Round Table
undefined

Insurance CXO Privacy Discussion

Elevating Enterprise Privacy Programmes for Insurers

A Discussion Reshaping Privacy Implementation

The DPDP Act reshapes how insurers handle customer data from lead generation to claims. For a risk-driven industry, this calls for a clear shift to privacy-first practices to avoid regulatory scrutiny.

In this discussion, prominent leaders from the insurance sector examined the challenges posed by the DPDPA and the path to compliance for insurers.

Speakers
Ashish Sahni

Ashish Sahni

Chief Technology Officer

IDfy

Paritosh Desai

Paritosh Desai

Chief Product & Marketing Officer

IDfy

Malcolm Gomes

Malcolm Gomes

COO

IDfy

Harsh Khemka

Harsh Khemka

Partner

Khaitan & Co.

Supratim Chakraborty

Supratim Chakraborty

Partner

Khaitan & Co.

Participants

Operationalising Privacy for Trust

Given the scale of personal data insurers handle, compliance requires an organisational reset. A focused, three-pillar approach can simplify this journey while turning privacy into a driver of trust and growth.

Consent Lifecycle Management: Modernise consent collection with verifiable digital workflows, purpose-specific notices, and trust-building checks at critical stages.

Personal Data Governance: Implement smart data erasure to balance data principals' deletion rights with IRDAI retention requirements. Ensure consent withdrawal for one function doesn't disrupt valid policies or claims.

Third-Party Risk Management & Continuous Compliance

  • Apply risk-based controls on TPAs and medical partners to prevent secondary use of health data.
  • Balance legacy consent remediation with strict digital-first compliance for new policies.
  • Provide DPOs with real-time visibility into data lineage to meet Data Protection Board requirements.


Key Takeaways

  • Privacy is the New Trust Engine:
    Embedding privacy into customer journeys is a strategic differentiator that builds the long-term trust required for high-value customer retention.
  • Regulatory Agility:
    Success requires harmonising DPDPA with sectoral regulation of IRDAI, ensuring a flexible data architecture that satisfies conflicting and evolving mandates.