DPDP NavigatorAct 2023 · Rules 2025
All guides
Sector Deep Dives

DPDP Compliance for Insurance Companies: Underwriting Data and Claims

27 Jul 202610 min read

Underwriting runs on medical and financial history, and claims investigations pull in hospitals, surveyors and reinsurers — each link needs its own basis.

Proposal forms collect data that determines a price

A life or health insurance proposal form typically asks for medical history, family health background, income details, and lifestyle habits, all of which directly determine whether cover is offered and at what premium. Because this data feeds a decision that materially affects the applicant, the accuracy obligation under Section 8(3) is not a formality here — a proposer who later disputes a loading or exclusion based on a data entry error has a legitimate basis to seek correction under Section 12.

Insurers often supplement self-declared proposal data with third-party medical tests, pre-policy check-up reports from empanelled labs, and sometimes data from insurance information bureaus. Each of those sources is a separate collection point requiring its own notice line, since a proposer consenting to “fill in a form” has not necessarily understood that a lab report will be pulled independently.

Claims investigation widens the circle sharply

A contested claim brings in hospital records, treating-doctor statements, independent medical examiners, and sometimes private investigators or surveyors, all reviewing what is often the claimant's most sensitive personal data at the exact moment they are least able to negotiate around it. The insurer's notice and claims documentation should be explicit that investigation may involve these additional parties, since claimants rarely expect a surveyor to visit a hospital independently of them.

Reinsurance arrangements mean large claims data sometimes moves to a reinsurer as well, often across borders — which brings Section 16's cross-border transfer restrictions into play alongside the ordinary processor-contract requirements for domestic claims vendors.

Rejected claims and the grievance pathway

A rejected claim is frequently the moment a policyholder first engages seriously with how their data was used, since the rejection reasoning often cites a specific data point — a pre-existing condition not disclosed, a discrepancy in the proposal form. Section 13's grievance redressal right means the insurer's internal grievance mechanism needs to meaningfully address disputes about the data underlying a rejection, not just the coverage decision itself, before a complainant escalates to the Board.

Where an insurer is notified as a Significant Data Fiduciary given the scale of sensitive data it holds, the periodic data protection impact assessment under Section 10 is a natural place to specifically review how claims-rejection data flows are documented and how consistently the accuracy duty is being met across regional offices and third-party administrators.

Where to go next

The Obligation Finder can help separate what underwriting data collection relies on consent versus what claims investigation can proceed under without fresh consent at each step. A Vendor Assessment covering empanelled labs, surveyors, and third-party administrators is also worth running, since claims data touches more external parties than most people initially assume.