Regulation & Compliance

The DPDP Act and the Advisor's Client Data: What Your Principal Will Push Down to You

Nobody has authoritatively said what an individual insurance advisor is under the DPDP Act. What is certain is the calendar: November 2026 for enforcement powers, May 2027 for the substantive provisions. Between now and then, the obligations reach you not from the regulator but through your engagement contract.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
10 min read

Listen to this article

Audio version • 10 min read

pospdpdpclient-dataconsentdata-retentionadvisor-operationsregulation-compliance

Last reviewed: July 2026

Three Dates, and Where July 2026 Sits Between Them

The calendar is the settled part, so start there.

MeitY notifications of 14 November 2025 brought both the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 into force, on staggered timelines. Three phases:

  1. 14 November 2025. Foundational provisions commence and the Data Protection Board of India is formally established.
  2. 14 November 2026. Enforcement powers and the penalty framework commence, along with registration of Consent Managers.
  3. 14 May 2027. The substantive provisions come into force, ending the eighteen month transition.

The Act's maximum penalty runs to INR 250 crore for major violations.

As of July 2026 the market sits inside the transition window, between the first and second dates. Commentary calls this period "soft enforcement," and the phrase needs care: it is a practitioner characterisation, not a statutory term and not a concession written anywhere. What it reflects is that the Board exists but its enforcement powers have not commenced, and that November 2026 is widely expected to mark the shift from awareness-building toward active supervision.

For an individual advisor, what happens between those dates matters more than the dates. Insurers and intermediaries are spending this window building their own posture, and they will not leave the last hundred metres of the data path, which is you, standing outside it. The obligations will reach your book. The question is by what route.

The Role Question Nobody Has Answered for You

Be clear about this first, because a great deal of confident writing on the topic is not.

The DPDP Act imposes its obligations on the data fiduciary, the person who determines the purpose and means of processing personal data. For a POSP or a tied agent, the entity determining purpose and means is realistically the insurer or the intermediary that engages you. You collect a proposal form because their product requires it, in the format they specify, for submission to them. You act on their behalf.

That is the sensible reading. It is not an authoritatively settled one.

Three things follow, each contradicting something an advisor has probably been told:

  • Do not assume you are a data fiduciary in your own right, and be sceptical of anyone selling you a compliance product on that premise.
  • A Consent Manager is a distinct registered entity whose registration commences in November 2026, sitting between individuals and fiduciaries to let people give and withdraw consent in one place. It is not a hat an advisor puts on. Anyone telling you a POSP must register as one has misread the Act.
  • The INR 250 crore ceiling is not pointed at you personally. It is the Act's maximum for major violations by those the Act penalises. It appears here only because it explains the intensity of what your principal is about to do.

The unsettledness is not a reason to wait. It is a reason to look somewhere other than the statute for what changes in your working week.

The Contract Is the Transmission Belt

An entity carrying an exposure it cannot discharge alone pushes the obligation down its distribution chain by contract, before its own deadline rather than on it.

This is the mechanism that already governs your relationship with your principal. A POSP is remunerated by the entity that engages them, under the contract of engagement. That contract already carries undertakings on truthful and prompt submission of KYC documentation and declarations, prior approval of anything you publish, and termination at the principal's discretion. It is the instrument through which your principal's regulatory life becomes your operational life.

DPDP will travel down the same wire. What arrives will look like an addendum, probably a link with a deadline attached, sometime before the middle of 2027. Expect four things:

  • Consent: what you may collect, on what basis, and what you must show the client first.
  • Purpose limitation: what you may do with it.
  • Retention: how long you may keep it and what happens when that ends.
  • Breach notification: what you tell your principal, and how fast, when something goes wrong.

The rest of this post takes those four in order, because each collides with a habit most individual advisor books are built on. None are predictions about the Act. They are predictions about your engagement terms, a safer thing to predict, because the drafting incentive runs one way. The principal holds the exposure. The principal writes the clause.

Consent, and the Notice You Did Not Write

Consent under the DPDP framework is not a signature at the bottom of a form. It attaches to a notice: the individual must be told, in plain terms, what data is collected and why, before agreeing.

An advisor does not write that notice. Your principal does, because your principal's purposes are what it describes. What lands on you is narrower and more awkward: you become the person who delivers it, at a kitchen table, in the language the household speaks, at the moment they are sending you a photograph of an Aadhaar card on WhatsApp because you asked.

That moment is where the habits break. The near-universal ones:

  • The client sends documents on WhatsApp. They live in your phone's gallery, backed up to a cloud account that is yours, mixed with photographs of your family.
  • You collect the whole family's KYC in one sitting for a floater, including members who never spoke to you.
  • You ask for documents "to check what is possible" before any proposal exists, so the purpose at collection is undefined.
  • You keep a prospect's details after they decline, in case they return next year.

Each is ordinary practice. Each sits badly with a consent-and-notice model, and each will be addressed in an addendum you are asked to sign.

The expensive one is the third. Speculative collection is the deepest habit in the channel, because the rhythm of advisory work is to gather first and find the product afterwards. If your principal's notice describes collection for a specific proposal, then documents collected before any proposal exists were collected outside the notice. This will not be resolved by you being careful. It will be resolved by your principal giving you a defined moment at which collection may begin.

Do not try to solve this by writing your own consent language. A notice describes the fiduciary's purposes, and you are not in a position to state those. An advisor-drafted notice contradicts your principal's, which is worse than having none.

Purpose Limitation and Retention, the Two That Change Your Week

Purpose limitation says data collected for one purpose is not available for another. Retention says you do not keep it after the purpose ends. Together they do the most damage to how an individual book runs, because an advisor's competitive advantage is built on holding things.

Purpose limitation. Three practices in a normal advisor's week sit in its path:

  1. Cross-selling from KYC. You collected dates of birth for a health floater. Six months later those dates tell you a term plan is about to get more expensive for the husband. Good advice, and also a use of data collected for a different purpose.
  2. Forwarding. A client's policy PDF sent to a colleague to ask what an add-on means. Ordinary, helpful, and a disclosure to a third party the client never heard of.
  3. The referral chain. A household gives you a cousin's number. You now hold the cousin's personal data, collected from someone who was not the cousin, for a purpose the cousin has not been told.

Retention. How long may you keep it? Resist the two wrong answers: inventing a period of your own, or transplanting one from somewhere adjacent because it is the only number you know. The POSP framework does carry a five year retention requirement, and it attaches to training and examination records, which the engaging entity must retain for at least five years. That is a real rule about a real category. It says nothing about client KYC, and moving it across is the kind of confident error that survives for years because it sounds specific.

The correct answer: the retention period on client data is your principal's to set, because the purpose is theirs. Have it in writing from them, not in your head from an article.

What you can do now, without waiting for anybody: know what you are holding. Most advisors cannot answer that. The data is spread across a phone gallery, a personal email account, a spreadsheet, a drawer of photocopies and four years of chat threads. A retention instruction is unexecutable against that. When the clause arrives saying delete on request or after N years, the advisor with one place where client documents live complies in an afternoon. The advisor without one will either lie or spend a month on it.

Breach Notification, the Clause With a Clock on It

Of everything coming down the contract, this is the one advisors have thought about least and that behaves worst.

A breach obligation runs on a clock. The fiduciary has to notify. To notify, it has to know. To know, it depends on the person at the point of loss telling it. For a book placed through individual advisors, the point of loss is very often an advisor's phone.

So expect a clause requiring you to report to your principal, immediately and by a named route, any loss, theft or unauthorised access affecting client data in your possession. Then consider events an advisor now treats as annoyances rather than incidents:

  • A stolen or lost phone with four years of client documents in the gallery.
  • A WhatsApp account taken over, common enough in India to be a standing risk rather than a hypothetical.
  • A policy PDF sent to the wrong client, which happens most weeks in most books, and is a disclosure of one person's personal data to another.
  • A junior assistant, unnamed to your principal and unknown to your clients, who has your login and does your data entry.

The third is the interesting case, because every advisor has done it and nobody has reported it. Under a notification clause, sending household A's policy schedule to household B is not a fumble to be quietly recalled. It is an event with a reporting duty attached.

What an Advisor Can Actually Do Before November 2026

None of this requires waiting for the role question to be settled, and none of it requires buying anything. Five things, in the order they pay off.

  1. Ask your principal, in writing, three questions. What is your consent notice and in which languages? What is the retention rule for client documents I hold? By what route do I report an incident? Your principal must be able to answer these, since it holds the fiduciary exposure. If it cannot today, the answers are being written, and having asked puts you on the list to receive them rather than the list to be audited.
  2. Put client documents in one place. Not a better place. One place. The number of surfaces holding client personal data decides whether any future instruction is executable. A phone gallery that also holds your family photographs is not a place, it is a leak with a passcode.
  3. Stop speculative collection. Ask for a document when there is a proposal it belongs to. This habit will cost the most to break and be hardest to defend once a notice exists.
  4. Separate work from personal. A separate number for the practice, a separate account for the documents, a separate device if the book justifies it. The mixing is why a lost phone becomes an incident with no boundary around it.
  5. Record what you collected, from whom, and when you passed it on. A field per document with a date, on the household record, rather than a folder of images named by timestamp. Consent is individual, so the member who handed the papers over matters: a floater covering four people whose documents came from one of them is the shape of the problem, and that record is the only thing that lets anyone reconstruct it.

Every item is worth doing on operational grounds alone, which is the test to apply to any DPDP advice aimed at individual advisors between now and May 2027. The role allocation for advisors is genuinely unsettled. The value of knowing what you hold, and where, and for whom, is not.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

Is an individual insurance advisor a data fiduciary under the DPDP Act?
That has not been authoritatively settled. The DPDP Act imposes obligations on the data fiduciary, the person determining the purpose and means of processing, and for a POSP or tied agent that is realistically the insurer or intermediary that engages them. No source located allocates DPDP roles across the insurer to intermediary to advisor chain, and IRDAI has issued no guidance specific to point of sales persons on the Act. The workable reading is that the advisor handles client personal data on behalf of the engaging entity, and the practical obligations will arrive through the engagement contract.
What are the DPDP dates an advisor should have in the diary?
Three. MeitY notifications of 14 November 2025 brought the Act and the DPDP Rules 2025 into force on staggered timelines. Foundational provisions commenced on 14 November 2025 and the Data Protection Board of India was established. Enforcement powers, the penalty framework and Consent Manager registration commence on 14 November 2026. The substantive provisions commence on 14 May 2027, ending the eighteen month transition. July 2026 sits between the first and second dates, which is why contract addenda are the thing to expect next rather than enforcement.
How long may an advisor keep a client's KYC documents?
Ask your principal and get the answer in writing. The retention period follows the purpose, and the purpose belongs to the insurer or intermediary that engages you. Do not invent a period, and do not borrow the five year figure that appears in the POSP framework, which attaches to training and examination records held by the engaging entity and says nothing about client KYC. What an advisor can do now is know exactly what they hold and where, since no retention instruction is executable against documents spread over a phone gallery, an email account and a drawer.
Does a POSP need to register as a Consent Manager?
No. A Consent Manager under the DPDP framework is a distinct registered entity that sits between individuals and data fiduciaries, allowing people to give, manage and withdraw consent through a single interface, and its registration commences on 14 November 2026. It is not a status an individual advisor takes on in the course of selling policies. Anyone advising a POSP to register as one has misread the Act.
What should an advisor do if a phone with client documents is lost?
Report it to your principal immediately, by whatever route the engagement terms specify, and ask for the route now if they do not. The engaging entity carries the fiduciary exposure and can only act on a breach it knows about, which is why breach notification clauses are among the things to expect in a DPDP addendum. The instinct to fix it quietly is the expensive one: an incident managed under the principal's framework is their problem, while an unreported incident discovered later is a breach of your engagement terms on top of it.

Related Glossary Terms

Related Insurance Types

Related Articles

Pratibimb by Sarvada

Bring your book to Pratibimb.

Every client, policy, renewal, and rupee of commission in one place, with Pratibimb on WhatsApp handling the follow-through.

Open Pratibimb