Confidential Dispatch
At a glance

Insurance intermediaries handle the rarest and riskiest data combination in ordinary commerce: health records and financial details, in the same client file. Under India’s DPDP Act a broker or agent is a Data Fiduciary in their own right — your insurer’s compliance doesn’t cover your files — and the sharpest duties land on the health layer: proposal-form disclosures and claims documents that reveal diagnoses, sent onward only where the policy genuinely requires. IRDAI-mandated records keep their statutory footing; the renewal-pitch habits built on old claims data don’t.

Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to insurance brokers, agents and intermediaries; it is not formal legal advice.

The situation

Every policy begins with disclosure: the proposal form asks about illnesses, surgeries, medications, family medical history — then staples them to income proofs, KYC and nominee details. Every claim adds discharge summaries and diagnostic reports. This data moves through the trade the way everything moves in India — WhatsApp to the insurer’s contact, photos of proposal forms, claims papers in a chat with the hospital desk — and it sits with intermediaries for years because renewals reward long memories. A leaked bank statement costs a client money; a leaked health disclosure costs them insurability, employability and privacy at once. That asymmetry is why this sector’s data discipline matters more than its size suggests.

Does DPDP apply to a broking or agency practice?

Yes — broker, corporate agent, individual agent or point-of-sale person: deciding why and how client data is used makes you a Data Fiduciary, separate from the insurer. The instinct that “the insurer handles compliance” fails at the file level: the copies on your phone, your agency’s shared drive and your assistant’s laptop are your processing, under your duties — notice, lawful basis, security, breach reporting, retention limits. The insurer is a fiduciary for its records; you’re one for yours; and where a platform or aggregator sits between you, it carries its own role too. Every hop in the chain owns its copy — which is exactly why the chain’s weakest phone is the sector’s real exposure.

The client data an insurance intermediary actually holds

Health, wealth, identity and family — the full sensitivity stack, per client.

  • Proposal-stage — the health questionnaire (conditions, medications, surgeries, family history, lifestyle declarations), income proofs for sum-assured justification, KYC documents, nominee details.
  • Policy-stage — policy schedules, premium and payment records, bank mandates.
  • Claims-stage — discharge summaries, diagnostic reports, bills, death certificates and legal heirs’ documents on life claims: the deepest health and family data in the file.
  • The book — renewal dates, claims histories, health conditions across your whole client base: the working asset of the practice, and a profiling database by any other name.
  • Third parties throughout — nominees, family members in medical histories, legal heirs: people who never signed your forms but live in your files.

The obligation that actually bites: the health layer

Health disclosures are collected under the shadow of claim-rejection — clients reveal everything because non-disclosure voids policies — which makes what happens to that candour your sharpest duty. The proposal form extracts honesty no doctor gets; the DPDP Act’s purpose-binding decides what that honesty may lawfully feed:

  1. Underwriting data flows to underwriting. The health questionnaire goes to the insurer assessing the risk — that’s its purpose. It doesn’t become the agency’s reference file for pitching top-ups, loadings or “better suited” products across the book without a separate consent.
  2. Claims files are the claim’s. Discharge summaries collected to process one claim don’t season the renewal conversation, the cross-sell list, or the anecdote told to another client — a claims history is a diagnosis trail.
  3. Family history is other people’s data. The parent’s cardiac history on a proposal form is a third party’s health data in your file; it exists for underwriting, and nothing else.
  4. The book is a profile database. Renewal lists annotated with conditions and claims are exactly the “profile of health behaviour at scale” that draws regulatory attention — handle the book like the health database it is: access-controlled, minimal, purpose-bound.

Where DPDP sits alongside IRDAI’s rules

IRDAI already binds intermediaries to conduct, confidentiality and record-keeping — the DPDP Act adds the data regulator, the client’s enforceable rights, and coverage of your practice beyond the regulated transactions. Licensing under the Insurance Regulatory and Development Authority of India (IRDAI) brings codes of conduct that include policyholder confidentiality, and record-maintenance expectations that keep transaction records for their mandated periods — retention that rests comfortably on the DPDP Act’s legal-obligation ground (Section 7). The familiar split follows: mandated records stay for their statutory periods, each hold traceable to the rule; everything beyond the mandate — the WhatsApp claim threads, the annotated renewal book, the lapsed-prospect pile — follows purpose and erasure. What the Act adds across all of it: the Data Protection Board as a second regulator, client rights (access, correction, erasure of the unmandated), breach notification duties on your files (not just the insurer’s), and vendor accountability for the platforms and TPAs (third-party administrators) in your workflow. A cyber-incident can additionally trigger the IT Act’s CERT-In cyber-incident reporting — parallel clocks.

Common mistakes insurance intermediaries make

Renewal-economy habits meeting health-grade data.

  • Claims papers on WhatsApp — discharge summaries and reports moving through personal chats between client, agent and insurer contact, persisting in every gallery and backup on the route.
  • The annotated book — client lists carrying conditions and claims histories as sales intelligence, uncontrolled and unconsented.
  • Cross-sell on disclosures — health and income data from proposals driving pitches for other products, with no separate consent.
  • The immortal proposal file — lapsed policies’ and rejected proposals’ full document sets kept forever “in case they come back.”
  • Family data as furniture — nominees’ and relatives’ details collected and held with no notice to them and no thought after.
  • “The insurer’s compliance covers me” — the chain’s most expensive assumption; your copies are your liability.

Collecting proposal and claims documents compliantly

One controlled channel, health data handled like the medical records it is, and a book that isn’t annotated into a liability. Proposal and claims documents flow through the insurer’s official intake or your agency’s controlled channel — not personal chats; the health layer gets medical-grade handling (protected files, minimal copies, no group threads); the ask names each document and its purpose; and renewals run on policy data, not on a conditions-annotated client list. The intake mechanics are the professional standard — see secure client document collection for professionals — and your clients are reading the medical-reports guide, which tells them to expect exactly this. The intermediary who can honestly say “your health disclosure goes to the underwriter and nowhere else” is selling trust in a trust product.

FAQ

I’m an individual agent — isn’t data compliance the insurer’s job?

The insurer answers for its systems; you answer for your copies — the proposal photos on your phone, the claims threads, your renewal book. Deciding how that data is used makes you a Data Fiduciary in your own right.

Can I use clients’ health and income disclosures to recommend other products?

Recommending within an engagement is one thing; using proposal disclosures as a cross-sell targeting layer needs its own specific consent. The health questionnaire was answered for underwriting — that’s its purpose.

How long can I keep proposal and claims documents?

IRDAI-linked record requirements keep mandated records for their periods — a legal-obligation ground. Beyond the mandate, purpose-and-erasure applies: lapsed proposals, settled claims’ working copies and ex-client files need a schedule, not a shelf.

What about nominees’ and family members’ details in my files?

They’re Data Principals too — their data exists in your file for the policy’s purposes only. Family medical history from proposal forms is the strictest case: third-party health data, held for underwriting, used for nothing else.

What single change matters most for a small agency?

Get claims and proposal documents out of personal WhatsApp — one controlled channel, protected files, cleaned threads. The health layer is where a leak does the most human damage, and the chat default is where it happens.

Reviewed by Confidential Dispatch Editorial Team
Last updated 19 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →