DPDP compliance for insurers, brokers and insurtech
Insurance runs on personal and health data shared across agents, brokers, TPAs and hospitals. The DPDP Act asks insurers to show a lawful basis for each use, honour policyholder rights on time and control every partner that touches the data.
What DPDP changes for you
- Underwriting, claims, renewals and marketing are separate purposes.
- Policy and claims records must often be kept for years under other rules.
- Agents, brokers, TPAs and hospitals form a long processor chain.
- Health data breaches cause serious harm and must be reported within 72 hours.
How ConsentLo helps
Purpose-level consent
Renewal reminders and cross-sell offers each get their own consent, separate from the policy itself.
Retention with legal holds
Erasure requests are checked against statutory retention and answered with a recorded reason.
Partner cascade
Withdrawals and erasures flow to agents, brokers and TPAs, with proof of delivery.
Breach desk
Board intimation, the 72-hour report and policyholder notices from a single incident record.
Frequently asked questions
Does DPDP apply to insurance agents and brokers?
Yes. Depending on the arrangement they act as Data Fiduciaries in their own right or as processors for the insurer, and the insurer must control its processors by contract.
Can policyholders ask insurers to delete their data?
They can ask, but insurers may keep data that another law or regulator requires them to retain, and should explain that to the policyholder.
Related DPDP guides
Legitimate uses under DPDP Section 7: processing without consent
The legitimate uses in Section 7 of the DPDP Act that allow processing without consent: voluntary sharing, State functions, legal duties, emergencies and employment.
Read the guide
Data Principal rights under the DPDP Act, and how to handle them
The rights of Data Principals under the DPDP Act, 2023: access, correction, erasure, withdrawal, nomination and grievance redressal, and how to answer them on time.
Read the guide
Data breach notification under DPDP: the 72-hour rule
How to report a personal data breach under India's DPDP Act and Rules: who to tell, what to include, the 72-hour Board report and how to prepare your team.
Read the guide