IRDAI — Insurance Data and Cybersecurity Rules
Insurers and insurtech platforms operate under IRDAI's data governance expectations alongside SPDI Rules 2011 and DPDP. Health data is among the most sensitive categories in India.
Data-handling expectations
- Data minimisation — collect only what underwriting requires.
- Explicit written consent before collecting health information.
- No repurposing of health data across products without fresh consent.
Information and Cyber Security Guidelines
- An information security policy that the Board signs off on.
- Annual security audits.
- 6-hour incident reporting, aligned with CERT-In.
- Pass-through security obligations on IT vendors and outsourced partners.
In plain English: if you handle health data through an insurer or insurtech, three rulebooks watch you at once. They are IRDAI, the SPDI Rules, and DPDP. Build once for the strictest of the three.
For binding obligations on a specific policy or product, consult qualified counsel. Also check the IRDAI source below.
Reporting a cyber incident: six hours
On 24 March 2025 IRDAI added incident and crisis rules to its 2023 Guidelines.
This applies if you are an insurer or a licensed intermediary. That includes:
- Brokers.
- Corporate agents.
- Insurance marketing firms.
- Web aggregators.
You must report a cyber incident within six hours of spotting it. You report it twice: once to IRDAI, and once to CERT-In.
That is the same six-hour clock CERT-In already sets for everyone else. The insurance rule sits on top of it, not instead of it.
Issued 24 April 2023. Supersedes the 2017 Guidelines and the circulars of 29 December 2020, 2 September 2022 and 11 October 2022.
Am I a Data Fiduciary?
Sector rules sit on top of DPDP, not instead of it. Run the self-check to confirm your baseline DPDP status first.
Run it now