DPDP for Insurance: Managing Consent Across the Quote-to-Claim Lifecycle
Learn how DPDP for insurance applies from quote to claim, covering consent, underwriting, TPAs, withdrawal and retention, with a practical insurer framework.

A policyholder shares personal data many times during one relationship with an insurer. It begins with a quote request and continues through underwriting and servicing to renewal and claim. Along the way, intermediaries such as agents and brokers join the data flow, and claims add third-party administrators (TPAs) and hospitals.
DPDP for insurance is the application of India's Digital Personal Data Protection Act, 2023 to this full journey. The central consent challenge for an insurer is consistency. A customer may buy through an agent, submit a claim through a TPA and receive offers from a marketing platform. Every relevant system and partner then needs the same current understanding of that customer's choices. You will see where consent applies, where other grounds for processing apply, and how choices can be recorded and evidenced from quote to claim.
Quick Answer: What Does DPDP Mean for Insurance Companies?
Under Section 4, the DPDP Act allows an insurer to process digital personal data for a lawful purpose, with the consent of the individual or under one of the legitimate uses listed in Section 7. Where consent is the ground, the insurer gives a clear notice, records the consent, honours withdrawal and can prove each step. The insurer also remains responsible for data handled on its behalf by processors. Core operational obligations under the DPDP Rules, 2025 take effect on 13 May 2027.
Why Is DPDP Compliance Important for Insurance Companies?
Insurance draws on identity and financial details, along with nominee and health records. The DPDP Act does not create a separate category of sensitive personal data. Health and financial details often receive tighter access controls as good practice.
Data also moves between organisations. A single claim can involve a TPA, a hospital and a surveyor. Under Section 8, the insurer acts as the Data Fiduciary, the organisation that decides why and how personal data is processed. It remains responsible for processing by a Data Processor, an organisation handling data on its behalf. IRDAI's Information and Cyber Security Guidelines, 2023 apply to insurers and to intermediaries such as brokers and TPAs, and address data shared with third parties.
Section 8(3) adds a data quality duty. It requires a Data Fiduciary to ensure the completeness, accuracy and consistency of personal data that is likely to inform a decision about the individual or be disclosed to another Data Fiduciary. Underwriting and claims decisions both match that description.
What Does DPDP Ask Insurers to Manage?
Six duties shape what you need to manage. The individual whose data is processed, such as a policyholder or claimant, is called the Data Principal.
1. Notice. Section 5 and Rule 3 call for a clear, standalone notice listing the data and purposes.
2. Consent. Section 6 describes consent as free, specific, informed, unconditional and unambiguous. Withdrawal must be as easy as giving consent, and processing then stops unless the law permits it to continue.
3. Accuracy. Data used in underwriting and claims decisions needs to be complete and consistent.
4. Processor oversight. TPAs and other partners operate under the insurer's responsibility.
5. Erasure. Section 8(7) asks for erasure once consent is withdrawn or the purpose is served, unless the law requires retention.
6. Grievance redressal. Section 13 and Rule 14 set a maximum of 90 days for resolution.
Where Does DPDP Apply Across the Insurance Lifecycle?
The lifecycle runs in this order:
Quote → Proposal → Underwriting → Policy Issuance → Servicing → Renewal → Claim → Settlement → Retention and Deletion
1. Quote Stage: What Data Is Collected Before Purchase?
A quote needs limited data, such as contact details and the asset or person to be insured. Your quote journey can treat data required for the requested quote separately from optional data used for marketing. Follow-up promotions call for a separate consent request, and abandoned quotes need a defined retention period.
2. Proposal and Application: Aligning Forms With Purposes
Proposal forms collect KYC records and declarations, along with medical and nominee details. A single blanket consent covering underwriting, marketing and partner sharing gives the customer limited clarity. Separate purposes let customers make specific choices, which matches the standard in Section 6. Reviewing your proposal forms against product-level purposes is a useful first step. Notices can be offered in English or any Eighth Schedule language.
3. Underwriting: How Does DPDP Affect Insurance Underwriting?
DPDP affects underwriting mainly through purpose clarity and data accuracy. Your underwriting workflows should retain the source and verification trail for data used in risk decisions, with a correction process that updates every connected system.
4. Policy Issuance: Creating the Consent and Data Record
Policy issuance creates the richest customer record an insurer holds. A consent evidence trail links the customer, purpose, notice version, consent action and timestamp with the channel and receiving systems. Section 6 places the burden of proof on the Data Fiduciary, so this trail lets the insurer demonstrate notice and consent on request.
5. Policy Servicing: Consent as a Continuing Status
Address changes and service requests generate new data and may need their own purpose and notice.
Consent is a status that can change at any moment. Your servicing teams work best when the current status appears in the tools they already use, so a preference given in the app or on a call updates the same record.
6. Renewal: Does an Insurer Need Fresh Consent?
The Act contains no blanket rule that every renewal requires fresh consent. You can review whether purposes, data categories or processors have changed since the last notice. Where consent is the ground, the record and withdrawal mechanism stay active across the renewal. Renewal reminders about the policy differ from cross-sell offers, which usually call for consent. Customers who consented before the Act took effect fall under Section 5(2), which asks for a notice as soon as reasonably practicable, and renewal is a natural touchpoint for it.
7. Claims: How Does DPDP Affect Data Sharing With TPAs and Hospitals?
Claims form the most complex data-sharing stage. Data can travel from the policyholder to the insurer, from there to a TPA or hospital, and on to a surveyor or repair partner.
Each party's role depends on what it does with the data. A TPA acting on the insurer's instructions is generally a Data Processor. A hospital holds its own patient records and is likely a Data Fiduciary for them. Your compliance team can document these roles for every claims partner.
A practical claims governance model should include:
• Written agreements that state the purpose and permitted use of claim data.
• Access limited to the data each partner needs for its task.
• Logs showing who accessed which records.
• A defined step for return or deletion when the claim closes.
8. Claim Settlement and Post-Claim Processing
Settlement involves payment and communication, with fraud checks where relevant. Withdrawal of consent does not require every insurance record to be deleted at once. Section 8(7) recognises retention where the law requires it, and IRDAI's Maintenance of Insurance Records Regulations, 2015 set record-keeping requirements. A retention schedule that links each record type to its legal requirement gives your teams a clear reference.
9. Retention, Erasure and Dormant Data
Expired policies and lapsed quotes remain in systems after the journey ends, as do rejected proposals and closed claims. Your teams can assign each dataset a named owner and a recorded reason for retention, with a review date. At the end of its purpose, erasure extends to processors and duplicate copies, and backups need a documented handling approach.
When Is Consent the Right Ground in the Insurance Journey?
Consent is one ground among several. Marketing messages, optional analytics and cross-selling usually call for consent. Other activities may rest on a Section 7 legitimate use or on obligations under other laws. The appropriate ground should be assessed for each insurance activity, with legal review where the applicability of a legitimate use is uncertain.
Why Is Insurance Consent Management Difficult?
Four features of your operations shape the design:
1. Multiple channels Customers reach an insurer through digital, branch and intermediary channels.
2. Multiple systems Consent status may need to appear in CRM, policy, claims and marketing tools.
3. Multiple partners Section 8 keeps the insurer responsible for partner processing, so consent states need to reach partners.
4. Changing choices A withdrawal made in the app should reach the CRM, the campaign platform and any agency database.
How Can Insurers Operationalise DPDP Consent?
A seven-step approach works well for your insurance teams:
1. Map where customer data enters the journey, from quote to claim.
2. Map the systems and partners that receive data at each stage, including TPAs and brokers.
3. Confirm the ground for each purpose, either consent or a legitimate use, with legal review.
4. Design notices and consent journeys for each product line, with purpose-specific wording.
5. Build a consent evidence layer that records the purpose and notice version, plus the timestamp and withdrawal status.
6. Propagate consent changes to internal systems and processors.
7. Link consent with retention and deletion so expired policies and closed claims follow the schedule.
Related Reading: How to implement a consent management system under the DPDP Act
How Should Consent Flow Across Insurance Systems and Partners?
Your website or app may capture a preference while the marketing, CRM, policy or partner systems continue to operate on older information. The architecture needs to connect the consent decision with every system that acts on it. Five functions work in sequence:
Capture → Store → Synchronise → Enforce → Audit
1. Capture consent at the website and app, and at agent or broker portals.
2. Store each decision centrally with its notice version and timestamp.
3. Synchronise the status to the CRM and customer data platform, and on to policy and claims systems.
4. Enforce the status at processors and partners, including TPAs.
5. Audit the full trail for review and regulator queries.
Which Consent KPIs Should Insurance Leaders Track?
These indicators give you a view of consent health. They are internal management measures with no statutory status, and they fall into three groups.
Governance
• Consent coverage: the share of processing purposes mapped to a valid ground.
• Processor enforcement coverage: the share of partners and systems receiving the current consent status.
Operations
• Withdrawal propagation time: the time a withdrawal takes to reach downstream systems.
• Evidence completeness: the share of consent records holding all required evidence fields.
Customer
• Consent capture rate: the share of consent requests that receive an affirmative response.
Related Reading: Consent management for Indian fintech and BFSI companies under DPDPA
DPDP for Insurance: A Readiness Checklist
Use this list to review your current position.
• Data inventory and purposes mapped for each lifecycle stage.
• Roles of brokers, TPAs and claims partners documented.
• Withdrawal available through every channel and reflected in connected systems.
• Retention periods and deletion workflows defined, including dormant quotes.
• Grievance process aligned to the 90-day maximum.
How OneConsent Supports Consent Across the Insurance Lifecycle
For insurers, the consent task is to make the same customer decision available and enforced across every system and partner in the policy lifecycle. OneConsent is a DPDPA-native consent management platform that provides this consent layer. It supports purpose-based consent and notice management, with time-stamped evidence and audit trails. Consent Sync Hub passes consent signals to connected applications such as the CRM and policy systems, and the Third-Party Governance Platform maps purposes to vendors such as TPAs and service partners.
A Consent Manager registered with the Data Protection Board under Rule 4 is a separate regulated entity. Those provisions take effect on 13 November 2026.
Conclusion: DPDP Readiness Is a Lifecycle and Systems Discipline
DPDP readiness for an insurer continues after consent is captured. The real test is whether the customer's decision remains visible, enforceable and auditable as data moves across underwriting, servicing, claims and third-party systems. Mapping this journey early gives you clarity on the ground for each activity, the partners involved and the point at which retention ends.
Build a DPDP-Ready Consent Layer for Your Insurance Data Lifecycle
Your policy and claims teams can work from one consent record, with purposes, notices and evidence in one place.
See how OneConsent supports consent across insurance journeys & book a demo.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.