Readiness assessment
Fintech & Banking · InsurTech

The DPDP Act for InsurTech & Insurance

Insurance runs on health and financial data shared across TPAs, reinsurers and hospitals.

In short

Insurance uses health and financial data, among the most sensitive the Act covers, shared across a wide chain of partners. You need explicit consent, tight sharing controls, and to reconcile DPDP with IRDAI rules. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Sensitive health data

Underwriting and claims use health data; collect and share only what the policy needs, with clear consent.

The data-sharing chain

TPAs, reinsurers, hospitals and aggregators are processors; contracts and oversight are on you.

Consent and purpose

Consent for underwriting is not consent for cross-sell; keep the purposes separate.

Policyholder rights

Insureds can access, correct and erase their data, subject to legal-retention needs.

Dual compliance

DPDP sits alongside IRDAI regulations, not instead of them.

Go deeper

Niche guides for this area, each naming the specific regulation.

Check your policy and claims data.

The readiness check surfaces health-data, sharing-chain and consent gaps.

Take the readiness check