Authority Guides6 mins

DPDP Act 2023 Authority Guide for Insurers: Managing Consent, TPAs, and IRDAI Overlap

A definitive guide for Chief Compliance Officers in the insurance sector navigating the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Learn how to map Section 8 processor oversight to TPA networks, align Section 12 rights with IRDAI retention mandates, and build regulator-ready audit trails before the compliance deadline.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Executive Summary

The Digital Personal Data Protection Act, 2023 reshapes how Indian insurers collect, process, and retain policyholder information. With 281 days remaining until the 13 May 2027 enforcement deadline, Chief Compliance Officers must align DPDP compliance with existing IRDAI data retention and cybersecurity guidelines. The DPDP Rules, 2025 require granular consent records, a maximum 72-hour timeline for reporting breaches to the Data Protection Board, and strict oversight of third-party processors like TPAs and brokers. Failure to maintain regulator-ready evidence packs exposes financial institutions to penalties up to 250 crore rupees per breach. Insurers must act immediately to bridge legacy policy administration systems with modern consent and rights management infrastructure.

Statutory Framework For Insurers

Section 8 of the DPDP Act, 2023 mandates that Data Fiduciaries remain fully accountable for any processing undertaken on their behalf by Data Processors. This means insurers cannot outsource legal liability to health TPAs, cloud providers, or distribution partners. Every data transfer to a processor requires a valid contract under Section 8. Section 8 also establishes strict purpose limitation, stating that personal data must be erased when the specified purpose is met, unless retention is required by another law. For insurers, this requires mapping Section 8 deletion triggers against IRDAI record-keeping mandates. Additionally, Section 12 gives Data Principals in India the right to correction, completion, updating, and erasure of their personal data. Insurers must ensure policyholders can easily update KYC details or request erasure, subject to regulatory retention mandates.

DPDP Rules 2025 Operational Layer

The DPDP Rules, 2025 introduce stringent operational requirements that deeply impact insurance operations. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Insurers must issue itemised notices in multiple languages before collecting data for underwriting or claims processing. The Rules require verifiable consent artefacts that trace exactly what a policyholder agreed to, when, and for what purpose. For Significant Data Fiduciaries, a designation highly likely for major insurers based on volume and risk, the Rules mandate appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, and engaging independent data auditors. Breach intimation is heavily regulated. Insurers must notify the Data Protection Board of India within 72 hours of a personal data breach and intimate affected Data Principals without delay.

Enforcement And The DPBI

The Data Protection Board of India operates as an independent enforcement body with powers to direct urgent remediation and impose financial penalties. Maximum penalties reach 250 crore rupees for failing to implement reasonable security safeguards to prevent personal data breaches. Shortfalls in fulfilling Data Principal rights under Section 12 or failing to supervise Data Processors under Section 8 carry penalties up to 200 crore rupees. The DPBI will demand verifiable audit trails to determine culpability. Legacy systems that cannot export an evidence pack demonstrating compliance will severely disadvantage insurers during an inquiry.

Comparative Context

While multinational insurers might possess mature privacy compliance frameworks, the DPDP Act requires an India-first localisation of controls. Cross-border transfers of personal data are permitted to any jurisdiction unless the Central Government notifies a specific restriction list. Furthermore, Indian law places a heavier emphasis on linguistic accessibility, requiring notices in languages specified in the Eighth Schedule of the Constitution. Adopting a blanket global privacy policy will fail to meet the specific requirements of the DPDP Rules, 2025.

Decision Matrix For Compliance Owners

1. TPA Claims Processing: Chief Compliance Officers must enforce Section 8 processor oversight through executed Data Processing Agreements and periodic processor audits to ensure valid contracts exist.

2. Right to Erasure Requests: IT Operations and DPOs must log deletion events or justify refusals by formally citing IRDAI retention laws to meet Section 12 mandates without violating sectoral rules.

3. Agent Portal Data Breaches: CISOs must trigger 72-hour breach intimation protocols to the DPBI under the Rules, 2025 while notifying affected Data Principals in India without delay.

What To Ask Any Compliance Provider

Enterprise buyers evaluating DPDP compliance platforms must look beyond basic dashboards to assess audit readiness. Ask if the platform provides an immutable audit trail of consent artefacts that an external auditor or the DPBI would accept as a formal evidence pack. Inquire about the capability to map data flows between core policy administration systems, CRM, and third-party TPAs to maintain an accurate Record of Processing Activities. Request detailed SLAs for how the tool automates Section 12 rights requests across legacy databases. Verify if the platform generates the specific incident report formats required by the DPDP Rules, 2025 for 72-hour breach intimation. Ensure the provider maintains data residency entirely within India and offers native capabilities to document processor compliance attestations.

Implementation Roadmap

1. Day 30: Complete a data mapping exercise identifying all personal data processed within India, categorising sources across underwriting, claims, and marketing to establish a baseline RoPA.

2. Day 60: Draft and deploy compliant itemised notices and consent mechanisms across customer portals, aligning with Section 7 legitimate use boundaries and IRDAI rules.

3. Day 90: Implement automated workflows for Section 12 rights requests and deploy a tested 72-hour breach intimation protocol for reporting to the DPBI.

Further Reading

To deepen your enterprise compliance strategy, explore our guides on structuring a compliant Record of Processing Activities, managing Data Processor contracts under Section 8, and mastering the 72-hour breach reporting window.

Next Steps

With 281 days remaining, your compliance team needs a solution that satisfies DPBI scrutiny without massive engineering overhead. Run a baseline assessment at freescan.complydp.com to evaluate your current exposure, or speak directly with our enterprise advisory team to structure your compliance roadmap.

Sources

Frequently asked questions

How does the DPDP Act 2023 affect IRDAI record-keeping mandates?

Under Section 8 of the DPDP Act, personal data must be erased when its purpose is served unless retention is required by other laws. Insurers can lawfully retain KYC and claims data beyond the customer relationship to comply with IRDAI mandates. However, they must document this legal necessity in their processing records to justify refusing a Section 12 erasure request.

What is the timeline for reporting a data breach under the new Rules?

The DPDP Rules, 2025 require Significant Data Fiduciaries to notify the Data Protection Board of India within 72 hours of a personal data breach. Insurers must also intimate affected Data Principals in India without delay. Failing to meet these timelines or lacking reasonable security safeguards can result in penalties up to 250 crore rupees.

Are insurance companies considered Significant Data Fiduciaries?

While the Central Government notifies specific Significant Data Fiduciaries, large financial institutions like insurers are highly likely to receive this designation due to the volume and risk associated with their processing. Once designated, they must appoint a resident Data Protection Officer, conduct periodic Data Protection Impact Assessments, and engage independent auditors.

How should insurers handle consent for health TPAs and brokers?

Section 8 mandates that insurers act as Data Fiduciaries and remain fully accountable for processors like TPAs. Insurers must establish valid contracts with these processors and ensure they implement adequate security measures. Consent collected by the insurer must clearly cover the transfer of data to these third parties for claims processing.

Can insurers transfer policyholder data outside India for reinsurance?

Yes, cross-border transfers are generally permitted unless the Central Government explicitly restricts transfers to a notified country or territory. Insurers must ensure these transfers comply with DPDP processor contract requirements and align with any separate sectoral data localisation rules issued by IRDAI.