The DPDP Audit Tool
Compliance for InsurTech
🛡️
InsurTech
Liability Check
💊
InsurTech companies process health records, income data, and nominees' details — all sensitive personal data requiring the highest security standards.
Why InsurTech is at Risk
Insurance involves deeply sensitive data: medical histories, income declarations, nominee details, and claim records. Under DPDP 2023, processing this data requires specific, informed consent for each purpose. You cannot use health data collected for underwriting to send marketing offers for other products without separate consent.
Common Violations
- 1.Bundling consent — single checkbox covers underwriting, marketing, and third-party sharing.
- 2.Sharing policyholder medical data with reinsurers without transparent disclosure.
- 3.Retaining claim investigation data (including surveillance footage) indefinitely.
The Immediate Fix
Implement **unbundled consent** — separate checkboxes for underwriting, marketing, and third-party sharing. Encrypt all medical data at rest and in transit. Set retention limits for claim data.
Projected Compliance Deadline: Immediate