Industries/Health Insurance

Your TPA sees everything. So does the regulator.

Health insurers sit at the centre of a data chain that spans policyholders, employers, TPAs, hospitals, and wellness partners. Under DPDP, every link in that chain is a compliance obligation. We build the consent infrastructure, processor agreements, and rights portal that make it hold up.

SDF Risk
Significant Data Fiduciary designation likely
The data chain

Six entities. One accountability chain.

Health insurance data rarely stays in one place. Under DPDP, accountability follows the data, not the org chart. Every entity that receives personal data needs a legal basis, a contract, and a defined role.

Policyholder

Data Principal

Data handled

Health history, pre-existing conditions, KYC, nominee details

DPDP obligation

Consent required before collection. Rights include access, correction, and nomination.

Employer

Data Fiduciary (group policies)

Data handled

Employee details, salary band, family composition

DPDP obligation

Must have a lawful basis for sharing employee data with the insurer.

Health Insurer

Primary Data Fiduciary

Data handled

Full claims history, diagnoses, prescriptions, risk scores

DPDP obligation

Owns consent, purpose limitation, rights fulfilment, and breach notification obligations.

TPA

Data Processor (sometimes joint Fiduciary)

Data handled

Claims records, treatment details, utilisation data

DPDP obligation

Data processing agreement required. Breach cooperation and sub-processor disclosure mandatory.

Hospital Network

Data Processor

Data handled

Discharge summaries, procedure records, lab results

DPDP obligation

Must operate under a processor contract. No secondary use without written authorisation.

Wellness and Analytics Partners

Data Processor or joint Fiduciary

Data handled

Lifestyle data, behavioural indicators, wearable feeds

DPDP obligation

If determining secondary uses independently, classified as a Fiduciary. Separate consent required.

What we build

Five obligations. All of them are engineering problems.

Verifiable consent

DeliverableConsent flow redesign, consent ledger, purpose registry

Blanket consent embedded in policy documents is not valid under DPDP. Each purpose, underwriting, claims processing, wellness profiling, and fraud analytics, requires a separate, affirmative consent action. We build the consent infrastructure that captures, stores, and surfaces purpose-specific consent at every touchpoint.

Data processing agreements

DeliverableDPA templates, vendor mapping, contract execution support

Every TPA, hospital, analytics vendor, and wellness partner that receives personal data is a processor under the Act. Each one needs a written data processing agreement covering purpose limitation, sub-processor disclosure, security obligations, and breach cooperation clauses. We draft and implement these at scale.

Data principal rights portal

DeliverableRights request portal, 7-day response automation, audit trail

Policyholders have the right to access their data, correct inaccuracies, and nominate a representative to exercise their rights. Under Rule 14, you must respond within seven days. We ship a rights portal integrated into your product that handles requests, triggers workflows, and generates audit trails.

Breach notification within 72 hours

DeliverableBreach runbook, detection integration, Board notification template

The DPDP Rules are expected to mandate breach notification within 72 hours. Health data breaches carry the highest penalty exposure and the most reputational risk. We build a breach notification runbook and technical detection hooks so your team is never improvising.

Retention limits and erasure

DeliverableRetention policy, erasure automation, legal basis documentation

Health data cannot be held indefinitely. Once the purpose is served, the data must be erased unless a legal basis for retention exists. Claims records, medical histories, and underwriting data each have different retention logic. We implement automated retention policies tied to policy lifecycle events.

Significant Data Fiduciary

Large insurers face a higher obligation tier.

If the central government designates your organisation as a Significant Data Fiduciary based on data volume and sensitivity, you take on five additional obligations beyond the base DPDP framework. We prepare you for both.

Appoint a Data Protection Officer based in India

Commission an independent data auditor annually

Conduct a Data Protection Impact Assessment every 12 months

Verify that all technical measures do not risk data principal rights

Ensure health data is not transferred outside India

Common questions

Questions we get from health insurers.

Does DPDP treat health data differently from other personal data?

The DPDP Act does not create a separate sensitive data category like GDPR. However, entities processing health data at scale are likely candidates for designation as Significant Data Fiduciaries, which triggers a materially higher set of obligations including mandatory DPOs, annual DPIAs, and independent audits. The practical effect is that health data receives heavier governance even without a formal sensitive-data classification.

What is the TPA's status under DPDP?

TPAs typically start as processors, handling claims administration under the insurer's instructions. But where a TPA exercises independent discretion in adjudicating claims or developing utilisation models, they may be classified as joint fiduciaries. Accountability follows actual control over purpose and means, not the contract label. Your processor agreements must reflect this nuance.

We already comply with IRDAI regulations. Does that cover DPDP?

IRDAI sets sector-specific requirements around underwriting, claims, and policy records. DPDP sets requirements around consent, purpose limitation, data principal rights, and breach notification. The two frameworks are complementary but separate. IRDAI compliance does not satisfy DPDP obligations and vice versa.

How do group employer policies affect our obligations?

In a group health policy, the employer acts as a data fiduciary for employee data they share with you. They need a lawful basis for that sharing. You need a data processing agreement with the employer that governs what you can do with that data, and separate consent from employees for purposes that go beyond the core insurance function, such as wellness profiling or targeted communications.

What penalties apply if we are found non-compliant?

Penalties under the DPDP Act can reach ₹250 crore for breach of general data fiduciary obligations. Given the sensitivity of health data and the scale at which insurers operate, the Data Protection Board is likely to treat violations in this sector with heightened scrutiny. Reputational consequences compound the financial exposure.

Penalties under the DPDP Act can reach ₹250 crore for breach of data fiduciary obligations. For entities handling health data at scale, the Data Protection Board is expected to treat violations with heightened scrutiny. This engagement does not constitute legal advice. Pair it with your legal counsel for complete coverage.

Ready to build compliance into your health insurance product?

Take the readiness check