAI circular, 24 March 2025 | Six-hour report to IRDAI, forensic readiness, crisis plan | Board compliance report required |
| IRDAI record-keeping requirements | Retention of policy and claim records | Attach to policies issued and claims made |
| Bima Sugam Regulations, 2024 | Insurance electronic marketplace; consent-based architecture | Its own consent layer |
| CERT-In directions, 2022 | Six-hour reporting, 180-day logs in India | Referenced by the IRDAI guidelines |
The obligation insurers get wrong: keeping declined proposals
Insurers collect health declarations, medical reports and financial details to assess proposals, and keep them after the proposal is declined or lapses, usually for fraud detection. Under section 8(7) the assessment purpose ends at decline. Keeping the data for fraud is a new purpose, needing its own basis, notice and period.
The distinction that gets missed is where IRDAI's record-keeping duties start. They attach to policies issued and claims made. A proposal that was never accepted is not a policy, and a quote that was never bought is not a claim. The retention exception in section 8(7) covers only what a law requires, so IRDAI's rules do not stretch to cover the underwriting file of a stranger.
Fraud detection may well be a defensible reason to keep a narrow slice of declined-proposal data: identifiers and the fact of a decline, rather than the full medical report. The DPDP route is to say so in the proposal-stage notice, limit the fields, set a period, and delete on schedule. What does not work is carrying the whole file forward silently because the underwriting system has no delete button.
Nominees, claimants and other people who never consented
An insurance file is full of personal data about people other than the customer: nominees, dependants, the other driver, the treating doctor. They are Data Principals too. Most never receive a notice, because the insurer's notice is addressed to the proposer who supplied their details.
Nominee data is the clearest case. The policyholder provides the nominee's name, relationship and often contact details, and the nominee may not know. Processing it is necessary to perform the policy, but the insurer still needs to decide its basis, how the nominee is told and when, and what happens to the record when the nomination changes. Health claims raise the same question for dependants' medical information passing through a TPA. The DPDP consent notice template shows the elements a notice must contain.
Leads, aggregators and the distribution chain
Insurance is sold through brokers, corporate agents, web aggregators, banks and, increasingly, Bima Sugam. Each hands a prospect's data to one or more insurers. Under the DPDP Act, the insurer that receives a lead is a Data Fiduciary for it and needs the prospect to have been told, in a notice, that the data would reach it.
The weak point is the comparison journey. A prospect enters age, health conditions and income on an aggregator's quote form, ticks a box agreeing to be contacted, and is then called by several insurers. Consent to be contacted "by our partners" does not tell the person which insurers will receive a health declaration, for what, or for how long. The notice should name the insurers, or at least the category and the purpose, and the consent record should travel with the lead so the insurer can prove what the prospect agreed to. The IRDAI guidelines already make insurers responsible for the security of the intermediaries they engage; the DPDP Act makes them responsible for the lawfulness of what arrives.
Bima Sugam adds its own consent architecture for access through the marketplace. As with Account Aggregator consent in banking, that governs the platform's data flow. It does not replace the notice each insurer owes.
Security and breach reporting for insurers
Insurers must report cyber incidents to CERT-In within six hours with a copy to IRDAI, and to IRDAI in its prescribed format within six hours. A personal data breach also goes to the Data Protection Board and each affected person, with the Board's detailed report within 72 hours. Intermediaries follow the same rules.
The 2026 guidelines also require an annual independent assurance audit, with the auditor rotated every three years, insurers filing with IRDAI within 90 days of year end or 30 days of the audit, and board-owned closure of gaps within twelve months. They name the DPDP Act and require measures to comply with it. For outsourced systems, insurers must contract for notice of a suspected cloud breach within four hours of discovery. The IRDAI guide covers the full set.
Insurance control checklist
For insurers, brokers, corporate agents, web aggregators and TPAs.
| Control | Why | Evidence to hold |
|---|---|---|
| Retention schedule separating proposals, policies and claims | DPDP s.8(7); IRDAI records | Schedule; deletion logs for declined proposals |
| Proposal-stage notice naming any fraud-screening use and its period | DPDP s.5, s.6(1) | Notice versions; proposer consent records |
| Minimised fraud record kept after decline | DPDP s.8(7) | Field list and period |
| Nominee notice approach decided and applied | DPDP s.5 | Written position; nominee communications |
| Six-hour reporting to CERT-In and IRDAI; 72-hour Board report | IRDAI 2026; March 2025 circular; DPDP Rule 7 | Runbook; drill records |
| Cloud contracts with four-hour suspected-breach notice | IRDAI 2026 cloud policy | Contract clause per provider |
| Web aggregator and portal tags held until consent | DPDP s.6 | Two-pass scan of quote journeys |
Where to go next
Read the IRDAI cybersecurity guide for the security rules and the retention and erasure guide for building the schedule. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.
The things people ask us
Can an insurer keep data from a declined proposal?
Not indefinitely. The purpose of collecting a proposal, assessing it, is served when the proposal is declined or lapses, and section 8(7) of the DPDP Act then requires erasure unless a law requires retention. Keeping it to detect fraud on later applications is a different purpose that needs its own basis, notice and retention period.
Do IRDAI record-keeping rules override DPDP erasure?
For the records they cover, yes, because retention required by law is an exception to section 8(7). IRDAI's record-keeping requirements attach to policies issued and claims made. They do not automatically extend to proposals never accepted, quotes never bought, or marketing data collected around them.
Does an insurer need consent from a nominee?
The nominee is a Data Principal whose data the insurer processes, usually supplied by the policyholder. Nomination is necessary to perform the policy, but the nominee has still received no notice. Insurers should decide their lawful basis for nominee data and how, and when, the nominee is told.
How fast must an insurer report a data breach?
A cyber incident goes to CERT-In within six hours with a copy to IRDAI, and to IRDAI in its prescribed format within six hours under the March 2025 circular. A personal data breach also goes to the Data Protection Board and every affected person without delay, with the detailed report to the Board within 72 hours.
Is Bima Sugam consent the same as DPDP consent?
No. The Bima Sugam regulations of March 2024 require the marketplace to use a consent-based architecture, which governs data access through the platform. An insurer or intermediary receiving a customer through Bima Sugam still owes its own DPDP notice, and needs its own record of what the customer agreed to.
Scan the pages where proposers type their health history.
Quote and proposal forms often carry analytics and ad tags. See what fires before consent, then see how the platform keeps each proposer's consent against the notice they saw.