DPDP Rules status: compliance window active. Read the update

Skip to content
Sector Rules · IRDAI

IRDAI — Insurance Data and Cybersecurity Rules

Insurers and insurtech platforms operate under IRDAI's data governance expectations alongside SPDI Rules 2011 and DPDP. Health data is among the most sensitive categories in India.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

Data-handling expectations

  • Data minimisation — collect only what underwriting requires.
  • Explicit written consent before collecting health information.
  • No repurposing of health data across products without fresh consent.

Information and Cyber Security Guidelines

  • An information security policy that the Board signs off on.
  • Annual security audits.
  • 6-hour incident reporting, aligned with CERT-In.
  • Pass-through security obligations on IT vendors and outsourced partners.

In plain English: if you handle health data through an insurer or insurtech, three rulebooks watch you at once. They are IRDAI, the SPDI Rules, and DPDP. Build once for the strictest of the three.

Educational only — not legal advice

For binding obligations on a specific policy or product, consult qualified counsel. Also check the IRDAI source below.

Reporting a cyber incident: six hours

On 24 March 2025 IRDAI added incident and crisis rules to its 2023 Guidelines.

This applies if you are an insurer or a licensed intermediary. That includes:

  • Brokers.
  • Corporate agents.
  • Insurance marketing firms.
  • Web aggregators.

You must report a cyber incident within six hours of spotting it. You report it twice: once to IRDAI, and once to CERT-In.

That is the same six-hour clock CERT-In already sets for everyone else. The insurance rule sits on top of it, not instead of it.

How government breach-response reporting works

Source
IRDAI — Information and Cyber Security Guidelines, 2023

Issued 24 April 2023. Supersedes the 2017 Guidelines and the circulars of 29 December 2020, 2 September 2022 and 11 October 2022.

Quick self-check

Am I a Data Fiduciary?

Sector rules sit on top of DPDP, not instead of it. Run the self-check to confirm your baseline DPDP status first.

Run it now